Time machine

Time machine: "

time machine





"

FSFE Founder Georg Greve Awarded German Cross of Merit

FSFE Founder Georg Greve Awarded German Cross of Merit: "


Free Software Foundation Europe (FSFE) founding president Georg Greve was awarded the German Cross of Merit for his intervention on the part of free software and open standards.

"

What is Firewall Builder? Introduction to new release 4.0

What is Firewall Builder? Introduction to new release 4.0: "

Introduction to Firewall Builder 4.0


By Vadim Kurland {vadim at fwbuilder DOT org}, the main author of Firewall Builder.




Vadim Kurland - vadim (at) fwbuilder {dot} org


Systems administrators have a choice of modern Open Source and commercial firewall platforms at their disposal. They could use netfilter/iptables on Linux, PF, ipfilter, ipfw on OpenBSD and FreeBSD, Cisco ASA (PIX) and other commercial solutions. All these

are powerful implementations with rich feature set and good performance. Unfortunately, managing security policy manually with all of these remains non-trivial task for several reasons. Even though the configuration language can be complex and overwhelming with its multitude of features and options, this is not the most difficult problem in my opinion. Administrator who manages netfilter/iptables, PF or Cisco firewall all the time quickly

becomes an expert in their platform of choice. To do the job right, they need to understand internal path of the packet inside Linux or BSD kernel and its interaction with different parts of packet filtering engine. Things get significantly more difficult in the

installations using different OS and platforms where the administrator needs to switch from netfilter/iptables to PF to Cisco routers and ASA to implement coordinated changes across multiple devices. This is where making changes get complicated and probability of human error increases. Unfortunately typos and more significant errors in firewall or router access list configurations lead to either service downtime or security problems, both expensive in terms of damage and time required to fix.

<!--break-->



Firewall Builder (also known as fwbuilder, http://www.fwbuilder.org) is a universal firewall configuration and management tool that lets you define security policy on a higher level of abstraction and hides internal structure of the target firewall platform. For example, it can decide which iptables chain is right for each generated iptables rule automatically, without your input. It can pick right iptables target for both policy and

NAT (Network Address Translation) rules as well as properly use most popular iptables modules, all automatically. Firewall Builder generates correct PIX translation rules, choosing between 'nat', 'global' and 'static' commands as appropriate, using the same definition of the NAT rules as it uses for iptables and PF. It is aware of the differences between various versions of iptables, PF and other platforms and chooses optimal syntax for each to utilize new features that constantly appear in these platforms as they evolve. It enforces best practices in policy design and helps you deploy and activate generated policy on the firewall.



Firewall Builder does not aim at just supporting one particular firewall platform. The goal is to be able to generate configuration for many different firewalls from the same representation in the GUI. To do this, Firewall Builder works with an abstract high level

model of a firewall which incorporates features found in all target firewalls. In other words, Firewall Builder is not another iptables GUI, or PF GUI, or ipfilter GUI. Firewall Builder works with a firewall that is neither one of these, and yet at the same time it

is all of them combined. It has useful features found in all of the target platforms. If a feature that it implements is not supported in some target firewall, it tries to emulate it (if possible) to make it look like the target really supports it.



Since Firewall Builder works with an abstract firewall, all discrepancies go away and you always see consistent model regardless of the chosen target firewall platform. For PIX, the

program can make it look like NAT is done after access control rules which is consistent with the behavior of iptables and PF (but this is optional). For PF, the program always uses PF option that switches it to the non-default 'first match' behavior. In the end,

the program takes care of translating the firewall model it presents to the user into configuration of the actual target firewall.



Policy and NAT rules built in Firewall Builder look very familiar to anyone who ever worked with Firewall-1, PIX, iptables, PF and so on. This is because these rules are just generalization of the ideas and features found in all of those firewalls. The program helps you create and manage rule sets and then translates them into

configuration language of the chosen target firewall platform.




Firewall Builder supports iptables (netfilter), ipfilter, pf, ipfw, Cisco ASA (FWSM, PIX) and Cisco routers extended access lists. Firewall Builder is more complex than many basic firewall configuration GUI such as Firestarter, but on the other

hand one can build very complex policies with Firewall Builder and fully utilize flexibility and power of iptables and other supported firewalls. Firewall Builder works well both as a configuration tool for the local firewall protecting machine where fwbuilder is running and as a firewall configuration UI that manages configuration on several remote dedicated firewalls and routers.



General idea should be familiar to anyone who ever worked with commercial firewall management systems. All configuration management operations can be performed from one central place, Firewall Builder GUI. You create and manage collection of objects that describe network addresses, hosts and firewalls, as well as services, and then build firewall policy and NAT rules using these objects. Policy rules are defined in terms of 'Source' and 'Destination' addresses and 'Service' and can have additional parameters such as interface association, direction, time interval and optional platform-dependent attributes. NAT rules are defined by addresses and services before and after translation.


Rules are built with simple drag and drop operations and then firewall configuration can be generated with one click of a mouse. Objects used to describe hosts, networks and services can be used multiple times in rules of many different firewalls. If you

make a change in one object, rules of all firewalls that use it will be automatically updated on the next recompile. Whenever you make a change to any object, all firewalls that use it directly or indirectly (as a member of a group, for instance) are marked as

requiring recompile in the GUI.


In the end, Firewall Builder produces a script or configuration file in the language of the target firewall. For iptables, it creates shell script that loads iptables rules, while for other platforms it creates configuration file suitable for them. This makes it simple to deploy and activate generated policy and also helps integrate Firewall Builder with existing automation scripts.


Firewall Builder GUI has built-in component that uses external ssh client to copy generated configuration to the firewall and then activate it. This works with all supported platforms, including iptables on Linux, PF, ipfilter or ipfw on BSD and Cisco routers and ASA (PIX) firewalls.


The program comes with a collection of over 100 standard objects that can be used to describe standard address blocks and networks, such as those defined by RFC1918, whole multicast address block as well as addresses of multicast groups used by popular protocols,

various standard IPv4 and IPv6 address allocations. The library of standard objects also includes popular TCP, UDP and ICMP services.


Firewall Builder implements many best practices in firewall policy design and firewall management procedures. Here are just a few examples:



  • It enforces policy structure that denies all traffic by default and only permits what is necessary.

  • You can define ip address of the management workstation and Firewall Builder will automatically add rule to ensure that ssh access from it to the firewall is always permitted. This rule is designed to ensure that ssh session over which installer activates new policy does not break or hang in the middle of the policy update. This helps avoid accidents when errors in the policy rules cut remote access to the firewall off in the middle of activation, making it impossible to fix the error and causing prolonged network outage.

  • For Cisco PIX (ASA) and IOS access lists, where each access-list commands are immediately activated as they are entered, Firewall Builder can optionally create temporary access list to ensure uninterrupted ssh access from the management

    workstation to the firewall for the duration of the policy reload session. This method provides the best protection against outages caused by loss of contact with the firewall because of errors in policy. Starting with fwbuilder 4.0, policy installer for Cisco routers and firewalls can use scp to copy configuration to the device before activating it, this makes it much faster and avoids line-by-line activation.

  • For iptables, Firewall Builder can generate script that would use iptables-restore for atomic activation. If iptables-restore detects an error in the script and refuses to load policy, script leaves the firewall in the state it was in before. For other firewall platforms it uses appropriate activation methods to achieve the same goal.

  • Built-in policy installer supports 'test' install mode with automatic roll-back. This is another safety mechanism that helps minimize outages in case of errors in the policy. It is available for all supported OS and firewall platforms. The implementation of this feature may not always be the most elegant, we are working to improve it.



New features in Firewall Builder 4.0


Recently released Firewall Builder 4.0 beta adds support for the high availability firewall configurations. It helps generate iptables configurations for member firewalls for clusters built with heartbeat, vrrpd and OpenAIS on Linux. Policy rules that permit packets sent by the failover protocol agents can be added automatically. You need to manage only one set of policy and NAT rules for the cluster and the program automatically does all address substitutions to generate separate iptables scripts for each member firewall. The program takes into account native addresses of each member and shared addresses managed by the failover protocol when it generates script for each member.


Other supported platforms for the high availability firewall configurations are CARP and pfsync on OpenBSD and Cisco ASA (PIX).


At this time Firewall Builder does not generate configuration for heartbeat, vrrpd or other HA agents on Linux, leaving this task to the other existing configuration management tools. It does, however, generate script that creates and manages CARP

and pfsync interfaces on OpenBSD, as well as complete Cisco ASA (PIX) failover configuration.


Script generated by the Firewall Builder 4.0 can also manage IP addresses of the firewall interfaces. The script adds and removes ip addresses of interfaces as needed when you add or removes them in the Firewall Builder GUI. All changes are done incrementally to avoid complete configuration resets. Firewall Builder 4.0 can also manage VLANs, bridge ports and bonding interfaces and follows the same principles of incremental management for these.


Firewall Builder 4.0 is the first release that provides mechanism by which user can modify generated configuration file or a script. All parts of generated files are defined in small template files that we call 'configlets'. These templates use very simple macro language that supports variable substitutions and conditional statements. Users can replace standard configlets shipped with fwbuilder with their own, where they can make any modifications they want to tailor generated scripts and configuration files to their needs. We plan to expand macro language in the future, make it more scalable and add more modern language constructs.


One of the most visible and welcome improvements in Firewall Builder v4.0 is ability to quickly compile single rule and immediately see the result in the GUI. Just select a policy or NAT rule in the GUI, click right mouse button in any rule element and choose menu item 'Compile' in the context menu that appears, the rule is compiled immediately and generated configuration in the language of the target firewall appears in the panel at the bottom of the main window. The screenshot above shows how this looks like. Keyboard shortcut 'x' performs this action too. This is a great way to experiment with different rule configurations and is specifically designed for administrators who are experts in iptables, PF or other platform to help them quickly check the configuration generated by

fwbuilder to make sure it is what they intended.


Firewall Builder 4.0 comes with host of other improvements in all components. These include unlimited depth undo/redo facility in the GUI, temporary password caching in the built-in policy installer, better integration of policy compiler components with the GUI and many other new features. Complete list is available in Firewall Builder 4.0.0 Release Notes


Conclusion


Firewall Builder is available in Debian, Ubuntu, Fedora Core Linux, Gentoo and other Linux distributions. It is part of OpenBSD and FreeBSD ports. NetCitadel LLC distributes commercially licensed Windows and Mac OS X packages that are available for download from this page.


As all Open Source projects, Firewall Builder depends on the user community who provide testing, bug reports and other forms of feedback. You can file bug reports and feature requests using bug

tracking system
. Our mailing list is great place to ask for help and discuss the program

with other users.


The project has been around for almost 10 years, you can see some interesting statistics on our Ohloh project page.


This was just a brief introduction to the Firewall Builder. If you are interested in the program, you can find more information on the project web site at http://www.fwbuilder.org. Firewall Builder 4.0 Beta web site is at http://www.fwbuilder.org/4.0.

Firewall Builder Users Guide provides very detailed explanation of all aspects of the program and has large 'Cookbook'

chapter that demonstrates how fwbuilder can be used to solve typical firewall rule design problems.




"

Jon Stewart Rips Into Apple Over Lost iPhone Debacle. That’s Going To Leave A Mark.

Jon Stewart Rips Into Apple Over Lost iPhone Debacle. That’s Going To Leave A Mark.: "

Over the last two weeks countless blog posts and articles have been written about the Gizmodo/iPhone leak and the subsequent police investigation. Few have been as scathing toward Apple as a segment that aired on tonight’s Daily Show. And while Apple has long made a habit of mostly ignoring what the press and media says about it, you can be sure this will get their attention.


In the segment, host Jon Stewart lambasts Apple for the police raid on Gizmodo editor Jason Chen’s house, and the fact that Apple employees showed up on the doorstep of the guy who originally found the phone. Stewart’s report glosses over some important points in the case and gets a few details wrong. But ultimately that doesn’t really matter — Stewart’s audience probably doesn’t care if there’s a chance a crime was committed here. To them, a guy found a phone in the bar, photos of it were posted on the Internet, and Apple responded by siccing the authorities on them.



The segment is full of great quotes, like:


“You guys are busting down doors in Palo Alto while Commandant Gates is ridding the world of mosquitoes. What the f**k is going on?”


“Apple you guys were the rebels man, the underdogs. People believed in you. But now, are you becoming The Man? Remember back in 1984, you had those awesome ads about overthrowing Big Brother? Look in the mirror, man!”


“If you want to break down someone’s door, why don’t you start with AT&T, for God sakes? They make your amazing phone unusable as a phone!”


But the most important, at least from Apple’s perspective, is this one:


“I’m telling you this because it’s important, man. And believe me, I’m taking a big chance here. This is my audience. And this is way more explosive than putting Muhammad in a bikini to my audience.”


And that right there is why Apple will probably be paying more attention to this than it did to myriad blog posts about the iPhone leak. Apple can often afford to ignore outraged tech bloggers and developers because its mainstream audience really doesn’t care about its inconsistent App Store policies or section 3.3.1 of the iPhone developer agreement. But the mainstream most definitely cares what Jon Stewart has to say, and I suspect the demographic watching this show plays a big part in making Apple’s laptops, iPhones, and iPods hits.


And if Stewart is tearing into them now, imagine what will happen if Gizmodo, Chen, and the unnamed iPhone finder get charged with crimes.




"

Ubuntu Manpage Repository

Ubuntu Manpage Repository: "
Ubuntu Manpage Repository

Launched almost 2 years ago, the ‘Ubuntu Manpage Repository’ website is a collection of Ubuntu command-line generated manuals, harvested from every installed package of every supported version of Ubuntu, from Ubuntu 6.06 LTS to upcoming Ubuntu 10.04 LTS – manpages are updated on a daily basis and are available in over 40 different languages – all languages with manpages.


Ubuntu Manpage Repository

Ubuntu fanbois have at their disposal an immense resource, work that many developers have poured into the manpage-web-based documentation. Next time you want to consult the man page, head over to the Ubuntu Manpage Repository.


A recent update of the manpage repository website added a printer icon on the top right corner that allows you to print or generate a PDF file of your favorite manpages for didactic purposes.





"

SCO Asks Judge To Give Them the Unix Copyright

SCO Asks Judge To Give Them the Unix Copyright: "Raul654 writes 'In March, the jury in the Novell/SCO case found that Novell owns the copyright to Unix. Now, SCO's lawyers have asked judge Ted Stewart to order Novell to turn over the Unix copyright to them. 'SCO contends the jury did not answer the specific issue before Stewart that involves a legal principle called 'specific performance,' under which a party can ask a court to order another party to fulfill an aspect of an agreement.'' Over at Groklaw, PJ is deep into a community project to annotate SCO's filing. It's for the benefit of future historians, but it makes amusing reading now.



Read more of this story at Slashdot.

"

Shuttleworth Clears Ubuntu 10.04 for Liftoff

Shuttleworth Clears Ubuntu 10.04 for Liftoff: "

It’s official: Ubuntu 10.04 Long Term Support arrives April 29, and this particular blogger was privy to the press conference about it. Canonical Chairman Mark Shuttleworth and CEO Jane Silber discussed the plans and progress of new operating system, and then fielded some Q and A. The key news: More than 80 ISVs are supporting Ubuntu. But here’s what it means for the desktop users and Canonical as a whole…


Ubuntu 10.04 is now certified on over 50 servers and laptops, and OEM support is taking off worldwide. Dell has embraced Ubuntu Enterprise Clouds, and Lenovo has just launched Ubuntu machines into China.


Of course, Ubuntu 10.04 comes with some tweaks, most notably the ’social’ desktop. Chris Tozzi has the nitty gritty details, but the basic rundown is an integration of your social media into your desktop for easy blogging, tweeting, and general communication.


During the press conference, Mark Shuttleworth spoke about the new design featured in 10.04:


“10.04 is a substantial step forward [and a] shift in the look and feel. For six years [we designed] around [the motto] “linux for human beings” and drove our work [into the] community….now we’ve shown Linux is not just for computer specialists; [it] can be a warm, positive and friendly-constructive desktop environment.”


Shuttleworth also commented on how he wanted Ubuntu to be ‘light-ware’ or lightweight software that didn’t feel weighed down or bloated.


“[We want Ubuntu to] feel lightweight, agile. Visually [we worked] on the theme of light, too.”


And indeed, screen shots of 10.04 show a somewhat similar background to Mac OS X’s Aurora light show. But enough about the good looks, let’s get back to the software and those ISVs. Since Ubuntu is gaining traction in the market, I asked Shuttleworth:


“With increased support form ISVs, do you see this as Ubuntu taking a step towards gaining a foothold as a more widely and commonly developed platform like Mac or Windows?”


Silber, then Shuttleworth responded:


“[It's] strong signal about general acceptance [with] growth in consumer space and enterprise space. ISVs won’t support [a platform] unless there’s a commercial or strategic reason to do it…ISVs and OEMs [make] a strong endorsement [and help]growth and traction”


Shuttleworth took it a bit farther, and brought up the comparison to Apple and the app store…


“[There's] a number of things we’re doing to increase attractiveness. [Right now] we’re a cycle early to highlight [these things]. In our next release we intend to make it possible to have a consumer experience around the software built into the Ubuntu Software Center…aimed at making it straightforward [for] developers [to] publish their software free or commercial. Ff we are able to deliver Ubuntu across a comprehensive set of OEMs we’re very well positioned for opportunistic developers in a large development market.”


There was also some talk about delivering a special channel in the Software Center for devs that want to introduce software that hasn’t gone through Canonical’s 6 month testing cycle in effort to connect publishers more directly to end users. Shuttleworth hinted that wouldn’t be around ’till Ubuntu 10.10.


Silber noted that this is the highest amount of ISVs ever signed on to support Ubuntu, and they’re committed to an ongoing relationship where Ubuntu can continue to be a distribution channel for software.


And as for challengers like Microsoft and Apple? Silber noted:


“I think…many people have more than one computer, so decisions [to pick Ubuntu] are additive instead of a replacement decision. But they (Apple and Microsoft) are competitors we look at and our users [will] decide… [But] we look at their products and features and use that to help inform some of our strategic decisions…”


Lastly, is Canonical making any money on this thing, yet?


Short answer? No. Shuttleworth sounded confident as ever though, as he noted they’re continually driving towards profitability and are keenly aware about the “depth of the channel and scale of investment required in markets” to make such a business profitable. But with all the OEM support, Shuttleworth seemed at ease.


Lastly, it was noted that Canonical is doing well enough that they’re slated for the next LTS release in April 2012 and they’re happy about the “rich ecosystem” Ubuntu and the Debian base have provided


"

Microsoft claims Android steps on its patents (CNet)

Microsoft claims Android steps on its patents (CNet): "CNet reports that
Microsoft is now claiming that Android, too, infringes on its patents.
'Microsoft and HTC announced they have inked a new patent deal that
specifically provides the Taiwanese cell phone maker with the right to use
Microsoft's patented technologies in phones running Google's Android
operating system. Microsoft said it has been in talks with other phone
makers.
' (Thanks to Amit Shah)."

Fight Image Spam With FuzzyOCR And SpamAssassin On Debian Lenny

Fight Image Spam With FuzzyOCR And SpamAssassin On Debian Lenny: "

Fight Image Spam With FuzzyOCR And SpamAssassin On Debian Lenny



This tutorial describes how to scan emails for image spam with FuzzyOCR on a Debian
Lenny server. FuzzyOCR is a plugin for SpamAssassin which is aimed at
unsolicited bulk mail containing images as the main content carrier.
Using different methods, it analyzes the content and properties of
images to distinguish between normal mails (ham) and spam mails.
FuzzyOCR tries to keep the system load low by scanning only mails that
have not already been categorized as spam by SpamAssassin, thus avoiding
unnecessary work.

"

TEABAGGER MELTDOWN! - Protestor Goes Mental At Interviewer For Asking Questions

TEABAGGER MELTDOWN! - Protestor Goes Mental At Interviewer For Asking Questions: "
I favorited a YouTube video: 24 April, 2010 Fixed News
"

Foreign Service Institute’s Extensive Language Courses Are Available Free Online

Foreign Service Institute’s Extensive Language Courses Are Available Free Online: "

The US Foreign Service Institute teaches foreign languages to government diplomats and personnel for duties abroad — and its courses are available online, for free. Which means you can access audio, texts and tests in 41 different languages. (more…)

"

I wish I could help you with your science homework, honey, but when I was in school we used a different textbook

I wish I could help you with your science homework, honey, but when I was in school we used a different textbook: "
"

Jesus And The Apostles

Jesus And The Apostles: "


Jesus2




"