Native One Time Password (OTP) – Citrix (Netscaler) Gateway - workaround for manageotp security and admin controls

Most of the time I follow "Carl Stalhood" and if you want to configure Native One Time Password for Citrix Gateway please visit Carl's site (https://www.carlstalhood.com/netscaler-gateway-12-native-one-time-passwords-otp/)

When I was proposing this to customers, I observed that the limitations on securing /manageotp page is quite challenging for some use cases. What I'm about to explain here is, how not to allow users to register their own OTP authenticator but let admin to give control. It's a workaround I used and it's a manual method.

I'm not going to explain how to configure Citrix ADC for native OTP here (please follow https://www.carlstalhood.com/netscaler-gateway-12-native-one-time-passwords-otp/ ) for the deployment.

With my workaround users don't need to access /manageotp page at all. So restrict it for only admin's subnet on otp page login schema rule by setting it as follows; (if you want to access it for any reason)

http.req.cookie.value("NSC_TASS").eq("manageotp") && client.IP.SRC.IN_SUBNET(192.168.100.0/24)

or completely disable it.

If I explain the method in brief, its as follows; i will explain them in details later.

1. Citrix admin to manually generate a secret key for the user (we can use simple excel function for this)
2. Citrix admin to share the secret key to AD admin to configure the attribute of the users ldap profile
3. Citrix admin to share the secret key with the end user to manually enroll their mobile device (or admin can do it by himself on users device without sharing the key)
4. Citrix admin update his database (ex. excel) manually for future references

1. Citrix admin to manually generate a secret key for the user - this will help you to create a secret key for users (with MS excel)

1a. Open MS excel and paste "ABCDEFGHIJKLMNOPQRSTUVWXYZ234567" on a cell and name it as "Source"
1b. for a secret of 26 characters use following function to randomly generate a string.

=MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)
& MID(Source,RANDBETWEEN(1,LEN(Source)),1)

it will randomly give you an out put similar to VLVLQJTETW2Z3O4UW5S4QQQCBT

2. Citrix admin to share the secret key to AD admin to configure the attribute of the users ldap profile

2a. Citrix admin can share the generated secret with AD admin in following format (shedev is the device name we provide for the user)

#@shedev=VLVLQJTETW2Z3O4UW5S4QQQCBT&,

2b. AD admin can insert the given value to the selected attribute of the user ldap profile (in our case its userParameters)


3. Citrix admin to share the secret key with the end user to manually enroll their mobile device (or admin can do it by himself on users device without sharing the key)

3a. we can now share the generated secret key to the user

secret - VLVLQJTETW2Z3O4UW5S4QQQCBT
device name - shedev

3b. user or the admin by him self can configure the OTP Authenticator as follows; and save it


c. now you dont need to access /manageotp page and directly go to the gateway login page to enter dual factors



Notes;
1. make sure you you store secret keys in a secure place. I use a password protected excel to store them for the time being. something similar to following (they are some sample data set :) )

2. To automatically get the AD attribute value i use following function for E column of the above image

="#@"&D2&"="&C2&"&,"

3. To remove an OTP authenticator of a user, just clear the attribute value

=================================================

My next target is to write a small web page to get this task automated with maybe following functionality. if anyone smart enough to write it, let me also know. (unfortunately I'm not a web developer)

Add a user
1. Search a user from AD ldap
2. Generate a key for user (about 27 characters long random string)
3. Enter a device name
4. Store the key on a predefined attribute of AD ldap profile of the user
5. Store data to a local sql db (in a storefront environment we can use the same IIS and DB)
6. Send and email to the user with the key in it

Delete a user
1. Select user from the local db
2. Clear users attribute from the AD ldap profile
3. Delete user from the local db

Edit an existing user - (regenerate key)
1. Select a user from local db
2. Regenerate a new key
3. Clear existing attribute value and write new value on AD attribute of ldap profile of the user
4. Update local db

Share key with the user
1. Select a user from local db
2. A button to send an email to the user with the key in it

Good to have
1. A page to track changes done for users (all tasks listed above) - reporting
2. Encrypt local db
3. A login page to the site from an AD ldap user (admin user)
4. A page to list all the users in local db

Hope you enjoy my blog and helped someone. Any modifications or changes are always welcome :)




XenApp 5 on Server 2003 R2 SP2 - Installation Guide - PoC

Today I successfully deployed a XenApp 5 on a Server 2003 R2 SP2. It was a Proof of Concept (PoC) to one of customer in Sri Lanka and their requirement was to publish one of their application (which is only run on Windows XP) to publish on Windows 7 users.

After gathering information we realized that the client application supports to run on terminal sessions and also can be hosted on server 2003 R2 SP2 machine.

So, We started a PoC to achieve customers requirements and we just used a Desktop with 4GB RAM and 3GHz processor with Server 2003 R2 SP2 installed.

Following are the installation steps we followed;

Step 01 - Prepare the server

Install Server 2003 R2 SP2 on a machine and add it to the AD. Get a Domain user account and add it to the local machine's administrator group (Or get a domain admin account) and login to the machine using this account.

Step 02 - Install Prerequisites

Install Dotnet Framework 3.5 SP1 and KB961118 hotfix (Download the correct update file for server 2003 and make sure you downloaded the file for the correct platform. In my case its 64 bit)

Get the files downloaded from following links


Step 03 - Install Windows components

Install Windows components which is required for the XenApp installation

  • Go to "Add or Remove Programs" from the control panel.
  • Click "Add/Remove Windows Components" in the left column.
  • Check the box next to "Application Server".
  • Scroll down to "Internet Explorer Enhanced Security Configuration" and uncheck it. (This is to prevent the annoyance of its popups and if you know how to deal with it, just keep it checked).
  • Scroll down and check the boxes next to "Terminal Server" and "Terminal Server Licensing".
  • Click next again Click Next on the Terminal Server setup notice.
  • Click Next on the next "Terminal Server Setup" notice about Security. (We will not be installing any legacy software so we are fine with the default selection of Full Security).
  • Click "I will specify a license server within 120 days" and click Next
  • Click Per User licensing mode and click Next.
  • Click Next and it will start installing selected windows components. (It will ask for the server 2003 CD and keep it ready).
  • When the Windows Components Wizard is complete, click Finish.
  • Adding Terminal Server in Application Server mode requires the server to be restarted. Click Yes to restart the Machine.

Step 04 - Install XenApp 5

Download the XenApp 5 for server 2003 from the Citrix Website. You can request a trial and a trial key will be provided to you.

To activate your trial license, go to My Account on Citrix.com and login using your existing credentials if you are not already logged in. After login, go to: My tools>Choose a Toolbox>Manage Licenses>Allocate. Select the "Don't see your product?" link located at the top right corner of the Allocate web key page. Enter the trial key in the Find your license dialog box and click Continue. When the Host Name warning page displays, select Continue. It will guide you through the four-step license file generation process. And download the license file.

  • Run the XenApp and Click on "Install XenApp".
  • Click on "Install Server-Hosted Apps".
  • Accept the Agreement and Click Next.
  • Select "XenApp Platinum Edition and click Next. (Select whatever the version you want).
  • Select "License Server" along with other default selection and click Next.
  • Click next on "Product Installation Directory".
  • Enter Farm Name and click Next. (Ex- NewFarm).
  • Accept other Defaults and it may take few minutes to complete the installation.

Step 05 - Configure XenApp

Open “License Management Console”
  • Click “Step 2: Copy license file to this license server”
  • Goto “Configure License Server”
  • Upload the license file

Open “Delivery Service Console”
  • Right Click on the Farm and Select “Properties”
  • Goto “Server default” → License Server
  • Enter the license server IP → ok

Open “Citrix Web Interface Management”

  • Right click on “XenApp Web Sites” → Creat Site
  • check “Set as the default page for the IIS site” → next
  • accept other default options
  • farm name = NewFarm
  • add XenApp server by its host name → next
  • Accept other default options


Step 06 - Publish a test application

  • Open “Delivery Service Console”
  • Expand the Farm and right click on Applications and click on "Publish Application"
  • Click Next at the Welcome screen.
  • Click Next, accepting the defaults for Application Type. (We are publishing a hosted application which is already installed on this server).
  • Browse to the application executable.
  • Select which Servers/Worker Groups will run the application and click Next. (In our case it's the local machine)
  • Select which Users/Groups will be allowed to run the application – it’s best to use Domain Groups for easier management/delegation.
  • Accept all the other default options. (Change settings as necessary. I accepted defaults in my case).

Step 07 - Run Published Applications

  • Open "Internet Explorer" and enter the server IP.
  • Login using a domain credentials. (This user must have permission to run the published application. Check Step 05)
  • Install the Citrix Receiver.
  • Now you will be able to see published applications on the site and they will be accessible by simply clicking on it.


So, that was the steps I followed for the Proof of Concept for my customer and it was successful. Hope this guide will help to someone and all of your comments are welcome!!

Create a custom selinux policy with audit.log

First install policycoreutils-python package;

yum install policycoreutils-python

then run following commands;

audit2why < /var/log/audit/audit.log
cat /var/log/audit/audit.log | audit2allow -M local

To make this policy package active, execute;

semodule -i local.pp

How do I find out what perl modules already installed on my system?

You need to use instmodsh (interactive inventory for installed Perl modules) command to find out what modules already installed on your system.

instmodsh command provides an interactive shell type interface to query details of locally installed Perl modules. It is a little interface to ExtUtils::Installed to examine locally* installed modules, validate your packlists and even create a tarball from an installed module.

To display the list enter the following command:

[root@localhost ~]# instmodsh

Output:

Available commands are:
l - List all installed modules
m - Select a module
q - Quit the program
cmd?

type l to list all installed modules:

cmd? l
Installed modules are:
Config::IniFiles
Perl
Text::Balanced
Time::HiRes
cmd?

Zorin OS - An alternative OS for windows users

Hi Guys, Recently i was searching for an open source OS for my desktop and found this Zorin OS whose interface was very similar to windows 7. It is one cool linux OS and very similar to Ubuntu.

Zorin OS is a multi-functional operating system designed specifically for Windows users who want to have easy and smooth access to Linux. It is based on Ubuntu which is the most popular Linux operating system in the world.

Zorin OS features unique Look Changer program that have created exclusively for Zorin OS. It allows users to change the user interface at the touch of a button. Other unique programs include Splash Screen Manager, Internet Browser Manager and Background Plus.

Zorin OS gives users more flexibility. It allows you to use Zorin OS alongside your current operating system and run Microsoft Windows programs in Zorin OS with the help of WINE and PlayOnLinux.

Visit www.zorin-os.com for more details..

Samba file server with AD authentication

Prerequities
Fedora 8 with base

vim /etc/selinux/config
"SELINUX=disabled"

vim /etc/hosts
"192.168.123.228 test-ad.contoso.com test-ad"

yum install ntp
ntpdate

yum install samba
yum install samba-common
yum install samba-client
yum install samba-swat

chkconfig smb on
service smb start
service nmb start
chkconfig nmb on

cp /etc/samba/smb.conf /etc/samba/smb.conf.original

vi /etc/xinetd.d/swat
"only_from = 127.0.0.1 192.168.123.0/24"
"disable = no"

service xinetd start
chkconfig xinetd on

connecting the samba server to the AD

setup -> Authentication configuration
(only check following options)
-Use Winbind
-use MD5 passwords
-Use Shadow Passwords
-Local authorization is sufficient

-> next ->

-Security Model = ads
-Domain = CONTOSO.COM
-Domain Controllers = test-ad.contoso.com
-ADS Realm = CONTOSO.COM
-Template Shell = /sbin/nologin

-> next -> yes ->

Domain Administrator = Administrator
Password =

-> Ok -> Ok -> Quit

("wbinfo -u" command returns domain user list if the ad join is successful)


####################################################

vim /etc/nsswitch.conf

passwd: compat winbind
shadow: compat
group: compat winbind

###################################################

init 6 (restart the server)

####################################################

iptables rules for samba share access

iptables -A INPUT -m multiport -p TCP -s 192.168.123.0/24 --destination-ports

631,139,445 -j ACCEPT
iptables -A INPUT -m multiport -p UDP -s 192.168.123.0/24 --destination-ports

631,137,138 -j ACCEPT

iptables rules for SWAT access on port 901

iptables -A INPUT -p TCP -s 192.168.123.0/24 --destination-port 901 -j ACCEPT

####################################################

use http://samba-server-IP:901 to configure shares

[global]
workgroup = CONTOSO
realm = CONTOSO.COM
server string = Samba Server Version %v
security = ADS
password server = test-ad.contoso.com
passdb backend = tdbsam
log file = /var/log/samba/log.%m
max log size = 50
socket options = TCP_NODELAY SO_RCVBUF=16384 SO_SNDBUF=16384
preferred master = No
dns proxy = No
ldap ssl = no
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
template shell = /sbin/nologin
winbind enum users = Yes
winbind enum groups = Yes
cups options = raw
[administrator]
path = /home/administrator
valid users = contoso\administrator
admin users = contoso\administrator
read only = No

####################################################
create samba directories on samba server

mkdir /home/administrator
chmod 777 /home/administrator
chmod a+s /home/administrator

####################################################
Please note that in my examples I've made following assumptions
192.168.123.0/24 is my LAN ip block
contoso.com is my AD domain
192.168.123.228 is my AD's IP
test-ad.contoso.com is my AD machine name

Change the Volume Licensing product key of win xp sp1 and later versions

Use the Activation Wizard

Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.

If you have only a few volume licensing product keys to change, you can use the Activation Wizard.

Note Microsoft recommends that you run System Restore to create a new restore point before you follow these steps. For information about how to create a restore point by using System Restore, see the "To Create a Restore Point" help topic in Help and Support.

1 - Click Start, and then click Run.
2 - In the Open box, type regedit, and then click OK.
3 - In the left pane, locate and then click the following registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\Current Version\WPAEvents

4 - In the right pane, right-click OOBETimer, and then click Modify.
5 - Change at least one digit of this value to deactivate Windows.
6 - Click Start, and then click Run.
7 - In the Open box, type the following command, and then click OK.

%systemroot%\system32\oobe\msoobe.exe /a

8 - Click Yes, I want to telephone a customer service representative to activate Windows, and then click Next.
9 - Click Change Product key.
10 - Type the new product key in the New key boxes, and then click Update.

If you are returned to the previous window, click Remind me later, and then restart the computer.

11 - Repeat steps 6 and 7 to verify that Windows is activated. You receive the following message:

Windows is already activated. Click OK to exit.

12 - Click OK.
13 - Install Windows XP SP1 or a later version of Windows XP.

If you cannot restart Windows after you install Windows XP SP1 or a later version of Windows XP, press F8 when you restart the computer, select Last Known Good Configuration, and then repeat this procedure.

scp - Linux command line tool to copy files over ssh

scp stands for secure cp (copy), which means that you can copy files across an ssh connection that will be encrypted, and therefore secured. The server should be capable of handling SSH and the port 22 should be open

You can this way copy files from or to a remote server, you can even copy files from one remote server to another remote server, without passing through your PC.

Usage

scp [[user@]from-host:]source-file [[user@]to-host:][destination-file]

Description of options

from-host Is the name or IP of the host where the source file is, this can be omitted if the from-host is the host where you are actually issuing the command

user Is the user which have the right to access the file and directory that is supposed to be copied in the cas of the from-host and the user who has the rights to write in the to-host

source-file Is the file or files that are going to be copied to the destination host, it can be a directory but in that case you need to specify the -r option to copy the contents of the directory

destination-file Is the name that the copied file is going to take in the to-host, if none is given all copied files are going to maintain its names

Options

-p Preserves the modification and access times, as well as the permissions of the source-file in the destination-file
-q Do not display the progress bar
-r Recursive, so it copies the contents of the source-file (directory in this case) recursively
-v Displays debugging messages

Examples

scp *.txt user@remote.server.com :/home/user/

This will copy all files with .txt extension to the directory /home/user in the remote.server.com host

scp -r eranga@10.1.2.2:/home/eranga/ eranga@10.1.2.3:/home/eranga/

This is going to recursively copy all files from eranga's Home directory on 10.1.2.2 host to his Home directory in 10.1.2.3 host.

Burn .bin file Without A .cue file

To burn a bin file, you will need an appropriate cue file.

You do exactly the same as for iso files, but when you click on “burn image,” you don’t browse to the bin itself, but instead to the cue file, and you open that one.
When the writer starts to burn, it will automatically search for the bin file and start burning it. In fact, the cue file tells the burning program where it can find the bin file that is attached to it. It is VERY IMPORTANT that you use the right cue file when you burn a bin. i.e both cue and bin files that are attached to each other must be located in the same folder, and every bin file has it’s own cue file.


Normally, when you download a bin file, you can download the appropriate cue file as well. If you do not have the cue file (or feel bold) you can make the cue file yourself, which is really easy to do:

a. Open notepad
b. Copy the folowing text into notepad:

FILE“nameofimage“BINARY
TRACK 01 MODE1/2352
INDEX 01 00:00:00

Where nameofimage.bin is the name of the bin file you want ot burn.

c. The rest is easy: just save the notepad text with the name of the bin, but with the cue extension.
d. The file should be saved in the same folder as its appropriate bin file and should be something like myfile.cue

Or you can use Alcohol 120% to burn directly from the bin file

A simple Perl script to convert Nagios/Squid logs time to a human readable format

########################################################

Installation steps

#######################

vim nagios-time-converter.pl

Paste the following codes and save the file

#!/usr/bin/perl

# ------------------------------------------------------------
# nagios-time-converter.pl
# ------------
# by:- Eranga Perera
# a perl script to convert Nagios "epoch time" (epoch seconds)
# into a human-readable format.
# ------------------------------------------------------------

$num_args = $#ARGV + 1;
die "Usage: this-program epochtime (something like '1279236316')" if
($num_args != 1);

$epoch_time = $ARGV[0];

($sec,$min,$hour,$day,$month,$year) = localtime($epoch_time);

# correct the date and month
$year = 1900 + $year;
$month++;

printf "%02d/%02d/%02d %02d:%02d:%02d\n", $year, $month, $day, $hour, $min, $sec;

chmod 755 nagios-time-converter.pl

Usage
#######################

./nagios-time-converter.pl 1279236316

########################################################

Groundwork, Nagios and SNMP Traps Integration....!!

Pre Requisites
Minimal installation of CentOS with base package

Disabling selinux
vi /etc/selinux/config
SELINUX=disabled

Yum –y install gcc
cd /usr/src/
wget http://search.cpan.org/CPAN/authors/id/N/NW/NWCLARK/perl-5.8.9.tar.bz2
tar xvf perl-5.8.9.tar.bz2
cd perl-5.8.9
./configure.gnu --prefix=/usr
make
make test
make install

Installing perl modules
perl -MCPAN -e shell
install Text::ParseWords
install Getopt::Long
install Config::IniFiles
install Time::HiRes
install Sys::Hostname
install File::Basename
install Text::Balanced

Installing groundwork
chmod +x groundwork-5.3.0-br46-gw333-linux-32-installer.bin
./groundwork-5.3.0-brXX-gwYYY-linux-32-installer.bin --mode text

Installing net-snmp
yum -y install net-snmp
download net-snmp package to /usr/src (http://www.net-snmp.org)
tar xvzf net-snmp-5.4.2.1.tar.gz
cd net-snmp-5.4.2.1
./configure --with-perl-modules
make
make test
make install

Installing snmptt
tar xvzf snmptt_1.2.tgz
cd /usr/src/snmptt_1.2
cp snmptt /usr/sbin/
cp snmptthandler /usr/sbin/
cd /usr/sbin/
chmod +x snmptt
chmod +x snmptthandler
cd /usr/src/snmptt_1.2
cp snmptt.ini /etc/snmp/
cd /etc/snmp/
create a new file;
vi snmptrapd.conf
and add the following line;
traphandle default /usr/sbin/snmptt

vi /etc/init.d/snmptrapd
Change the OPTIONS="-Lsd -p /var/run/snmptrapd.pid" as below
OPTIONS="-On -Lsd -p /var/run/snmptrapd.pid"

/etc/init.d/snmptrapd restart
cp /usr/src/snmptt_1.2/snmptt-init.d /etc/init.d/snmptt
cd /etc/init.d/
chmod 755 snmptt
chkconfig --add snmptt
chkconfig --level 2345 snmptt on
/etc/init.d/snmptt start

cp /usr/src/snmptt_1.2/snmpttconvert /usr/bin
cp /usr/src/snmptt_1.2/snmpttconvertmib /usr/bin
cd /usr/bin/
chmod 755 snmpttconvert

chmod 755 snmpttconvertmib

snmptt.ini configurations with following values (/etc/snmp/snmptt.ini)
dns_enable = 1
strip_domain = 1
net_snmp_perl_enable = 1
pre_exec_enable = 0
unknown_trap_log_enable = 1


/etc/init.d/snmptt start

Opening 80 port from the firewall
vi /etc/sysconfig/iptables
add the following line
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
/etc/init.d/iptables restart

Access groundwork through a web browser
User name: admin
P/w: admin

Enable notifications
Go to Control --> Nagios main Configurations --> Enable notifications: check the box --> save --> commit

Adding a host
Go to Configuration --> Host Wizard and follow steps Go to Control --> commit --> commit

Submit-check-results
Download submit_check_result from nagios standard distribution
Copy it to /usr/local/groundwork/nagios/eventhandlers/

chmod +x submit_check_result
vi submit_check_result
and change the nagios.cmd file path
/usr/local/groundwork/nagios/var/spool/nagios.cmd

Compiling a MIB
snmpttconvertmib --in= --out=/etc/snmp/snmptt.conf1 --net_snmp_perl

Edit the compiled file and add the following to each and every trap
EXEC /usr/local/groundwork/nagios/eventhandlers/submit_check_result $R TRAP 1 "$*"

Add compiled file paths to the /etc/snmp/snmptt.ini script [...]
[TrapFiles]
snmptt_conf_files = << END
/etc/snmp/snmptt.conf1
/etc/snmp/snmptt.conf2
END

Creating TRAP service
Create a new service with following details

Name : TRAP
use :generic-service
is_volatile :1
check_command :check-host-alive
max_check_attempts :1
normal_check_interval :1
retry_check_interval :1
passive_checks_enabled :1 Active_checks_enabled :0
check_period :24/7
notification_interval :31536000
contact_groups :somegroup

To enable audio alerts edit the following file.
/usr/local/groundwork/apache2/confg/httpd.conf
Add following lines.

ScriptAlias /nagios/cgi-bin "/usr/local/groundwork/nagios/sbin"
< Directory "/usr/local/groundwork/nagios/sbin">
# Uncomment for Guava Single Sign On
AuthType Basic
require valid-user
# The following line should be change to specify the default page for invalid access attempts to this directory
TKTAuthLoginURL http://localhost:80/monitor/index.php
TKTAuthCookieName nagios_auth_tkt
TKTAuthTimeout 0
# Uncomment to disable Guava Single Sign On
# AllowOverride AuthConfig
# Options ExecCGI
# Order allow,deny
# Allow from all
PassEnv LD_LIBRARY_PATH
PassEnv NAGIOS_CGI_CONFIG
< /directory>

Alias /nagios/media "/usr/local/groundwork/nagios/share/media"
< Directory "/usr/local/groundwork/nagios/share/media">
# Uncomment for Guava Single Sign On
AuthType Basic
require valid-user
# The following line should be change to specify the default page for invalid access attempts to this directory
TKTAuthLoginURL http://localhost:80/monitor/index.php
TKTAuthCookieName nagios_auth_tkt
TKTAuthTimeout 0
< /directory>

Do you want to bypass a proxy server??? [Anonymous surfing]

Free anonymous web surfing
Protect your identity during web surfing
Encrypt your Internet communication
Bypass network censorship

Welcome to GPass, your key to anonymous, secure, and unrestricted Internet surfing.

GPass wraps the network traffic of your Internet applications in various formats and tunnels the wrapped packets through various dynamic channels to its servers. The GPass servers unwrap the packets and forward them to their destination on your behalf, yet they hide your identity (i.e., IP address).

GPass adds security to your online activities because the content you transfer on the Internet is encrypted and disguised to avoid sniffing by your friends (well, you know, your boss, your DSL company, or even the national gateway of your country). GPass hides your identity as well as the websites you are visiting (but sorry, porn sites are blocked in GPass) because the worldwide distributed GPass servers act as your middle agents. In addition, while some websites may be blocked by the firewalls of your company, ISP, or country, GPass brings them back to you.


Click here to download via rapidshare....


Enjoy Anonymous web surfing.........


Data Recovery - GetDataBack for NTFS & FAT v3.03



GetDataBack will recover your data if the hard drive's partition table, boot record, FAT/MTF or root directory are lost or damaged, data lost due to a virus attack, the drive was formatted, fdisk has been run, a power failure has caused a system crash, files were lost due to a software failure, files were accidentally deleted.

GetDataBack can even recover your data when the drive is no longer recognized by Windows. It can likewise be used even if all directory information - not just the root directory- is missing.

The software enables the regular user to conduct his own data recovery by guiding him through five easy to understand steps, thus gives the advanced user the possibility to interfere with the recovery and improve the results, by examining the scan log, the file system details, file and directory information, by selecting the sector range to be scanned, by choosing excessive search for file systems or search for lost files, by calling Runtime's DiskExplorer.

To download click below links and enjoy the software.......

GetDataBack for FAT v3.03

GetDataBack for NTFS v3.03

Outlook Express and MS Outlook mail recovery software (R-Mail)

R-Mail - is a family of email recovery utilities for damaged files and deleted messages created by Microsoft Outlook (later referred to as "Outlook") and Microsoft Outlook Express (later referred to as "Outlook Express") software. R-Mail utilities are based on the highly effective IntelligentRebuild Email recovery technology that allows R-Mail software users to repair damaged *.pst and *.dbx files and restore lost e-mail messages just in three steps.

R-Mail for Outlook v1.5 - recovers accidentally deleted Outlook e-mail messages, contacts, notes, tasks and other items, and repairs damaged Outlook data files (*.pst) files where Outlook stores folders with the data. The recovered data can be saved in the *pst, *.msg, and *.eml formats that Outlook can open and import. When doing any operation, including Outlook data file recovery, R-Mail for Outlook never deletes from disks, writes to, or modifies in any way original Outlook data file.

Supported *.pst file format: Microsoft Outlook 97/2000/XP/2003.

R-Mail for Outlook Express v1.5 - is a tool designed to undelete accidentally deleted Outlook Express e-mail messages and recover damaged *.dbx files where Outlook Express stores folders with email messages. The messages are recovered in the .eml format and can be simply imported into Outlook Express mail and news bases.

Supported *.dbx file formats: Microsoft Outlook Express 5.0, 5.01, 5.5, 6.0.

Host OS: Windows 98/ME/NT/2000/XP/2003/Vista.

DownLoad R-TT R-Mail for Outlook v1.5. + License.
download [ 0.6mb ] (RapidShare)

DownLoad R-TT R-Mail for Outlook Express v1.5. + License.
download [ 0.6mb ] (RapidShare)

Hi Guys n' gals.......

How are you all??????
feeling hot hot hot???
here's d correct place 2 b cooooool...
come n' join wid me...
let's start a new era with Era....

What do you all think about technology??
is it boring??
i dont think so...
coz, for me it's very interesting...
however sometimes it's making me mad..
ya it's true...
Technology is a good joke..
Sooooo......
Wot do you think????
aren't you agree??
are you?

As i told before um mad.......
..........but don't worry......
.........join wid me.......
....for a new era....
.....wid Era......
....... :-) .......
..............
.......
..
.
.
.
.
.......
.....
...
.

Hi Friends,,,