Re: Internet Cafe

From: Nick Shapley (nick.shapley@ntlworld.com)
Date: 01/17/03

  • Next message: Robert Buel: "RE: Email server+network architecture"
    From: "Nick Shapley" <nick.shapley@ntlworld.com>
    To: <security-basics@securityfocus.com>
    Date: Fri, 17 Jan 2003 21:43:08 -0000
    
    

    Linux is the way to go. I use Squid to throttle certain downloads on my
    network.
    If you haven't already found it, check out
    http://www.tldp.org/HOWTO/Bandwidth-Limiting-HOWTO/

    As for monitoring, you could even use something like snort to alert you of
    both external and internal threats.
    Make sure NTFS permissions are set on the W2K boxes (and use them!) and
    limit them to save to only to a network drive.
    You can set Linux up with the latest Samba and it will act as a W2K DC (the
    clients can't tell the difference!), another think to mention is that it
    might be worth using some form of imaging software, such as Norton Ghost to
    distribute the clients, especially when patching etc.

    Regards,

    Nick

    ----- Original Message -----
    From: "Matti Haack" <m.haack@haack-it.de>
    To: <security-basics@securityfocus.com>
    Sent: Friday, January 17, 2003 11:56 AM
    Subject: Re: Internet Cafe

    >
    >
    >
    > > Anyways, anyone got any suggestions/comments on what I really have to
    > > look out for? I'm thinking it should be reasonably secure, but in places
    > > like this you always have the added risc of people wanting to damage the
    > > OS/system or use it as a place from which to attack others.
    > Install a personal firewall. (www.kerio.com)
    >
    > I suggest kerios Personal firewall for some reasons:
    > - You can create a policy file on one maschine and copy it to all the
    > others
    > - The Firewall administration can be looked down with a password
    > - It calculates MD5 Chekcsums for all used applications, so that you
    > can't rename a forbidden aplication to a allowed and pass the firewall
    > with this.
    > - It knows trusted adress groups, maybe to allow some more network Traffic
    > inside your cafe (for games etc.)
    >
    > Allow only IE and whatever you like to allow for your customers.
    > Switch off learning mode, set a password. So noone can use newly
    > installed Internet Software like Kazaa or a massmailer.
    >
    > with best regards
    > Matti Haack
    >
    > -
    > Matti Haack - Hit Haack IT Service Gmbh
    > Neuburger Strasse 35, D-94032 Passau
    > +49 851 50477-22 Fax: +49 851 50477-29
    > http://www.haack-it.de



    Relevant Pages

    • Omniquad Personel Firewall v1.4.92 Released...
      ... Omniquad Personal Firewall keeps your computer shielded from hackers by ... computer is fully locked - Medium - everything closed to Internet ... hosts and your computer still open to trusted zone computers - Low - ... immediately shut down all network access, ...
      (comp.software.shareware.announce)
    • Omniquad Personal firewall v1.4.92 Released
      ... Omniquad Personal Firewall keeps your computer shielded from hackers by ... computer is fully locked - Medium - everything closed to Internet ... hosts and your computer still open to trusted zone computers - Low - ... immediately shut down all network access, ...
      (comp.software.shareware.announce)
    • Re: Is Samba the answer?
      ... the scenario is we have a Linux web server that we use ... or without Samba) -- just as exposing NFS services across the internet ... your _internal_ network using one of the most insecure means possible. ... etc. Can you really secure it? ...
      (comp.os.linux.networking)
    • Re: Hi, having trouble with networking
      ... I have setup modem and internet, ... >> tutorials on the web I have found just dont help. ... >> New to linux and having a bit of trouble networking. ... > outward Net and the other for the internal shared network. ...
      (comp.os.linux.networking)
    • Re: SuSe 9.1 installation
      ... >came up with installation options. ... >configure the network and the installation hung up at Running Internet ... Linux is supposed to be a great os ...
      (comp.os.linux.misc)