Who’s hogging the pipe?

If you’ve found yourself in a Network/System Admin position without the proper tools, and can’t seem to get them, there’s usually a way to do things for free with Linux or at least using the repos provided under an enterprise support package such as RHEL. 🙂 This is for monitoring who’s chewing up the pipe by IP address.

* Obviously there’s 100 ways to skin a cat in Open Source, but this is one way that can take you from “Who’s hogging the pipe” to “HEY! Stop doing that” in 15 minutes. Granted this isn’t meant for controlling the traffic, that’s another story. *

How To: ( Warning! – You may need to verify this action with your IT Dept – Warning!)

1. On the Core switch just before the “Gateway” hop takes place, and Pre-NAT rules, you’ll need to enable a port for monitoring the traffic (both TX and RX) to and from the “Gateway”. This box could also be used as a SNORT box. (once again another story)

2. You’ll need a Linux box with dual NIC’s (for remote usage) or a single NIC with Physical terminal access for direct access only.

3. Install and run/configure “iptraf” (using sudo or root access) 
#sudo yum install -y iptraf
#sudo iptraf (once the Screen launches, hit any key)
Scroll down to “Configure” (enter)
Set “Force Promiscuous mode” to ON
(You may wish to keep “Reverse DNS Lookups” off as well)
(Adjust “Additional ports” or any other settings if needed)
“Exit Configuration”
Select “IP Traffic Monitor”
Select the interface that’s plugged into the “Monitored” port. (from Step 1.)
Once the monitoring begins you can sort by bytes or packet count etc.

Find the “Hogger”.

Note: I really like the “iftop” tool as well, but it’s not in the RHEL Repos. ;0)

You can’t control the traffic from this app, but at least you can verify if the traffic is legit or not. Once you have the ip you can do the standard ip/arp/mac table lookups etc. to locate the machine.

HTH.

dbcooper

Practical Security: Wireless Network Security & WPA

In light of the latest wireless vulnerability found, which can break “WPA” using “TKIP” for encryption, I thought I would advise everyone to review your home wireless setup.

The subject of securing your wireless (or wired) networks at home could be talked about for hours on end, and depending on what hardware (model/brand) you have, your set-up and configurations may vary. Please see the documentation that came with your device or the company’s website for more information on the specific model you have. Also, don’t hesitate to call or email the vendor for help if needed.

Basically it comes down to these few things:

  1. Don’t broadcast your SSID if possible. (See your manual, and see this link)
  2. Use Wireless MAC filtering if possible. (See your manual, and see this link)
  3. Don’t use WEP for encryption.
  4. Don’t use WPA w/TKIP (this is now breakable).
  5. Change your WPA from TKIP to AES for encryption. (See your manual)
  6. If your hardware (computer and wireless router) supports it, move to WPA2. (See your manual)

General Home Computer Security Info:

  1. Make sure your Anti-virus application is updating/updated and enabled.
  2. At a minimum, make sure the Windows Firewall is enabled (unless you are on a Mac, in which case you should turn yours on too).
  3. Use strong passwords comprised of alpha/numeric/special characters on all your “Admin” level computer accounts.
  4. If you have any files or folders shared over your home network, make sure they are password protected.

There are a million resources for articles on computers and security online, but here are a few good ones if you are new or inexperienced with the subject (or just need a refresher).

Microsoft Security Resource for Home Users:
http://www.microsoft.com/protect/default.mspx

US-CERT.GOV – Home Users:
http://www.us-cert.gov/nav/nt01/
http://www.us-cert.gov/reading_room/home-network-security/

CERT.ORG – Home Users:
http://www.cert.org/homeusers/
http://www.cert.org/homeusers/HomeComputerSecurity/
http://www.cert.org/tech_tips/home_networks.html

With all that said, have a safe, secure, and happy computing day.

More on Putty

The other day I showed you how to configure the look and feel of Putty for improved usability and performance.  As I was doing some digging, I discovered two tools which extend the awesomeness of Putty.

First is Putty Connection Manager, which takes control and allows you to manage multiple Putty sessions from one, convenient tabbed interface.  Did I mention that I love tabbed interfaces?

Second, there is Putty Tray, which seems to be a customized version someone made that in and of itself improves the Putty interface, while enabling you to minimize it to the Windows System Tray.

HTML Form Elements for Photoshop

If you are a web designer, you have probably found yourself needing an easy way to make HTML form fields when creating mockups of your designs in Photoshop (or any image editing application).  I know I have, and I usually resort to grabbing screen shots of web pages that contain forms that look close to the design I am trying to implement.  Occasionally I have found myself actually making form fields in Photoshop, which can take a lot of time.

I found a tool today that makes all of this much simpler.  It allows you to define the look and feel of every form element, including colors, widths, and other styles, and have them appear on the page.  Once you have the form elements looking spiffy, you can take a screenshot of the page and load it into Photoshop where you then crop out the elements you want to use and slap them into your mockup.  Very handy!

HTML Form Elements for Photoshop can be used directly from the developer’s web site, or you can download a copy for yourself and run it locally.

Configure Putty Settings For Improved Performance

Not sure about you, but I use Putty perhaps more than any other application on my Windows PC’s.  Putty is a powerful, fast, free application which can be used to connect you quickly and securely to your Linux/Unix environment.

A person named “dag” from the Field Commander Wieers blog has provided an excellent article on configuring Putty for optimal usability and performance called “Improving Putty Settings on Windows“.  After walking through the steps listed in the article, I fired up Putty and was amazed by the improved text rendering, colors, and more.

A brief summary of settings gleaned from the article:

Category: Session
Connection type: SSH

Category: Window
Lines of scrollback: 20000

Category: Window > Appearance
Font: Lucida Console, 9-point
Font quality: ClearType
Gap between text and window edge: 3

Category: Window > Translation
Character set: UTF-8
Handling of line drawing characters: Unicode

Category: Window > Selection
Action of mouse buttons: xterm (Right extends, Middle pastes)
Paste to clipboard in RTF as well as plain text: enabled

Category: Window > Colours
ANSI Blue: Red:74 Green:74 Blue:255
ANSI Blue Bold: Red:140: Green:140 Blue:255

Category: Connection
Seconds between keepalives (0 to turn off): 25

Category: Connection > SSH > X11
Enable X11 forwarding: enabled

Read the whole article here.

Geeky Greats: Useful & Interesting Web Sites

The timeline of Internet Memes is an amazing journey through time, all the way back to the early days of the internet.  What makes it funny and interesting is that it chronicalizes a thorough history of internet memes:  those funny themes that run through the internet subculture.

ColorCombos.com is a useful site which helps you test and select color combinations for use on your web sites or digital creations.  I love this type of tool, not being a person who can match colors very well.

For the desktop, I recommend carrying a copy of the awesome, free tool known as Color Cop.  I’ve been using it for years, so I donated to them a while back, and if you find it useful, you should too!  Color Cop is an eyedropper tool that provides much of the same functionality as the eyedropper in Photoshop, but is lightweight, versatile, and easy to use.

FormatFactory does and amazing job of converting your Windows media files from one format to another, and it does it all for free.

Do you freelance from home?  Check out FreelanceSwitch, who offers a bunch of good resources for freelancers.  I have found their page on Legal Resources for Freelancers to be very helpful.

This Web Site is Changing

As much as I love WordPress, I have found myself using Tumblr a lot more.  I like it’s mobile-friendly interface, simplicity, and ease of use.

You can find my regular blog posts at http://blog.www.willchatham.com now

I will be updating this site some day so that it all makes more sense now that I am relocating the blog portion of it.  Look out!

Google Chrome – Installation

Chrome just came out, and I downloaded it and have it installed.  Expect a review here once I have time to kick the tires a little bit.

One thing that made me chuckle during the installation was a dialog box that popped up when I told Chrome to import my settings from Firefox:

Sadly?  I’m impressed they feel so compassionate about the fact that Firefox was open on my computer.

Anyway, the first 3 minutes of messing with Chrome have been a series of “oooh cool!” moments for me.  Look for more opinions soon…

Google Chrome – The GBrowser

Holy friggin moly Google is coming out with a web browser tomorrow.

Presenting Google Chrome.

This should be interesting.

I can only wonder:

  • Will it have plugins that could ever match those of Firefox?  Enough to lure me away?
  • What will standards support be like?  Will it pass the Acid3 test?
  • How pervasive will it end up being?  Could it really be the Windows killer?
  • How will it tie into Google apps, docs, search, and services?

I know what I’ll be doing tomorrow…

Captchas. No, I didn’t sneeze.

Are captchas annoying to you?  They are to me.  I probably fail at solving them about 15% of the time, which is far too often for my liking.  They get annoying, and as spammers find ways to automate solving them, the captchas continue to get more difficult to read.

Someone who knows a lot about combating spam, and has done a pretty darned good job at it, Matt Mullenweg, suggests in a recent Guardian article that “…Captchas are useless for spam because they’re designed to tell you if someone is ‘human’ or not, but not whether something is spam or not.”  I would have to agree.

There are many efforts to improve upon Catpchas, such as the 3-D Captcha.  In my opinion, this is just making things more complicated than necessary, and would be difficult to implement easily on a typical blog or contact form.

I run about 6 to 8 blogs (depending on my mood from week to week), and have been reluctant to use Captchas on any of them, partly out of usability concerns, but also because they are so easy to fail.  Instead, for my blog comments, I rely upon Mullenweg’s own Kismet spam system.  This feature is built into WordPress blogs, which makes it a breeze to set up, and I am constantly amazed at the loads of spam comments that it stops.

As Mullenweg suggests, focusing on the content rather than the submitter, is the way to go in the long term, and Kismet is great at doing that.

However, I also rely on a simpler test to determine if someone is a human or not mainly because it’s not as annoying as a Captcha, and it prevents a lot of spam comments from making it through in the first place.  It’s easy to add a basic question to a form which must be answered correctly in order for the form to be submitted succesfully.  Questions could be as simple as:

  • What color is an orange?
  • What is 3 plus 3?
  • How many wheels does a car have?

There is a great WordPress plugin which provides this capability and is relatively easy to set up called the Secure and Accessible PHP Contact Form.  If you run any WordPress blogs, I recommend you try it out.

By having a list of simple questions that are randomly selected to appear on your forms, you can stop automated scripts from filling out your forms quite easily.  This, combined with Kismet, a content-based filter of what gets submitted, will pretty much stop spammers in their tracks without creating a hassle for your visitors.