Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, July 25, 2015

[SSH] Configure SSH Key-Based Authentication (windows as client , linux as server) - part1

Client Side part (windows)

Step 1

Download PuTTYgen from this page:
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html


Step 2

Run the file you downloaded:

Step 3

Click "Generate" button at PuTTY Key Generator:

Step 4

And then you will get the Public key for OpenSSH authorized_keys file.Copy your "Public key for pasting into OpenSSH authorized_keys file" to wordpad or some editor and save it. Be care don't forget the your txt file location.

Step 5

Enter your key passphrase , make a note of that since you may need it later:


Step 6

Click “save private key”, input the file name you like and save it.

This save private key to your PC.

Continue please visit this acticle:

[SSH] Configure SSH Key-Based Authentication (windows as client , linux as server) - part2

This article continue with this post:
[SSH] Configure SSH Key-Based Authentication (windows as client , linux as server) - part1

Step 7


Download PuTTY from this page and open it:
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html

Step8

Input your hostname or ip address and check open.


Step 9

Follow the instruction input your username and password to login in puTTY command promt.

Step 10

Use this command to create a .ssh directory with a blank authorized_keys file in your home directory on your server, and also set the access permissions.

mkdir ~/.ssh; touch ~/.ssh/authorized_keys; chmod 700 ~/.ssh

Step 11

Use this command for opening the file you just created to edit.
nano ~/.ssh/authorized_keys

Step 12

Paste the Public key for OpenSSH authorized_keys you marked in step5 (if can't edit, press i to enter insert mode), paste it and save.


Step 13

Type "logout" to end your session.
logout

Step 14

Select "SSH"->"Auth" in category and then browse the private key generated at step 6  , click open.

Step 15

Select "session" at category, input your ip address or hostname shown at the image:

Step 16

Follow the instruction to enter your login username, and then it would ask for your "passphrase", you should enter the passphrase you set at Step5


If your passphrase is correct, you can enter the server by SSH Key-Based Authentication successfully

Friday, June 6, 2014

[Security] Prevent Email address harvesting

According to wikipedia , Email harvesting is the process of obtaining lists of email addresses using various methods for use in bulk email or other purposes usually grouped as spam.
There is one of the method to In Prevent Email address harvesting, for detail please visit the site provided at the end of this blog post.

<style>
  my-email::after {
    content: attr(data-domain);
  }
  my-email::before {
    content: attr(data-user);
  }
</style>

<!-- Set data-user and data-domain as your
       email username and domain respectively -->

<my-email data-user="john" data-domain="gmail.com">@</my-email>
Result:

Reference:
http://www.labnol.org/internet/hide-email-address-web-pages/28364/
http://en.wikipedia.org/wiki/Email_address_harvesting

Thursday, June 5, 2014

[Apache][Security] A Hotlinking protection method

To block people display your image from another website and waste your bandwidth,
and also display a custom image as error message, you can use these code at your .htaccess:





1RewriteEngine On
2RewriteCond %{HTTP_REFERER} !^$
3RewriteCond %{HTTP_REFERER} !^http://(www\.)?naturefocused\.com [NC]
4     RewriteRule \.(jpe?g|gif|bmp|png)$ http://google.com/res/images/blockimg.jpg [NC,R,L]

line 3 is your domain,
line 4 is your image url for display if sb used your images's url directly at his/her website.

As the example code shown above,
line 3 was set as "http://www.naturefocused.com", if sb used &lt;img src="http://www.naturefocused.com/images/test.png"&gt; at their website, it displays image "http://google.com/res/images/blockimg.jpg".

Remarks:
The error message image better if isn't using the domain you specific in line 3

Reference
http://www.naturefocused.com/articles/image-protection.html