Recently I helped one of my client to setup a VPS on DigitalOcean (DO). The price is very competitive (the cheapest plan is $5 per month) and they offer SSD as the storage. I highly recommend to give a try if someone is looking for a virtual hosting.
Actually a VPS is just a server running on other location. Once you subscribe a plan and start to OS, it's your responsibility to maintain the system.
The steps below are to enhance the security once the server is deployed ( we are using Ubuntu 14.04 in this case). The objective is to harden the server so that it can only be accessed from a client with ssh
1. Setup ssh keyfrom a linux server at home or office. Assumed you have a linux client with a user "user1"
Contains technical document about Unix/Linux, Java, Python, Raspberry Pi and other IT related topics. Not a full tutorial but as a quick reference guide
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Thursday, September 24, 2015
Monday, February 25, 2008
Using Truecrypt to protect your data
In Hong Kong the "pron" photos topic is still very hot. It showed the limitation and contradiction between ethics, Law system and Information Technology. As a so called "IT person", I just want to point out that, if the photo owner had kept the photos well, nothing could have happened. Hence, it is very important for us to protect our personal data.
So how to protect and secure our data? At least we have to achieve the following things:
1. Only the owner can access the data
2. Even the data was stolen, the data still need to be decrypted
In order to implement the above points, the simplest way is to zip the data files with a password. In normal case other people would not access the access so easily. However, if you have a lots of data, just like Mr. Chan who owners thousands of photos, zipping files will be quite trouble. So it is recommended to use a free encryption tool "truecrypt", which can protect your data in an easy and secure way.
Truecrypt is different from Zip, we have to create a blank file and encrypt it (Using password or a keyfile), then mount it as a Windows drive or Linux mount point for storing your sensitive data. That encrypted file can be named or sized as you like, very flexible. Even though your hard disk is stolen, nobody will know which file can be mounted. In addition, you can also encrypt a partition rather than a file, which makes the hackers have a hard time.
There is also a "hidden mode", which is a encrypted area inside the file or partition, but with another password or keyfile. So in some situation you are forced to tell the password, you can just give the password of the "outer" part. As nobody can ensure the existence of the hidden part, your most important data will not be exposed.
Remember, do protected your important data !
Ref:
Truecrypt offical site
Truecrypt Tutorial in Chinese
So how to protect and secure our data? At least we have to achieve the following things:
1. Only the owner can access the data
2. Even the data was stolen, the data still need to be decrypted
In order to implement the above points, the simplest way is to zip the data files with a password. In normal case other people would not access the access so easily. However, if you have a lots of data, just like Mr. Chan who owners thousands of photos, zipping files will be quite trouble. So it is recommended to use a free encryption tool "truecrypt", which can protect your data in an easy and secure way.
Truecrypt is different from Zip, we have to create a blank file and encrypt it (Using password or a keyfile), then mount it as a Windows drive or Linux mount point for storing your sensitive data. That encrypted file can be named or sized as you like, very flexible. Even though your hard disk is stolen, nobody will know which file can be mounted. In addition, you can also encrypt a partition rather than a file, which makes the hackers have a hard time.
There is also a "hidden mode", which is a encrypted area inside the file or partition, but with another password or keyfile. So in some situation you are forced to tell the password, you can just give the password of the "outer" part. As nobody can ensure the existence of the hidden part, your most important data will not be exposed.
Remember, do protected your important data !
Ref:
Truecrypt offical site
Truecrypt Tutorial in Chinese
Sunday, September 09, 2007
Cisco VPN client
vpnc is Cisco VPN client for Linux. I always use it to connect to my company at home. However, I found that I couldn't connect on one day. After checking, it was because I have updated the Ubuntu vpnc package. The new config file need to add a "NAT Traversal Mode cisco-udp":
...
IPSec gateway
IPSec ID
IPSec secret
Xauth username
Xauth password
NAT Traversal Mode cisco-udp
...
After added the list line, everything is okay again :>
...
IPSec gateway
IPSec ID
IPSec secret
Xauth username
Xauth password
NAT Traversal Mode cisco-udp
...
After added the list line, everything is okay again :>
Monday, July 09, 2007
AOL Active Virus Shield Save Me!
I used to think I am a 'careful' person. I don't install untrusted software, make my Windows as 'clean' as possible. However, my notebook still got infected.
Actually I have installed the F-Secure anti virus, but obviously that it failed to scan the virus. As a result, it always prompted out a "service.exe error 1073740972" and ask to restart in 60 seconds. I am so frustrated!. While I search the web for solution, a page mentions that try to use AOL Active Virus in safe mode. Okay, so I did have a try...
AOL Active Virus Shield use Kaspersky engine. It is totally free, and the most important thing is that it does help me. After a full scan, I found that my notebook was infected with 1 virus and 2 trojans(how come the F-Secure doesn't help?!). It was PECompact, Trojan.Win32.Dialer.qn and Trojan-Proxy.Win32.Agent.mx. I deleted the files without hesitation. Now my notebook runs smoothly and no more services.exe error comes out. Thanks AOL Anti Virus Shield!!
Finally, just let you know that apart from AOL Anti Virus Shield, there are still free anti virus software, such as AVG and ClamAV (Windows version). Just put the name and you should find the things.
Actually I have installed the F-Secure anti virus, but obviously that it failed to scan the virus. As a result, it always prompted out a "service.exe error 1073740972" and ask to restart in 60 seconds. I am so frustrated!. While I search the web for solution, a page mentions that try to use AOL Active Virus in safe mode. Okay, so I did have a try...
AOL Active Virus Shield use Kaspersky engine. It is totally free, and the most important thing is that it does help me. After a full scan, I found that my notebook was infected with 1 virus and 2 trojans(how come the F-Secure doesn't help?!). It was PECompact, Trojan.Win32.Dialer.qn and Trojan-Proxy.Win32.Agent.mx. I deleted the files without hesitation. Now my notebook runs smoothly and no more services.exe error comes out. Thanks AOL Anti Virus Shield!!
Finally, just let you know that apart from AOL Anti Virus Shield, there are still free anti virus software, such as AVG and ClamAV (Windows version). Just put the name and you should find the things.
Friday, March 16, 2007
TrueCrypt in Linux
Installation
- The following package are needed:
- kernel-source
- dmsetup
- device mapper
./build.sh
./install.sh
Creating a file based encryption volume
- Can be use normal user
$ truecrypt --size 10M
$ cd /tmp
$ truecrypt
$ pwd
/tmp
$ truecrypt --size 10M -c 10m.tc
Volume type:
1) Normal
2) Hidden
Select [1]: 1
Filesystem:
1) FAT
2) None
Select [1]: 1
Hash algorithm:
1) RIPEMD-160
2) SHA-1
3) Whirlpool
Select [1]: 2
Encryption algorithm:
1) AES
2) Blowfish
3) CAST5
4) Serpent
5) Triple DES
6) Twofish
7) AES-Twofish
8) AES-Twofish-Serpent
9) Serpent-AES
10) Serpent-Twofish-AES
11) Twofish-Serpent
Select [1]: 2
Enter password for new volume '10m.tc':
Re-enter password:
Enter keyfile path [none]:
TrueCrypt will now collect random data.
Is your mouse connected directly to computer where TrueCrypt is running? [Y/n]: n
Please type at least 320 randomly chosen characters and then press Enter:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Done: 9.75 MB Speed: 6.09 MB/s Left: 0:00:00
Volume created.
$ truecrypt -p abcd1234 -u 10m.tc /tmp/ttt/
$ cd /tmp/ttt/
$ df -k /tmp/ttt
Filesystem 1K-blocks Used Available Use% Mounted on
/dev/mapper/truecrypt0
130794 0 130794 0% /tmp/ttt
$ truecrypt -d /dev/mapper/truecrypt0
- In fact we can create the encryption volume in a partition / LV. But this time root is required.
(assume there is a VG called vg01)
#lvcreate -L 128M -n abc_lv vg01
Logical volume "abc_lv" created
#truecrypt -c /dev/vg01/abc_lv
Volume type:
1) Normal
2) Hidden
Select [1]: 1
Filesystem:
1) FAT
2) None
Select [1]: 1
Hash algorithm:
1) RIPEMD-160
2) SHA-1
3) Whirlpool
Select [1]: 2
Encryption algorithm:
1) AES
2) Blowfish
3) CAST5
4) Serpent
5) Triple DES
6) Twofish
7) AES-Twofish
8) AES-Twofish-Serpent
9) Serpent-AES
10) Serpent-Twofish-AES
11) Twofish-Serpent
Select [1]: 2
Enter password for new volume '/dev/vg01/abc_lv':
Re-enter password:
Passwords do not match.
Enter password for new volume '/dev/vg01/abc_lv':
Re-enter password:
Enter keyfile path [none]:
TrueCrypt will now collect random data.
Is your mouse connected directly to computer where TrueCrypt is running? [Y/n]: n
Please type at least 320 randomly chosen characters and then press Enter:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Done: 125.55 MB Speed: 15.26 MB/s Left: 0:00:00
Volume created.
#truecrypt /dev/vg01/abc_lv /abc
Enter password for '/dev/vg01/abc_lv':
#df -k /abc
Filesystem 1K-blocks Used Available Use% Mounted on
/dev/mapper/truecrypt1
130794 0 130794 0% /abc
#df -T /abc
Filesystem Type 1K-blocks Used Available Use% Mounted on
/dev/mapper/truecrypt1
vfat 130794 0 130794 0% /abc
#truecrypte -d /dev/mapper/truecrypt1
- Please note that vfat/fat32 is the default filesystem. So how about if we want to have an encrypted reiserfs filesystes?
#truecrypte --filesystem reiserfs /dev/vg01/abc_lv
(skip the interactive wizard)
#truecrypte -N 0 /dev/vg01/abc_lv
#mkfs.reiserfs /dev/mapper/truecrypt0
mkfs.reiserfs 3.6.19 (2003 www.namesys.com)
A pair of credits:
Joshua Macdonald wrote the first draft of the transaction manager. Yuri Rupasov
did testing and benchmarking, plus he invented the r5 hash (also used by the
dcache code). Yura Rupasov, Anatoly Pinchuk, Igor Krasheninnikov, Grigory
Zaigralin, Mikhail Gilula, Igor Zagorovsky, Roman Pozlevich, Konstantin
Shvachko, and Joshua MacDonald are former contributors to the project.
Lycos Europe (www.lycos-europe.com) had a support contract with us that
consistently came in just when we would otherwise have missed payroll, and that
they kept doubling every year. Much thanks to them.
Guessing about desired format.. Kernel 2.6.17-11-generic is running.
Format 3.6 with standard journal
Count of blocks on the device: 32752
Number of blocks consumed by mkreiserfs formatting process: 8212
Blocksize: 4096
Hash function used to sort names: "r5"
Journal Size 8193 blocks (first block 18)
Journal Max transaction length 1024
inode generation number: 0
UUID: 7ffaa516-0015-46bc-bfc0-6fdd7dca59ba
ATTENTION: YOU SHOULD REBOOT AFTER FDISK!
ALL DATA WILL BE LOST ON '/dev/mapper/truecrypt0'!
Continue (y/n):y
Initializing journal - 0%....20%....40%....60%....80%....100%
Syncing..ok
Tell your friends to use a kernel based on 2.4.18 or later, and especially not a
kernel based on 2.4.9, when you use reiserFS. Have fun.
ReiserFS is successfully created on /dev/mapper/truecrypt0.
#truecrypt /dev/vg01/abc_lv /abc
truecrypt: Volume already mapped
#truecrypt -d /dev/vg01/abc_lv
#truecrypt /dev/vg01/abc_lv /abc
Enter password for '/dev/vg01/abc_lv':
#df -T /abc
Filesystem Type 1K-blocks Used Available Use% Mounted on
/dev/mapper/truecrypt0
reiserfs 131000 32840 98160 26% /abc
Monday, December 18, 2006
Create a "Encrypted Drive" with Truecrypt
Everyone must have some information that is confidential and not want to be accessed by others. However, when you left your laptop behind, lose it or even just a portable hardisk, your information are exposed. So anything can be done such that people can't read the confidential data?
With Truecrypt, you can setup a "Encrypted Drive" in Windows, or a "Encrypted mountpoint" in Linux. But before started the Truecrypt, the drive or the mountpoint is just a single file, or even a partition. People cannot decrypt the data from the file or the partition without the pass key which can be a password or a file.
There is also a 'hidden volume' feature. Encrypted data can be stored in an existing Encrypted drive/mountpoint but with a different pass key. So when you are forced to tell the pass key, you can just tell the 'less confidential' pass key and your data in the 'hidden volume' is still safe.
Using Truecrypt can definitely protect your data. But please don't forget your pass key or you will never get back the data.
Ref:
Truecrypt website: http://www.truecrypt.org
Doucmentation: http://www.truecrypt.org/docs/
With Truecrypt, you can setup a "Encrypted Drive" in Windows, or a "Encrypted mountpoint" in Linux. But before started the Truecrypt, the drive or the mountpoint is just a single file, or even a partition. People cannot decrypt the data from the file or the partition without the pass key which can be a password or a file.
There is also a 'hidden volume' feature. Encrypted data can be stored in an existing Encrypted drive/mountpoint but with a different pass key. So when you are forced to tell the pass key, you can just tell the 'less confidential' pass key and your data in the 'hidden volume' is still safe.
Using Truecrypt can definitely protect your data. But please don't forget your pass key or you will never get back the data.
Ref:
Truecrypt website: http://www.truecrypt.org
Doucmentation: http://www.truecrypt.org/docs/
Subscribe to:
Posts (Atom)