<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Walker News &#187; Security</title>
	<atom:link href="http://www.walkernews.net/category/software/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.walkernews.net</link>
	<description>A capsule of walker's experience in life...</description>
	<pubDate>Fri, 03 Oct 2008 03:00:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>How To Crack Targus DEFCON CL Laptop Lock BY CHANCE In 3 Seconds?</title>
		<link>http://www.walkernews.net/2008/07/20/how-to-crack-targus-defcon-cl-laptop-lock-by-chance-in-3-seconds/</link>
		<comments>http://www.walkernews.net/2008/07/20/how-to-crack-targus-defcon-cl-laptop-lock-by-chance-in-3-seconds/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 05:41:45 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Hardware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Cable Lock]]></category>

		<category><![CDATA[Crack]]></category>

		<category><![CDATA[DEFCON CL]]></category>

		<category><![CDATA[Howto]]></category>

		<category><![CDATA[Know-how]]></category>

		<category><![CDATA[Laptop]]></category>

		<category><![CDATA[Targus]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=827</guid>
		<description><![CDATA[Do you know how easy for someone to unlock or crack a laptop lock in just 3 seconds? Check this out...]]></description>
			<content:encoded><![CDATA[<p>Believe me, it&#8217;s not a 3-seconds or <a href="http://www.walkernews.net/tag/3-minutes/" title="All 3-minutes related posts in WalkerNews.net" rel="bookmark">3-minutes</a> job to unlock, to break or to crack a laptop cable lock, especially the Targus DEFCON lock that built with cut-resistant, vinyl-coated, galvanized steel cable and a user-settable combination lock with up to 10,000 possible settings!<br />
<!--more--><br />
<div style="float:left;margin:0px 10px 1px 0;"><script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
/* 250x250, created 7/2/08 */
google_ad_slot = "1128449464";
google_ad_width = 250;
google_ad_height = 250;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div>But, you&#8217;ll know how could someone &#8220;crack&#8221; your laptop lock &#8220;by chance&#8221; in just three seconds&#8230;</p>
<p>Question 1: Where do you normally use the laptop computer cable lock? Most likely the answer is in the office.</p>
<p>Question 2: How many people used to scramble or reset the security code after unlocking the laptop for a meeting at next door?</p>
<p>Well, I&#8217;m afraid that not many users remember to reset the security code, i.e. leave the cable lock in unlock state.</p>
<div id="attachment_829" class="wp-caption alignnone" style="width: 510px"><img src="http://www.walkernews.net/wp-content/uploads/2008/07/targus-defconcl-a.jpg" alt="How to crack a highly secured Targus DEFCON CL laptop lock in just 3 seconds?" title="How to crack a highly secured Targus DEFCON CL laptop lock in just 3 seconds?" width="500" height="305" class="size-full wp-image-829" /><br /><sup>How to crack a highly secured Targus DEFCON CL laptop lock in just 3 seconds?</sup></div>
<p>So, it happened last week in my office. A 3rd-party office cleaner, who came for cleaning works during lunch hour, stole a premium Dell XPS M1330 that was secured with a Targus DEFCON CL lock (the branded cable lock bundled with most Dell laptop package).</p>
<p>The CCTV footage shows that the guy unlocked the &#8220;super secured&#8221; cable lock as if he knows the security code.</p>
<p>Is there a <a href="http://www.walkernews.net/2007/04/01/unlock-nokia-cellphone-for-free/" title="Freeware to unlock a forgotten Nokia DCIT-4 security lock code." rel="bookmark">master unlock code</a> of this 30 over bucks cable lock, that allowed him to crack it so easily?</p>
<p>(We highly believe that) the answer is the careless of owner. The manager recalled that he used to leave the cable lock in unlock state whenever he took the laptop away his office, especially when rushed for a meeting.</p>
<p>So happen that he used to back his cubic after lunch in case the meeting was in morning session, and the cleaner is so smart to remember his security code of the cable lock that was left in unlock status.</p>
<p>That&#8217;s how the cleaner crack the Targus DEFCON CL Laptop lock <span class="subhead2">BY CHANCE</span> in 3 seconds on the next day lunch hour, when the manager left for lunch with his Dell laptop &#8220;locked&#8221; in office.</p>
<p>This careless could lead someone to break just any cable locks, not limited to the tough Targus DEFCON CL lock!</p>
<p>Verdict: Remember to scramble / reset the security code after unlock the laptop!<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/" title="Bypass Exchange Server Attachment Filtering System">Bypass Exchange Server Attachment Filtering System</a><br />&raquo; <a href="http://www.walkernews.net/2008/10/03/how-to-send-program-file-as-attachment-in-gmail/" title="How To Send Program File As Attachment In Gmail?">How To Send Program File As Attachment In Gmail?</a><br />&raquo; <a href="http://www.walkernews.net/2008/08/16/windows-movie-maker-how-to-extract-audio-track-from-video-clip/" title="Windows Movie Maker: How To Extract Audio Track From Video Clip">Windows Movie Maker: How To Extract Audio Track From Video Clip</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/how-to-reboot-or-shutdown-windows-vista-in-remote-desktop-connection/" title="How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?">How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/windows-movie-maker-fix-the-half-green-bar-problem-in-the-movie-made/" title="Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made">Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/15/how-to-fix-windows-photo-gallery-yellow-tint-and-photoshop-monitor-profile-problem/" title="How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?">How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/07/linux-dummy-guide-how-to-send-email-with-content-and-attachment/" title="Linux Dummy Guide: How To Send Email With Content And Attachment?">Linux Dummy Guide: How To Send Email With Content And Attachment?</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/07/20/how-to-crack-targus-defcon-cl-laptop-lock-by-chance-in-3-seconds/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How To Email Executable Program File In Gmail Or Hotmail</title>
		<link>http://www.walkernews.net/2008/06/25/how-to-email-executable-program-file-in-gmail-or-hotmail/</link>
		<comments>http://www.walkernews.net/2008/06/25/how-to-email-executable-program-file-in-gmail-or-hotmail/#comments</comments>
		<pubDate>Tue, 24 Jun 2008 17:28:27 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Attachment Filtering]]></category>

		<category><![CDATA[Email]]></category>

		<category><![CDATA[Embedded Object]]></category>

		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[Hotmail]]></category>

		<category><![CDATA[Howto]]></category>

		<category><![CDATA[Know-how]]></category>

		<category><![CDATA[Live Mail]]></category>

		<category><![CDATA[Microsoft Excel]]></category>

		<category><![CDATA[Microsoft Office]]></category>

		<category><![CDATA[Microsoft Word]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Tricks]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=787</guid>
		<description><![CDATA[Do you know that Gmail and Hotmail both disallow users to send or receive emails that attached with executable program files? How could you make it happen if you really need the email an exe program with these Internet email system?]]></description>
			<content:encoded><![CDATA[<p>Few hours ago, I wrote a post about <a href="http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/" title="How to bypass Exchange server attachment filtering system to email program file immediately, without asking email administrator to release the blocked email?" rel="bookmark">how to send an executable program file</a> with the office email server that enforce attachment filtering. (Although it&#8217;s a &#8220;useful&#8221; trick, but I hope the trick is applied in an ethical manner).<br />
<!--more--><br />
If you&#8217;re a student who relies on Internet email for communication, you might encounter similar problem where the attachment filtering system blocks emails that attach potentially dangerous file types from sending or receiving.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
With Yahoo! Mail, you can send and receive emails that attach executable program files (max 10MB). It&#8217;s working at this moment, but I believe this won&#8217;t be forever. Anyway, I guess that&#8217;s why most of my fellow friends and colleagues keep their Yahoo! Mail active, no matter how responsive the Gmail is.</p>
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/yahoo-mail-allow-exe-program-attachment.jpg" alt="Yahoo! Mail allows users to send and receive executable program files." title="Yahoo! Mail allows users to send and receive executable program files." width="415" height="231" class="alignnone size-full wp-image-789" /> </p>
<p>However, Gmail or Windows Live Mail (previous known as Hotmail) do not allow users to send and/or receive executable program files.</p>
<blockquote><p>
Hotmail / Windows Live Mail:<br />
Windows Live Mail has blocked some attachments in this email because they appear unsafe.</p>
<blockquote><p>Outlook / Ms Exchange Server:<br />
Outlook blocked access to the following potentially unsafe attachments:md5sum.exe</p></blockquote>
<p>Gmail:<br />
72.14.253.27 failed after I sent the message.<br />
Remote host said: 552-5.7.0 Our system detected an illegal attachment on your message.<br />
552-5.7.0 Please visit <a href="http://mail.google.com/support/bin/answer.py?answer=6590" target="_blank" rel="nofollow">http://mail.google.com/support/bin/answer.py?answer=6590</a></p></blockquote>
<p><span class="subhead">How to send program file in Gmail or Windows Live Mail</span></p>
<p>If you prefer Gmail or Hotmail (Windows Live Mail) than Yahoo! Mail, you can use the trick I mentioned in earlier post, i.e. embed the compressed executable program files (any blocked file types) into Microsoft Office document that support <a href="http://www.walkernews.net/2008/03/22/how-to-extract-swf-flash-from-excel-or-word/" title="How to extract embedded SWF flash object from Microsoft Excel?" rel="bookmark">embedded object</a> feature (e.g. Microsoft Word or Microsoft Excel) and then email the Office document as a normal attachment will do! (Again, I believe that this trick will fail eventually, if someone abuses it for non-ethical purpose!)</p>
<blockquote><p>You can&#8217;t simply compress or zip the executable program file and email it. Most of the email attachment filtering system, e.g. those available in Gmail or Exchange server, can scan compressed or zipped attachment files and block them from sending/receiving if any executable program is detected!</p></blockquote>
<p><span class="subhead2">How to embed a compressed program file into Microsoft Word document?</span> (<a href="http://www.walkernews.net/2008/02/25/youtube-video-direct-download-link/" title="How to extract the direct download link of YouTube flash video?" rel="bookmark">FLV video</a> played by <a href="http://www.walkernews.net/2008/01/11/how-to-embed-flv-flash-in-wordpress-or-html/" title="How to embed FLV flash video in html web page?" rel="bookmark">JW Media Player</a>)</p>
<p><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" width="500" height="380"><param name="flashvars" value="file=http://walkernewsdownload.googlepages.com/WalkerNews-Video-0041.flv&#038;image=http://walkernewsdownload.googlepages.com/Word-Embedded-Object-a.jpg" /><param name="movie" value="http://walkernewsdownload.googlepages.com/mediaplayer.swf" /><embed src="http://walkernewsdownload.googlepages.com/mediaplayer.swf" width="500" height="380" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" flashvars="file=http://walkernewsdownload.googlepages.com/WalkerNews-Video-0041.flv&#038;image=http://walkernewsdownload.googlepages.com/Word-Embedded-Object-a.jpg" /></object></p>
<p>Apparently, recipient has to open this attachment with Microsoft Word (not sure can Microsoft Word Viewer open the embedded object) and uncompress program (e.g. Winzip, Power Archiver, WinRar, etc) to extract the zipped executable program file.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/10/03/how-to-send-program-file-as-attachment-in-gmail/" title="How To Send Program File As Attachment In Gmail?">How To Send Program File As Attachment In Gmail?</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/" title="Bypass Exchange Server Attachment Filtering System">Bypass Exchange Server Attachment Filtering System</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/how-to-reboot-or-shutdown-windows-vista-in-remote-desktop-connection/" title="How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?">How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/windows-movie-maker-fix-the-half-green-bar-problem-in-the-movie-made/" title="Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made">Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/15/how-to-fix-windows-photo-gallery-yellow-tint-and-photoshop-monitor-profile-problem/" title="How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?">How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/05/how-to-read-iso-image-file-in-linux/" title="How To Read ISO Image File In Linux">How To Read ISO Image File In Linux</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/30/how-to-edit-and-rewrite-post-slug-or-permalink-in-wordpress-25/" title="How To Edit And Rewrite Post Slug / Permalink In WordPress 2.5?">How To Edit And Rewrite Post Slug / Permalink In WordPress 2.5?</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/25/how-to-email-executable-program-file-in-gmail-or-hotmail/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bypass Exchange Server Attachment Filtering System</title>
		<link>http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/</link>
		<comments>http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/#comments</comments>
		<pubDate>Tue, 24 Jun 2008 10:49:34 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Howto]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Attachment Filter]]></category>

		<category><![CDATA[Email Client]]></category>

		<category><![CDATA[Email Server]]></category>

		<category><![CDATA[Embedded Object]]></category>

		<category><![CDATA[Exchange Server]]></category>

		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[Know-how]]></category>

		<category><![CDATA[Microsoft Excel]]></category>

		<category><![CDATA[Microsoft Office]]></category>

		<category><![CDATA[Microsoft Word]]></category>

		<category><![CDATA[MS Outlook]]></category>

		<category><![CDATA[Office Document]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Tricks]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=783</guid>
		<description><![CDATA[How could you send an executable program file Gmail or Exchange server that filter attachment file types?]]></description>
			<content:encoded><![CDATA[<p>I was told to send an executable program file urgently to vendor for debugging. However, the Exchange server attachment filtering system block all emails that attached with potentially dangerous file types (e.g. exe, msi, bat, csh, wsh, vbe, etc).<br />
<!--more--><br />
To get this email relayed successfully, I&#8217;ve to inform email administrators at both end to release the email. Due to urgency, we can&#8217;t wait for the escalation processes that take some time to happen.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
So, what could I do to get my email bypass the attachment filtering system? There are two choices for you to try (both methods work well at this moment, but not they work forever):</p>
<p><span class="subhead">Using Microsoft Office program to embed the compressed executable file</span></p>
<p>This is the first option I&#8217;ve used this morning to email an executable program file to vendor.</p>
<p>By inserting the compressed executable program file as an embedded object in <a href="http://www.walkernews.net/2008/03/22/how-to-extract-swf-flash-from-excel-or-word/" title="How to extract the embedded FLV or SWF flash from Microsoft Excel document?" rel="bookmark">Microsoft Excel</a> / Word, the Exchange server attachment filtering system automatically &#8220;allow&#8221; the email that attach Microsoft Office document, to be send and receive at both end. </p>
<blockquote><p>This guide refer to <a href="http://www.walkernews.net/2007/06/04/office-2007-add-in-direct-download-for-firefox/" title="How to extract the direct download link of Microsoft Office 2007 Add-ins?" rel="bookmark">Microsoft Word 2007</a>. However, you may use Microsoft Excel 2007 or any other version of <a href="http://www.walkernews.net/2007/08/27/direct-download-office-2007-from-microsoft/" title="Direct download Microsoft Office 2007 for OEM users." rel="bookmark">Microsoft Office</a> program that support embedded object feature.</p></blockquote>
<ol>
<li>Compress the executable program file (or any other file types that the email attachment filtering system blocks by default).<br />
&nbsp;</li>
<li>Open Microsoft Word 2007, click Insert menu, look at the Text ribbon and click the Object icon to bring up the Object dialog box, go to Create From File tab, use the Browse button to select the compressed exe file and click OK to complete.
<p><a href='None'><img src="http://www.walkernews.net/wp-content/uploads/2008/06/insert-word-embedded-object-b.jpg" alt="Using Microsoft Word embedded object feature to bypass email server attachment filtering system." title="Using Microsoft Word embedded object feature to bypass email server attachment filtering system." width="341" height="113" class="alignnone size-full wp-image-786" /></a></p>
<p><a href='None'><img src="http://www.walkernews.net/wp-content/uploads/2008/06/insert-word-embedded-object-a.jpg" alt="Use Microsoft Word embedded object feature to insert a compressed executable file." title="Use Microsoft Word embedded object feature to insert a compressed executable file." width="450" height="308" class="alignnone size-full wp-image-784" /></a></p>
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/insert-word-embedded-object-2-a.jpg" alt="Embed compressed exe files into Microsoft Word to bypass email server attachment filtering system" title="Embed compressed exe files into Microsoft Word to bypass email server attachment filtering system" width="451" height="340" class="alignnone size-full wp-image-785" /><br />
&nbsp;</li>
<li>Now, send the Microsoft Word document (that embed the compressed executable file) as normal attachment.</li>
</ol>
<p><span class="subhead">Using Yahoo Mail! to send and receive executable file attachment</span></p>
<p>No special requirements for this method to work, except that you have to send and receive the email that attached with executable program files in Yahoo! Mail account. That&#8217;s to say, you don&#8217;t have to compress the exe file or embed it to MS Office document.</p>
<p>I tested it before and it still work at this time being. The testing just now proved that an email attached with md5sum.exe (28KB) can be sent from my Yahoo! Mail account and open by another Yahoo! Mail account as normal.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/06/25/how-to-email-executable-program-file-in-gmail-or-hotmail/" title="How To Email Executable Program File In Gmail Or Hotmail">How To Email Executable Program File In Gmail Or Hotmail</a><br />&raquo; <a href="http://www.walkernews.net/2008/10/03/how-to-send-program-file-as-attachment-in-gmail/" title="How To Send Program File As Attachment In Gmail?">How To Send Program File As Attachment In Gmail?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/how-to-reboot-or-shutdown-windows-vista-in-remote-desktop-connection/" title="How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?">How To Reboot or Shutdown Windows Vista In Remote Desktop Connection?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/20/windows-movie-maker-fix-the-half-green-bar-problem-in-the-movie-made/" title="Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made">Windows Movie Maker: Fix The Half Green Bar Problem In The Movie Made</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/15/how-to-fix-windows-photo-gallery-yellow-tint-and-photoshop-monitor-profile-problem/" title="How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?">How To Fix Windows Photo Gallery Yellow Tint and Photoshop Monitor Profile Problem?</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/05/how-to-read-iso-image-file-in-linux/" title="How To Read ISO Image File In Linux">How To Read ISO Image File In Linux</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/30/how-to-edit-and-rewrite-post-slug-or-permalink-in-wordpress-25/" title="How To Edit And Rewrite Post Slug / Permalink In WordPress 2.5?">How To Edit And Rewrite Post Slug / Permalink In WordPress 2.5?</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/24/bypass-exchange-server-attachment-filtering-system/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Secure Public PC And Shared Computer With Windows SteadyState</title>
		<link>http://www.walkernews.net/2008/06/17/secure-public-pc-and-shared-computer-with-windows-steadystate/</link>
		<comments>http://www.walkernews.net/2008/06/17/secure-public-pc-and-shared-computer-with-windows-steadystate/#comments</comments>
		<pubDate>Mon, 16 Jun 2008 17:31:42 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[OS]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Juzt-Reboot]]></category>

		<category><![CDATA[Microsoft]]></category>

		<category><![CDATA[System Administration]]></category>

		<category><![CDATA[Vista SP1]]></category>

		<category><![CDATA[Windows SteadyState]]></category>

		<category><![CDATA[Windows Vista]]></category>

		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=764</guid>
		<description><![CDATA[How easier and convenient to protect shared PC or public computers that running on Windows XP or Windows Vista? Microsoft Windows SteadyState has the answer!]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d077a52d-93e9-4b02-bd95-9d770ccdb431&#038;displaylang=en&#038;Hash=w6mSL4M5ppxzBTlh9H5ExFUprzAZ56E4mQT6EnGQ4bA1xUqF%2f%2ff%2fIj7CqQ8RTSy%2fMxlZrecrvRJjXQG6a06WxA%3d%3d" target="_blank" rel="nofollow">Windows SteadyState</a> makes Windows security administration easier for most average Windows users who are looking for ways to protect their shared PC and public computers.<br />
<!--more--><br />
You don&#8217;t have to be a Microsoft certified engineer (MSCE), but I thought even a professional administrator appreciates to have <a href="http://download.microsoft.com/download/a/f/4/af4fca6d-1202-4c30-a1bc-853e9a166695/SteadyState.msi" title="Direct download Windows SteadyState v2.5" target="_blank">Windows SteadyState</a> installed.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Windows SteadyState provides an intuitive graphical user interface (sort of TweakUI tool) to safeguard few ten units of shared PCs and public computers in a small network (with no luxury IT expenditures), such as cyber cafe, shopping mall, library, class room, learning centre, etc.</p>
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/windows-steadystate-1.jpg" alt=" Windows SteadyState v2.5 available for Windows XP and Windows Vista, to secure and protect shared PC and public computers." title="Windows SteadyState v2.5 available for Windows XP and Windows Vista, to secure and protect shared PC and public computers." width="500" height="336" class="alignnone size-full wp-image-765" /></p>
<p>If the <a href="http://www.juzt-reboot.com/" target="_blank" rel="nofollow">Juzt-Reboot</a> card is too costly, Windows SteadyState v2.5 is the FOC alternative! Windows Disk Protection is one of the really cool features of Windows SteadyState, where the service could discards all kind of changes made on the Windows system partition on next system boot!</p>
<p>That&#8217;s to say, the good and healthy state of Windows system partition will be reinstated, regardless of program installation/un-installation, Registry editing, setting changes, file deletions, etc, made by end users.</p>
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/windows-steadystate-14.jpg" alt="Windows SteadyState v2.5 is alternative to Juzt-Reboot card, where the service could discards any kind of changes made on Windows system partition." title="Windows SteadyState v2.5 is alternative to Juzt-Reboot card, where the service could discards any kind of changes made on Windows system partition." width="421" height="254" class="alignnone size-full wp-image-766" /></p>
<p>Unlike Windows Ultimate Extras, Windows SteadyState available for all editions of 32-bit Windows XP and Windows Vista, i.e. Windows XP Professional, Windows XP Home Edition, Windows XP Tablet PC Edition, Windows Vista Business, Windows Vista Ultimate, Windows Vista Home Basic, Windows Vista Home Premium, and Windows Vista Starter. However, the default installation will not proceed if the copy of these Windows OS could be validated as genuine copy.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/07/17/vista-lunar-calendar-download-microsoft-chinese-date-and-time-installer/" title="Vista Lunar Calendar: Download Microsoft Chinese Date And Time Installer">Vista Lunar Calendar: Download Microsoft Chinese Date And Time Installer</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/21/where-does-putty-keeps-ssh-host-key-fingerprint-in-windows-registry/" title="Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?">Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/30/how-to-extract-audio-music-from-a-video-clip-in-windows-movie-maker/" title="How To Extract Audio Music From A Video Clip In Windows Movie Maker">How To Extract Audio Music From A Video Clip In Windows Movie Maker</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/23/windows-vista-date-and-time-matter/" title="Windows Vista Date And Time Matter">Windows Vista Date And Time Matter</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/20/using-magicdisc-emulator-to-read-cd-image/" title="Using MagicDisc Emulator To Read CD Image">Using MagicDisc Emulator To Read CD Image</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/18/how-to-check-windows-last-boot-up-time/" title="How To Check Windows Last Boot Up Time">How To Check Windows Last Boot Up Time</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/12/how-to-cut-mp3-as-mobile-phone-ringtone/" title="How To Cut MP3 As Mobile Phone Ringtone">How To Cut MP3 As Mobile Phone Ringtone</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/17/secure-public-pc-and-shared-computer-with-windows-steadystate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Configure Secured Private Key For Password-less SSH Login</title>
		<link>http://www.walkernews.net/2008/06/09/configure-secured-private-key-for-password-less-ssh-login/</link>
		<comments>http://www.walkernews.net/2008/06/09/configure-secured-private-key-for-password-less-ssh-login/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 15:49:39 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Howto]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Authentication]]></category>

		<category><![CDATA[Cryptography]]></category>

		<category><![CDATA[Freeware]]></category>

		<category><![CDATA[Guide]]></category>

		<category><![CDATA[Key Management]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Non-Interactive]]></category>

		<category><![CDATA[Open Source]]></category>

		<category><![CDATA[PAgeant]]></category>

		<category><![CDATA[Password-less]]></category>

		<category><![CDATA[Private-key]]></category>

		<category><![CDATA[Protocol]]></category>

		<category><![CDATA[Public-key]]></category>

		<category><![CDATA[Putty]]></category>

		<category><![CDATA[Remote Access]]></category>

		<category><![CDATA[Secure Shell]]></category>

		<category><![CDATA[SSH]]></category>

		<category><![CDATA[SSH-Add]]></category>

		<category><![CDATA[SSH-Agent]]></category>

		<category><![CDATA[Tutorial]]></category>

		<category><![CDATA[Vista SP1]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=743</guid>
		<description><![CDATA[If the private key is secured with a passphrase, how to configure the ssh key manager to support non-interactive, password-less ssh login?]]></description>
			<content:encoded><![CDATA[<p>To enable non-interactive SSH login, you could generate <a href="http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/" title="How to setup a non-interactive ssh login session" rel="bookmark">a pair of password-less cryptographic keys</a> for the sake of simplicity, i.e. creates a private key that is not secured with a passphrase (by assuming the server that hosts private key is hardened).<br />
<!--more--><br />
However, what if the rigid security policies require a secured private key (even the server box and its daily system backup image are highly secured)?<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Well, the answer is to rely on key management software, key manager, or sort of. For example, the ssh-agent (<a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="How to configure OpenSSH for password-less ssh login?" rel="bookmark">OpenSSH package</a>) and Pageant.exe (<a href="http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/" title="How to configure Windows-based Putty to support non-interactive ssh login?" rel="bookmark">Putty suite</a>).</p>
<p><em>This trick doesn&#8217;t work for the scheduled shell script / batch file that needs non-interactive ssh login. See next post that cover this (as more works need to be done in order to <span class="subhead2">get ssh-agent works for cronjob</span>).</em></p>
<p><span class="subhead">How to configure ssh-agent</span> for secured private key to support non-interactive, password-less SSH login?</p>
<p>In my <a href="http://www.walkernews.net/2008/01/15/how-to-install-rhel4-in-hp-netserver-lh3000/" title="How to install RHEL 4 Update 5 on the aging HP NetServer LH 3000 server?" rel="bookmark">RHEL machine</a>, the ssh and ssh-agent bundled with OpenSSH package work very well for this job:</p>
<ol>
<li>Login to Linux machine and execute eval command to invoke ssh-agent, so that the environment variable (SSH_AUTH_SOCK and SSH_AGENT_PID) output by ssh-agent could be exported to the current shell. Take note that the back-quote <code>`</code> is used to enclose ssh-agent, not the normal single-quote <code>'</code>:
<pre>eval `ssh-agent`</pre>
</li>
<li>Next, use ssh-add command to add the secured private keys to ssh-agent. Enter the passphrase of the private key when prompted. For example, to add private key $HOME/.ssh/walkerkey to ssh-agent:
<pre>ssh-add ~/.ssh/walkerkey</pre>
</li>
</ol>
<p>Now, all ssh connections initiated from the current shell (before log out the current session) will be automatically authenticated via ssh-agent that caches the private keys.</p>
<p><span class="subhead">How to configure Putty Pageant.exe</span> for secured private key to support non-interactive, password-less SSH login?</p>
<ol>
<li><img style="float:right;margin:0 0 0 5px;" src="http://www.walkernews.net/wp-content/uploads/2008/06/putty-pageant-a.jpg" alt="Putty authentication tool - Pageant.exe is the windows-based ssh-agent that used to cache a secured private key" title="Putty authentication tool - Pageant.exe is the windows-based ssh-agent that used to cache a secured private key" width="241" height="49" />Locate the Putty folder and double-click <code>PAGEANT.exe</code> (will run in the Windows System Tray).<br />
&nbsp;</li>
<li><img style="float:right;margin:0 0 0 5px;" src="http://www.walkernews.net/wp-content/uploads/2008/06/putty-ssh-agent-a.jpg" alt="Windows ssh-agent called Pageant.exe, a Putty suite program." title="Windows ssh-agent called Pageant.exe, a Putty suite program." width="217" height="125" class="alignnone size-full wp-image-745" />Right-click the Pageant.exe in System Tray, click Add Key option, locate and open the private key, and enter the passphrase when prompted. (Alternatively, you can right-click Pageant.exe, click View Keys, followed by Add Key).<br />
&nbsp;</li>
<li>Now, initiate a SSH connection with Putty.exe to the target server and login with user ID that keeps the public key for the secured private key cached by Pageant.exe. You should notice that Putty automatically authenticate and a message (below) prints on the session window:
<p><strong>Authenticating with public key &#8220;dsa-key-20080609&#8243; from agent</strong></li>
</ol>
<p>As mentioned earlier, the wonderful of these ssh key managers don&#8217;t natively work in cronjob or scheduler environment. Although, these toolkits provide a base to expand the possibility of configure non-interactive / password-less ssh login with a secured private key (see next post).<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/" title="How To Setup Non-Interactive SSH Login">How To Setup Non-Interactive SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/" title="Configure Putty To Support Password-less SSH Login">Configure Putty To Support Password-less SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="Auto SSH Login By Using Public-key Cryptography">Auto SSH Login By Using Public-key Cryptography</a><br />&raquo; <a href="http://www.walkernews.net/2008/05/11/how-to-keep-inactive-ssh-session-from-disconnected/" title="How To Keep Inactive SSH Session From Disconnected">How To Keep Inactive SSH Session From Disconnected</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/21/where-does-putty-keeps-ssh-host-key-fingerprint-in-windows-registry/" title="Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?">Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/12/how-to-cut-mp3-as-mobile-phone-ringtone/" title="How To Cut MP3 As Mobile Phone Ringtone">How To Cut MP3 As Mobile Phone Ringtone</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/30/how-to-extract-audio-music-from-a-video-clip-in-windows-movie-maker/" title="How To Extract Audio Music From A Video Clip In Windows Movie Maker">How To Extract Audio Music From A Video Clip In Windows Movie Maker</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/09/configure-secured-private-key-for-password-less-ssh-login/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How To Setup Non-Interactive SSH Login</title>
		<link>http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/</link>
		<comments>http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 07:51:57 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Howto]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Authentication]]></category>

		<category><![CDATA[Batch File]]></category>

		<category><![CDATA[Cryptography]]></category>

		<category><![CDATA[Freeware]]></category>

		<category><![CDATA[Guide]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Non-Interactive]]></category>

		<category><![CDATA[Open Source]]></category>

		<category><![CDATA[Password-less]]></category>

		<category><![CDATA[Private-key]]></category>

		<category><![CDATA[Protocol]]></category>

		<category><![CDATA[Public-key]]></category>

		<category><![CDATA[Putty]]></category>

		<category><![CDATA[Puttygen]]></category>

		<category><![CDATA[Remote Access]]></category>

		<category><![CDATA[SCP]]></category>

		<category><![CDATA[Secure Shell]]></category>

		<category><![CDATA[SFTP]]></category>

		<category><![CDATA[Shell Scripts]]></category>

		<category><![CDATA[SSH]]></category>

		<category><![CDATA[SSH-Keygen]]></category>

		<category><![CDATA[Tutorial]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[WinSCP]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=742</guid>
		<description><![CDATA[How simple to setup a password-less, non-interactive SSH login for shell scripts or batch file?]]></description>
			<content:encoded><![CDATA[<p>When I am sitting in front of a computer, it doesn&#8217;t really matter if Putty or WinSCP prompts me to enter password for authentication.<br />
<!--more--><br />
But, how could I handle this interactive authentication process in <a href="http://www.walkernews.net/2007/05/08/auto-file-transfer-via-ftp-batch-scripts/" title="How to write a non-interactive Windows FTP batch files to automate file transfer, i.e. Windows batch file that capable to perform non-interactive FTP login" rel="bookmark">Windows batch files</a> or <a href="http://www.walkernews.net/2008/02/18/how-to-log-db2-tablespaces-free-pages-statistics/" title="Automate Linux shell script to track DB2 tablespace statistics for hard disk space planning." rel="bookmark">Linux shell scripts</a> that scheduled to trigger file transfer between networked hosts on a daily basis?<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Apparently, in order for the scheduled shell scripts or batch files to execute in this way, I need these two components:</p>
<ul>
<li><span class="subhead2">a command line SSH utility</span> such as pscp (for Windows batch file) or scp (for Linux shell scripts).<br />
&nbsp;</li>
<li><span class="subhead2">a pair of password-less cryptographic keys</span> (i.e. private key that is without passphrase) for non-interactive authentication.
<p><em>Additional steps required for &#8220;password-less&#8221; ssh login if the private key is secured with a passphrase.</em></li>
</ul>
<p><span class="subhead">The generic concept: How to setup a password-less, non-interactive ssh login?</span></p>
<p>This is not a detailed guide for a specific ssh suite. Indeed, this is just a generic view of what you should do, in order to get a <span class="subhead2">OpenSSH-compatible suite</span> to work in a non-interactive authentication way. (As of 2005, OpenSSH is the single most popular SSH implementation). </p>
<blockquote><p>Personally, I like Putty suite for Windows and OpenSSH for <a href="http://www.walkernews.net/2008/05/17/direct-download-fedora-and-red-hat-linux-iso-cd-image/" title="Direct download the archive of official Red Hat Linux CD images" rel="bookmark">Red Hat Linux</a>. The guides of configuring these tools to support non-interactive ssh login can be referred on these earlier posts:</p>
<ul>
<li><a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="How to configure OpenSSH for password-less SSH login" rel="bookmark">How to configure OpenSSH for password-less SSH login</a></li>
<li><a href="http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/" title="How to configure Putty for non-interactive ssh login" rel="bookmark">How to configure Putty for non-interactive ssh login</a></li>
</ul>
</blockquote>
<p>SSH-2 protocol (secure shell version 2) supports at least two authentication methods, i.e. legacy system password authentication and public-key cryptography authentication. For password-less or non-interactive SSH login to work, public-key cryptography authentication is preferable:</p>
<ol>
<li>Execute ssh key generator to create a pair of keys. For example, the Linux OpenSSH key generator <code>ssh-keygen -t dsa</code> defaulted to create a pair of DSA-based keys called id_dsa (private key) and id_dsa.pub (public key).<br />
&nbsp;</li>
<li>When the SSH key generator prompts you to enter a passphrase (to secure the private key), leave it empty (i.e. to disable the passphrase).<br />
<blockquote><p>The passphrase secures the private key. So, if someone steals the private key has to know the passphrase to unlock the secured private key. The server that trigger automated shell scripts or batch files keeps the private key, and hence should be secured as well. Otherwise, what&#8217;s the justification to only secure file transfer but leave the server box to be vulnerable for attack?</p></blockquote>
</li>
<li>Keep the private key in .ssh (a hidden directory) at client side and make sure the private key file access permission is restricted to 600, i.e. only grants read and write access to file owner.<br />
&nbsp;</li>
<li>Transfer the public key to all target servers (which are expected to receive files) and append the public key file content to authorized_key file that resides in .ssh directory. Again, the authorized_key file access permission must be restricted to 600 mode.</li>
</ol>
<p>Once all those generic steps are done, the client shell scripts / batch file is then capable to automate file transfer in password-less, non-interactive authentication mode.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
//2007-10-29: WakerNews-Banner
google_ad_channel = "9409943921";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "99CC33";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
<span class="subhead2">Suggestion:</span></p>
<p>If you&#8217;re about to write a Linux shell scripts or Windows batch file to automate file transfer between networked hosts via ssh protocol, try to use scp (in Linux) or pscp (Putty suite for Windows) rather than sftp or psftp, for the benefit of coding simplicity, given the fact that secure copy (SCP / PSCP) command is highly non-interactive and straight-forward.</p>
<p><span class="subhead2">The scp syntax:</span></p>
<pre>scp source_file user_id@hostname:[path/file]</pre>
<p><span class="subhead2">Some scp examples:</span></p>
<p><em>Assume all these scp commands are executed at server WalkerNews-A using walker-a user login ID</em></p>
<pre>scp -i $HOME/.ssh/id_dsa file1 walker-b@WalkerNews-B:newfile1</pre>
<p>meant to</p>
<ul>
<li>use the -i option switch to <span class="subhead2">explicitly</span> specify which private key to used for authentication, i.e. $HOME/.ssh/id_dsa. This option is useful when the ssh_config configured with a non-default IdentityFile option or there are multiple private keys kept inside the .ssh directory).<br />
&nbsp;</li>
<li>upload file1 to walker-b home directory at server WalkerNews-B as a new file named &#8220;newfile1&#8243;</li>
</ul>
<pre>scp file1 file2 log* walker-b@WalkerNews-B:/tmp</pre>
<p>meant to <span class="subhead2">upload</span> multiple source files (i.e. file1, file2, log*) to server WalkerNews-B using the walker-b user login ID and save those source files into /tmp directory.</p>
<pre>scp walker-b@WalkerNews-B:/tmp/f1 walker-b@WalkerNews-B:/tmp/f2 tmp</pre>
<p>meant to <span class="subhead2">download</span> /tmp/f1 and /tmp/f2 from server WalkerNews-B using walker-b user ID to the local tmp directory at walker-a home directory.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/06/09/configure-secured-private-key-for-password-less-ssh-login/" title="Configure Secured Private Key For Password-less SSH Login">Configure Secured Private Key For Password-less SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/" title="Configure Putty To Support Password-less SSH Login">Configure Putty To Support Password-less SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="Auto SSH Login By Using Public-key Cryptography">Auto SSH Login By Using Public-key Cryptography</a><br />&raquo; <a href="http://www.walkernews.net/2008/05/11/how-to-keep-inactive-ssh-session-from-disconnected/" title="How To Keep Inactive SSH Session From Disconnected">How To Keep Inactive SSH Session From Disconnected</a><br />&raquo; <a href="http://www.walkernews.net/2008/09/21/how-to-copy-youtube-video-or-flv-file-from-google-chrome-cache-folder/" title="How To Copy YouTube Video or FLV File From Google Chrome Cache Folder?">How To Copy YouTube Video or FLV File From Google Chrome Cache Folder?</a><br />&raquo; <a href="http://www.walkernews.net/2008/08/29/gnu-coreutils-gnu-date-is-easier-for-date-time-calculation-in-linux-shell-script/" title="GNU Coreutils: GNU Date Is Easier For Date Time Calculation In Linux Shell Script">GNU Coreutils: GNU Date Is Easier For Date Time Calculation In Linux Shell Script</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/21/where-does-putty-keeps-ssh-host-key-fingerprint-in-windows-registry/" title="Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?">Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Configure Putty To Support Password-less SSH Login</title>
		<link>http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/</link>
		<comments>http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 16:50:35 +0000</pubDate>
		<dc:creator>Walker</dc:creator>
		
		<category><![CDATA[Freeware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Authentication]]></category>

		<category><![CDATA[Authorized_Keys]]></category>

		<category><![CDATA[Cryptography]]></category>

		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Open Source]]></category>

		<category><![CDATA[Private-key]]></category>

		<category><![CDATA[Protocol]]></category>

		<category><![CDATA[Public-key]]></category>

		<category><![CDATA[Putty]]></category>

		<category><![CDATA[Puttygen]]></category>

		<category><![CDATA[Red Hat]]></category>

		<category><![CDATA[Redhat]]></category>

		<category><![CDATA[Remote Access]]></category>

		<category><![CDATA[RHEL]]></category>

		<category><![CDATA[SSH]]></category>

		<category><![CDATA[SSH-Keygen]]></category>

		<category><![CDATA[Vista SP1]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.walkernews.net/?p=739</guid>
		<description><![CDATA[How to generate public key and private key with Puttygen? How to update Putty-generated public key to the OpenSSH-based authorized_key file in order password-less ssh login to work?]]></description>
			<content:encoded><![CDATA[<p>Putty is a great terminal emulator freeware written by <a href="http://www.chiark.greenend.org.uk/~sgtatham/putty/team.html" target="_blank" rel="nofollow">Simon Tatham and team</a> in <a href="http://www.walkernews.net/2007/06/14/high-performance-compiler-for-intel-based-system/" title="Intel high performance C++ compiler optimize compiled code for Intel family processors." rel="bookmark">C language</a>.<br />
<!--more--><br />
This open source freeware was originally made as a Windows client for <a href="http://www.walkernews.net/tag/SSH/" title="All posts related to SSH in WalkerNews.net" rel="bookmark">ssh</a>, telnet, rlogin, and raw TCP computing protocols. Over the time, however, Putty has been ported to run on other operating systems, including the <a href="http://www.walkernews.net/2007/04/02/using-n73-symbian-s60-shortcut-key/" title="Are you familiar with Symbian S60 user interface shortcut keys?" rel="bookmark">mobile Symbian OS</a> that power my <a href="http://www.walkernews.net/tag/n73/" title="All posts related to Nokia N73 in WalkerNews.net" rel="bookmark">Nokia N73</a>!<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-02-15: walkernews-midpost
google_ad_channel = "1891269234";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
<span class="subhead">How to setup Putty for non-interactive, password-less SSH login</span></p>
<p>Similar to <a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="How to configure Linux SSH client to support password-less or non-interactive SSH login?" rel="bookmark">OpenSSH client setup</a>, we could create a pair of public key and private key in <a href="http://www.walkernews.net/2007/07/30/setup-remote-desktop-port-forwarding/" title="How to configure RDP port forwarding via SSH protocol with Putty client?" rel="bookmark">Putty SSH client suite</a> for the sake of password-less/non-interactive SSH login.</p>
<p><span style="color:#FF6666;font-weight:bold;">Assumption made for this example:</span></p>
<p>Putty client running in <a href="http://www.walkernews.net/tag/windows-vista/" title="All posts related to Windows Vista in WalkerNews.net" rel="bookmark">Windows Vista Ultimate</a> needs a non-interactive, password-less ssh login to walker-b at Linux server WalkerNews-B. WalkerNews-B is running <a href="http://www.walkernews.net/2008/01/15/how-to-install-rhel4-in-hp-netserver-lh3000/" title="How to install Red Hat Enterprise Linux 4 in an aging HP NetServer LH3000?" rel="bookmark">RHEL 4 Update 5</a> and installed with the bundled openssh-server-3.9p1-8.RHEL4.1 and openssh-clients-3.9p1-8.RHEL4.1.</p>
<ul>
<li>Locate and run the Puttygen.exe (Putty Key Generator), select the SSH-2 DSA key type, press the Generate button and move the mouse over the blank area (as prompted) to generate some randomness on the keys:
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/putty-keygen-1.jpg" alt="Using Puttygen.exe to generate SSH public key and private key for password-less ssh login." title="Using Puttygen.exe to generate SSH public key and private key for password-less ssh login." width="465" height="448" class="alignnone size-full wp-image-734" /><br />
&nbsp;</li>
<li>When the key generation completed, copy all text of public-key in the box and append it to walker-b&#8217;s $HOME/.ssh/authorized_keys files.
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/puttygen-public-key-2.jpg" alt="Copy the all text of public key in the box and append it to $HOME/.ssh/authorized_keys file." title="Copy the all text of public key in the box and append it to $HOME/.ssh/authorized_keys file." width="468" height="183" class="alignnone size-full wp-image-735" /><br />
&nbsp;</li>
<li>Click <strong>Save Private Key</strong> button to save the Putty-generated private key that pair the public key appended to $HOME/.ssh/authorized_key file.
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/puttygen-public-key-3.jpg" alt="Click Save Private Key button to save the Putty-generated private key." title="Click Save Private Key button to save the Putty-generated private key." width="468" height="246" class="alignnone size-full wp-image-736" /><br />
&nbsp;</li>
<li>Run the Putty client (putty.exe) to specify the saved private key and auto-login username before initiating connection to WalkerNews-B.
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/puttygen-public-key-4.jpg" alt="Navigate to Auth option and specify the Puttygen-created private key for authentication before initiating connection to remote ssh server" title="Navigate to Auth option and specify the Puttygen-created private key for authentication before initiating connection to remote ssh server" width="443" height="345" class="alignnone size-full wp-image-737" /></p>
<p>Specify the login user ID (i.e. walker-b):<br />
<img src="http://www.walkernews.net/wp-content/uploads/2008/06/putty-auto-ssh-login-a.jpg" alt="Specify the login ID in Putty for password-less ssh login" title="Specify the login ID in Putty for password-less ssh login" width="456" height="280" class="alignnone size-full wp-image-740" /></li>
</ul>
<p>The Putty command line SSH clients support non-interactive, password-less ssh login too. This is useful if you need some Windows batch files or Windows scripts to automate file transfer between networked hosts via the SCP protocol.</p>
<p>For example, to transfer sourcefile to walker-b&#8217;s home directory at WalkerNews-B, execute PSCP.exe program (equivalent to OpenSSH scp command) in this way:</p>
<pre>pscp -i id_dsa.ppk sourcefile walker-b@WalkerNews-B:</pre>
<p>The -i option switch is used to specified a private key. In this case, it&#8217;s a Puttygen-generated private key that I&#8217;ve saved it as id_dsa.ppk.</p>
<p>If the Putty fails to work in password-less ssh login fashion, it automatically attempts to perform legacy login ID and password authentication. For troubleshooting, you can refer to Putty Event Log window, i.e. right-click the Putty window title bar and click on the <strong>Event Log</strong> menu:</p>
<p><img src="http://www.walkernews.net/wp-content/uploads/2008/06/puttygen-public-key-5-a.jpg" alt="Refer to Putty Event Log window to troubleshoot password-less SSH login related problem." title="Refer to Putty Event Log window to troubleshoot password-less SSH login related problem." width="452" height="217" class="alignnone size-full wp-image-741" /><br />
<script type="text/javascript"><!--
google_ad_client = "pub-9150838093899057";
google_alternate_color = "000000";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text_image";
//2007-05-22: walkernews-mid-3
google_ad_channel = "3198031927";
google_color_border = "000000";
google_color_bg = "000000";
google_color_link = "FFA303";
google_color_text = "CACACA";
google_color_url = "CACACA";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /></p>
<br /><strong>Similar Articles:</strong><br />&raquo; <a href="http://www.walkernews.net/2008/06/09/configure-secured-private-key-for-password-less-ssh-login/" title="Configure Secured Private Key For Password-less SSH Login">Configure Secured Private Key For Password-less SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/06/how-to-setup-non-interactive-ssh-login/" title="How To Setup Non-Interactive SSH Login">How To Setup Non-Interactive SSH Login</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/04/auto-ssh-login-by-using-public-key-cryptography/" title="Auto SSH Login By Using Public-key Cryptography">Auto SSH Login By Using Public-key Cryptography</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/21/where-does-putty-keeps-ssh-host-key-fingerprint-in-windows-registry/" title="Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?">Where Does Putty Keeps SSH Host Key Fingerprint In Windows Registry?</a><br />&raquo; <a href="http://www.walkernews.net/2008/05/11/how-to-keep-inactive-ssh-session-from-disconnected/" title="How To Keep Inactive SSH Session From Disconnected">How To Keep Inactive SSH Session From Disconnected</a><br />&raquo; <a href="http://www.walkernews.net/2008/06/20/configure-vnc-server-to-auto-start-up-in-red-hat-linux/" title="Configure VNC Server To Auto Start Up In Red Hat Linux">Configure VNC Server To Auto Start Up In Red Hat Linux</a><br />&raquo; <a href="http://www.walkernews.net/2008/07/06/how-to-create-iso-image-of-directory-or-filesystem-in-linux/" title="How To Create An ISO Image Of Directory / Filesystem In Linux">How To Create An ISO Image Of Directory / Filesystem In Linux</a><br />]]></content:encoded>
			<wfw:commentRss>http://www.walkernews.net/2008/06/05/configure-putty-to-support-password-less-ssh-login/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
