Sunday, November 18, 2007

Remote Control Your Office PC when at Home

Most of the organizations today use their own VPN solution allowing their employee to access their office pc from home. This is generally limited to very few and eligible associates, but what about them who are not eligible. For our friends who do no have idea of VPN, let me give a brief introduction about this VPN. VPN is an abbreviation of Virtual Private Network. This is the network established between two computers over internet cloud. You may get a question, what is the difference between other computers connected over internet. The difference is that VPN is highly secured network, it establishes a tunnel between two computers so that other computers will not be able to interfere between this communication. This is highly secured and encrypted as most of the company data will flow over this tunnel. Generally a client is installed on your laptop to access office PC. But the new VPN technology called SSL is totally browser based and runs with some Active X controls installed on your laptop.

The above was a brief introduction to what is VPN. But our discussion today is about other methods of accessing your PC. Infact, using this software you can access any PC over internet. These two services are GotoMypc and LogMeinrescue, GotomyPC is a client based where, you need to install a client on the PC which you want to take control, whereas LogMein is browser based and works like a SSL VPN. I came to know about this services a year back but didn’t find time to review it on Technical Herald. Now I got the time, so doing the same, Lets see how you can use these services.

GotoMyPC

This is a direct remote control, a client should be installed and configured with an Access code on your office pc. For remote controlling your office PC, you can directly login to the site and click on connect button beside the name which you have given to your office PC. Let’s see step by step procedure to use this tool.

  • Login to gotomypc.com site and create an account to get a free 30 days trial to use this service.


  • I would recommend you to enter the credit card details, so that the account will be renewed after 30 days of trial period. But there is also another way to get the free trial without entering the credit card details.


  • If you close the browser without entering the credit card information, you will get a pop up advertisement as below:



  • Just click yes and you are in for installing the client. Installing the client will take a few minutes based on your connection speed.


  • While installing gotmypc client, you will be asked to enter the email address which you have used for logging onto the site. One more thing is Access Code which must be 8 characters in length.



  • All the above steps makes your office PC ready to be connected from home. Follow the below steps to remote control your office PC.

  • login to gotomypc.com site with the account used for configuring client on office pc.


  • You will see the name of your office PC in your account. Click on connect and you are in within few mins of installing ActiveX controls on your home pc.



  • You can also place a shortcut icon on your desktop so that you don’t have to login to the account while connecting your pc next time. For this, click on File and select create shortcut to “officepc” where officepc is the nick name given to the pc which you want to remote control


    This is how you can use Gotomypc service. Please check the Demo of this service here


    Logmein

    Another service is logmein, As I have mentioned above, this is just like SSL VPN solution. There is no need to install any client on the PC which you want to remotely login. This is generally used for commercial purpose by home based system administrators wherein, the technician can remotely login to customer’s desktop over internet to resolve the issue reported by customer. So you can find this useful only if you are working for such organization. However a trial version of this service can also be used for remote controlling your office PC. But only disadvantage is that, some one should be available near your office PC to accept the connection initiated by you. Lets see step by step procedure for using this serice.

  • First and foremost, is creating an account on the site Logmeinrescue


  • After creating a trial account, a technician console will be installed on the pc form which you want to initiate the connection.




  • This is just an Active X kind of control which will be installed on your desktop. However the connection is through the web browser over internet.


  • Technician console contains links for starting a new session. Click on this button will get one popup which contains the secure token to establish communication. You can communicate the token key to the person sitting on your office PC or you can also use the free email service to mail the secure link to that person


  • Clicking that link will bring your pc in your control, but not fully.


  • Now you need to click on start remote control button present on the technician console. This will generate a popup window on your office pc, to allow or cancel the connection. When allowed, you are in




  • Security Concerns


    Let me warn you, this is not the most secure way to remote control your office pc, hence most of the organizations might have already blocked these services from entering their network. The only security concern is that, as this whole connection is over internet, there is a possibility that your pc either office or home may be hacked by a bad guy. However in large scale organizations, this is protected by firewall system, but as you know bad guys can do what we cannot imagine. Both the organizations, Logmein and Gotomypc claims that this is very secure and that they do not store any official data that goes on during the communication over internet.




    Friday, November 16, 2007

    Apple fixes its Firewall Vulnerabilities

    In my last post on Sunday I have updated about the vulnerable Firewall in Apple’s latest operating system Leopard. As always, Apple has released a fix for this vulnerability. Below are the details for some of the updates released by Apple this week.







    One update was for Safari browser in tiger, Apple has released a update to get Safari to version 3.0 on earlier versions of its operating systems. Safari 3.0 is a default browser in Leopard. This is just like IE 7 update for windows xp which is a default browser in Vista. This update also fixes many vulnerabilities which could allow a bad guy over internet to execute malicious code on your machine. There are also updates released for earlier version Panther through a separate download link.

    Firewall Fix
    Yesterday there was also an update released for the firewall vulnerability in Apple’s latest OS Leopard. According to Apple, this update fixes the firewall vulnerability which was described in my Sunday’s post.

    Apart from all the above updates, there was also an update for Safari which runs on windows platform. This is a fix for several cross-browser scripting vulnerabilities which exists in Safari, if used on Windows platform.


    Read What Apple Has to Say

    About the security content of the Mac OS X 10.5.1 Update (client and server)


    About the security content of Mac OS X 10.4.11 and Security Update 2007-008


    About the Mac OS X 10.4.11 Update


    About the security content of Safari 3 Beta Update 3.0.4


    Thursday, November 15, 2007

    Top 5 Best Practices for Exchange Server 2007

    If you are a system Administrator managing Exchange Server or interested to learn about this server, then this one is for you. Early this year when Microsoft released Exchange Server 2007, this was a boon for IT market. Infact this server is used even in non IT industry. Microsoft has put together many new services to make our office life easier and the project is still moving. They are also in process of integrating this service with the newly established era by Microsoft which is “Unified Communication”. For the readers who are not in this field, let me give an overview. Exchange Server is the name given to one of the server softwares by Microsoft which is used for e-mail communication by an organization. You see the mail ID’s like Virast.Khan@technicalherald.com that is because of a exchange server in which the email id (called as mailbox) is created which we can access to send and receive mails with the client software which is Microsoft Outlook and few others.


    The best Practices of an Administrator managing Exchange Serve 2007 are as below:

  • Placing the exchange server in correct Network: As there will be many incoming and outgoing connections to this server, the network in which the server is placed really matter.


  • Use Security Configuration Wizard disable un-used connection ports as even a small security hole will be a major fallback.


  • Don’t Use Default certificates if you are using Microsoft’s firewall software ISA then you should know that there is no support for SNA (Subject Alternate name) in ISA 2004. To keep your support, you should upgrade to ISA 2006.


  • Disable HTTP connections if you have enabled web based access then make sure that encryption is on else snooping will be on.


  • Use client submission port. In Exchange 2007 you have different connectors for receiving and sending SMTP traffic.



  • Read indepth about each of the 5 above points at Microsoft Technet Center.

    Tuesday, November 13, 2007

    Android, the Future Phone’s OS.

    Google has entered the mobile market and this is not new to us. Google has been in news for all that they are trying to do to develop mobile market. Now it looks like the days are not very far away when we can see all the mobile phones running on Google’s software like presently all the desktops run on Microsoft’s windows softwares. With the announcement of GPhone (Gnome-e-Phone), Google has made us realize that they are not going to sit back in this market. Now Google has joined hands with some other firms to develop a open source software for mobiles, they want to develop a software which can run on any mobile phone. This Alliance is named as Open Handset Alliance. If this comes in, Google will definitely revolutionaries the mobile market as Microsoft did for PC market. Google has released the SDK for this OS Yesterday, which gave a push to the developers to start coding for this product which is due to start shipping in 2008

    This open source software is presently termed as Android. This will be based on Linux operating system. Android was a small firm which was overtaken by Google in early 2005. Some of the major firms which have joined hands with Google in this race are HTC (High Tech Computers), Intel, Motorola, Qualcomm, T-Mobiles and the list is still growing. The work is on its peek and Google has declared to release this phone early next year. The Alliance is spending nearly $10 million to develop this software. There are also speculations that the present hardware used is 32 MB RAM, 32 MB Flash and 200 MHz of processor however the alliance is working to get this numbers down. Andy Rubin, the director for Mobile platform at Google said that there are about 34 companies in this Alliance and every one has contributed their own share for the development of this operating system. When asked about the IPhone, he said that it is a different business, he also appreciated Apple’s effort in building high quality consumer products. By this we can also think of Apple joining the race with Google. I don’t think so, because Apple has revolutionaries the mobile industry with its IPhone and Google with GPhone. They both can be great competitors but not partners. Read a review about this software at CNet


    Get the latest from this development at Android

    Sunday, November 11, 2007

    Leopard's Firewall is Vulnerable

    After releasing its latest operating system named Leopard, Apple is suffering from a very bad security vulnerability. This is about the type of firewall used in Leopard. There were reports that this firewall doesn’t blocks all the programs which are marked under block category. Infact, it doesn’t work even if it is set to block all incoming connections. If you are new to Apple’s range of operating systems, please do not get confused by these names. Tiger was the name of previous version of Mac OS X and Leopard is the one which was released last month ie. Oct 26th. Tiger was named as Mac OS X 10.4 and Leopard as Mac OS X10.5 and here we are talking about Leopard.

    There are speculations that the firewall program automatically turns off while installing this operating system or while upgrading from the previous version. The major flaw is that, even if the user selects the option to block all incoming connections, an attacker can enter the computer easily just by injecting a small code via worm. This will lead to giving full control of your PC to the attacker. However if you have the extra security built into your router or you are using your Mac in an organization which has a hard core firewall solution, then you don’t have to worry at all.


    Rich Mogull a security analyst’s research about the firewall revealed the following outcomes. According to him, Leopard firewall has 3 options, one to block all incoming connections, second to allow all incoming connections and final to allow users to select the application level blocking facility. Another facility allows user to enable stealth mode, in which the system will be on high security area wherein, the attacker cannot even see the machine when he/she scans the internet for a victim. But Mogull’s study revealed that none of these settings behave in their normal fashion. Even the high secure stealth mode works partially and if the user sets the application level settings, the applications starts behaving abnormally. Some of which are Skype service which gets killed automatically. Some games are not running as they do on other operating systems, Adobe creative suite users have also complained about the performance issue. The Photoshop issue which is not running properly or crashing at the time of launch. Some wireless network problems the bandwidth getting chocked while browsing.


    So, don’t be in a confusion that your Leopard’s new sandboxing feature will protect your PC. I am sure Apple must be more worried than us, and very soon you will see a security patch to overcome this hurdle.

     
    ©2009 Technical Herald

    The articles are copyrighted to Virasat Khan and can only be reproduced given the author's permission