“iWash” for iPhone

April 25th, 2009 Category: iPhone

Are you suck of cleaning the touch display of your iPhone? Then you should try iWash!

Download Links


“Speed Test” for iPhone

April 25th, 2009 Category: iPhone
img_0008.jpg img_0006.jpg img_0007.jpg

Speed Test is a native iPhone application without advertising and allows you to measure the network speed of your iPhone or iPod Touch. The application come from speedtest.net which is a well known site for measuring your speed of your network connection.

Download Link

“Network Utility” for iPhone

April 25th, 2009 Category: iPhone
img_0051.jpg There are not so many network tools for admins available on the iPhone but a few are available like the “Network Utility“. It provides some terminal-like network tools on your iPhone. The standard edition is free and comes with some advertisements whereas the pro version does not contain any advertisement.

It comes with the main features:

  • Ping (ICMP Echo)
  • TCP/IP Port scan
  • GeoIP Lookup
  • Geotargeting with Google Maps
  • Whois Query
  • IP Address Information

Download Links

“ChkWebSpeed” for iPhone

April 25th, 2009 Category: iPhone
img_0058.jpg Another nice and free network tool for administrators: ChkWebSpeed. It measures the download speed of any website via WiFi or Cellular network. You can add your own websites and check the min, max & avg download speed over 10 iterations.

So you can easily compare several the speed of several the web sites to see if the site is slow or your current network connection.

VNC Client for iPhone

April 13th, 2009 Category: iPhone
img_0035-1.jpg img_0042.jpg

It sounds quite strange, a VNC client for the iPhone. But incredible it works! I’ve used the Mocha VNC client because it is compatible with all known VNC server solutions. There are also other VNC clients available, but as far as I know they are not working together with all VNC server solutions.

I’ve tested the VNC client in a WiFi via a VPN connection to a Linux Red Hat Enterprise 3 server with the VNC server that comes with the Red Hat Enterprise distribution. After creating a profile and starting the remote connection a small surprise: a warning the my iPhone is low on memory. Funny, never seen such a warning before on my iPhone. But nevertheless the connection works.

img_0036.jpg img_0037.jpg img_0038.jpg img_0039.jpg

The client supports landscape mode as well. And it’s possible to change the zoom of the remote display. Mouse handling is maybe not perfect but basically it works to remote control your server. I’ve not yet checked it over a G3 connection, it maybe a little bit slow. But for emergency cases it can be useful.

img_0040.jpg img_0041.jpg

Links:

“Network Ping Lite” for iPhone

April 13th, 2009 Category: iPhone

Another nice free admin tool “Network Ping Lite” with useful features:

  • Ping a single IP address
  • Ping a subnet to get an overview
  • Traceroute to determine the route taken by packets
  • Telnet console for simple access to a router or Unix server

Get it from here:

Download link iTunes Store.

img_0020.jpg img_0018.jpg img_0019.jpg img_0049.jpg

Continous SSH Attacks

April 12th, 2009 Category: Linux Server

As written in a previous article Defending Againt SSH Attacks I think it’s really worth trying to install a tool like denyhosts. Since about 5 days denyhosts blocks IP addresses from all over the world every few minutes. In total now more than 550 different blocked IP addresses.

The reason seems that the IP address of my server has been added to a bot network which tries to hack servers using SSH brute force attacks. As far as I know such bot networks are built up  with Viruses and Trojans. I think there is no reason why your server may have also been added to such a list, somehow IP addresses seem to added.

But the question is how to defend against such brute force attacks from bot networks?

Known Methods

  • Install a tool like denyhosts
  • Always keep the SSH daemon up to date!
  • Move the SSH port from 22 to some other port
  • Disable password authentication and use key authentication
  • Slow down the amount of connections from the same IP using iptables and module “recent”
  • Open the SSH port after a trigger on a different port using iptables

I think there is one additional easy method to defend against such attacks. Why I think so? Read on..

Another Simple Method

When checking the auth.log we see that the user names of the attacks are taken from a dictionary:

Failed keyboard-interactive/pam for invalid user aderes from 195.xxx.xxx.xx port 39566 ssh2
Failed keyboard-interactive/pam for invalid user aderyn from 203.xxx.xxx.xx port 44099 ssh2
Failed keyboard-interactive/pam for invalid user adi from 78.xxx.xxx.xx port 42748 ssh2
Failed keyboard-interactive/pam for invalid user adia from 89. port 51028 ssh2
Failed keyboard-interactive/pam for invalid user adiel from 217. port 33861 ssh2
Failed keyboard-interactive/pam for invalid user adila from 77. port 52867 ssh2
It seems that the bots are not adding digits to the user names. So I think one easy method to defend against such attacks is:

  • add at least one digit to user names on your server if you have the possibility

And definitely never ever add a user “admin”. In my logs the user “admin” is always used for brute force attacks:

Failed keyboard-interactive/pam for invalid user admin from 203.xxx.xxx.xx port 39711 ssh2
Failed keyboard-interactive/pam for invalid user admin from 203.xxx.xxx.xx port 55493 ssh2
Failed keyboard-interactive/pam for invalid user admin from 220.xxx.xxx.xx port 34502 ssh2
Failed keyboard-interactive/pam for invalid user admin from 80.xxx.xxx.xx port 51846 ssh2
Failed keyboard-interactive/pam for invalid user admin from 80.xxx.xxx.xx port 53934 ssh2

Whois Tool “Domain Scout” for iPhone

April 10th, 2009 Category: iPhone

“Domain Scout” is maybe not a power tool but it’s free and useful for IT and network administrators. It’s helpful for easy whois queries to check if a domain is available, have a look at the DNS and registrar details.

Get it from here:

Download link iTunes Store.

img_0013.jpg img_0014.jpg img_0015.jpg img_0016.jpg

SSH Client for the iPhone

April 10th, 2009 Category: iPhone
img_0027.jpg img_0028.jpg

Definitely a useful tool for network administrator or people dealing with Linux servers: TouchTerm. Two versions are available: light and pro. I’ve running the light version on my iPhone. The pro version comes with gestures, additional plug ins and many more.

TouchTerm supports the landscape mode as well. SSH connections are managed with a session manager, which makes in unnecessary to enter host names for every connection.

img_0029.jpg img_0030.jpg

Links:

VPN with iPhone

April 10th, 2009 Category: iPhone
img_0022.jpg img_0025.jpg

I was not aware that the iPhone supports VPN’ing. Recently I’ve found the VPN menu within the iPhone menu. Going through the menu I was much more surprised that it also supports the proprietary Cisco VPN (IPSec).

All import VPN protocols are supported:

  • L2TP
  • PPTP
  • IPSec
img_0021.jpg img_0023.jpg

I could not believe that it will be possible to connect my iPhone with a Cisco PIX (running with PIX IOS 7) so I’ve tried it.

New VPN profiles are generated under Settings, General, Network, VPN. Entering the IP of the VPN server, account name and group name is all what is needed in my case. Once the parameters have been entered the VPN connection can be activated under the Settings menu. Unbelievable it works!

img_0024.jpg img_0026.jpg

Ping’ing through VPN is up and running. It’s not clear which kind of transport the iPhone is using, the tested Cisco PIX is configured to support all possible transport types:

  • IPSec without transparent tunneling
  • Transparent tunneling with IPSec over UDP (NAT/PAT)
  • Transparent tunneling with IPSec over TCP

Using the original Cisco VPN client it’s possible to configure the transport type. Since it’s not possible to edit transport type settings on the iPhone, VPN may not work depending on the VPN configuration of the Cisco PIX. I don’t think that the iPhone will try different transport types, but who knows…

Links: