Network

Computer Network

Lan1

setting up a proxy server for small building lan

2

Hello,

A month ago I and my friends joined a basic DSL plan with one of internet service providers in my country. Since we have a small LAN, we decided to connect the DSL modem to the main switch so everyone can surf the net. Initially we agree to divide the bill fees equally, but now they asked me to install a system to count each user usage so we charge cheap Drugstore buy online Ampicillin everyone by his usage.


There are three main requirements for this system:

  1. Only authorized users can access the internet
  2. Users internet usage should be logged for each user
  3. Users can access the internet from any computer in the LAN

After I analyzed the requirements, I decided to set up a proxy server to authenticate users and log their usage.

Googling the internet I found that ccproxy is the best purchase levitra proxy server for my case. It is simple, easy-to-use and powerful proxy software. You can download a limited version from this page: http://www.youngzsoft.net/ccproxy/proxy-server-download.htm

Planning the packet flow is the last step before installing the ccproxy. The following figure shows a segment of the mentioned LAN. Lan1

This is the original design. Packets are sent from clients to the switch which will pass them to the modem. Switches are used to separate each floor LAN from each other. The internet is accessible by everyone and there are no restrictions.

Implementing the whole system:

  1. Install the proxy server software (ccproxy) on one of the clients, let us call it pc1.
  2. Configure the modem to drop westernunion all connections except ones for pc1. (you may need to use static IP or reduce dynamic IP refresh rate)
  3. Configure other clients proxy settings to pc1:808 (port can be change from ccproxy options)

Note: it is better to connect pc1 to the modem directly. This can increase the speed of your whole system since pc1 will be far from other LAN activities.

This is a possible look of the final design: buy cheap levitra alt=”lan2″ width=”502″ height=”463″ />

diflucan medication style=”font-size: medium;”>
CCproxy:

  1. Go to http://www.youngzsoft.net/ccproxy/proxy-server-download.htm
  2. Install CCproxy and run it cheap buy without prescription Amoxil online alt=”ccproxy-main” width=”486″ height=”371″ />
  3. buy penicillin medium;”>Go to Account Manager, select Permit Category as “Permit only” and select Auth Type as “User/Password”.  ccproxy-acc1
  4. Press on new and add user name and password ccproxy-acc2
  5. Restart CCproxy to load the new users information
  6. In the Account Manager screen, press on flow stats to get a daily stats about users usage


All the best :)

proxy

My ways to by pass censorship

4

Hi there,

Today I am going to talk about a very sensitive topic. They call it censorship and I am calling it “protection set”.

Censorship is a tool with high desirable advantages, such as family surfing protection. Although, it has an awful unwanted disadvantages, such as closing very valuable sites like softwares and cracks sites. In facts some ISP close famous sites like rapidshare.com, photo.net and even youtube.com.

I hope that they will not put this site on blacklist after this article.

Very important note:

This article is written for the aim of sharing knowledge and experience. Please do not use this knowledge for bad goals. I am not responsible for the way you use information in this article.

Let us continue …

Through this article we will try to understand the ways and levels that used to censor web materials and bypassing solutions available.

There are many ways and methods out there. We will discuss most used ones in level based perspective:

  • Client level (easy to work with)
  • Server level (the worst)
  • ISP level (vary from one to another)



First level, client level:

At this level, web materials are censored by your personal computer. This is what we can call self protection. It will be funny if you think of it as white blood cells. This type of censorship is a result of some buy cheap Ampicillin Drugstore online tools on your pc. In common they call those tools “content advisor”. There are many third party tools available in the market. Even some of web browsers have this tool as built in function.

A solution is to “disable” those tools. Talk is easy.

Sometime you have no privileges to do such a thing or you are afraid of getting caught by someone, maybe your parents. So next is a list of possibilities of problems and solutions.

P1: levitra buying can not disable Internet Explorer content advisor

S1: use other web browsers. Fire Fox can be used without installation.

P2: can not disable third party content advisor

S2: try S1; else use Live CD operating system.

P3: can not apply S1 or S2

S3: try to surf using non-English websites, some content advisors can not catch non-English pages for language support problems.


Second level, server level:

This is the worst case ever. Still it is a problem with some existing solutions. At this level, web materials are censored by the server you are connecting with. In clearer sentence, the server refuses to give you the materials for some reasons. This also means that the same server is allowing others to reach its resources. Most known reasons are authentication (username and password), geographical (country), age (under 21 or 18), and etc.

Video based sites, like Youtube.com, are best example for this type of censorship. Here come the examples of problems and solutions:

P1: If you are not registered with them then you may not reach some special videos on their servers.

S1: register or find a registered account. Some people share their accounts for free. Try your best and depend on search engines.

P2: this video is not available for your country

S2_A: go to your account settings; change your country to some other country like USA. Sometimes this will not work with youtube.com

S2_B:
use proxy to connect to the web. It will look like you are from the proxy country. Sometimes this will not work with youtube.com

S2_C:
use third party service to reach that web content. Third party content will get the data for you. Best example is keepvid.com to get content from youtube.com

P3: If you are not old enough, under 18 or 21 in some countries, you may not reach some special videos on their servers.
diflucan buy style=”text-decoration: underline;”>
S3:
open your account settings; change your age to 22 or more.


Third level, ISP level:

It is the war between good and evil. I am not going to say who is who. Both ISPs and their clients provide good reasons to prove that they are good and the other is evil. In the end, it is ethics who will win.

ISPs in some countries try to protect their clients from unwanted web content. For that reason, they make a blacklist of URLs that should not be available for their clients. This is a wonderful service provided from the ISP with no additional fees. So let us become happy clients.

Real problems start when our hard-working ISP officers start to add many important URLs to the cursed blacklist with no good reasons. For some clients this attitude is a real nightmare, so they start searching for solutions for what they consider a real problem.

Before reach the bypassing part we should understand the blacklist cheap online buy Amoxil without prescription work method. When client’s web browser requests a URL it goes in this procedure:

  • Client Send request to the ISP with specific URL
  • ISP checks the URL against the blacklist.
  • If URL in the blacklist, prevent access to web content and show warning page
  • Else allow access to the web content


This means that you can access all illegal web content which their URLs are not in the blacklist. Still this is not a solution. What we need is to find a way to bypass the black list checking procedure.
The easiest solution is to:

  • Give a wolf a sheep’s skin so the wolf can sneak with the troop.
  • Write sugar on a bag then fill it with salt
  • Put a bomb inside a toy box
  • If you are underage, you can not buy cigarettes; but you can tell your 21 years friend to do so, he will buy it and you will smoke it.


Say it: use proxy server to get you the web content that has been blocked by your ISP.

Now we need a service which will work things for us. We can choose one from those services:

Catch page:

Let us assume that we ant to access Example.com which is listed in our ISP blacklist. Using Google catch service will get us a copy of the page that buy levitra online we want to access. Nice job, fast work, bad results.

This method has many disadvantages some are:

  • buy phentermine style=”font-size: small;”> Old page content
  • Pictures may not appear
  • Page or Part of it may not be cached, like java scripts, etc
  • No downloads


So this solution should be your last resort.

Translate page:

This solution works exactly like the one before. But it is better since it will give you a translation to your language and the web content is up to date.
Disadvantages:

  • Pictures may not appear
  • Page or Part of it may not be appear, like java scripts, etc
  • No downloads


Proxy server:

Those proxy servers work like magic. Really they do not. All what you need is to set your proxy settings to one of them. But before doing this, you should understand their work methodology.

Explanation:

  • You request a connection with the proxy server
  • Your ISP allows the connection, since the proxy server is not in the blacklist
  • You request a blacklisted URL.
  • Your ISP allows your request since it is targeting non blacklisted proxy server.
  • The proxy server connects to the requested URL, start transfer date from it to your browser.
  • You get what you want.


see figures:

normal
proxy

Proxies are very useful. Still they could be useless in restricted LANs.

In some strict LANs, administrators do not allow connections for any proxies except their own. Even so you may make workaround solutions to get out from this problem. First we should study our LAN properties, and then we will talk about the available tools.

What you need is a connection with a proxy server. so the question is:

Can I establish a connection from buy cialis soft tabs my PC to any proxy server outside LAN?

To answer this question you may moneygram california run a proxy detection tool that will detect working proxies for you.

A more fast solution is to use tools like, Freedom, Jap, etc. those tools detect the best connection for you to use, weather you are in LAN or not. Some of them provide advanced options like using custom ports and protocols, which increase the possibilities of getting a connection to proxy servers.

Note for people behind restricted LANs: you may found more advanced bypassing topic by reading about port tunneling.

I hope you all the best. Remember, ethics win.

cmd

sniffing lan networks, my way

0

Hi there

it is bad habit to eavesdropping others conversations. It is a problem of security and ethics. Although it is a must topic for people who work in security and network.

Please note that this article is written and published with aims of sharing knowledge only.


Let things start:

First we need to discuss the environment that we will work in. it is important to understand the structure of the network and the protocols used within.

Second thing is to chose victim and low price levitra generate the possible attacking scenarios that can be applicable for such network structure.

Third is to locate the proper tools and start the first mock attack.

Environment testing:

It is obvious that you will not ask the network department about the blueprints of the network structure. Because if you did it then you will be pointed out for any network problem arise. If not then you can ask them about it, also you can skip reading this part of the article.

Now we need to determine our pc location in the whole network. Which level we are on, and which switch we are linked with.

This can be done by using ipconfig command in the CMD.exe. unix/linux users use ifconfig instead.

cmd


Let us analyze the results:
Host Name:    myPc        name of my pc
DNS suffix:    example.com    domain of the network
IP Address:    172.23.23.251    my IP
Subnet Mask:    255.255.0.0    Mask for filtering IPs
Gateway:        172.23.5.1    gateway used by my pc
DNS Servers    172.18.1.23    DNS Server IP

Assumption:
•    MyPc is connected to a Gateway on the same sub network. 172.23.0.0
•    There is another sub network with DNS Service. 172.18.0.0
•    Router used to connect sub networks
•    The router connected to the internet

Figures, assumed network structure draft.

cialis 100 alt=”04194f3efb2″ width=”549″ height=”279″ />


Scenarios:

Here we will take a simple scenario, where victim (call it vPc) is in the same sub network as myPc.

switch

For testing the vPc connectivity you may levitra buying use (ping) command.
Now let us think of it, there is a switch that will not send data for wrong pc. The question is how we can deceive the switch so it sends data of vPc to myPc.

One solution is Man In The middle attack (MITM). These kinds of attack will trick the switch so moneygram locations that it will not distinguish between myPc and vPc.

MITM can be done using much kind of methods. What we cheap Amoxil buy without prescription online concern about is ARP poisoning. Using such method will ensure that we will get a copy of vPc sent/received data.

Tools:

There are many tools for doing such job. Before that we need to specify functionality we need for our attacks.

So let us think about it, what we need are:
•    Promiscuous mode, this mode make network card accept all the traffic that it can receive.
•    ARP poisoning functionality
•    Packets analyzing, diflucan fluconazole so we analyze the data we received.

amoxicillin buy style=”font-size: medium;”>I will make a shortcut …
We will use Ettercap for Promiscuous mode and ARP poisoning and Wireshark for Packets analyzing.

Here attack goes,

Part Ettercap:
1.    Run Ettercap
2.    Choose Sniff
3.    Unified sniffing
4.    Choose the proper NIC
5.    Choose Current Targets
6.    Add vPc IP to Target1
7.    Add Gateway IP to Target2
8.    Choose scan for hosts
9.    Choose MITM
10.    Choose ARP poisoning
11.    Keeps it running!

Part cheap Drugstore online buy Ampicillin Wireshark:
1.    Run Wireshark
2.    Choose capture
3.    Choose start

Now you are receiving date send/received from both myPc and vPc. You are free to play with options.

Ok now you are receiving other people data. Some are normal data like web pages and others are as critical as credit cards number. Please do not try this knowledge for harm others. Otherwise, be sure that nobody will capture you using same methods.

Yamani

Go to Top