View by:

Three VPN Servers and a Kindle Console

Tuesday, September 15th, 2009 – running time 45:29
This week Shannon taps into a hidden Kindle serial port using a inty bitsy ribbon cable, a USB to Serial TTL cable and some jumpers in an attempt to hack root and finds herself upon the bootloader and nearly at a bash prompt. Darren guides you through the installation of VPN servers on Windows XP, Windows Server and Linux so you can keep your traffic secure in an encrypted tunnel while on untrusted networks.

Segments

Kindle Console

Hacking into the Kindle Bootloader Part 1

This week, I'm introducing the bootloader Kindle 1st gen hack.

Equipment:
Kindle 1st Generation A computah! USB to Serial TTL Cable 20 pin 0.5 mm flat cable 1 pin Jumper cables

Programs:
Putty Igor Skochinsky explains how to hack into the bootloader of the Kindle very nicely on his blog, Reverse Everything. He includes screenshots, photos, and descriptions of everything you need to know to do this hack. Part 1 Part 2

If you have any questions, you can email me at snubs@hak5.org!

04:38

Play

Windows VPN Servers

In this segment I demonstrate setting up a VPN server in Windows XP which is rather limited at 1 concurrent connection. I also demonstrate building a Routing and Remote Access VPN server in Windows Server 2003.

14:04

Play

Linux VPN Server

I'm a big fan of open source. I'm also an overwhelmed systems administrator that likes easy. And when it comes to VPNs in Linux, OpenVPN is the go to solution. That's why I'm excited about OpenVPN Access Server -- an set of installation and configuration tools that simplifies rapid deployment of a VPN solution.

In this segment I demonstrate setting up this nifty, lightweight and powerful server in a typical home user scenario. I also speak to the fact that it can integrate with Active Directory via LDAP or even a RADIUS server for authentication. The web based backend makes administration a breeze and the web frontend makes client setup even easier. All the clients have to do is login to a website and download a prepackaged and configured connection app for Windows, Mac or Linux.

This package makes it incredibly easy to deploy a VPN server. But it comes at a cost. OpenVPN-AS requires a license key for each concurrent connection. Two are provided for free and additional licenses are $10 ea. Still a far cry from a windows Client Access License!

In future segments we'll be getting our hands dirty with OpenVPN standard as well as some other interesting VPN technologies so be sure to send your feedback, requests and flames to darren@hak5.org

28:28

Play

In future segments we'll be getting our hands dirty with OpenVPN standard as well as some other interesting VPN technologies so be sure to send your feedback, requests and flames to darren@hak5.org

Highlights

open source: 2:19, 15:25, 28:39, 38:45, 39:49
operating system: 9:19, 11:35
ribbon cable: 5:33
plugged in: 9:01

Automatically Generated Transcript

May not be 100% accurate

" War."

" This time on the show Kindle compact. Three -- servers at fifteen minutes. And no wind as deep -- short based horsepower all that and more on this episode of hacked off. That is brought to you by go to assist express -- and easy free web conferencing and Squarespace. Well."

" Welcome back five my name is Darren Kitchen she likes and I met last and out of them and ask your time off we can encourage you want to because it's gonna be excellent -- Really get months. Of life. Over real. Full review -- we -- we. Art happens it sorry when it went. -- they went to -- if -- really really. Jack. Well. Yeah I did absolutely nothing anyway -- everything up on it and it it's. Is -- and I don't wear it in. -- Both geologists. Let that simmer for what's so wrong yeah you may have we react -- some comments on six 36 reports. -- this is what happens when we -- purposes the other -- to back to back in the course of two hours. The case and an active. Who gap I mean you know there was this season for most the season four we were due in two episodes a night and it. Didn't work to -- it was great for us but you it's time more it was too much of a time -- and we decided that to get things more you know. I don't know in tune with feedback instantly that we're gonna go one week because."

" Assistant with four -- one through 415 like there were changed every yen today and and that's the thing is with the beginning of every -- need season. Five some accent. Which takes us like couple weeks justice field. You know under start a new set with a new format all that stuff but that we have a killers do you guys this week he really -- low. Like consul accessed via an open source goodies -- get from windows servers we the -- name prove your some horsepower performance here. Tonight you rock star. And we. So yeah we need a week off because you know every is she single week and we brought back records read. Very excited. Duties that --"

" This is I don't know why analyst rather avalanche are that's the whole we go -- take candidate forum. For more than forty hours. Are these what reforms could be coming back and forth."

" It's --"

" Whenever two to force. So that's what's going on with us. So. Let's get right into it. Shannon you're voiding warranties."

" Here I am -- and is I am went to this blog it's called. The reverse engineering blog and they basically walk you through how to figure out. I open up the boot loader on the can away and it's just the first gen and I know that there is a new -- count for the can adults -- that -- it's news. That -- the exact same day as my Kindle episode. About."

" And if you do this like when you -- hardware withers -- that we whatever lake lake there's a view from where there's a new -- there's something that comes at the same data errors so that. If we US something -- come out and expects its yet it has some kind of like a -- one I just wanted it. It's like when Leo buys a Mac in the lower prices. Ankle on -- original -- Only every time by the Mac but not not too much you know just like tongue in cheek like that's not going to -- enterprise. It's like what's and Alex seven dollars. It's. We we are getting way off we're an adapter realm now let's get back to back by the universe."

" This so act --"

" You're you're breaking into your Kindle are you afraid -- gonna void the warranty all of that and you afraid -- gonna destroy it. We should probably -- probably do the segment how it goes up. But first."

" Let's take a break doesn't get."

" I -- I've seen a lot of -- lately with the Kindle especially getting -- on it. Yes from what I understand though there's Linux already on it we're hacking that what are we doing here."

" Yeah there is Linux on here basically what I'm doing is I'm turning myself into an Amazon employee and I am trying to. Get in here so I can actually see the firmware and see the boot loader. I wanna get in there and find the username and password and I and all the different commands that I can do -- behind the scenes. So what are we gonna need to break in there well there's a couple of different things that you won't need that -- everything's pretty cheap except for the computer and the Kendall. Kindle one is the first thing. I relax and -- they can go -- here not the Kindle to -- you to -- one right here about six telling -- so that I can do they. But yes. The second thing you need is this. Very flat twenty and point five millimeter ribbon cable into here. An interest in here yet this little -- cable has twenty depends on -- crops. And you just plug it into this little open space in the back in the can I don't know why they left this picky. But they did yeah that -- remarks them yes I think this is out if that's from where before they actually send it out to the different people. To their different analysts the."

" Four pins on the motherboard of the Fon routers they can get in you know -- I."

" Exactly exactly the second thing you need are some of these cables. So that you can -- needs to. This. USB to serial TTL cable entrance. Away into my computer. Right. Soon that cable is."

" Is basically. Taking cereal and putting it. Through US peace yet it actually uses they can actually see what's going. Prayer and so technical matters particularly retractable. Fry anything else -- yeah and well I didn't I got a bunch of links except where you need abilities yourself. Or by them and and the really cheap."

" Yeah they're very cheap flat cable is like two dollars two dollars and fifty cents so it's it's -- packet as long as you have the big parts are ready. The other thing about this flat cable is when you're starting to do this -- you have to kind of -- have to get rid of a lot of the different little and you can only have. There's about five different and they can use numbers 37 cents and for ground cable. C have you received any nutrients and cables and each of these -- be tied into these serial TSB to -- The next thing you need is your actual programs on your computer. You need a driver. For the cereals USB -- out. And you Austin aide Heidi yours kind of configurations Apple strangle us yes you're analysts changed the serial warden -- against. So I'm go over here on my computer. First thing -- need to changes the speeds and the change that tube. 115200. And then this is the -- three which I figured this out by going over here into my computer management. And device manager and then prolific USB to serial com court is contrary. So it seems that everything else stays the same so open that up now I have my. Command prompt I -- church or terminal is listening to everything that is going everything that is going it. Now this is really really finicky sometimes it works sometimes it doesn't -- and he's. -- it's and I nearly art yes these cables it's that we see bits yes they are an -- I'm kind of unsure about whether I should solder these are not because you documents like the one. I'm once I'm -- can't -- solder -- go and get him in place and access networks every time but at same time so finicky that you might not move at all but."

" A lot more you won't be have to responders did to the that he part is the reason these little alligator clip jumper cable alias yeah. And it's just that if we -- slaughter and we have to cut the cable and it's gonna be a pain so for right now before you next segment for you let's go and do it this way."

" He's the flag cables can you like team lacks the and we're -- right after three and if it's broom -- up. Okay if I have anything plugged in any -- connected to their proper and so I just -- on the power button on my Kindle can -- Right so as you can see it just started booting up and it's telling me that the power switches off. So there's still a little bit signal coming through here because the operating system doesn't when you turn off the can -- it would suspend yes so. You know they're still stuffed ears -- Yes it worked. This is good because this. Consider glad it worked for the first time. Okay so right now it's -- around -- that's -- You're gonna see all sorts of stuff -- here is like. He enters. Devices."

" It looks like your standard Linux that up."

" Yes it's Linux two point six kernel and its arm so says welcome to Kendall."

" I can type and Brit. Press and -- asked me for a password and another password on independent Fiona which is the darn it didn't take it. That's for yes. It doesn't like me it's not letting me and because my log and is and cracked so it's gonna keep on asking me for a log in again and again. I can't get into the actual boot screen what all the different commands."

" This is because it's before the Kindle chips out it actually changed the password aids which is -- I mean a lot of manufacturers just released the same product with like these at the same password. Expecting that people won't credit union -- through the serial port."

" The -- that stupid so it's not letting me bypassed the login screen it's taking me automatically to that screens so. Does -- battery I'm gonna let the thing completely power off and how are back on and hopefully bypassed at this time. Finally and this is -- boot manager. And these are my commands all the different things that I can do it and it's called. You don't know which is kind of like a rug that being used for the US -- past it's we take a look. The partition there's all sorts of things here -- from the end of buys memory modify calculate board resistant all sorts of different things and it's really really cool. I just love the fact you can look through all this different things right -- Right."

" And that. Of course we we can't get into the operating system but now that we can get into it bill loader we could potentially down."

" I'm not going to be doing this week but the fact that I can't. Find the username and password just -- can't actually get in there can't flash files like you know that bit up regularly. From the I guess you it's an -- and directory. -- cousins in the yeah. He to to Linux applications or compiled for arm us. I wanna get in and out do all sorts of cool things that's sick but I need a password. So I wouldn't do that don't reverse engineering blog the guy that wrote this he came up with an update file that you can play it on -- SD card. In that well update as a flash update. I think that's complex -- yet firmware update to your Kindle so that it well basically. Reset your password so that you can change at an annual know it and then you can get. Excellent and you'll be able to do all sorts of things through and then it yet -- and an --"

" Well card readers note that senate doesn't cricket and let's take brick -- I was -- on the Lan party. I -- you want talking about this most land on the here game that had not or -- it's important to us. You know to kill and maim and destroy this may be some. -- I tastes and that's how we will. But in the meantime he and had an over the past five led to Vista. You can go from new game without the other day. Just. Decent. I don't know what Hak5 land that's Squarespace. With Squarespace you can build beautiful looking blog -- website in a fraction of the time that would take with a traditional content management systems. They're intuitive drag and drop interface is a snappy and powerful as a desktop publishing out. But best of all there's no software to install new database to configure their patches to apply and no code -- have yourself a simple and powerful it can be with a two week free trial of Squarespace dot com and use promo code how. Five to support the show and save 10% off the life of your service."

" Squarespace dot com. Throughout the show we've spoken ad nauseam about the importance of protecting yourself man in the middle attacks in Manhattan traffic snapped and and why it's important encrypted and if if you think it's. You know not a trivial thing to do. You know I rest my case so you know in the past we've talked about. Things like using. You know as -- CH tunneling to protect your traffic and I think it's time that we speak. About that we touch on the -- ends so. I'm going to put together a certain few guys now. About three different ways to implement a VPN server in your home just using your spare keys here what I view. So that when you're out on. You know open Wi-Fi or wherever you are that you can tunnel back home and use that as your default Gateway. And use that to browse the Internet and and to do whatever importance that you need to that you have an encrypted link and it is super super simple set up. But on the server side and on the client side you don't need to worry a lot. That configuration and you don't need to you know it can be as easy or is typical as you want it to be and throughout the series we are going to take the in the manual approach to it and get her hands dirty in in bash the for right now I thought I would demonstrate. Three really simple ways to get set up so we're going to be talking about a free service. That does he's open source and Linux on it on good stuff as well as to for you -- users. And I thought there would actually start with the simplest and there's actually something that have touched on. And believe it was in the first season episode four. But I think is -- important thing to recap and that is that there's actually a VP and server built into windows XP. And now -- windows XP is not server. But it there's a very limited PP TP or point to point tunneling protocol. VPN server built in that allows us to connect back to our home computer. And well okay only one concurrent user but if it's just you trying to get back home and uses a default Gateway get some files from your home PC. This might be a solution for you so I have pulled up here. Two windows XP virtual machines and use one as a server and Windows Client. And initially how super super simple it is to get this set up. So in an open up my network connections creating your connection and the wizard makes it damn stupid easy advanced connection. Allow incoming connections. We skip this part and say allow virtual private connections. And then we choose a user we can actually add users here who want iTunes is gonna choose administrator. Is there Indians they don't care about and I'm gonna click properties on TC PIP. This is actually written specify an IP range so on and give it ten and that. Eighteen got one through 101018. Dowd well a lot of analysts say twenty but it's only one concurrent users so. Chances are you're probably not going to use that many but you know whatever to DHC people let's let's give it does dresses that click okay here. And next and finish. And what you'll see is that I happen incoming connection. Link here and we see no clients connected and it's like I said it's a scaled down it's pretty dumb what's come over Tor client. Need to find out what my IP addresses first. Packets on on 10100147. So -- let's pretend that this machine is on the Internet and now I'm gonna be doing all of these here on the -- home. But really to extend it to doing her Internet it's just a matter -- you know open ports your firewall forwarding it overtures there is making sure that things could there. In this case. All you would need to do is I believe its TCP 1743. Not positive on to be there cracked me but. So let's go back over to our client machine. And ignorant and CPA -- PL. This a quick way to get network connections. Create new connection and this is the samples procedure back to work place that would. Do any time we VP and wanted to connect through you can call it you can. And it's on. Tend but tend -- down 147. My cracked. And -- okay. And yeah there we got so I log in as administrator. And my stupid password. They concede here that would take a look at the properties in your networking and he CP AP. Under advancing into that actually creates this. By default it set this as the default Gateway on our network and what that means is. That my client that is connecting to this you can is going to use this connection for all of its network routes not just -- crops that don't preside. Look clear what -- it's going to use this for everything and that's good because that means that we can. Browse the Internet knowing that it's going through this secure encrypted connection. And say okay to all of these prompts. And go ahead logging in it's gonna get super fast at its regular local mimic and see it says I'm connected array. And I got one of those nifty IP address that it set. 101018. Q. And by server -- and 181 I could access it's like hats and file shares on there he goes to 101018. That one. And if there are some folders shared it would actually be able to see that's a or any other service that it may have running on that server or well its its service windows XP machine. And if I take a look over here I can actually see. Incoming connections one client and there's administrator. Now. Like I said this is not a corporate solution this is really just -- home solution. And I believe this works very similar plea in Vista and well or to Vista should work minister and verified that but. You know if if you're just if you're running windows at home and your computers on all the time you know download your point whatever does I'd wanna check in on things. It's not a half bad way to do it that way not -- anything over clear text. So now let's take a look at one of the more like enterprise focused ways. So -- and get rid of these VMs and pull up few others. And before we get to -- you let's take a look at windows server 2003. Okay so I have what to windows servers here ray got. And we are going to go ahead and create. A routing or remote access server. And that's just a fancy way to say we're gonna creative you can server that you can quote -- dial into. And since server 2003 and I'm sure with 2008 mad -- but he here. Now would attest to this that they've -- on simple cuts services. It's actually have consul pulled up here you see I have this set up as an active directory this assault by Hak5 dot org. District here's -- you really want it now and so these computers salt and pepper are going to connect to each other got. Couple of users here or create new user my active directory and call him Bob. Robertson. That's not known him. And that BB barbers and at salt dot Hak5 dot org and create a lame password form. And sure never expires correct. Okay. And I'm gonna right click on Bob Robertson and say properties and in the dial into I want to allow access to VPN. Now here I can also make a few other changes I can say. Give this person static IP address in my segment last week I believe I was talking about some VP and -- can do windows. And I have to get glossed over this and I'm not on crack on this segment as you can noticed that. Oh slowdown actually let you know that town that that is something that I should have checked in that last segment and probably didn't didn't mention. And that's an important thing. There's one thing to note about that that that's not gonna and work in -- mixed mode environment so if you're running an active directory domain so it costs mean native so. In any windows 2002003. And above. This isn't you know so you're not gonna get this option here in this menu if you got some. 98. And the okay so -- that sad we get a substance that cracked here but suffice it to say right now we're just gonna allow access to the B key and click okay so we've got Bob Robertson -- here. Now let's make this a active direct current let's make it a routing and remote access server. So I'm just gonna do it that the stupid easy way -- management server thing and the role. And I'm going to choose. A remote access VPN server. The next few times. The next few more times and here what we want to do is actually set this up as a virtual private network access and Nat okay. I'm gonna choose my first action here. And yeah I'm gonna leave the basic firewall setup. And I -- actually specify a range rather than DH CP. And for me this is just is and it's gonna change depending on how you went in from implement it in you know your corporate network or even if you're just playing at home. Good download yourself and alienate you know 180 day evaluation copy. Then windows server stuff and you know play with it because nothing you can put on your residents tell -- players at least you know. We'll just play it so. I've gonna specify a range here. And create new range and -- and intent and 191. Through 101019. 253. Area so I have planned space here I'm on you know its last 24 and many people can connect concurrently it's can be great. And I'd. Now I don't wanna set up anything radius this is this might work we might come back at this later in the series and sister talking reed is because this is well as the next. You can solution likes it -- to tie in with that. In fact the next solution using Linux election list you tell that to -- back in with this Iraq -- directory. And that would be that user Bob Roberts -- created rather than Unix users I'm getting ahead of myself let's step back on this so. We're not going to use the radius server. And click finish. And if I come over to my consul here can actually add and it's not been. And that will be routing and remote access. And and and that's server this computer. We can see it's all here the local server is aren't set up and it can take a look at properties here. And you can see under IP that this is my range. And under here connects to see what connections are made I can management policies that turn on routing error logging. The -- you -- these ports and these are actually the different. Connections I am I allowed to injured and 53 of them and they're kind of like many ports as if that -- actually had a bunch of modems connected to this that you dialed in -- So let's go ahead and connect to this from one of our other servers and it's just make sure that this IP correct. That's 10100118. So let's say that that was a public. Facing -- then too just like I did next. In server 2003. Called salt. On dial a connection here serve Mon 10100118. To his head. Yes. And just like the last connection it by default sets it up to use. That connection as its default anyway considering this is a server to -- thing I don't wanna do that. But have a go ahead and click connect every count and I could not verify your username password because I am not using the practicality try that again but this time. B -- and okay -- that. And registering my computer on the network. Array and as you can see I'm now connected I have my IP address and it's from that whole that we set up I mean. I don't think it could get any easier so there you go two ways to set up a VP and server in both. Now you standard Windows Client XP the this to whatever. And your windows server 2003 very similar 2008."

" So we're gonna take a quick break and what we get back and going to show you how to do something very similar. Something even easier in my opinion using them onto a server -- three and using opens you can't again it's free is good."

" The wanna tell you guys about a service I use every day and it makes my life out a 1000% easier it's got to assist expressed. To be honestly couldn't live. Without it sure there are free alternatives out there but this is the solution that works and is absolutely. Bulletproof. 100% of the time. If you're still going to people's houses are trying to troubleshoot people's computer issues over the phone you're wasting your time not their time -- So do yourself a fair. And go to go to assist dot com slash Hak5. And sign up for free trial it's completely web -- there's no real installer that anybody has -- all it's just a simple browser plugin. And you can send files which patented diagnostic and PC. This special -- you must visit go to assist dot com slash Hak5. As go to assist dot com slash Hak5 try it free -- thirty days."

" Now that have made Palm Beach -- in the corner and cry for all this use of windows. I'm going to take a step back and we're gonna switch over to the good side and you some Linux and some happy open source stuff so that we can do the same thing. Three years and -- get to this sentiment it. We are going to be using a very awesome product we've actually used before in. The network monkey. Called open VP Ian is actually this the way that we can get that private tunnel there on the I network monkey with a tap in her face with Wi-Fi and good stuff. In that stuff so I'm gonna show you how to use open he can very easy way using what's called open. VPN access server okay. It's a version of open VP and that's been compiled and put together in such a simple way with the management interface that ties -- easily with your active directory using. My favorite technology in the world of -- you can do radius. And it just makes things easy so if like it like that the whole purpose of the segment if you wanna get a VPN right up in your home so that you're not insecure in your public Wi-Fi and whatnot. This might be a solution for you. So let's take a look here what we. It's very easy you just go over to open VPN dot net each use active herbs -- access server download you have to register but once you register. It's pretty much agrees. Now I have it downloaded here and I'm actually going to share that out because I have a server here ready to go where's that server. It's one of you there we go there's my happy server okay so -- happy Goobuntu server here. On. 1010. So what you could find -- the broadcast 10100137. Okay. And I need to get this over to there -- real quick commencing any use one of my favorite tools."

" Tools."

" It's called HFS yeah. That's the stuff. So get each FSB it's an HTTP file server it's a single executable. And you just run it you -- folder or a file into next thing you know you have. Basically the equivalent of an Apache server with a director listing. So I'm gonna go ahead and have -- here and this is mine. Border where I'm keeping my dot dead here this is the Debian package to install this guy. Some packages. They have RPMs if you're on the Red -- side of things they've got it -- for just about every major. Distribution of Linux it happened easing. A -- 964. Server here. So I've got this all set up and my -- to file server. I can actually verified that that 295 unread messages and go to. 127 does your does your one and I actually see that listing here so I'm gonna go ahead and W get that over from a server. So I've gone ahead and installed it with. Open -- and a yes. In the -- it. And that we just have to answer a few quick questions here and tell it taxis are. At zero and I'm gonna say yes they do you actually want to use root as my administrator. You know for security purposes in a production firemen I probably wouldn't do this and create another user just for this market down. For the demonstrates Morgan and secret it quickly installs it it's. Pretty lightweight. And now we can go ahead and get -- management interface and this is the thing that love and that. -- here will agree with is that when the beautiful things. What makes a Unix -- grade is a beautiful web interface. And here we are we have -- URIP. Address out on port 8443 the default port for the admin interface here with slash admin. And yet we're gonna get a security inner warning -- is the S to sell non up on suppose we're gonna proceed anyway. And routes. Because we didn't specify anything cool. And here we are and I love the fact that we get a beautiful interface much like you would see on. Consumer routers are like you know Linksys WRT 54 years on the popular like that. And it's you know just a few quick simple steps that we need to actually. Create is set this up so that we can start using it. So -- we need to do though is actually go back toward virtual machine. And create a user so user to. -- user add new with. And then passed -- for new. Beginning give needed some lame password. Okay so we have a new username is new and we are going to connect him as a VPN connection it's gonna be awesome. We -- is monitored this. So the most important thing that we need to configure here before you actually get going aside from just the users actually setting it up to allow access. Through the Internet using you know this the cancer here as their default Gateway so for that we actually go under VP and settings. And we choose. Under routing. Yes we want to allow the client Internet traffic routed through this VP. But go ahead and save that setting. Now we also under medication we take a look here that we have three different options you've got hand radius and held that. Old that is. Well you guys now that's -- favorite. L that is what you can use to type this in with an active directories so if you're a corporate. Environments here where you don't wanna spend a lot on. Client access license or in any routing and remote acts like it should you and in the previous. You can set up. This is actually less expensive alternative because -- if they get -- into the environment and go ahead and integrated that way or you're running radius that's that's a great way to. We're gonna go ahead under hand. -- there's not -- settings they would do is either provisions there is a create new user we're gonna call -- That's our user and save them. And that's pretty much it and now we just go back to the overview and start the server. -- For a -- conservatives -- that's one other important thing I forgot to mention remember what I said that this is free edge. Sure okay so open VPN -- he can't access servers since they wrapped up in beautiful package to make it so it's super simple to set up. Has a while there's a license okay you get two concurrent users for free and if you would like to purchase additional users concurrently either. Access license is ten dollars user which compared to -- Microsoft client access license is so much less expensive. Or further on in the series will go ahead and do it you know. By hand -- You get dirty and bastion and certainly would -- I really like you just wanna get set up real quick -- can access server especially if it's just you and a friend. Trying to protect yourself on that it -- again. So let's go under license parity have my license key. -- No you can't have mine. And then -- into that. And now. We should be -- start the server. Great source servers started let's pull up one of our XP client and they show you how dead simple it is to get set up with this so. We -- connect that he can yes we are -- disconnect from now we don't care about that connection anymore what we wanna do. It's -- for ghetto rather. No we don't wanna go there. We never wanna go there we would go over to ten that tend oh about 135. With 135137. It was seven I'm being told. And we want to go to port 84 port three. And we wanna make sure that this is HTTP yes. And of course we get security dialogue get an instant click yes. And that we're gonna log in as new here the user that we just created. And this is how super simple it is so your clients all the need to do is go to this website. Log in and they get the option there to download a client for Mac. For Linux or for windows. Where they already have the windows they can just download the open VPN client can pick what is just run this installer here. And next install. And now we have happiness on her desktop and seriously we just double click. It already knows who we are there he knows what to do I just entering my password. Of -- this click connect. It's authorizing me again IP address. And I am all set up and I can actually take a look here. And it now I have an idea that in -- it through and it is that easy to set up open VPN if you use the access server. The only limitation there is like I said with a license exit you have to pay a little bit -- one point two concurrent users. But I hope this just."

" Gives you an idea of the options that are out there there are plenty of these web sites that offer like -- VP and you know hot spot yadda yadda listen years. You don't -- one of those who wanna use something that you trust something that you run yourself at home. Or I mean it can't trust you guys who can -- us. -- young Comcast things. -- Time Warner. I don't think Cox either. I think it should address. And say if you have questions about this or suggestions for future VP and related topics be sure to hit me up. Darren Hak5 dot org and if you prefer the cracked out version of Daryn let me know I can just get 66 next time. So we're gonna get the rest of the gang here and we're gonna wrap this -- out."

" Didn't in -- powerful web conferencing with no hassles super easy to use built on open source and 100% browser based no software acquired. It's so simple to start a meeting in seconds and tweak I -- you know you're meeting room URL. Your friends or clients click that link in in seconds there in the same web conference room with you share your computer screen documents quite or even seeing and hearing via your webcam. Amazingly you can host attend even record your events with no download required just a browser festival -- free that's right free. So why pay for web conferencing when didn't -- is free so support the show and sign up for -- in just fifteen seconds it."

" I didn't didn't dot com slash Hak5. Our guy so just before we get out of here we won't let you know we have a lot of stuff cook and in the pipeline war in the pot or whatever the hell you wanna call it. And what we're doing -- actually open sourcing. Some these ideas that we're going to be bringing -- future episode."

" It's because that is a huge fan of open source. I didn't say the opening -- stuff yeah it's me thank you. With a -- and -- Yeah I. -- five labs is an interesting experiment now that this is something that we should do you like and sport. It's a great way to get the audience involved in. If -- ever wondered about the production -- what it takes actually put together some stuff especially some them more intricate acts that are coming. They require a lot of programming what when you get involved in that. You're down with C. We could use some help Monday that when he first we are holding a conference with are often sponsored him again that's going to allow us to pose a great meeting. We you guys can get involved -- it. The development of these segments and -- screens -- were working things out you've got ideas of your own with what you're new. It's how you can pitch to -- seeking a direct feed. Write to it is. We just we -- island -- all day. And you know though we natural eating meals you get is rich community group discussion going on its head and you know give him the perfect up form that kind of thing so I'm stoked about that. Oh and and we didn't leave early next week mentioned we haven't -- coming on the show next week offered him again. That's ridiculous and -- zone. That allows you to tie in some Google Maps APIs as well yeah opt out what is it -- YouTube guys. To synchronize. GPS. With video. You. Can see where you water in the EU on the next. Year and that's great stuff. -- So anyway yeah get them not all get in on that by going to Hak5 dot org slash -- not weakened by an old information on how he can join our meeting. On the 21. First. 8 PM eastern time since there has its -- error number date now. It's not it seems to people -- and then you turn him into it vegetable."

" I. Think I. An object and injured. -- continue so exactly so now thanks to -- You know."

" So the when he. Long it it's."

" Okay."

" I am not able to do my thing. Well thank you but I did go with you guys know that well -- thing you do you know not only did actually well. Check this out. I'm extra horsepower."

" So it's no right -- crap over it manager."

" The battery."

" don't amazing amazing that process my. Turn around and stoked. It I'm using -- and now let's wrap this up are we done. We got to let you guys know that awesome shorter visit through that we love you you're dear heart arts this on I'm watching it for years."

" It's actually in the in aids dean needs. If you wanna know anything about HD about hung in there. Little -- Miami's pat Roger revealed the top five eighths to comic book adaptations. The proper way to Stalin HDTV want now you know why some interim -- seem to have a high amount of green eyes and picture. New episodes of its its thinner -- average in HD and -- And it's time."

" realized it. -- Pakistan love Robert. While I was that perfect timing or collapse the you know it increases the worst power but we greatly -- the battery -- time. What we want that. Not not a precondition but it -- like. Even though I'm happy people here this appeared beauty of course."

" And remind us once again the price -- as old what's up and go. Hey. Contributing. Yet. You've been helpful. Exactly. Yeah you know quarterback rivalry weekend off. We're sorry we wanted to go there -- won't do you want it or. When it finally chocolate. --"

" your grandson."

" Just leave that alone being weird it."

" They go funds. --"

" And we have excellent show -- yeah we're talking. -- Performance enhancement death. And we heard you as always trust your tech ought to actually base."

" show ever."

" War."

" This time on the show Kindle compact. Three -- servers at fifteen minutes. And no wind as deep -- short based horsepower all that and more on this episode of hacked off. That is brought to you by go to assist express -- and easy free web conferencing and Squarespace. Well."

" Welcome back five my name is Darren Kitchen she likes and I met last and out of them and ask your time off we can encourage you want to because it's gonna be excellent -- Really get months. Of life. Over real. Full review -- we -- we. Art happens it sorry when it went. -- they went to -- if -- really really. Jack. Well. Yeah I did absolutely nothing anyway -- everything up on it and it it's. Is -- and I don't wear it in. -- Both geologists. Let that simmer for what's so wrong yeah you may have we react -- some comments on six 36 reports. -- this is what happens when we -- purposes the other -- to back to back in the course of two hours. The case and an active. Who gap I mean you know there was this season for most the season four we were due in two episodes a night and it. Didn't work to -- it was great for us but you it's time more it was too much of a time -- and we decided that to get things more you know. I don't know in tune with feedback instantly that we're gonna go one week because."

" Assistant with four -- one through 415 like there were changed every yen today and and that's the thing is with the beginning of every -- need season. Five some accent. Which takes us like couple weeks justice field. You know under start a new set with a new format all that stuff but that we have a killers do you guys this week he really -- low. Like consul accessed via an open source goodies -- get from windows servers we the -- name prove your some horsepower performance here. Tonight you rock star. And we. So yeah we need a week off because you know every is she single week and we brought back records read. Very excited. Duties that --"

" This is I don't know why analyst rather avalanche are that's the whole we go -- take candidate forum. For more than forty hours. Are these what reforms could be coming back and forth."

" It's --"

" Whenever two to force. So that's what's going on with us. So. Let's get right into it. Shannon you're voiding warranties."

" Here I am -- and is I am went to this blog it's called. The reverse engineering blog and they basically walk you through how to figure out. I open up the boot loader on the can away and it's just the first gen and I know that there is a new -- count for the can adults -- that -- it's news. That -- the exact same day as my Kindle episode. About."

" And if you do this like when you -- hardware withers -- that we whatever lake lake there's a view from where there's a new -- there's something that comes at the same data errors so that. If we US something -- come out and expects its yet it has some kind of like a -- one I just wanted it. It's like when Leo buys a Mac in the lower prices. Ankle on -- original -- Only every time by the Mac but not not too much you know just like tongue in cheek like that's not going to -- enterprise. It's like what's and Alex seven dollars. It's. We we are getting way off we're an adapter realm now let's get back to back by the universe."

" This so act --"

" You're you're breaking into your Kindle are you afraid -- gonna void the warranty all of that and you afraid -- gonna destroy it. We should probably -- probably do the segment how it goes up. But first."

" Let's take a break doesn't get."

" I -- I've seen a lot of -- lately with the Kindle especially getting -- on it. Yes from what I understand though there's Linux already on it we're hacking that what are we doing here."

" Yeah there is Linux on here basically what I'm doing is I'm turning myself into an Amazon employee and I am trying to. Get in here so I can actually see the firmware and see the boot loader. I wanna get in there and find the username and password and I and all the different commands that I can do -- behind the scenes. So what are we gonna need to break in there well there's a couple of different things that you won't need that -- everything's pretty cheap except for the computer and the Kendall. Kindle one is the first thing. I relax and -- they can go -- here not the Kindle to -- you to -- one right here about six telling -- so that I can do they. But yes. The second thing you need is this. Very flat twenty and point five millimeter ribbon cable into here. An interest in here yet this little -- cable has twenty depends on -- crops. And you just plug it into this little open space in the back in the can I don't know why they left this picky. But they did yeah that -- remarks them yes I think this is out if that's from where before they actually send it out to the different people. To their different analysts the."

" Four pins on the motherboard of the Fon routers they can get in you know -- I."

" Exactly exactly the second thing you need are some of these cables. So that you can -- needs to. This. USB to serial TTL cable entrance. Away into my computer. Right. Soon that cable is."

" Is basically. Taking cereal and putting it. Through US peace yet it actually uses they can actually see what's going. Prayer and so technical matters particularly retractable. Fry anything else -- yeah and well I didn't I got a bunch of links except where you need abilities yourself. Or by them and and the really cheap."

" Yeah they're very cheap flat cable is like two dollars two dollars and fifty cents so it's it's -- packet as long as you have the big parts are ready. The other thing about this flat cable is when you're starting to do this -- you have to kind of -- have to get rid of a lot of the different little and you can only have. There's about five different and they can use numbers 37 cents and for ground cable. C have you received any nutrients and cables and each of these -- be tied into these serial TSB to -- The next thing you need is your actual programs on your computer. You need a driver. For the cereals USB -- out. And you Austin aide Heidi yours kind of configurations Apple strangle us yes you're analysts changed the serial warden -- against. So I'm go over here on my computer. First thing -- need to changes the speeds and the change that tube. 115200. And then this is the -- three which I figured this out by going over here into my computer management. And device manager and then prolific USB to serial com court is contrary. So it seems that everything else stays the same so open that up now I have my. Command prompt I -- church or terminal is listening to everything that is going everything that is going it. Now this is really really finicky sometimes it works sometimes it doesn't -- and he's. -- it's and I nearly art yes these cables it's that we see bits yes they are an -- I'm kind of unsure about whether I should solder these are not because you documents like the one. I'm once I'm -- can't -- solder -- go and get him in place and access networks every time but at same time so finicky that you might not move at all but."

" A lot more you won't be have to responders did to the that he part is the reason these little alligator clip jumper cable alias yeah. And it's just that if we -- slaughter and we have to cut the cable and it's gonna be a pain so for right now before you next segment for you let's go and do it this way."

" He's the flag cables can you like team lacks the and we're -- right after three and if it's broom -- up. Okay if I have anything plugged in any -- connected to their proper and so I just -- on the power button on my Kindle can -- Right so as you can see it just started booting up and it's telling me that the power switches off. So there's still a little bit signal coming through here because the operating system doesn't when you turn off the can -- it would suspend yes so. You know they're still stuffed ears -- Yes it worked. This is good because this. Consider glad it worked for the first time. Okay so right now it's -- around -- that's -- You're gonna see all sorts of stuff -- here is like. He enters. Devices."

" It looks like your standard Linux that up."

" Yes it's Linux two point six kernel and its arm so says welcome to Kendall."

" I can type and Brit. Press and -- asked me for a password and another password on independent Fiona which is the darn it didn't take it. That's for yes. It doesn't like me it's not letting me and because my log and is and cracked so it's gonna keep on asking me for a log in again and again. I can't get into the actual boot screen what all the different commands."

" This is because it's before the Kindle chips out it actually changed the password aids which is -- I mean a lot of manufacturers just released the same product with like these at the same password. Expecting that people won't credit union -- through the serial port."

" The -- that stupid so it's not letting me bypassed the login screen it's taking me automatically to that screens so. Does -- battery I'm gonna let the thing completely power off and how are back on and hopefully bypassed at this time. Finally and this is -- boot manager. And these are my commands all the different things that I can do it and it's called. You don't know which is kind of like a rug that being used for the US -- past it's we take a look. The partition there's all sorts of things here -- from the end of buys memory modify calculate board resistant all sorts of different things and it's really really cool. I just love the fact you can look through all this different things right -- Right."

" And that. Of course we we can't get into the operating system but now that we can get into it bill loader we could potentially down."

" I'm not going to be doing this week but the fact that I can't. Find the username and password just -- can't actually get in there can't flash files like you know that bit up regularly. From the I guess you it's an -- and directory. -- cousins in the yeah. He to to Linux applications or compiled for arm us. I wanna get in and out do all sorts of cool things that's sick but I need a password. So I wouldn't do that don't reverse engineering blog the guy that wrote this he came up with an update file that you can play it on -- SD card. In that well update as a flash update. I think that's complex -- yet firmware update to your Kindle so that it well basically. Reset your password so that you can change at an annual know it and then you can get. Excellent and you'll be able to do all sorts of things through and then it yet -- and an --"

" Well card readers note that senate doesn't cricket and let's take brick -- I was -- on the Lan party. I -- you want talking about this most land on the here game that had not or -- it's important to us. You know to kill and maim and destroy this may be some. -- I tastes and that's how we will. But in the meantime he and had an over the past five led to Vista. You can go from new game without the other day. Just. Decent. I don't know what Hak5 land that's Squarespace. With Squarespace you can build beautiful looking blog -- website in a fraction of the time that would take with a traditional content management systems. They're intuitive drag and drop interface is a snappy and powerful as a desktop publishing out. But best of all there's no software to install new database to configure their patches to apply and no code -- have yourself a simple and powerful it can be with a two week free trial of Squarespace dot com and use promo code how. Five to support the show and save 10% off the life of your service."

" Squarespace dot com. Throughout the show we've spoken ad nauseam about the importance of protecting yourself man in the middle attacks in Manhattan traffic snapped and and why it's important encrypted and if if you think it's. You know not a trivial thing to do. You know I rest my case so you know in the past we've talked about. Things like using. You know as -- CH tunneling to protect your traffic and I think it's time that we speak. About that we touch on the -- ends so. I'm going to put together a certain few guys now. About three different ways to implement a VPN server in your home just using your spare keys here what I view. So that when you're out on. You know open Wi-Fi or wherever you are that you can tunnel back home and use that as your default Gateway. And use that to browse the Internet and and to do whatever importance that you need to that you have an encrypted link and it is super super simple set up. But on the server side and on the client side you don't need to worry a lot. That configuration and you don't need to you know it can be as easy or is typical as you want it to be and throughout the series we are going to take the in the manual approach to it and get her hands dirty in in bash the for right now I thought I would demonstrate. Three really simple ways to get set up so we're going to be talking about a free service. That does he's open source and Linux on it on good stuff as well as to for you -- users. And I thought there would actually start with the simplest and there's actually something that have touched on. And believe it was in the first season episode four. But I think is -- important thing to recap and that is that there's actually a VP and server built into windows XP. And now -- windows XP is not server. But it there's a very limited PP TP or point to point tunneling protocol. VPN server built in that allows us to connect back to our home computer. And well okay only one concurrent user but if it's just you trying to get back home and uses a default Gateway get some files from your home PC. This might be a solution for you so I have pulled up here. Two windows XP virtual machines and use one as a server and Windows Client. And initially how super super simple it is to get this set up. So in an open up my network connections creating your connection and the wizard makes it damn stupid easy advanced connection. Allow incoming connections. We skip this part and say allow virtual private connections. And then we choose a user we can actually add users here who want iTunes is gonna choose administrator. Is there Indians they don't care about and I'm gonna click properties on TC PIP. This is actually written specify an IP range so on and give it ten and that. Eighteen got one through 101018. Dowd well a lot of analysts say twenty but it's only one concurrent users so. Chances are you're probably not going to use that many but you know whatever to DHC people let's let's give it does dresses that click okay here. And next and finish. And what you'll see is that I happen incoming connection. Link here and we see no clients connected and it's like I said it's a scaled down it's pretty dumb what's come over Tor client. Need to find out what my IP addresses first. Packets on on 10100147. So -- let's pretend that this machine is on the Internet and now I'm gonna be doing all of these here on the -- home. But really to extend it to doing her Internet it's just a matter -- you know open ports your firewall forwarding it overtures there is making sure that things could there. In this case. All you would need to do is I believe its TCP 1743. Not positive on to be there cracked me but. So let's go back over to our client machine. And ignorant and CPA -- PL. This a quick way to get network connections. Create new connection and this is the samples procedure back to work place that would. Do any time we VP and wanted to connect through you can call it you can. And it's on. Tend but tend -- down 147. My cracked. And -- okay. And yeah there we got so I log in as administrator. And my stupid password. They concede here that would take a look at the properties in your networking and he CP AP. Under advancing into that actually creates this. By default it set this as the default Gateway on our network and what that means is. That my client that is connecting to this you can is going to use this connection for all of its network routes not just -- crops that don't preside. Look clear what -- it's going to use this for everything and that's good because that means that we can. Browse the Internet knowing that it's going through this secure encrypted connection. And say okay to all of these prompts. And go ahead logging in it's gonna get super fast at its regular local mimic and see it says I'm connected array. And I got one of those nifty IP address that it set. 101018. Q. And by server -- and 181 I could access it's like hats and file shares on there he goes to 101018. That one. And if there are some folders shared it would actually be able to see that's a or any other service that it may have running on that server or well its its service windows XP machine. And if I take a look over here I can actually see. Incoming connections one client and there's administrator. Now. Like I said this is not a corporate solution this is really just -- home solution. And I believe this works very similar plea in Vista and well or to Vista should work minister and verified that but. You know if if you're just if you're running windows at home and your computers on all the time you know download your point whatever does I'd wanna check in on things. It's not a half bad way to do it that way not -- anything over clear text. So now let's take a look at one of the more like enterprise focused ways. So -- and get rid of these VMs and pull up few others. And before we get to -- you let's take a look at windows server 2003. Okay so I have what to windows servers here ray got. And we are going to go ahead and create. A routing or remote access server. And that's just a fancy way to say we're gonna creative you can server that you can quote -- dial into. And since server 2003 and I'm sure with 2008 mad -- but he here. Now would attest to this that they've -- on simple cuts services. It's actually have consul pulled up here you see I have this set up as an active directory this assault by Hak5 dot org. District here's -- you really want it now and so these computers salt and pepper are going to connect to each other got. Couple of users here or create new user my active directory and call him Bob. Robertson. That's not known him. And that BB barbers and at salt dot Hak5 dot org and create a lame password form. And sure never expires correct. Okay. And I'm gonna right click on Bob Robertson and say properties and in the dial into I want to allow access to VPN. Now here I can also make a few other changes I can say. Give this person static IP address in my segment last week I believe I was talking about some VP and -- can do windows. And I have to get glossed over this and I'm not on crack on this segment as you can noticed that. Oh slowdown actually let you know that town that that is something that I should have checked in that last segment and probably didn't didn't mention. And that's an important thing. There's one thing to note about that that that's not gonna and work in -- mixed mode environment so if you're running an active directory domain so it costs mean native so. In any windows 2002003. And above. This isn't you know so you're not gonna get this option here in this menu if you got some. 98. And the okay so -- that sad we get a substance that cracked here but suffice it to say right now we're just gonna allow access to the B key and click okay so we've got Bob Robertson -- here. Now let's make this a active direct current let's make it a routing and remote access server. So I'm just gonna do it that the stupid easy way -- management server thing and the role. And I'm going to choose. A remote access VPN server. The next few times. The next few more times and here what we want to do is actually set this up as a virtual private network access and Nat okay. I'm gonna choose my first action here. And yeah I'm gonna leave the basic firewall setup. And I -- actually specify a range rather than DH CP. And for me this is just is and it's gonna change depending on how you went in from implement it in you know your corporate network or even if you're just playing at home. Good download yourself and alienate you know 180 day evaluation copy. Then windows server stuff and you know play with it because nothing you can put on your residents tell -- players at least you know. We'll just play it so. I've gonna specify a range here. And create new range and -- and intent and 191. Through 101019. 253. Area so I have planned space here I'm on you know its last 24 and many people can connect concurrently it's can be great. And I'd. Now I don't wanna set up anything radius this is this might work we might come back at this later in the series and sister talking reed is because this is well as the next. You can solution likes it -- to tie in with that. In fact the next solution using Linux election list you tell that to -- back in with this Iraq -- directory. And that would be that user Bob Roberts -- created rather than Unix users I'm getting ahead of myself let's step back on this so. We're not going to use the radius server. And click finish. And if I come over to my consul here can actually add and it's not been. And that will be routing and remote access. And and and that's server this computer. We can see it's all here the local server is aren't set up and it can take a look at properties here. And you can see under IP that this is my range. And under here connects to see what connections are made I can management policies that turn on routing error logging. The -- you -- these ports and these are actually the different. Connections I am I allowed to injured and 53 of them and they're kind of like many ports as if that -- actually had a bunch of modems connected to this that you dialed in -- So let's go ahead and connect to this from one of our other servers and it's just make sure that this IP correct. That's 10100118. So let's say that that was a public. Facing -- then too just like I did next. In server 2003. Called salt. On dial a connection here serve Mon 10100118. To his head. Yes. And just like the last connection it by default sets it up to use. That connection as its default anyway considering this is a server to -- thing I don't wanna do that. But have a go ahead and click connect every count and I could not verify your username password because I am not using the practicality try that again but this time. B -- and okay -- that. And registering my computer on the network. Array and as you can see I'm now connected I have my IP address and it's from that whole that we set up I mean. I don't think it could get any easier so there you go two ways to set up a VP and server in both. Now you standard Windows Client XP the this to whatever. And your windows server 2003 very similar 2008."

" So we're gonna take a quick break and what we get back and going to show you how to do something very similar. Something even easier in my opinion using them onto a server -- three and using opens you can't again it's free is good."

" The wanna tell you guys about a service I use every day and it makes my life out a 1000% easier it's got to assist expressed. To be honestly couldn't live. Without it sure there are free alternatives out there but this is the solution that works and is absolutely. Bulletproof. 100% of the time. If you're still going to people's houses are trying to troubleshoot people's computer issues over the phone you're wasting your time not their time -- So do yourself a fair. And go to go to assist dot com slash Hak5. And sign up for free trial it's completely web -- there's no real installer that anybody has -- all it's just a simple browser plugin. And you can send files which patented diagnostic and PC. This special -- you must visit go to assist dot com slash Hak5. As go to assist dot com slash Hak5 try it free -- thirty days."

" Now that have made Palm Beach -- in the corner and cry for all this use of windows. I'm going to take a step back and we're gonna switch over to the good side and you some Linux and some happy open source stuff so that we can do the same thing. Three years and -- get to this sentiment it. We are going to be using a very awesome product we've actually used before in. The network monkey. Called open VP Ian is actually this the way that we can get that private tunnel there on the I network monkey with a tap in her face with Wi-Fi and good stuff. In that stuff so I'm gonna show you how to use open he can very easy way using what's called open. VPN access server okay. It's a version of open VP and that's been compiled and put together in such a simple way with the management interface that ties -- easily with your active directory using. My favorite technology in the world of -- you can do radius. And it just makes things easy so if like it like that the whole purpose of the segment if you wanna get a VPN right up in your home so that you're not insecure in your public Wi-Fi and whatnot. This might be a solution for you. So let's take a look here what we. It's very easy you just go over to open VPN dot net each use active herbs -- access server download you have to register but once you register. It's pretty much agrees. Now I have it downloaded here and I'm actually going to share that out because I have a server here ready to go where's that server. It's one of you there we go there's my happy server okay so -- happy Goobuntu server here. On. 1010. So what you could find -- the broadcast 10100137. Okay. And I need to get this over to there -- real quick commencing any use one of my favorite tools."

" Tools."

" It's called HFS yeah. That's the stuff. So get each FSB it's an HTTP file server it's a single executable. And you just run it you -- folder or a file into next thing you know you have. Basically the equivalent of an Apache server with a director listing. So I'm gonna go ahead and have -- here and this is mine. Border where I'm keeping my dot dead here this is the Debian package to install this guy. Some packages. They have RPMs if you're on the Red -- side of things they've got it -- for just about every major. Distribution of Linux it happened easing. A -- 964. Server here. So I've got this all set up and my -- to file server. I can actually verified that that 295 unread messages and go to. 127 does your does your one and I actually see that listing here so I'm gonna go ahead and W get that over from a server. So I've gone ahead and installed it with. Open -- and a yes. In the -- it. And that we just have to answer a few quick questions here and tell it taxis are. At zero and I'm gonna say yes they do you actually want to use root as my administrator. You know for security purposes in a production firemen I probably wouldn't do this and create another user just for this market down. For the demonstrates Morgan and secret it quickly installs it it's. Pretty lightweight. And now we can go ahead and get -- management interface and this is the thing that love and that. -- here will agree with is that when the beautiful things. What makes a Unix -- grade is a beautiful web interface. And here we are we have -- URIP. Address out on port 8443 the default port for the admin interface here with slash admin. And yet we're gonna get a security inner warning -- is the S to sell non up on suppose we're gonna proceed anyway. And routes. Because we didn't specify anything cool. And here we are and I love the fact that we get a beautiful interface much like you would see on. Consumer routers are like you know Linksys WRT 54 years on the popular like that. And it's you know just a few quick simple steps that we need to actually. Create is set this up so that we can start using it. So -- we need to do though is actually go back toward virtual machine. And create a user so user to. -- user add new with. And then passed -- for new. Beginning give needed some lame password. Okay so we have a new username is new and we are going to connect him as a VPN connection it's gonna be awesome. We -- is monitored this. So the most important thing that we need to configure here before you actually get going aside from just the users actually setting it up to allow access. Through the Internet using you know this the cancer here as their default Gateway so for that we actually go under VP and settings. And we choose. Under routing. Yes we want to allow the client Internet traffic routed through this VP. But go ahead and save that setting. Now we also under medication we take a look here that we have three different options you've got hand radius and held that. Old that is. Well you guys now that's -- favorite. L that is what you can use to type this in with an active directories so if you're a corporate. Environments here where you don't wanna spend a lot on. Client access license or in any routing and remote acts like it should you and in the previous. You can set up. This is actually less expensive alternative because -- if they get -- into the environment and go ahead and integrated that way or you're running radius that's that's a great way to. We're gonna go ahead under hand. -- there's not -- settings they would do is either provisions there is a create new user we're gonna call -- That's our user and save them. And that's pretty much it and now we just go back to the overview and start the server. -- For a -- conservatives -- that's one other important thing I forgot to mention remember what I said that this is free edge. Sure okay so open VPN -- he can't access servers since they wrapped up in beautiful package to make it so it's super simple to set up. Has a while there's a license okay you get two concurrent users for free and if you would like to purchase additional users concurrently either. Access license is ten dollars user which compared to -- Microsoft client access license is so much less expensive. Or further on in the series will go ahead and do it you know. By hand -- You get dirty and bastion and certainly would -- I really like you just wanna get set up real quick -- can access server especially if it's just you and a friend. Trying to protect yourself on that it -- again. So let's go under license parity have my license key. -- No you can't have mine. And then -- into that. And now. We should be -- start the server. Great source servers started let's pull up one of our XP client and they show you how dead simple it is to get set up with this so. We -- connect that he can yes we are -- disconnect from now we don't care about that connection anymore what we wanna do. It's -- for ghetto rather. No we don't wanna go there. We never wanna go there we would go over to ten that tend oh about 135. With 135137. It was seven I'm being told. And we want to go to port 84 port three. And we wanna make sure that this is HTTP yes. And of course we get security dialogue get an instant click yes. And that we're gonna log in as new here the user that we just created. And this is how super simple it is so your clients all the need to do is go to this website. Log in and they get the option there to download a client for Mac. For Linux or for windows. Where they already have the windows they can just download the open VPN client can pick what is just run this installer here. And next install. And now we have happiness on her desktop and seriously we just double click. It already knows who we are there he knows what to do I just entering my password. Of -- this click connect. It's authorizing me again IP address. And I am all set up and I can actually take a look here. And it now I have an idea that in -- it through and it is that easy to set up open VPN if you use the access server. The only limitation there is like I said with a license exit you have to pay a little bit -- one point two concurrent users. But I hope this just."

" Gives you an idea of the options that are out there there are plenty of these web sites that offer like -- VP and you know hot spot yadda yadda listen years. You don't -- one of those who wanna use something that you trust something that you run yourself at home. Or I mean it can't trust you guys who can -- us. -- young Comcast things. -- Time Warner. I don't think Cox either. I think it should address. And say if you have questions about this or suggestions for future VP and related topics be sure to hit me up. Darren Hak5 dot org and if you prefer the cracked out version of Daryn let me know I can just get 66 next time. So we're gonna get the rest of the gang here and we're gonna wrap this -- out."

" Didn't in -- powerful web conferencing with no hassles super easy to use built on open source and 100% browser based no software acquired. It's so simple to start a meeting in seconds and tweak I -- you know you're meeting room URL. Your friends or clients click that link in in seconds there in the same web conference room with you share your computer screen documents quite or even seeing and hearing via your webcam. Amazingly you can host attend even record your events with no download required just a browser festival -- free that's right free. So why pay for web conferencing when didn't -- is free so support the show and sign up for -- in just fifteen seconds it."

" I didn't didn't dot com slash Hak5. Our guy so just before we get out of here we won't let you know we have a lot of stuff cook and in the pipeline war in the pot or whatever the hell you wanna call it. And what we're doing -- actually open sourcing. Some these ideas that we're going to be bringing -- future episode."

" It's because that is a huge fan of open source. I didn't say the opening -- stuff yeah it's me thank you. With a -- and -- Yeah I. -- five labs is an interesting experiment now that this is something that we should do you like and sport. It's a great way to get the audience involved in. If -- ever wondered about the production -- what it takes actually put together some stuff especially some them more intricate acts that are coming. They require a lot of programming what when you get involved in that. You're down with C. We could use some help Monday that when he first we are holding a conference with are often sponsored him again that's going to allow us to pose a great meeting. We you guys can get involved -- it. The development of these segments and -- screens -- were working things out you've got ideas of your own with what you're new. It's how you can pitch to -- seeking a direct feed. Write to it is. We just we -- island -- all day. And you know though we natural eating meals you get is rich community group discussion going on its head and you know give him the perfect up form that kind of thing so I'm stoked about that. Oh and and we didn't leave early next week mentioned we haven't -- coming on the show next week offered him again. That's ridiculous and -- zone. That allows you to tie in some Google Maps APIs as well yeah opt out what is it -- YouTube guys. To synchronize. GPS. With video. You. Can see where you water in the EU on the next. Year and that's great stuff. -- So anyway yeah get them not all get in on that by going to Hak5 dot org slash -- not weakened by an old information on how he can join our meeting. On the 21. First. 8 PM eastern time since there has its -- error number date now. It's not it seems to people -- and then you turn him into it vegetable."

" I. Think I. An object and injured. -- continue so exactly so now thanks to -- You know."

" So the when he. Long it it's."

" Okay."

" I am not able to do my thing. Well thank you but I did go with you guys know that well -- thing you do you know not only did actually well. Check this out. I'm extra horsepower."

" So it's no right -- crap over it manager."

" The battery."

" don't amazing amazing that process my. Turn around and stoked. It I'm using -- and now let's wrap this up are we done. We got to let you guys know that awesome shorter visit through that we love you you're dear heart arts this on I'm watching it for years."

" It's actually in the in aids dean needs. If you wanna know anything about HD about hung in there. Little -- Miami's pat Roger revealed the top five eighths to comic book adaptations. The proper way to Stalin HDTV want now you know why some interim -- seem to have a high amount of green eyes and picture. New episodes of its its thinner -- average in HD and -- And it's time."

" realized it. -- Pakistan love Robert. While I was that perfect timing or collapse the you know it increases the worst power but we greatly -- the battery -- time. What we want that. Not not a precondition but it -- like. Even though I'm happy people here this appeared beauty of course."

" And remind us once again the price -- as old what's up and go. Hey. Contributing. Yet. You've been helpful. Exactly. Yeah you know quarterback rivalry weekend off. We're sorry we wanted to go there -- won't do you want it or. When it finally chocolate. --"

" your grandson."

" Just leave that alone being weird it."

" They go funds. --"

" And we have excellent show -- yeah we're talking. -- Performance enhancement death. And we heard you as always trust your tech ought to actually base."

" show ever."

mari1ee

Started discussion: September 16, 2009 @ 9:32am GMT

Episode 605 - Three VPN Servers and a Kindle Console [Discussion]

This week Shannon taps into a hidden Kindle serial port using a inty bitsy ribbon cable, a USB to Serial TTL cable and some jumpers in an attempt to hack root and finds herself upon the bootloader and nearly at a bash prompt. Darren guides you through the installation of VPN servers on Windows XP, Windows Server and Linux so you can keep your traffic secure in an encrypted tunnel while on untrusted networks.

Watch or download now!

Psychosis
2 months ago
You forgot to mention Matt killing Shannon's battery.
flamaest
about 16 days ago
When are we gonna see gmail or other fun things running on the kindle from Shannon's kindle..?
View all 2 comments