- HTTPS Everywhere
- Privacy Badger
- Ublock origin
- Umatrix
- Self-Destructing Cookies
¯¯̿̿¯̿̿’̿̿̿̿̿̿̿’̿̿’̿̿̿̿̿’̿̿̿)͇̿̿)̿̿̿̿ ‘̿̿̿̿̿̿\̵͇̿̿\=(•̪̀●́)=o/̵͇̿̿/’̿̿ ̿ ̿̿
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Sunday, 30 April 2017
Favorite Firefox privacy extensions 2017
Labels:
configuration,
extensions,
firefox,
Internet,
privacy,
security,
software,
trick
Saturday, 10 September 2016
My favourite Chrome privacy extensions
These are my favourite five chrome privacy extensions...
removed
- "The Web Of Trust (WOT) extension is a website reputation rating tool that helps you make informed decisions about whether to trust a website or not when you are searching, shopping or browsing online."
- "An efficient blocker: easy on memory and CPU footprint, and yet can load and enforce thousands more filters than other popular blockers out there."
ScriptSafe
- "A Chrome extension that gives users control of the web and more secure browsing while emphasizing simplicity and intuitiveness."
HTTPS Everywhere
- "HTTPS Everywhere is an extension created by EFF and the Tor Project which automatically switches thousands of sites from insecure "http" to secure "https". It will protect you against many forms of surveillance and account hijacking, and some forms of censorship
Flashcontrol
- "Have more control of flash content by preventing it from loading in webpages until you allow it."
Saturday, 3 September 2016
LINUX HOWTO: Limiting SSH access to specific IP addresses
Intro:
This is a simple way to permit a select few IP addresses to access your raspberry pi though SSH and deny any others. By white listing certain IP addresses from networks you know you are adding a layer of security helping prevent others from accessing your machine. This is handy if you only access your machine from a few set locations, such as on the LAN and at work.
There are a few methods you could go about doing this, but i find this the most easy to implement, allowing you do accomplish basic permit and deny without iptables.
The two files needed to be edited are /etc/hosts.allow and /etc/hosts.deny
Step 1)
Enter:
sudo nano /etc/hosts.allow
sudo nano /etc/hosts.allow
The file should be empty. At this point just add the ip addresses or subnets which you want to permit, for example:
sshd: 10.0.0.0/255.255.255.0
TIP: For specific IP addresses, just enter the address without the subnet.sshd: 192.168.0.0/255.255.255.0
Step 2)
Enter:
sudo nano /etc/hosts.deny
By entering the following you will deny all other addresses which were not explicitly defined before (everyone else).
sshd: ALL
Conclusion:
Now only those ip addresses or subnets defined will be able to get ssh access to your ssh server, others will not be able to connect.
RASPI: Installing and configuring fail2ban on the RaspberryPi
Wikipedia:Fail2ban is an intrusion protection software which will prevent brute force attempts from accessing your ssh service. This is accomplished by logging the failed attempts and banning the offending ip addresses in iptables.Fail2ban operates by monitoring log files (e.g. /var/log/auth.log, /var/log/apache/access.log, etc.) for selected entries and running scripts based on them. Most commonly this is used to block selected IP addresses that may belong to hosts that are trying to breach the system's security. It can ban any host IP address that makes too many login attempts or performs any other unwanted action within a time frame defined by the administrator. Fail2ban is typically set up to unban a blocked host within a certain period, so as to not "lock out" any genuine connections that may have been temporarily misconfigured. However, an unban time of several minutes is usually enough to stop a network connection being flooded by malicious connections, as well as reducing the likelihood of a successful dictionary attack.
In this short tutorial i will show you how to install and configure fail2ban on Raspbian in four easy steps.
Step 1) Update
First thing to do is update your repositories...sudo apt-get update
Step 2) Install
Secondly install fail2ban...sudo apt-get install fail2ban
After installing, fail2ban will now protect ssh with default settings, so it will work after installing. Section three will show you how to customize these configurations.
Step 3) Configure
3.1)
Now take a look in this file at the default configurations, focusing on the defaults at the top and those under [ssh]. Don't change anything, just take a look around as our configurations will not be added here.sudo nano /etc/fail2ban/jail.conf
The default configurations are stored in the jail.conf file, however changes should not be directly here, instead they should be added to the jail.local file. - By adding our amendments to the .local, we can avoid adding everything and just those that we want to override.
Now open up jail.local:
sudo nano /etc/fail2ban/jail.local
3.2)
Here are my settings. You can paste these directly in to the empty jail.local file in if you want and use them as a template.[ssh]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
bantime = 600
banaction = iptables-allports
maxretry = 3
ignoreip = 127.0.0.1/8 192.168.1.0/24
What they mean:
- 'enabled' is set to true so that fail2ban operates for ssh.
- 'port' is what port to monitor, the default will be ssh (port 22). You may want to change this if you are running ssh on a different port than 22, but most users will use 22 however.
- 'logpath' is the default log file used by fail2ban to track login attempts.
- 'bantime' is measured in seconds and is the amount of time an offender will have to wait until attempting to connect again. The default is 600 seconds (10 minutes). To add permanent bans set this to -1 or bellow.
- 'maxretry' is the amount of login attempts until the offender will be locked out.
- 'ignoreip' can be set to define ip addresses or subnets which the rules do not apply to. In the example i have added the loopback address and the private address space for my LAN. Change appropriately to suite your private addressing on your LAN.
In nano: ctrl+o saves, and ctrl+x exists.
Step 4) Restart fail2ban to take effect
Once the configurations are added to jail.local and saved, you can restart the fail2ban service for changes to take effect..sudo service fail2ban restart
View banned ip addresses
sudo iptables -L INPUT -v -n | lessNote: keep in mind, whenever fail2ban is restarted, all the previous bans will be removed.
Sunday, 10 July 2016
Legal wargames
Fun war games in working though which are for beginners to advances users. I have been playing over the wire this week and its really fun.
http://overthewire.org/
See the following link for a list of plenty:
https://hackerlists.com/hacking-sites/
Monday, 26 October 2015
Sandboxie for Windows. A must have.
This is a simply must have program if your a windows user. There are so many situations where this would come in useful.
Its a piece of security software isolates a program, known as a sandbox-based isolation program.
Wikipedia:
Its a piece of security software isolates a program, known as a sandbox-based isolation program.
Wikipedia:
It creates a sandbox-like isolated operating environment in which applications can be run or installed without permanently modifying the local or mapped drive.[8][11] An isolated virtual environment allows controlled testing of untrusted programs and web surfinghttp://www.sandboxie.com/
Subscribe to:
Posts (Atom)