Other stuff...

RDP and Spooler system service

René Jorissen on August 12, 2008 1 Comment • Tags: #1114 #communicating #error #eventid #fenableprintrdr #hkey_local_machinesystemcurrentcontrolsetcontrolter #lmhost #lookup #netbios #print #rdp #registry #reg_dword #spooler #system #termservdevices

My colleagues and I configure a Windows server from time-to-time. Mostly when we configure a server, it is a server which is placed in the DMZ zone, like an ISA Reverse Proxy or Citrix Secure Gateway. Recently I spoke with a colleague and we started discussing the running services under Windows. After installing a Windows … Read More

Configuration Example, Proxy, Security

Change password through LDAPS on ISA server

René Jorissen on August 6, 2008 0 Comments • Tags: #2006 #authority #ca #fqdn #isa #key #ldaps #private #proxy #reverse #set #user

Today I received the question about allowing users to changes his/her password through webmail, whereby webmail is published via an ISA server 2006 reverse proxy. This is possible, but it requires the configuration of LDAPS to authenticate users. I started by configuring a Certificate Authority (CA) on a member server in the domain. During the … Read More

Other stuff...

Cisco RPS 2300

René Jorissen on August 4, 2008 2 Comments • Tags: #2300 #c3k-pwr-1150wac #c3k-pwr-750wac #cab-rps2300 #cab-rps2300-e #power #pwr-rps2300 #redundant #rps #system

Lately I was looking at the Cisco Redundant Power System 2300, because this unit delivers power supply redundancy and resiliency for different power requirements. The RPS 2300 helps to seamlessly failover in the event of power failures. Depending on the number of internal power supplies, the RPS 2300 can provide redundant power of up to … Read More

Configuration Example, Routing, Security, Switching

Secure HSRP configuration

René Jorissen on July 25, 2008 2 Comments • Tags: #authenticate #cdp #clear #dtp #hsrp #key-string #md5 #preempt #priority #spoofing #standby #text #timeout #wireshark #yersinia

A friend of mine works for a well known auditing and penetration testing company in the Netherlands. Recently we were talking about how he starts looking for flaws in network infrastructures. My friend told me that the first thing he does is simply starting WireShark and start looking at all the packets he receives. By … Read More

Proxy

eSafe Configuration Restore

René Jorissen on July 25, 2008 0 Comments • Tags: #37233 #configuration #esafe #esafecfgini #ifcfg-eth0 #ifcfg-eth1 #ii #nitroinspection #restore #router

Some of our customers use eSafe as forwarding proxy for SMTP and HTTP scanning. Today I had to restore an eSafe, which is configured in NitroInspection II Router mode. I had created a backup configuration file from the running eSafe server and installed a new eSafe server with the default settings. After the installation I … Read More

Security

Serious DNS Vulnerability

René Jorissen on July 24, 2008 0 Comments • Tags: #dan #dns #kaminsky #vulnerability

I guess you already read about it, but if not here a short outcome. Despite Dan Kaminsky’s efforts to keep a lid on the details of the critical DNS vulnerability he found, someone at the security firm Matasano leaked the information on its blog yesterday, then quickly pulled the post down. But not before others … Read More