Showing posts with label something different. Show all posts
Showing posts with label something different. Show all posts

Tuesday, December 10, 2013

Keep your Networks and Data Safe.


Home Wireless Devices: 


Most wireless access points are ready-to-go right out of the box, but from a security perspective, they are wide open and insecure. This means that anyone driving (or walking) by your house or living in close proximity to your house can instantly connect to your wireless access point. Without proper security configurations enabled, your neighbors can even connect to the Internet through your network at no cost to them and could possibly access files on your home systems which reside on your PC or network.


We urge you to follow and apply the guidelines below where possible.


Protect Your Personal Information:


•Remember that everyone can view data in the airspace. Protect it appropriately by encrypting the data by using Wi-Fi Protected Access (WPA and preferably WPA2).
•Install personal firewalls and Anti-Malware software on all devices and have the most up-to-date signature files installed. You should also have the latest security patches (such as Microsoft Windows updates and Adobe Reader updates) installed on your system.
•Change the administration password on the Access Point to something other than the default one assigned by the manufacturer.
•The Service Set ID (SSID) is the name of your wireless network. For example, a Linksys router most commonly has a default SSID of "linksys." You should change your SSID from the manufacturer default, but not to something that is easily guessable.  Avoid using mailing addresses, street names, or your last name.  This can give away too much information about your physical location or identity. Suggestions might include: "homenet8273" or "h563."

Keep a Clean Machine:

•Make sure you’re using the latest firmware update for your specific Access Point / Wireless Router. Not only will you benefit from hardware bug fixes, you may also gain improved security features as well. Firmware updates are usually freely available from the manufacturer’s website and include instructions on how to perform the upgrade.
•Using Internet Security all-in-one tools are also recommended as they usually have Host Intrusion Prevention tools which are not dependent on signature files and are more behavior based.

Connect with Care:

•For the more technically savvy, you can filter, by Media Access Control (MAC) address, what devices/computers can connect and obtain an IP address from your wireless Access Point. There is a table where you can enter the MAC address from each device/computer on your network that you want to allow to communicate.
•Disable "remote administration" for the Access Point (usually the default setting). This is different from local administration, which is always enabled. Remote administration can potentially allow untrusted users on the Internet to connect to your wireless access point and administer it.



LearnSecurityOnline.com is a highly interactive online security training experience. We do this by utilizing simulators, security games, challenge servers, and hacking competitions to give you both the technical knowledge and hands-on experience required to be a competent IT & IT Security Professional all in a safe and legal environment.

Friday, May 10, 2013

How TCP and UDP work



Transmission Control Protocol (TCP) and User Datagram Protocol (UDP)is a transportation protocol that is one of the core protocols of the Internet protocol suite. Both TCP and UDP work at transport layer TCP/IP model and both have very different usage.




Lets imagine, that we need to transfer certain amount of data. You may transfer only certain amount at the time (you have limitation on the packet size, which is below TCP/UDP).

In case of TCP, first you should establish connection (you may read about "3-Way handshake"). During this you agree on the "TCP Window Size" (explained  below). Then you start actual data transfer...

You transfer a packet, and then you wait for a confirmation, that the packet received. If you didn't receive confirmation within certain amount of time, you transmit the same packet again (Retransmission occured). If you agreed on certain "TCP Window Size", you may transmit multiple packets without waiting for a confirmation, and then you receive one confirmation for all these packets (not many, usually a few, just "more than one"). If you sent 3 packets, but only two confirmed, you will send that missing packet, if no confirmation was received at all, then you send all 3 packets again. But the bottom line is - each and every packet should be confirmed.

TCP has tweaked for performance over the years. ACKs are often piggy-backed with replies to messages so there is no extra packet or waiting. It can also dynamically adjust to changing network performance with features like slow start and congestion avoidance. TCP optimizes the amount of data sent per packet to avoid IP fragmentation. With UDP, if you send a message greater than 1472 bytes (for 'normal' Ethernet) the IP layer will fragment it into multiple datagrams and it will buffered and re-assembled in the receiving stack.


In case of UDP, you just blindly split your data into packets, and transfer them without any care, if they were received or not. You may do it "at the wire speed". And if you need some kind of control over the data, this should be taken care on higher layers of OSI model (for example, you should implement transfer verification at the Application Layer).


So, in theory, TCP actual performance is at least twice slower (for example, your one-way-trip time is 100ms, you sent a packet, and wait for a response), plus depends on receiver (how long it takes to prepare and send a confirmation), while UDP may send packets "as a stream" without any delay.

That said, there are many case where UDP may be a better choice. there isn't much use for retransmissions with applications like VOIP. For a simple exchange where you don't need the overhead of establishing and tearing down a connection UDP is likely the way to go, DNS being a perfect example. Note that even DNS will switch to TCP when the server sees that the reply will be lengthy due to multiple addresses and/or MX records.

If you are creating a VoIP application, there is no need constantly to check if the other end is on-line, so you can use UDP to transfer the main payload (voice) and a second TCP connection to handle connection/disconnection at a lower speed (once a second is ok).

If you are transmitting a public radio station over IP, you need only to enable your players to join one multicast channel. In the latest case, UDP is far more effective and is causing less overhead, since all the network balancing is handled by the multicast enabled routers.

In areas of video streaming and VoIP the overhead of TCP would be intolerable, so they use UDP and they work pretty well- mainly because the network infrastructure and the protocols have "matured" to the extent where reliability is largely taken for granted.



Clear as mud?



Monday, March 25, 2013

CCNA networking quick questions

Another random assortment of Cisco based networking questions you can use as a primer for achieving CCNA certification or as a refresher.  

Scroll to the bottom for examination tips .. 

1.  How many IP access lists can you assign on an outbound interface?

A.) 1
B.) 1-100
C.) Unlimited


2. What type of switch port can belong to multiple VLANS?

A.) Access port
B.) Trunk port
C.) Voice access port
D.) No port can belong to multiple VLANs


3. What happens if a packet does not match any of the ACL statements?

A.) Nothing
B.) It is rejected
C.) It is allowed


4. Protocol Data Units of the Physical layer are called?

A.) Bits
B.) Frames
C.) Segments
D.) Packets


5. Bridges can only have one spanning tree instance, while switches can have many.

A.) True
B.) False









1.  Correct Answer A

2.  Correct Answer B

3.  Correct Answer B

4.  Correct Answer A

The Layer 1 (Physical Layer) PDU is the bit
The Layer 2 (Data Link Layer) PDU is the frame
The Layer 3 (Network Layer) PDU is the packet
The Layer 4 (Transport Layer) PDU is the segment


5.  Correct Answer A




Here are some revision tips to help you revise for the CCNA exam, or any Cisco exam for that matter...

1.)  Make sure you only learn topics which are covered by the exam.
2.)  Glance through the course/exam topics and highlight the areas you think you'll need to concentrate on more.
3.)  Get a good CCNA book that suits your learning style.
4.)  Practice what you learn frequently by using practice tests and flash cards. Highlight your weakest subjects and aim to improve them.
5.)  Create a set of revision notes for each topic. Try to stick to one page of paper per topic.
6.)  Read through your revision notes frequently.
7.)  You want to retain the information beyond the exam, so forget about cramming the night before the exam. Spread out your revision into 30 minute revision periods.
8.)  Condense your revision notes. The act of rewriting them will help you memorize them.
9.)  Practice your IOS configuration on a Cisco router or router simulator.

Saturday, February 2, 2013

Star fleet engineering


Gives you a headache doesn't it, maybe IKEA can get some tips :-)




I failed a Health and Safety course at the office yesterday. 
One of the questions was: "In the event of a fire, what steps would you take?" 

"F*%king' big ones" was apparently the wrong answer.