Samba: Talking to 4 5 Windows Networks 6 7 8 9
Total Page:16
File Type:pdf, Size:1020Kb
Load more
Recommended publications
-
The Downadup Codex a Comprehensive Guide to the Threat’S Mechanics
Security Response The Downadup Codex A comprehensive guide to the threat’s mechanics. Edition 2.0 Introduction Contents Introduction.............................................................1 Since its appearance in late-2008, the Downadup worm has become Editor’s Note............................................................5 one of the most wide-spread threats to hit the Internet for a number of Increase in exploit attempts against MS08-067.....6 years. A complex piece of malicious code, this threat was able to jump W32.Downadup infection statistics.........................8 certain network hurdles, hide in the shadows of network traffic, and New variants of W32.Downadup.B find new ways to propagate.........................................10 defend itself against attack with a deftness not often seen in today’s W32.Downadup and W32.Downadup.B threat landscape. Yet it contained few previously unseen features. What statistics................................................................12 set it apart was the sheer number of tricks it held up its sleeve. Peer-to-peer payload distribution...........................15 Geo-location, fingerprinting, and piracy...............17 It all started in late-October of 2008, we began to receive reports of A lock with no key..................................................19 Small improvements yield big returns..................21 targeted attacks taking advantage of an as-yet unknown vulnerability Attempts at smart network scanning...................23 in Window’s remote procedure call (RPC) service. Microsoft quickly Playing with Universal Plug and Play...................24 released an out-of-band security patch (MS08-067), going so far as to Locking itself out.................................................27 classify the update as “critical” for some operating systems—the high- A new Downadup variant?......................................29 Advanced crypto protection.................................30 est designation for a Microsoft Security Bulletin. -
CIFS/NFS) Administrator's Guide
Hitachi Data Ingestor File System Protocols (CIFS/NFS) Administrator's Guide Product Version Getting Help Contents MK-90HDI035-13 © 2013- 2015 Hitachi, Ltd. All rights reserved. No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying and recording, or stored in a database or retrieval system for any purpose without the express written permission of Hitachi, Ltd. Hitachi, Ltd., reserves the right to make changes to this document at any time without notice and assume no responsibility for its use. This document contains the most current information available at the time of publication. When new or revised information becomes available, this entire document will be updated and distributed to all registered users. Some of the features described in this document might not be currently available. Refer to the most recent product announcement for information about feature and product availability, or contact Hitachi Data Systems Corporation at https://portal.hds.com. Notice: Hitachi, Ltd., products and services can be ordered only under the terms and conditions of the applicable Hitachi Data Systems Corporation agreements. he use of Hitachi, Ltd., products is governed by the terms of your agreements with Hitachi Data Systems Corporation. Hitachi is a registered trademark of Hitachi, Ltd., in the United States and other countries. Hitachi Data Systems is a registered trademark and service mark of Hitachi, Ltd., in the United States and other countries. Archivas, Essential NAS Platform, HiCommand, Hi-Track, ShadowImage, Tagmaserve, Tagmasoft, Tagmasolve, Tagmastore, TrueCopy, Universal Star Network, and Universal Storage Platform are registered trademarks of Hitachi Data Systems Corporation. -
Samba-3 by Example
Samba-3 by Example Practical Exercises in Successful Samba Deployment John H. Terpstra May 27, 2009 ABOUT THE COVER ARTWORK The cover artwork of this book continues the freedom theme of the first edition of \Samba-3 by Example". The history of civilization demonstrates the fragile nature of freedom. It can be lost in a moment, and once lost, the cost of recovering liberty can be incredible. The last edition cover featured Alfred the Great who liberated England from the constant assault of Vikings and Norsemen. Events in England that finally liberated the common people came about in small steps, but the result should not be under-estimated. Today, as always, freedom and liberty are seldom appreciated until they are lost. If we can not quantify what is the value of freedom, we shall be little motivated to protect it. Samba-3 by Example Cover Artwork: The British houses of parliament are a symbol of the Westminster system of government. This form of government permits the people to govern themselves at the lowest level, yet it provides for courts of appeal that are designed to protect freedom and to hold back all forces of tyranny. The clock is a pertinent symbol of the importance of time and place. The information technology industry is being challenged by the imposition of new laws, hostile litigation, and the imposition of significant constraint of practice that threatens to remove the freedom to develop and deploy open source software solutions. Samba is a software solution that epitomizes freedom of choice in network interoperability for Microsoft Windows clients. -
Clustered Data ONTAP 8.3 CIFS File Access Reference Guide
Clustered Data ONTAP® 8.3 CIFS File Access Reference Guide February 2016 | 215-10876_A0 [email protected] Updated for 8.3.2 Table of Contents | 3 Contents Deciding whether to use this guide ........................................................... 12 Understanding SMB file access with Data ONTAP ................................. 14 How namespaces and volume junctions affect SMB access on SVMs with FlexVol volumes .................................................................................................. 14 What namespaces in SVMs with FlexVol volumes are ................................. 14 Volume junction usage rules ......................................................................... 14 How volume junctions are used in SMB and NFS namespaces .................... 15 What the typical NAS namespace architectures are ...................................... 15 LIF configuration requirements for file access management .................................... 18 How security styles affect data access ....................................................................... 19 What the security styles and their effects are ................................................ 19 Where and when to set security styles .......................................................... 20 How to decide on what security style to use on SVMs with FlexVol volumes .................................................................................................... 20 How security style inheritance works .......................................................... -
Chapter 2: Installing Samba on a Unix System
,ch02.26865 Page 31 Friday, November 19, 1999 3:28 PM Chapter 2 2 Installing Samba on a Unix System Now that you know what Samba can do for you and your users, it’s time to get your own network set up. Let’s start with the installation of Samba itself on a Unix system. When dancing the samba, one learns by taking small steps. It’s just the same when installing Samba; we need to teach it step by step. This chapter will help you to start off on the right foot. For illustrative purposes, we will be installing the 2.0.4 version of the Samba server on a Linux* system running version 2.0.31 of the kernel. However, the installation steps are the same for all of the platforms that Samba supports. A typical installa- tion will take about an hour to complete, including downloading the source files and compiling them, setting up the configuration files, and testing the server. Here is an overview of the steps: 1. Download the source or binary files. 2. Read the installation documentation. 3. Configure a makefile. 4. Compile the server code. 5. Install the server files. 6. Create a Samba configuration file. 7. Test the configuration file. 8. Start the Samba daemons. 9. Test the Samba daemons. * If you haven’t heard of Linux yet, then you’re in for a treat. Linux is a freely distributed Unix-like oper- ating system that runs on the Intel x86, Motorola PowerPC, and Sun Sparc platforms. The operating sys- tem is relatively easy to configure, extremely robust, and is gaining in popularity. -
TANDBERG VIKING SERIES NAS APPLIANCE Storage Server Administration Manual
TANDBERG VIKING SERIES NAS APPLIANCE Storage Server Administration Manual TANDBERG DATA ASIA 20 Bendemeer Road, #04-05 Cyberhub, Singapore 339914 Phone + 65 6396 0786 Part No. 65 82 X2 - 01 Telefax + 65 6396 0787 January 2008 © Tandberg Data Asia Related publications available from Tandberg Data Asia: Part No. Title 6582B7 Tandberg Viking FS-1600 NAS Hardware User Manual 6582A7 Tandberg Viking FS-1500 NAS Hardware User Manual 658297 Tandberg Viking FS-412 NAS Hardware User Manual This publication may describe designs for which patents are granted or pen- ding. By publishing this information, Tandberg Data Asia conveys no license under any patent or any other rights. Every effort has been made to avoid errors in text and diagrams. However, Tandberg Data Asia assumes no responsibility for any errors which may ap- pear in this publication. It is the policy of Tandberg Data Asia to improve products as new techniques and components become available. Tandberg Data Asia therefore reserves the right to change specifications at any time. We would appreciate any comments on this publication. __________________________________________________________________________________________________ Table of Contents Table of Contents i 1. System Overview 1-1 1.1. Product Information 1-1 1.1.1. Product Manageability 1-2 1.2. Redundancy 1-2 1.2.1. Configuring RAID using 4 HDD (1U) 1-3 1.2.2. Configuring RAID using 16 HDD (3U) 1-4 1.2.3. System Volume (SV) 1-5 1.2.4. Data Volume (DV) 1-5 1.4. Deployment 1-5 1.4.1. File Server Consolidation 1-5 1.4.2. Multi-protocol Environments 1-5 1.4.3. -
Samba's AD DC: Samba 4.2 and Beyond
Samba's AD DC: Samba 4.2 and Beyond Presented by Andrew Bartlett of Catalyst // 2014-09 About me ● Andrew Bartlett ● Samba Team member since 2001 ● Working on the AD DC since 2006 ● These views are my own, but I do with to thank: – My employer: Catalyst – My fellow Samba Team members Open Source Technologies Samba's AD DC ● The combination of many years work – File server – Print server – Active Directory Domain controller – (and many other features) ● First Release Dec 2012 ● Now on the road to Samba 4.2 – Due for RC1 on Monday Sep 22 Re-opening the heart of the network ● Samba's AD DC brings open source to the heart of the network again ● Samba has long provided a Domain Controller – But without support for Group Policy and other AD features like Kerberos ● Organizations again have a practical choice other than Microsoft Windows The flexibility to innovate ● Open Source lets you do more ● Just as Samba is in many NAS devices, including NETGEAR's ReadyNAS ● Samba inside Catalyst's print server – No CALs, multi-device access ● Imagine – What if was also an AD DC? – Instant branch office solution – Perhaps managed from the cloud? Breaking vendor lock in ● Samba can migrate to and from Microsoft Windows based AD domains – Without loss of data – Without password resets or domain joins ● Samba 4.0 can upgrade existing Samba 3.x domains to AD – And you can even migrate that to a Microsoft Windows AD if you want to – We won't hold you against your will! Uses Native Microsoft Admin tools ● Microsoft Management Console snap-ins – In general, fully -
Client Side Samba Linux Clients in Microsoft Windows Environments
Client Side Samba Linux Clients in Microsoft Windows Environments Ralf Haferkamp OpenLDAP Team Lars Müller Samba Team May 8, 2006 Motivation Operating Systems Market Share (Client and Server) 1,80% 2,70% Microsoft Apple Linux 95,50% 2 © Novell Inc, Confidential & Proprietary Mandatory Requirements Overview • Domain join • Single Sign On Authentication • Name Service Switch (NSS) • X11 Display Manager integration (KDM, GDM) 3 © Novell Inc, Confidential & Proprietary Mandatory Requirement Authentication • Seamless PAM Integration – Let PAM winbind behave like other PAM modules – Mapping Microsoft to PAM error messages and codes • Kerberized PAM Winbind – Automatic ticket refresh and renew • Account Policies – Password – Logon hours – Lockout 4 © Novell Inc, Confidential & Proprietary Architecture Overview 5 © Novell Inc, Confidential & Proprietary Supplementary Requirements • Winbind Offline mode • Kerberized Client Applications – web browsers (konqueror, FireFox) – MUA (KMail) • File Access – libsmbclient using apps (konqueror, nautilus) – CIFS system wide? • Printing 6 © Novell Inc, Confidential & Proprietary YaST Integration (1) 7 © Novell Inc, Confidential & Proprietary YaST Integration (2) 8 © Novell Inc, Confidential & Proprietary Samba Winbind AD Integration Demo To do • Acessing CIFS Home Directory • Machine Account Password Changes • Localisation • GUI integration for Services For UNIX (SFU) • Group Policy Support (GPO) • Roaming Profiles • Logon Scripts 10 © Novell Inc, Confidential & Proprietary Available Resources • SUSE Linux Enterprise Desktop 10 • http://openSUSE.org/Samba • Samba.org samba-docs subversion Questions & Answers ? 11 © Novell Inc, Confidential & Proprietary Unpublished Work of Novell, Inc. All Rights Reserved. This work is an unpublished work and contains confidential, proprietary, and trade secret information of Novell, Inc. Access to this work is restricted to Novell employees who have a need to know to perform tasks within the scope of their assignments. -
Page 1 of 3 Global Knowledge IT Training 04/19/2005
Global Knowledge IT Training Page 1 of 3 Choose Your Country United States Home Company IT & Management Training Enterprise Solutions OnDemand Software Contact Us My Global Knowledge Course Catalog How to...'Stealth' Microsoft Windows XP Professional Certifications February 2005 - Tim Warner Partners In a former position, I worked as a senior-level network engineer for a high-profile research institute at a leading Government university in the southern United States. Within the institute, there were some Windows XP Professional workstations Delivery Methods that hosted top-secret data and, at the same time, required access both to the local area network (LAN) as well as to Savings Programs the Internet. Therefore, my challenge was to harden the security on these computers as much as possible. (I know as much as any security professional does that the only true way to ensure the security of a computer is to remove its Training Locations connectivity to any network altogether. However, I also understand that in some cases, this measure is impractical Resource Center and sometimes impossible to implement in practice.) Shopping Cart In this article, I will share some tips for putting a Windows XP Professional-based workstation into "stealth mode." We Search For won't be delving into the intricacies of Internet Protocol Security (IPSec) or hardware firewall traffic policies. Instead, Keyword I'll present a series of tips, tweaks and suggestions that you can apply quickly and easily to improve the security of any Windows XP Professional box on your network. Advanced Search Shall we get started? Tip 1: Disable the Server Service The Server service, which is also known as the "File and Printer Sharing for Microsoft Networks" component in Windows XP, can be very dangerous when enabled on a Windows XP computer that is not actually going to host shared resources on a network. -
Sample Content from Windows Administration Resource Kit: Productivity Solutions for IT Professionals
Windows® Administration Resource Kit: Productivity Solutions for IT Professionals Dan Holme PREVIEW CONTENT This excerpt contains uncorrected manuscript from an upcoming Microsoft Press title, for early preview, and is subject to change prior to release. This excerpt is from Windows® Administration Resource Kit: Productivity Solutions for IT Professionals from Microsoft Press (ISBN 978-0-7356-62431-3, copyright 2008 Dan Holme (All), all rights reserved), and is provided without any express, statutory, or implied warranties To learn more about this book, visit Microsoft Learning at http://www.microsoft.com/MSPress/books/11297.aspx 978-0-7356-2431-3 © 2008 Dan Holme (All). All rights reserved. Table of Contents FrontMatter 2 Managing Files, Folders, and Shares Scenarios, Pain and Solution 2-1: Work effectively with the ACL editor user interface 2-2: Manage Folder structure 2-3: Manage access to root data folders 2-4: Delegate the management of shared folders 2-5: Determine which folders should be shared 2-6: Implement folder access permissions based on required capabilities 2-7: Understand shared folder permissions (SMB permissions) 2-8: Script the creation of an SMB share 2-9: Provision the creation of a shared folder 2-10: Avoid the ACL inheritance propagation danger of files and folder movement 2-11: Preventing users from changing permissions on their own files 2-12: Prevent users from seeing what they cannot access 2-13: Determine who has a file open 2-14: Send messages to users 2-15: Distribute files across servers 2-16: Use quotas to manage storage 2-17: Reduce help desk calls to recover deleted or overwritten files 2-18: Create an effective, delegate DFS namespace PREVIEW CONTENT This excerpt contains uncorrected manuscript from an upcoming Microsoft Press title, for early preview, and is subject to change prior to release. -
SMB Analysis
NAP-3 Microsoft SMB Troubleshooting Rolf Leutert, Leutert NetServices, Switzerland © Leutert NetServices 2013 www.wireshark.ch Server Message Block (SMB) Protokoll SMB History Server Message Block (SMB) is Microsoft's client-server protocol and is most commonly used in networked environments where Windows® operating systems are in place. Invented by IBM in 1983, SMB has become Microsoft’s core protocol for shared services like files, printers etc. Initially SMB was running on top of non routable NetBIOS/NetBEUI API and was designed to work in small to medium size workgroups. 1996 Microsoft renamed SMB to Common Internet File System (CIFS) and added more features like larger file sizes, Windows RPC, the NT domain service and many more. Samba is the open source SMB/CIFS implementation for Unix and Linux systems 2 © Leutert NetServices 2013 www.wireshark.ch Server Message Block (SMB) Protokoll SMB over TCP/UDP/IP SMB over NetBIOS over UDP/TCP SMB / NetBIOS was made routable by running Application over TCP/IP (NBT) using encapsulation over 137/138 139 TCP/UDP-Ports 137–139 .. Port 137 = NetBIOS Name Service (NS) Port 138 = NetBIOS Datagram Service (DGM) Port 139 = NetBIOS Session Service (SS) Data Link Ethernet, WLAN etc. Since Windows 2000, SMB runs, by default, with a thin layer, the NBT's Session Service, on SMB “naked” over TCP top of TCP-Port 445. Application 445 DNS and LLMNR (Link Local Multicast Name . Resolution) is used for name resolution. Port 445 = Microsoft Directory Services (DS) SMB File Sharing, Windows Shares, Data Link Ethernet, WLAN etc. Printer Sharing, Active Directory 3 © Leutert NetServices 2013 www.wireshark.ch Server Message Block (SMB) Protokoll NetBIOS / SMB History NetBIOS Name Service (UDP Port 137) Application • Using NetBIOS names for clients and services. -
Parallels Remote Application Server Administrator's Guide V16.5 Update 4
Parallels Remote Application Server Administrator's Guide v16.5 Update 4 Parallels International GmbH Vordergasse 59 8200 Schaffhausen Switzerland Tel: + 41 52 672 20 30 www.parallels.com Copyright © 1999-2019 Parallels International GmbH. All rights reserved. This product is protected by United States and international copyright laws. The product’s underlying technology, patents, and trademarks are listed at http://www.parallels.com/about/legal/. Microsoft, Windows, Windows Server, Windows Vista are registered trademarks of Microsoft Corporation. Apple, Mac, the Mac logo, OS X, macOS, iPad, iPhone, iPod touch are trademarks of Apple Inc., registered in the US and other countries. Linux is a registered trademark of Linus Torvalds. All other marks and names mentioned herein may be trademarks of their respective owners. Contents Introduction ............................................................................................................. 11 About Parallels RAS ...................................................................................................... 11 About This Guide .......................................................................................................... 12 Terms and Abbreviations Used in This Guide ................................................................. 12 Installing Parallels RAS ........................................................................................... 15 System Requirements ..................................................................................................