Postano 28.06.2009 09:13:18

U Linksys WRT54GL sam ubacio DD-WRT firmware, v24 preSP2 [BETA] Build 12188.
Vazno je samo da se pocetno flashiranje obavi sa mini_generic.bin pa tek nakon toga nadograditi na standard generic.

DD-WRT is a Linux based alternative OpenSource firmware suitable
for a great variety of WLAN routers and embedded systems.
The main emphasis lies on providing the easiest possible handling
while at the same time supporting a great number of functionalities within the
framework of the respective hardware platform used.

DD-WRT mi djeluje malo buggy ali radi dobro.

http://www.desicrazy.com/2008/01/29/upgrade-your-60-router-into-a-fancy-600-router/

Prije flashiranja, obavezno procitati:

http://www.barik.net/archive/2004/12/03/220751/

Preventative Measures

First, let’s talk about what to do if your device is already working.
These are some preventative measures that will really help out if you do
eventually end up turning your router into a brick.
If you’re already using a third-party firmware, for example,
you should go ahead and set the boot_wait parameter to on in your nvram:

nvram set boot_wait=on
nvram commit

There should be no need to ever unset boot_wait.
The variable allows you a three to five second window to tftp
over new firmware at bootup and avoid otherwise catastrophic failure.

Prije flashiranja trebalo bi preuzeti orginalni najnoviji firmware u slucaju problema s DD-WRT, trebalo bi preuzeti i Tftp.exe upgrade utility:

http://forums.linksys.com/linksys/board/message?message.uid=263241

Dobre upute za flashiranje:

http://it.toolbox.com/blogs/php-bsd-me/linksys-wrt54gl-ddwrt-software-15026

Ako nesto ode u krivom smjeru i primjetite da lampica power stalno blinka cak i nakon resetiranja:

The WRT54G Revival Guide

Naravno, ovo sve koristite na vlastitu odgovornost i mozda ce te izgubiti garanciju! Guns

Postano 19.06.2009 20:59:33

RED, ORANGE, BLUE, GREEN Konfiguracija

IPCop::The bad packets stop here! 

BackTrack is the most top rated linux live distribution focused on penetration testing 

Došlo je vrijeme za promjene.

U 10 mjesecu, sada davne, 2007 godine na P1 Siemens Nixdorf SCENIC PRO C5 (CPU 133MHz, RAM 64MB, HDD 1.2GB), ubacio sam dva NIC-a (RED + GREEN) te instalirao IPCop 1.4.16, ubacio nekoliko addona (Advanced Web Proxy, URL filter, Banish),
malo podesio i radio je kao sat. Malo je ta konfiguracija slabija ali cist dovoljno. 8 portni switch GREEN, RED ADSL modem.

Odlucio sam ubacit i wireless te zamijeniti postojeci hardware.

Slozio sam od starih dijelova jedan stroj,
Celeron 900 Mhz, RAM 450MB, HDD 20GB, 3 x NIC (GREEN + BLUE + RED).

Ubacio bi Linksys WRT54GL, Linksysa bi zakacio u BLUE, switch bi ostao GREEN a RED na ADSL modem.
IPCop 1.4.20 je podignut na ovom Celeronu, ovo sad leti u odnosu na P1.

Sad ce bit vise mogucnosti za addons.

Slijedi umrezavanje i podesavanje.

Jos jedan zgodan addon za IPCop: http://www.ban-solms.de/t/IPCop-wlanap.html

Aleluja Wink http://backtrack.offensive-security.com/index.php/HCL:Wireless#Dlink_DWL-G520

 

Postano 19.06.2009 20:08:55

Koristan PDF… Ovo mi je stajalo u draftovima skoro 3 godine Wink

http://www.olekasper.no/articles/security_aspects_of_login_systems.pdf

PHP Security Mistakes 

http://www.devshed.com/c/a/PHP/PHP-Security-Mistakes/

The Open Web Application Security Project (OWASP)

The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.

Top Ten 2007

The primary aim of the OWASP Top 10 is to educate developers, designers, architects and organizations about the consequences of the most common web application security vulnerabilities. The Top 10 provides basic methods to protect against these vulnerabilities – a great start to your secure coding security program.

http://www.owasp.org/index.php/Top_10_2007

ModSecurity

ModSecurity is a web application firewall that can work either embedded or as a reverse proxy. It provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.

It is also an open source project that aims to make the web application firewall technology available to everyone.

An introduction to mod_security

http://atomicplayboy.net/blog/2005/01/30/an-introduction-to-mod-security/

http://www.modsecurity.org/documentation/