2010년 11월 3일 수요일

239.255.255.250:1900

NOTIFY * HTTP/1.1
HOST: 239.255.255.250:1900
CACHE-CONTROL: max-age=100
LOCATION: http://192.168.1.1:1900/igd.xml
NT: uuid:060b7353-fca6-4070-85f4-
NTS: ssdp:alive
SERVER: ipos/7.0 UPnP/1.0 TL-WR941/2.0
USN: uuid:060b7353-fca6-4070-85f4-

Disable Windows Messenger broadcasts on UDP port 1900

In XP, the Simple Service Discovery Protocol (SSDP) discovery service searches for Universal Plug and Play devices on your home network. SSDP searches for upstream Internet gateways using UDP port 1900 - a potential security risk many organizations will want to block. OK, you decide to block SSDP services but to your surprise, your firewall and network sniffers continue to see the UDP port 1900 packets. You have disabled XP's SSDP and even Universal Plug and Play Device Host. Whats going on? This is Universal Plug and Play Network Address Translation (NAT) traversal discovery used by Messenger. If you run a sniffer trace, the following information is displayed in the data section of the packet:

SSDP: Method = M-SEARCH
SSDP: Uniform Resource Identifier = *
SSDP: HTTP Protocol Version = HTTP/1.1
SSDP: Host = 239.255.255.250:1900
SSDP: Search Target = urn:schemas-upnp-org:device:InternetGatewayDevice:1
SSDP: Mandatory Extension = "ssdp:discover"
SSDP: Maximum Wait = 3
XP's Windows Messenger is attempting to communicate to an Internet host. To block Windows Messenger's broadcasts:

Hive: HKEY_LOCAL_MACHINE
Key: Software\Microsoft\DirectPlayNATHelp\DPNHUPnP
Name: UPnPMode
Type: REG_DWORD
Value: 2 disabled
With UPnPMode=2, Universal Plug and Play Network Address Translation (NAT) traversal discovery does not occur.

2010년 9월 8일 수요일

아 ㅅㅂ Onenote

이런 말도 안되는 빵꾸가...
OneNoteOfflineCache_Files

C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\OneNote\12.0\OneNoteOfflineCache_Files

음성이고 파일이고...이건 비밀번호 걸어두는게 의미가 없자나 -_ -;

2010년 4월 18일 일요일

windows wget

disk encryption software

Free open-source disk encryption software for Windows 7/Vista/XP, Mac OS X, and Linux


공짜다! 프리웨어다! 근데 오픈소스이기도 하다!

http://www.truecrypt.org/

언어팩도 있다!


아래..자세한 설명이 있어서 별첨..
http://blog.naver.com/hahaj1?Redirect=Log&logNo=20066993267

2010년 4월 15일 목요일

윈도우에서 리눅스 명령어 사용하기


UnxUtils.zip

괜츈한 공개/오픈소스 프로그램

1. Nessus : 취약점 scanner. NASL 이라는 script 로 제작된 signature 의 plug-in 방식.
2. Snort : IDS. 대부분의 상용 IDS 도 snort 기반이라죠.
3. Nagios : 모니터링 툴. 네트워크와 시스템의 상태를 그래프로 보여줍니다.
4. SpamAssassin : Spam 차단. 학습을 시켜서 똑똑하게 만들면 SPAM 95% 이상 없앨수 있습니다.
5. ClamAV : 우리말로 백신인 안티바이러스(Anti-virus). 하루에서 몇 번씩 pattern 이 업데이트 됩니다.
6. OpenSSL : Secure 전송해주는 고마운 툴킷과 암호화 library.
7. OpenSSH : Secure Shell.  Telnet/FTP 말고  SSH/SFTP 사용합시다.
8. Nmap : 포트 스캐너 라고 만 하기엔 기능이 너무 다양한 스캐너. 옵션이 너무 많아서 걱정.
9. Ossec HIDS : 자칭, 타칭 Host 기반 IDS 의 최고.
10. Wireshirk : ethereal 의 새 이름. 패킷 캡처(pcap) 분석기

Open Source Security Apps

[The Top 75 Open Source Security Apps]
http://www.esecurityplanet.com/article.php/3741146

[26 Open Source Security Apps with Commercial Support]
http://itmanagement.earthweb.com/secu/article.php/3799501/26-Open-Source-Security-Apps-with-Commercial-Support.htm

A little over a year ago, we took a look at 10 Commercial Open Source Security Vendors. As we set out to update that list, two facts jumped out: 1) the number of open source security apps with commercial support has grown substantially and 2) the line between open source and commercial applications continues to blur.

On the one hand, open source developers want to find a way to make money from their projects. On the other hand, many application users, particularly enterprise users, are looking for applications with fee-based support. Rightly or wrongly, they feel that paying a fee brings greater accountability, and often these users lack the skills to manage open source apps on their own and would rather pay someone else to do it.

With pressure from both sides, it's no wonder that so many open source security applications now have commercial components. In all, we’ve covered 26 open source applications that have fee-based support available in some form.

It's also worth noting that the revenue models for that fee-based support vary substantially from project to project. Our list includes subscription-based services where users pay a yearly or monthly fee for access to e-mail or telephone assistance, as well as "open core" products, which are based on open source projects but incorporate additional features.

Other projects on the list provide links to third parties, often "mom-and-pop" style shops, who can provide support and consulting on a small scale. And one enterprising developer simply offers his own services as an independent contractor as his project's "commercial support.


"No matter which revenue model they use, the apps on this list offer users the best of both worlds—the flexibility, security, and cost savings of open-source combined with the peace of mind that comes with commercial support.

Anti-Spam

1. SpamAssassin

SpamAssassin is not only one of the best open-source anti-spam solutions available, it's also one of the best anti-spam solutions period. The project developers do not provide commercial support directly, but they do offer a list of third-party vendors who offer supported products or services based on SpamAssassin. Operating System: OS Independent.

2. Mailwasher

Mailwasher comes in two flavors: Mailwasher Server is the free, open-source version and Mailwasher Pro is the commercially supported version. A new Enterprise Server edition is due to be released soon. Operating System: Windows, Linux, Unix, Solaris

Anti-Virus

3. ClamAV

One of the best-known open-source security applications available, ClamAV is often embedded in commercial applications. You can also buy commercial support (sold as "Certified ClamAV") from Sourcefire, the project's owner. Operating System: Unix, Linux, BSD.

Data Removal

4. Eban

Eban is the enterprise version of Darik's Boot and Nuke (also known as Dban). In additional to professional support, the enterprise version adds a couple of notable features: network booting (so you can erase a lot of hard drives at once) and advanced reporting. Operating System: OS Independent.

Firewall

5. IPCop

Designed for small businesses, IPCop turns any PC into a Linux-based network firewall appliance. Support is not available directly from the project owners, but the site does list a number of consultants located around the world who provide fee-based support. Operating System: Linux.

6. Smoothwall

This commercial version is based on "the world's favorite" open-source firewall, Smoothwall Express. In addition to the firewall software, Smoothwall also offers gateway appliances and web security/content filtering, email security/anti-spam, and bandwidth management (QoS) software. Operating System: Linux, Unix.

7. Vuurmuur

Vuurmuur acts as a firewall manager for iptables on Linux. This is a smaller project than some of the more well-known open-source firewalls, and as such it takes a pretty unique approach to fee-based support. If you click the "commercial support" link, you'll find that the project owner is willing to contract himself out as a consultant. Operating System: Linux.

8. Vyatta

We've classified it with the firewalls, but Vyatta (vee-AH-ta, sanskrit for "Open") also includes a router, intrusion prevention, and VPN. Various levels of support are available by subscription and pre-configured appliances are also available. Operating System: OS Independent.

9. AppArmor

While most of the firewalls on our list are network firewalls, AppArmor is an application-level firewall that makes sure programs only do what they're supposed to do. You can download it as a standalone program, but it's also included in Novell's openSUSE and SUSE Linux Enterprise. Operating System: Linux.

10. ModSecurity

Another Web application firewall, ModSecurity provides real-time monitoring and anlysis of attacks. Hardened appliances and commercial support are available from project developer Breach Security. Operating System: OS Independent.

Intrusion Detection and Prevention (IDS/IPS)

11. Snort

Sourcefire, developer behind ClamAV, also manages Snort, "the de facto standard for intrusion prevention." On the Sourcefire web site, you'll find a number of commercially supported products based on Snort, as well as training and support. Operating System: Linux, Unix, BSD, Mac OS X.

12. OSSEC

With more than 5,000 downloads a month, this IDS is among the world's most popular. Commercial support is available through Third Brigade. Operating System: Windows, Mac, Linux, Unix, BSD, Solaris.

Inventory Management

13. OCS Inventory NG

Having an up-to-date list of the hardware and software on your network can be invaluable for security planning. This handy app simplifies inventory management and deployment of new technology. Commercial support is available through the sservice partners listed on the site. Operating System: OS Independent.


14. Zimbra

As a messaging and collaboration suite, Zimbra isn't exactly a security solution. However, because it includes built-in anti-virus (provided by ClamAV) and anti-spam capabilities, we felt it was worth inclusion. In addition to the open-source version, Zimbra comes in a multitude of commercially supported flavors that each offer a different feature set. Operating System: Linux, Unix, OS X.

Network Monitoring

15. SNARE

Intersect Alliance offers a number of open-source SNARE (System iNtrusion Analysis and Reporting) agents which provide log analysis for a variety of platforms. If you want commercial support, you can purchase their SNARE server, which is a Linux-based appliance. Operating System: Windows, Linux, Unix, Solaris.

16. Tripwire

Tripwire audit and control software lets you know when changes have been made to your IT configuration. The Enterprise and Server editions are based on the open-source version and offer additional features and commercial support. Operating System: Linux, Unix

17. Nagios

Nagios offers enterprise-class monitoring for systems, applications, or networks. The Nagios Enterprises group offers commercial support and consulting. Operating System: Linux, Unix.

18. Wireshark

"The de facto standard" network protocol analyzer, Wireshark offers deep inspection of hundreds of protocols, live capture for offiline analysis, VOIP analysis, and much more. Support and training are both available through Cace Technologies. Operating System: Windows, Mac, Linux, Unix, BSD, Solaris.

19. ntop network monitoring app. Nmon offers both software and hardware for packet capture and analysis. Operating System: Windows, Linux, Unix.

Passwords and Authentication

20. WiKID

On this site you'll find both the free, open-source community edition of WiKID two-factor authentication software and the proprietary commercial version. In addition to support, the commercial edition adds a few features that aren't available for free. Operating System: OS Independent.

Unified Threat Management (UTM)

21. Endian Firewall

Endian sells a variety of UTM appliances built on the successful, open-source Endian Firewall Community Edition. If you prefer to create your own appliance using an old PC but still want support, Endian will also sell you a supported version of the software. Operating System: Linux.

22. Untangle

Untangle combines 18 separate applications (anti-virus, anti-spam, web filtering, firewall, etc.) into a single package that can be downloaded for free (Open Source Package) or purchased with subscription-based support (Professional Package). Either way, you will need one or more dedicated PCs to run the software, because Untangle does not sell pre-configured appliances. Operating System: Linux.

Virtual Private Network (VPN)

23. OpenVPN

Winner of numerous awards, OpenVPN provides medium and large enterprises with remote access, site-to-site VPNs, Wi-Fi security, and more. Although commercial support isn't available yet, this ap snuck onto the list because the Web site promises that commercial support will be available soon. Operating System: Windows, Linux, Mac OS X, Solaris, BSD

Vulnerability Assessment

24. Nessus

The newest versions of the Nessus network vulnerability scanner are closed-source (though still largely available for free). However, we included Nessus on our list because it's based on the older open-source version, which is still available on the site, and it offers enterprise-grade commercial products for network monitoring. Operating System: Windows, Linux, Mac OS X, Solaris, BSD.

25. Milescan Web Security Auditor

Milescan is the commercial version of Paros. Java-based, this scanner intercepts all http and https data transmitted between server and client to help evaluate the security of Web applications. Operating System: OS Independent.

Web Filtering

26. iSAK

Short for "Internet Secure Access Kit," iSAK controls access to Web sites based on user-defined rules and provides a variety of reports. Commercial support is available through Savoir-Faire Linux. Operating System: Linux, Unix.

2010년 2월 24일 수요일

바이러스 백신 소프트웨어 공급업체 목록

http://support.microsoft.com/default.aspx/kb/49500



바이러스 백신 소프트웨어는 바이러스를 감지하고 예방하도록 특별히 설계된 소프트웨어입니다. 컴퓨터에서 바이러스 백신 소프트웨어를 사용하는 것이 좋습니다. 이 문서에는 독립된 바이러스 백신 소프트웨어 공급업체 목록이 포함되어 있습니다.

다양한 Microsoft 제품에서 동작하도록 설계된 추가 바이러스 백신 리소스와 바이러스 백신 제품 목록을 보려면 다음 Microsoft 웹 사이트를 방문하십시오.

AhnLab, Inc.

  • V3
  • ACS
V3와 ACS에 대한 자세한 내용을 보려면 다음 AhnLab, Inc. 웹 사이트를 방문하십시오.

Aladdin Knowledge Systems

  • eSafe
eSafe에 대한 자세한 내용을 보려면 다음 Aladdin Knowledge Systems 웹 사이트를 방문하십시오.

ALWIL Software

  • avast!
avast!에 대한 자세한 내용을 보려면 다음 ALWIL Software 웹 사이트를 방문하십시오.

Authentium, Inc.

  • Windows용 Command Antivirus(tm)
Windows용 Command Antivirus(tm)에 대한 자세한 내용을 보려면 다음 Authentium, Inc. 웹 사이트를 방문하십시오.

Avira

  • Avira AntiVir
Avira AntiVir에 대한 자세한 내용을 보려면 다음 Avira 웹 사이트를 방문하십시오.

Computer Associates International, Inc.

  • eTrust Antivirus
eTrust Antivirus에 대한 자세한 내용을 보려면 다음 Computer Associates International, Inc. 웹 사이트를 방문하십시오.

Doctor Web, Ltd.

  • Dr. Web
Dr. Web에 대한 자세한 내용을 보려면 다음 웹 사이트를 방문하십시오.

Eset

  • NOD32
NOD32에 대한 자세한 내용을 보려면 다음 Eset 웹 사이트를 방문하십시오.

FRISK Software International

  • F-Prot Antivirus
F-Prot Antivirus에 대한 자세한 내용을 보려면 다음 FRISK Software International 웹 사이트를 방문하십시오.

F-Secure Corp.

  • F-Secure Anti-Virus
F-Secure Anti-Virus에 대한 자세한 내용을 보려면 다음 F-Secure Corp. 웹 사이트를 방문하십시오.

GFI Software Ltd

  • Microsoft Exchange/SMTP용 GFI MailSecurity
  • ISA Server용 GFI WebMonitor
자세한 내용을 보려면 다음 GFI Software Ltd 웹 사이트를 방문하십시오.

Grisoft

  • AVG Anti-Virus
AVG Anti-Virus에 대한 자세한 내용을 보려면 다음 Grisoft 웹 사이트를 방문하십시오.

HAURI Inc.

  • ViRobot Expert
ViRobot Expert에 대한 자세한 내용을 보려면 다음 HAURI Inc. 웹 사이트를 방문하십시오.

Kaspersky Lab

  • Kaspersky Anti-Virus
Kaspersky Anti-Virus에 대한 자세한 내용을 보려면 다음 Kaspersky Labs 웹 사이트를 방문하십시오.

McAfee, Inc.

자세한 내용을 보려면 다음 McAfee, Inc. 웹 사이트를 방문하십시오.

Microsoft Corporation

  • Microsoft Security Essentials
Microsoft Security Essentials에 대한 자세한 내용은 다음 Microsoft 웹 사이트를 참조하십시오.

MicroWorld Technologies, Inc.

  • eScan
eScan에 대한 자세한 내용을 보려면 다음 MicroWorld Technologies, Inc. 웹 사이트를 방문하십시오.

Norman

  • NVC(Norman Virus Control)
NVC에 대한 자세한 내용을 보려면 다음 Norman 웹 사이트를 방문하십시오.

Panda Software

  • Panda Titanium Antivirus
Panda Titanium Antivirus에 대한 자세한 내용을 보려면 다음 Panda Software 웹 사이트를 방문하십시오.

Proland Software

  • Protector Plus
Protector Plus에 대한 자세한 내용을 보려면 다음 Proland Software 웹 사이트를 방문하십시오.

Sophos

  • Sophos Anti-Virus
Sophos Anti-Virus에 대한 자세한 내용을 보려면 다음 Sophos 웹 사이트를 방문하십시오.

Sunbelt Software

  • VIPRE
VIPRE에 대한 자세한 내용을 보려면 다음 Sunbelt Software 웹 사이트를 방문하십시오.

Sybari Software, Inc.

  • Antigen
Antigen에 대한 자세한 내용을 보려면 다음 Sybari Software, Inc. 웹 사이트를 방문하십시오.

Symantec

자세한 내용을 보려면 다음 Symantec 웹 사이트를 방문하십시오.

Trend Micro, Inc.

  • PC-cillin 2003
PC-cillin 2003에 대한 자세한 내용을 보려면 다음 Trend Micro, Inc. 웹 사이트를 방문하십시오.

TrustPort

  • TrustPort Antivirus
  • TrustPort PC Security
TrustPort Antivirus 및 TrustPort PC Security에 대한 자세한 내용을 보려면 다음 TrustPort 웹 사이트를 방문하십시오.이 문서에 포함된 다른 공급업체의 연락처 정보는 기술 지원을 받는 데 도움을 주기 위한 것입니다. 이 연락처 정보는 예고 없이 변경될 수 있습니다. Microsoft는 이러한 다른 공급업체 연락처 정보의 정확성을 보증하지 않습니다.

바이러스와 웜을 예방하고 복구하는 방법에 대한 자세한 내용은 다음 문서 번호를 클릭하여 Microsoft 기술 자료 문서를 참조하십시오.
129972  컴퓨터 바이러스: 설명, 예방 및 복구

이 문서에 나와 있는 다른 공급업체 제품은 Microsoft와 무관한 회사에서 제조한 것입니다. Microsoft는 이들 제품의 성능이나 신뢰성에 관하여 명시적이든 묵시적이든 어떠한 보증도 하지 않습니다.

2010년 2월 9일 화요일

복동이 미투데이 오픈!

현재 칭구 1명 ㅋㅋㅋㅋㅋ

핸드폰 인증은 5번 실패로.. 다음달 부터..
돈내고 더 할 수 있게 하던가..이건멍뮈 -,.-

아무튼 열었고, 이제는 써봐야지



2010년 2월 5일 금요일

원격제어 세션시간 설정

원격제어 세션시간 설정하기
(mstsc/rdp)

관리도구 -> 터미널 서비스 구성 -> 연결 -> RDP-TCP 설정 -> Session 탭
Override User Settings 체크 후 시간설정



2010년 1월 30일 토요일

2010년 1월 28일 목요일

료마전

사카모토 료마

책으로도 읽고, 만화로도 보고, 이제는 드라마로 본다 ㅠㅠ
료마를 좋아하는 나로서는 이런 희소식이 아닐 수 없지 ㅠㅠ

무슨인물인지 별로 안 궁금한가?..ㅋㅋ
곧 료마의 마력에 빠지리라...

료마의 고향을 찾아 일본한번 가야겠다 ㅠㅠ


자세한 소식은 아래 사이트로 접속~

季景沁园

눈이 펑펑 내린 그날과 손님 한분 ㅋ

2010년 1월 23일 토요일

占い!人生グラフ LIFE GRAPH

재미로 보는 인생 굴곡 그래프
(스펀지에 소개된 무료할 때 즐기는 무료사이트)

占い!人生グラフ
http://uremon.com/life_graph/

한글
한자
중국어
영어

MY LIFE, May Be HAPPY !
즐거운 인생 ;)

2010년 1월 4일 월요일

한글 URL Decode

>>> import urllib
>>> print urllib.unquote("%b1%e2%ba%bb%b5%bf%c0%db")
기본동작
>>> print urllib.quote("기본동작")
%B1%E2%BA%BB%B5%BF%C0%DB
>>>

2010년 1월 2일 토요일

만리장성

달에서도 보인다는 만리장성..
중국에서는 남자라면 한번은 꼭 가봐야 한다고 하더라..
가서 보면 왜 만리장성인지 알게 된다
정말 길~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~다