<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Newz &#187; Dave Taylor</title>
	<atom:link href="http://www.networknewz.com/author/dave-taylor/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networknewz.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 27 Jan 2012 18:02:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>How To Forget Networks On Your Mac</title>
		<link>http://www.networknewz.com/2011/01/31/how-to-forget-networks-on-your-mac/</link>
		<comments>http://www.networknewz.com/2011/01/31/how-to-forget-networks-on-your-mac/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 13:30:30 +0000</pubDate>
		<dc:creator>Dave Taylor</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.networknewz.com/?p=199</guid>
		<description><![CDATA[I used to leech Internet access from a neighbor, but after they gave me grief about it, I set up my own wireless network and am paying for my own Internet. Good citizen, right? Problem is, every time I start up my trusty old MacBook it automatically picks my neighbor&#8217;s network and I have to [...]]]></description>
			<content:encoded><![CDATA[<p>I used to leech Internet access from a neighbor, but after they gave me grief about it, I set up my own wireless network and am paying for my own Internet. Good citizen, right?  Problem is, every time I start up my trusty old MacBook it automatically picks my neighbor&#8217;s network and I have to explicitly switch it to use my own. Isn&#8217;t there some way to fix this annoying wifi network behavior??</p>
<p><span id="more-199"></span></p>
<p>Dave&#8217;s Answer:</p>
<p>You&#8217;re right, you&#8217;ve become a good network citizen, and just in time. Cities are starting to establish laws that define leeching off another person&#8217;s wireless wifi network without permission as an illegal act of theft. How you&#8217;d get caught I don&#8217;t know, but you can imagine that from the other party&#8217;s point of view, it&#8217;d be alarming if you were, say, pirating movies and it was their computer network that was tagged!</p>
<p>Like many other computer systems (think Windows Vista, for example) the Mac OS X system is smart and tries to simplify your life by remembering what you&#8217;re doing and automate the process subsequently. Sometimes that&#8217;s a pain. <img src='http://www.networknewz.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>What happened was that you have a setting in your &#8220;Network&#8221; System Preferences that tells your computer to remember networks you&#8217;ve joined and prefer them over new ones that it hasn&#8217;t seen before. Since your neighbor&#8217;s network is now marked as a &#8220;preferred&#8221; network, well, you know the problem you&#8217;re seeing!</p>
<p>I actually had a similar problem in a hotel room during the Consumer Electronics Show recently, where the first night I was there I used the hotel network &#8220;Encore &#8211; Rooms &#8211; Wireless&#8221;, but then set up a wireless router so my roommate and I could share a single connection.</p>
<p>In the pull-down menu from the wifi icon on the menu bar, I saw this:</p>
<p><img src="http://www.askdavetaylor.com/5-blog-pics/mac-forget-wireless-wifi-network-1.png" alt="mac forget wireless wifi network 1" title="mac forget wireless wifi network 1" border="0" height="213" width="295"></p>
<p>The shortcut to get the right spot to change or forget the preferred wireless network can be reached by choosing &#8220;Open Network Preferences&#8230;&#8221; at the bottom of that menu, which takes you here:</p>
<p><img src="http://www.askdavetaylor.com/5-blog-pics/mac-forget-wireless-wifi-network-2.png" alt="mac forget wireless wifi network 2" title="mac forget wireless wifi network 2" border="0" height="359" width="415"></p>
<p>Don&#8217;t worry about what network it shows you as connected to at this point. You want to click on the &#8220;Advanced&#8221; button:</p>
<p><img src="http://www.askdavetaylor.com/5-blog-pics/mac-forget-wireless-wifi-network-3.png" alt="mac forget wireless wifi network 3" title="mac forget wireless wifi network 3" border="0" height="322" width="415"></p>
<p>Now scroll down and find the network in question. It&#8217;ll be somewhere on the list:</p>
<p><img src="http://www.askdavetaylor.com/5-blog-pics/mac-forget-wireless-wifi-network-4.png" alt="mac forget wireless wifi network 4" title="mac forget wireless wifi network 4" border="0" height="322" width="415"></p>
<p>Click on the &#8220;-&#8221; button and that wifi network is no longer on the preferred list. Also notice that right below it is the option to &#8220;Remember networks this computer has joined&#8221;: if you want to choose a network each and every time just unselect it.</p>
<p>Done?  Just click on the red button on the top left and it&#8217;ll ask if you want to save the changes:</p>
<p><img src="http://www.askdavetaylor.com/5-blog-pics/mac-forget-wireless-wifi-network-5.png" alt="mac forget wireless wifi network 5" title="mac forget wireless wifi network 5" border="0" height="120" width="415"></p>
<p>That&#8217;s all there is to it. Good luck, and thanks for not stealing bandwidth. <img src='http://www.networknewz.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a href="http://www.askdavetaylor.com/mac_forget_known_preferred_wifi_wireless_network.html">Comments</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.networknewz.com/2011/01/31/how-to-forget-networks-on-your-mac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Combat A DDoS Attack On Your Network</title>
		<link>http://www.networknewz.com/2010/04/05/how-to-combat-a-ddos-attack-on-your-network/</link>
		<comments>http://www.networknewz.com/2010/04/05/how-to-combat-a-ddos-attack-on-your-network/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 12:30:48 +0000</pubDate>
		<dc:creator>Dave Taylor</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Network]]></category>

		<guid isPermaLink="false">http://www.networknewz.com/?p=139</guid>
		<description><![CDATA[If you&#8217;re reading this, odds are you are under attack. Your Web server is being crushed under the extraordinary load of thousands or even millions of bogus requests. How do you deal with it? Before we jump into that, a quick definition, courtesy of Wikipedia: A distributed denial of service attack (DDoS) occurs when multiple [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re reading this, odds are you are under attack. Your Web server is being crushed under the extraordinary load of thousands or even millions of bogus requests. How do you deal with it?</p>
<p>Before we jump into that, a quick definition, courtesy of Wikipedia:</p>
<p><span id="more-139"></span></p>
<p>A distributed denial of service attack (DDoS) occurs when multiple systems flood the bandwidth or resources of a targeted system, usually one or more web servers. These systems are compromised by attackers using a variety of methods, though most commonly it&#8217;s due to malware or trojan attacks, either pre-scheduled or triggered by an external event.</p>
<p>There are a number of ways to deal with a DDoS attack, but to find out best practices, I checked with a top sysadmin, who offered this advice based on a recent experience he had with a client site:</p>
<p>As you may know, one of our ecommerce customers suffered a devastating DDoS attack which started early Friday morning and lasted until we finally contracted with a DDoS mitigation service late Saturday night. The service was implemented by pointing the &#8220;A&#8221; record for the domain to their server. The cost of the service was $350 per month plus $150 setup. </p>
<p>The effects of the attack stopped instantly once DNS resolved to their IP. </p>
<p>There are several of these companies around. All seem to have about the same price structure for the same services. I didn&#8217;t do much research but choose the first one to respond on a Saturday. All likely had support available on the weekend but sales staff apparently get time off.</p>
<p>Gathering the information on the attack has been somewhat difficult since during the attack our server was virtually shut down. In fact the only way we were able to get access to shell was to change the DNS to point to a different server then establish an ssh login and run &#8220;top&#8221; or something similar to keep it open when we switched it back.</p>
<p>It is interesting to note that the attack followed DNS according to the TTL set. We had had it down to 10 seconds as we were in the process of moving the account from one server to another when the attack occurred. The attack followed the DNS within 10 seconds or less. There was very little residual attack activity after the DNS switched and that stopped within a minute or two.</p>
<p>So here is what we think we encountered based on information from the colo support&#8217;s anecdotal observations and information from the mitigation service after we blocked the attack. It is interesting to note that the mitigation service does not log activity so the information they provided is from spot observations rather than reliable metrics.</p>
<p>1. Incoming IPs were estimated at reaching as much as 100/sec. Each IP attempted to open between 5 to 25 connections</p>
<p>2. IPs were from all around the net but a sufficient number were from the US so that trying to isolate by country was useless (the customer was not regional but does business across the US).</p>
<p>3. At any one time the number of unique IPs was between three and four hundred. Since the software on the mitigation servers expires the IPs it blocks after 15 minutes and we did not see many instances of the same IPs recurring, the IP pool must have be in the thousands.</p>
<p>4. The sustained attack was estimated to be less than 20MB/sec however an accurate measurement is not available.</p>
<p>Observations:</p>
<p>1. Apache based access control lists proved useless. Apache simply ran out of processes within the first wave and stopped before it could even begin to reject connections. Turning keep alive off and other tuning tricks might have helped if the attack was significantly less but provided no relief as apache was simply swamped in the first few milliseconds.</p>
<p>2. When traffic was moved to a more powerful host it might have been possible to use the firewall by using a script to build the IPtables, however the number of entries in the IP table are limited and the unique IPs exceeded three hundred at a time. That fact plus the overhead of the script and the constant updating of the tables would have brought the server to its knees and the excess IP would still have flooded Apache. </p>
<p>Solutions such as running http as server type inetd (a significant performance hit in itself) with a massive deny list or a very restrictive allow list in the hosts.allow file might have given us back control of the server but would have done little to bring customers back since the store sells country wide and if you arbitrarily block massive ranges of IPs you block customers too. We could have spent days trying to identify safe ranges and never succeeded.</p>
<p>3. There is an additional complication in that the traffic looks like normal traffic with proper handshake and all. Scripts that flag IPs based on the number of connections would only be partially effective since the first few connection would be allowed until the max was reached. The techs at the mitigation service revealed that they relied on pattern matching and signatures which means to be totally effective scripts would need to be constantly updated by someone or some other service similar to virus and spam protection schemes.</p>
<p>4. This level of attack would probably be sustainable by a server with a reasonable firewall implementation in place, although some performance degradation would likely be evident.</p>
<p>5. Finally we were told by knowledgeable sources that there were multiple attacks of this kind against other websites that are in the same business as our customer. According to our sources this is not uncommon. The attacks are not random mischief but are paid for by someone to whittle down the completion. Also this was really a modestly sever attack. I&#8217;m told that attacks of hundreds of time more severity than we saw happen regularly.</p>
<p>Take Aways:</p>
<p>Attacks are not likely the result of anything a website owner may have done. You cannot avoid them simply by not offending anyone. If you have any standing in the search engines you will get targeted when someone decides they want the traffic your industry is serving.</p>
<p>You can not wait until an attack occurs to plan for it. Moving to a better hosted server and adding protocols to mitigate attacks will help with smaller attacks and may give you early warning of a larger attack. This attack started sporadically with reports of the server being slow several days before. We do not know if that was testing or if there is just some normal ramp up to an attack like this.</p>
<p>Smaller server setups simply do not have the resources to fend off even a moderate attack. If you can&#8217;t justify putting each ecommerce site on its own managed private server (yeah that&#8217;s going to happen) then perhaps getting an MPS and stacking several accounts on each with separate IPs might be a solution. Hopefully only one of your accounts gets attacked at once and perhaps the MPS firewall could be made to be effective at protecting all of the sites (needs a little engineering I suspect).</p>
<p>Better still create your own DMZ and front end all of your accounts with a robust firewall appliance (probably not as easy as it sounds).</p>
<p>All in all this has been a wakeup call for us. It is without a doubt a topic that we will give great attention to from now on. I hope this post will be helpful to you all and I thank you all again for your suggestions and offers of help.</p>
<p><a href="http://www.askdavetaylor.com/deal_with_ddos_distributed_denial_of_service_attack.html">Comments</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.networknewz.com/2010/04/05/how-to-combat-a-ddos-attack-on-your-network/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Changing The Network Name On Your iMac</title>
		<link>http://www.networknewz.com/2009/06/29/changing-the-network-name-on-your-imac/</link>
		<comments>http://www.networknewz.com/2009/06/29/changing-the-network-name-on-your-imac/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 15:33:51 +0000</pubDate>
		<dc:creator>Dave Taylor</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Restrictions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.networknewz.com/?p=68</guid>
		<description><![CDATA[I just bought a used iMac and am frustrated to find that it identifies itself as &#8220;Susie&#8217;s Q&#8221; on the network. Since I&#8217;m not Susie &#8211; and never have been! &#8211; I really want to change this. How do I change my iMac&#8217;s name in Mac OS X on the network? Dave&#8217;s Answer: The way [...]]]></description>
			<content:encoded><![CDATA[<p>I just bought a used iMac and am frustrated to find that it identifies itself as &#8220;Susie&#8217;s Q&#8221; on the network. Since I&#8217;m not Susie &#8211; and never have been! &#8211; I really want to change this. How do I change my iMac&#8217;s name in Mac OS X on the network?</p>
<p><span id="more-68"></span></p>
<p></p>
<p>Dave&#8217;s Answer:</p>
<p>The way that Mac OS X and its underlying Unix foundation are designed, it&#8217;s relatively easy to set up account and computer names and related on first run, but can be quite complicated to change them once you&#8217;ve gotten apps installed, documents created and otherwise have used the machine for a while.</p>
<p>In fact, I recently changed the admin account on a MacBook, including the home directory, and it took almost half an hour of careful steps, most done from the Terminal at the command line, before I was convinced it was done correctly and wouldn&#8217;t blow up on the new owner of the system when they tried to restart or log in.  (if you&#8217;re trying to do that, you might well find that the Apple support docs are insufficient for 10.5 and above too)</p>
<p>Changing the name of your used iMac on the network shouldn&#8217;t be quite so difficult because there&#8217;s a place in the System Preferences to do just that, but what is a bit tricky is that you have to change the name twice for it to work.</p>
<p>First off, go to <b>Apple</b> &#8211;&gt; <b>System Preferences&#8230;</b>. You&#8217;ll see this:</p>
<p><img src="http://www.askdavetaylor.com/3-blog-pics/apple-mac-system-preferences.png" alt="apple mac system preferences" width="500" border="0" height="419"></p>
<p>What you seek here is &#8220;Sharing&#8221;, almost exactly dead-center in the window.</p>
<p>Click on it and you&#8217;ll jump into the sharing configuration window:</p>
<p><img src="http://www.askdavetaylor.com/3-blog-pics/apple-mac-system-preferences-sharing.png" alt="apple mac system preferences sharing" width="500" border="0" height="409"></p>
<p>As you can see, I already have a name collision on my network, which is why this computer is identifying itself as &#8220;Dave&#8217;s MacBook Pro (2)&#8221;: the &#8220;(2)&#8221; is added by Mac OS X when it finds another computer on the network with the same name. Not so good, but let&#8217;s fix things in order. First, click on the &#8220;Edit&#8230;&#8221; button:</p>
<p><img src="http://www.askdavetaylor.com/3-blog-pics/apple-mac-system-preferences-sharing-edit-name.png" alt="apple mac system preferences sharing edit name" width="490" border="0" height="187"></p>
<p>Change the computer name here to what you want to have as your computer&#8217;s identity on the local network, and click &#8220;OK&#8221;.</p>
<p>Now, while you&#8217;re at the main Sharing window, change the name here too:</p>
<p><img src="http://www.askdavetaylor.com/3-blog-pics/apple-mac-system-preferences-sharing-edit-name-2.png" alt="apple mac system preferences sharing edit name 2" width="500" border="0" height="75"></p>
<p>If you close this window and restart the computer, you should find that your iMac now identifies itself with the new name you&#8217;ve specified.</p>
<p>Good luck with your new Apple iMac!</p>
<p><a href="http://www.askdavetaylor.com/how_to_change_imac_mac_name_on_network.html">Comments</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.networknewz.com/2009/06/29/changing-the-network-name-on-your-imac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

