Encrypting Gtalk, Facebook & other XMPP IM's on Android
Posted by Sharar Ravitz in Android, Encryption, XMPP on Friday, January 4, 2013
Xabber is a neat little XMPP client for Android with built in OTR support, allowing you to encrypt your messages. Simply install the app, configure your accounts, and enable OTR support under settings, security, OTR.
Encrypting email on your Android
Posted by Sharar Ravitz in Android, Encryption, K-9 Mail
It's fairly easy to set up sending and receiving encrypted email on your Android using a few simple, free apps.
APG - Public key encryption for the Android. Encrypt/decrypt emails/files via OpenPGP.
K-9 Mail - K-9 Mail is an open-source e-mail client with search, IMAP push email,
multi-folder sync, flagging, filing, signatures, bcc-self, PGP, mail on
SD & more.
OI File Manager - allows you to browse your SD card, create directories, rename, copy,
move, and delete files. It also acts as an extension to other
applications to display "Open" and "Save" dialogs.
Import your keys using the APG app which automatically integrates with K-9 mail.
If you need more basic details on encryption see here.
Using /etc/hosts to route around censorship
Posted by Sharar Ravitz in Censorship, DNS blocking, Linux, The Pirate Bay on Saturday, September 22, 2012
Censorship being all the rage, and DNS blocking being a popular enforcement method - I thought I'd show you guys a little trick to route around DNS blocking using your /etc/hosts file. We'll be using thepiratebay.com in this example, as it's a frequent target of ISP DNS blocking. Open up your /etc/hosts file from the terminal by typing: sudo gedit /etc/hosts
Add this entry to the bottom of the page:
194.71.107.80 thepiratebay.com tpb
Save the file, and close. You can now access The Pirate Bay by typing tpb in your browser address bar.
Using SSH server capabilities for secure chat with a trusted party
Posted by Sharar Ravitz in Encryption, Linux, proxy server, secure chat, secure communications, secure email, SSH, SSH server on Monday, September 3, 2012
The situation: Not wanting instant messages monitored, not trusting the IM clients out there. Running an SSH server on your Linux machine can provide secure chat with a trusted party, and much more.
Getting started:
A dynamic DNS provider is needed (your computer will need its own web address). Try these guys: http://freedns.afraid.org/menu/
Now that you have a dynamic DNS provider let's install the SSH server, and some additional security. For Debian based users: apt-get install openssh-server denyhosts
For other system users see OpenSSH here: http://www.openssh.org/ and denyhosts here: http://denyhosts.sourceforge.net/
Once these are installed it's time to do some configuration. Many routers allow you to set dynamic dns for your network. Check your router first. You can also use a dynamic dns client on the computer running the SSH server, see here: http://freedns.afraid.org/scripts/freedns.clients.php
Time to configure the server. We need the edit the file /etc/ssh/sshd_config, for debian based users: gedit /etc/ssh/sshd_config
I run my server on a non-standard port to prevent annoying port scans. Pick any number above 10000. I want the computer to listen on all interfaces/protocols so I don't set a specific ListenAddress
# What ports, IPs and protocols we listen for
Port 12121
# Use these options to restrict which interfaces/protocols sshd will bind to
#ListenAddress ::
#ListenAddress 0.0.0.0
Protocol 2
# HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
HostKey /etc/ssh/ssh_host_ecdsa_key
#Privilege Separation is turned on for security
UsePrivilegeSeparation yes
To tighten security adjust the PermitRootLogin option to "no"
Denyhosts has been installed for added security. How does it work?
"When run for the first time, DenyHosts will create a work directory. The work directory will ultimately
store the data collected and the files are in a human readable format, for each editing, if necessary.
DenyHosts then processes the sshd server log (typically, this is /var/log/secure, /var/log/auth.log, etc)
and determines which hosts have unsuccessfully attempted to gain access to the ssh server. Additionally,
it notes the user and whether or not that user is root, otherwise valid (eg. has a system
account) or invalid (eg. does not have a system account).
When DenyHosts determines that a given host has attempted to login using a non-existent user account a
configurable number of attempts (this is known as the DENY_THRESHOLD_INVALID), DenyHosts will add that host
to the /etc/hosts.deny file. This will prevent that host from contacting your sshd server again."
For more see here: http://denyhosts.sourceforge.net/faq.html#1_5
Next step is creating user accounts for the trusted party/parties you want secure communications with.
Debian based users can use the useradd command, see here: http://www.debianadmin.com/users-and-groups-administration-in-linux.html or use your distro's desktop administration tool like Gnome control center.
The user you've created accounts for can now use an SSH client to log directly into your computer. Linux has an SSH client by default. From the terminal type: ssh -p 12121 user@domain.com The -p option specifies port, so if your SSH server runs on port 44223 the user would type -p 44223. user is username and domain.com is your dynamic dns address.
For windows SSH clients: http://www.openssh.org/windows.html
Once logged in the user can leave you messages via the wall command: http://linux.die.net/man/1/wall talk command: http://linux.die.net/man/1/talk or classic email on the local system using mailx or another mail program: http://linux.die.net/man/1/mailx
SSH servers have many other uses:
Encrypted file transfer using the scp command: http://www.linuxtutorialblog.com/post/ssh-and-scp-howto-tips-tricks
An SSH server provides a proxy server for secure communications from work computers, for breaking out of corporate firewalls, etc: http://kimmo.suominen.com/docs/proxy-through-ssh/
Set up an IRC server using ngircd
Posted by Sharar Ravitz in IRC server, Linux, ngircd on Friday, September 11, 2009
This is a lightweight IRC server without the extra features. From the developers: "Next generation IRC Server ngircd is a IRC Daemon for small or private networks. It does not contain all the functions like the professional ones, e.g services. It is written from scratch and is not based upon the original IRCd like many others."
Install ngircd - on debian based systems: apt-get install ngircd
Edit the configuration file, on debian based systems it's: /etc/ngircd/ngircd.conf
Here's an example:
# Server name in the IRC network, must contain at least one dot
# (".") and be unique in the IRC network. Required!
Name = GNU/Linux IRC Server
# Info text of the server. This will be shown by WHOIS and
# LINKS requests for example.
Info =
# Global password for all users needed to connect to the server
Password =
# Information about the server and the administrator, used by the
# ADMIN command. Not required by server but by RFC!
AdminInfo1 =
AdminInfo2 =
AdminEMail =
# Ports on which the server should listen. There may be more than
# one port, separated with ",". (Default: 6667)
Ports = 6667
# IP address on which the server should listen. (Default: empty,
# so the server listens on all IP addresses of the system)
Listen =
# Text file with the "message of the day" (MOTD). This message will
# be shown to all users connecting to the server:
MotdFile = /etc/ngircd/ngircd.motd
# A simple Phrase (<256 motdphrase = "Hello. This is the Debian default MOTD sentence" serveruid =" 65534" servergid =" 65534" pidfile =" /var/run/ngircd/ngircd.pid"> seconds of inactivity the server will send a
# PING to the peer to test whether it is alive or not.
PingTimeout = 120
# If a client fails to answer a PING with a PONG within
# seconds, it will be disconnected by the server.
PongTimeout = 20
# The server tries every seconds to establish a link
# to not yet (or no longer) connected servers.
ConnectRetry = 60
# Should IRC Operators be allowed to use the MODE command even if
# they are not(!) channel-operators?
OperCanUseMode = yes
# Maximum number of simultaneous connection the server is allowed
# to accept (<=0: unlimited):
MaxConnections = 250
# Maximum number of simultaneous connections from a single IP address
# the server will accept (<=0: unlimited):
MaxConnectionsIP = 50
# Maximum number of channels a user can be member of (<=0: no limit):
MaxJoins = 50
[Operator]
# [Operator] sections are used to define IRC Operators. There may be
# more than one [Operator] block, one for each local operator.
# ID of the operator (may be different of the nick name)
Name =
# Password of the IRC operator
Password =
[Server]
# Other servers are configured in [Server] sections. If you
# configure a port for the connection, then this ngircd tries to
# connect to to the other server on the given port; if not it waits
# for the other server to connect.
# There may be more than one server block.
#
# Server Groups:
# The ngIRCd allows "server groups": You can assign an "ID" to every
# server with which you want this ngIRCd to link. If a server of a
# group won't answer, the ngIRCd tries to connect to the next server
# in the given group. But the ngircd never tries to connect to two
# servers with the same group ID.
# IRC name of the server
;Name = irc2.debian.org
# Internet host name of the peer
;Host = connect-to-host.the.net
# Port of the server to which the ngIRCd should connect. If you
# assign no port the ngIRCd waits for incoming connections.
;Port = 6666
# Own password for the connection. This password has to be configured
# as "PeerPassword" on the other server.
;MyPassword = MySecret
# Foreign password for this connection. This password has to be
# configured as "MyPassword" on the other server.
;PeerPassword = PeerSecret
# Group of this server (optional)
;Group = 123
[Channel]
# Pre-defined channels can be configured in [Channel] sections.
# Such channels are created by the server when starting up and even
# persist when there are no more members left.
# Persistent channels are marked with the mode 'P', which can be set
# and unset by IRC operators like other modes on the fly.
# There may be more than one [Channel] block.
# Name of the channel
Name =
# Topic for this channel
Topic =
# Initial channel modes
;Modes = tn
# -eof-
To make the server accessible outside your LAN open port 6667 on your firewall/router. I highly encourage setting a strong global server password if you choose to do this. Requires a static IP or dynamic dns.
mutt with gmail, gpg encryption, and a signature
First step to setting up mutt with your gmail - make sure imap access is enabled in your gmail settings. Now let's configure the ~/.muttrc file. Here's an example basic setup (taken from shreevatsa.wordpress.com):
set smtp_url = "smtp://accountname@smtp.gmail.com:587/"
set smtp_pass = "XXX"
set from = "accountname@gmail.com"
set realname = "Your Name"
set folder = "imaps://imap.gmail.com:993"
set spoolfile = "+INBOX"
set postponed="+[Gmail]/Drafts"
set header_cache=~/.mutt/cache/headers
set message_cachedir=~/.mutt/cache/bodies
set certificate_file=~/.mutt/certificates
set move = no
set sort = 'threads'
set sort_aux = 'last-date-received'
set imap_check_subscribed
ignore "Authentication-Results:"
ignore "DomainKey-Signature:"
ignore "DKIM-Signature:"
hdr_order Date From To Cc
Next let's add gpg support, encryption is good... Add this to your ~/.muttrc file (be sure to replace my key ID with your own):
set pgp_decode_command="gpg %?p?--passphrase-fd 0? --no-verbose --batch --output - %f"
set pgp_verify_command="gpg --no-verbose --batch --output - --verify %s %f"
set pgp_decrypt_command="gpg --passphrase-fd 0 --no-verbose --batch --output - %f"
set pgp_sign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor --detach-sign --textmode %?a?-u %a? %f"
set pgp_clearsign_command="gpg --no-verbose --batch --output - --passphrase-fd 0 --armor --textmode --clearsign %?a?-u %a? %f"
set pgp_encrypt_only_command="pgpewrap gpg --batch --quiet --no-verbose --output - --encrypt --textmode --armor --always-trust --encrypt-to 0x7890D0B4 -- -r %r -- %f"
set pgp_encrypt_sign_command="pgpewrap gpg --passphrase-fd 0 --batch --quiet --no-verbose --textmode --output - --encrypt --sign %?a?-u %a? --armor --always-trust --encrypt-to 0x7890D0B4 -- -r %r -- %f"
set pgp_import_command="gpg --no-verbose --import -v %f"
set pgp_export_command="gpg --no-verbose --export --armor %r"
set pgp_verify_key_command="gpg --no-verbose --batch --fingerprint --check-sigs %r"
set pgp_list_pubring_command="gpg --no-verbose --batch --with-colons --list-keys %r"
set pgp_list_secring_command="gpg --no-verbose --batch --with-colons --list-secret-keys %r"
set pgp_autosign=yes
set pgp_sign_as=0x7890D0B4
set pgp_replyencrypt=yes
set pgp_timeout=1800
set pgp_good_sign="^gpg: Good signature from"
Here's some info on encrypting email.
And finally, let's add a custom signature. Create a file to store the signature in. I used ~/.signature
The text in this file will be your sig. Add a line referencing the file in your ~/.muttrc file:
set signature="~/.signature"
Enjoy using gmail in your terminal!
Encrypt IM's
Posted by Sharar Ravitz in Encryption, im, instant messaging, twitter on Tuesday, June 16, 2009
Users of Debian based systems can apt-get install pidgin pidgin-otr libpurple-dev
First a good multi-protocol client. Pidgin is a chat client that can connect to Google Talk, MSN, Yahoo, Aol, facebook, myspace, and even now - twitter.
http://www.pidgin.im/
Using the off-the-record messaging add on, we can encrypt instant messages
http://www.cypherpunks.ca/otr/
and now with the new libpurple-twitter-protocol - we can chat with twitter friends
http://code.google.com/p/libpurple-twitter-protocol/
The OTR encryption plugin works with included protocols - but not with the facebook and twitter ad-ons. The Twitter ad-on does offer SSL, and the ability to direct through a standard proxy. Facebook im's can be directed through a standard proxy also.