jueves, 1 de septiembre de 2016

Disable xml-roc attacks in wordpress

XML-RPC service was disabled by default for the longest time mainly due to security reasons. In WordPress 3.5, this is about to change. XML-RPC will be enabled by default, and the ability to turn it off from your WordPress dashboard is going away. In this article, we will show you how to disable XML-RPC in WordPress and talk further about the decision of having it enabled by default.

What is XML-RPC?

According to Wikipedia, XML-RPC is a remote procedure call which uses XML to encode its calls and HTTP as a transport mechanism. In short, it is a system that allows you to post on your WordPress blog using popular weblog clients like Windows Live Writer. It is also needed if you are using the WordPress mobile app. It is also needed if you want to make connections to services like IFTTT.
If you want to access and publish to your blog remotely, then you need XML-RPC enabled.
In the past, there were security concerns with XML-RPC thus it was disabled by default. In his comment on trac ticket #21509, @nacin one of the core contributors of WordPress said:
Quite a bit has changed since we introduced off-by-default for XML-RPC. Their code has improved, and it is no longer considered a second-class citizen when it comes to API development, thanks to the work of a large team of awesome contributors. Security is no greater a concern than the rest of core.
There is no longer a compelling reason to disable this by default. It’s time we should remove the option entirely.
With the increasing use of mobile, this change was imminent. However some security cautious folks may say that while the XML-RPC’s security is not that big of an issue, it still provides an additional surface for attack if a vulnerability was ever found. Thus, keeping it disabled would make more sense. 
To keep everyone happy, while the user interface option and the database option to turn off XML-RPC has been removed, there is a filter that you can use to turn it off if needed.

How to Disable XML-RPC in WordPress 3.5

All you have to do is paste the following code in a site-specific plugin:
1add_filter('xmlrpc_enabled', '__return_false');
Alternatively, you can just install the plugin called Disable XML-RPC. All you have to do is activate it. It does the exact same thing as the code above.

How to Disable WordPress XML-RPC with .htaccess

While the above solution is sufficient for many, it can still be resource intensive for sites that are getting attacked.
In those cases, you may want to disable all xmlrpc.php requests from the .htaccess file before the request is even passed onto WordPress. 
Simply paste the following code in your .htaccess file:
1# Block WordPress xmlrpc.php requests
2<Files xmlrpc.php>
3order deny,allow
4deny from all
5allow from 123.123.123.123
6</Files>
Because we do not use any mobile app or remote connections to publish on WPBeginner, we will be disabling XML-RPC by default. What are your thoughts on the issue?

miércoles, 31 de agosto de 2016

Tabla resumen de codecs

La comunicación de voz es analógica, mientras que la red de datos es digital. El proceso de convertir ondas analógicas a información digital se hace con un codificador-decodificador (el CODEC). Hay muchas maneras de transformar una señal de voz analógica, todas ellas gobernadas por varios estándares. El proceso de la conversión es complejo. Es suficiente decir que la mayoría de las conversiones se basan en la modulación codificada mediante pulsos (PCM) o variaciones.
Además de la ejecución de la conversión de analógico a digital, el CODEC comprime la secuencia de datos, y proporciona la cancelación del eco. La compresión de la forma de onda representada puede permitir el ahorro del ancho de banda. Esto es especialmente interesante en los enlaces de poca capacidad y permite tener un mayor numero de conexiones de VoIP simultaneamente. Otra manera de ahorrar ancho de banda es el uso de la supresión del silencio, que es el proceso de no enviar los paquetes de la voz entre silencios en conversaciones humanas.
A continuación se muestra una tabla resumen con los códecs más utilizados actualmente:

- El Bit Rate indica la cantidad de información que se manda por segundo.
- El Sampling Rate indica la frecuencia de muestreo de la señal vocal.(cada cuanto se toma una muestra de la señal analógica)
- El Frame size indica cada cuantos milisegundos se envia un paquete con la información sonora.
- El MOS indica la calidad general del códec (valor de 1 a 5)

Para entender mejor la formación de un codec y los parametros expresados en la tabla recomendamos leer el apartadofuncionamiento de un codec donde se puede aprender como funciona detallamente el codec G.711 y que significan en su caso los parametros de la tabla.
NombreEstandarizadoDescripciónBit rate (kb/s)Sampling rate (kHz)Frame size (ms)Observaciones
MOS (Mean Opinion Score)
G.711 *ITU-TPulse code modulation (PCM)648MuestreadaTiene dos versiones u-law (US, Japan) y a-law (Europa) para muestrear la señal
4.1
G.711.1 *ITU-TPulse code modulation (PCM)80-96Kbps8MuestreadaMejora del codec G.711 para abarcar la banda de 50 Hz a 7 Khz. Mas info
G.721ITU-TAdaptive differential pulse code modulation (ADPCM)328MuestreadaObsoleta. S e ha transformado en la G.726.
 
G.722ITU-T7 kHz audio-coding within 64 kbit/s6416MuestreadaDivide los 16 Khz en dos bandas cada una usando ADPCM
 
G.722.1ITU-TCodificación a 24 y 32 kbit/s para sistemas sin manos con baja perdida de paquetes24/321620 
 
G.722.2 AMR-WBITU-TAdaptive Multi-Rate Wideband Codec (AMR-WB)23.85/ 23.05/ 19.85/
18.25/ 15.85/ 14.25/
12.65/ 8.85/ 6.6
1620Se usa principalmente para compresíon de voz en tecnología movil de tercera generación. Mas info
 
G.723ITU-TExtensión de la norma G.721 a 24 y 40 kbit/s para aplicaciones en circuitos digitales.24/408MuestreadaObsoleta por G.726. Es totalmente diferente de G.723.1.
 
G.723.1ITU-TDual rate speech coder for multimedia communications transmitting at 5.3 and 6.3 kbit/s5.6/6.3830Parte de H.324 video conferencing. Codifica la señal usando linear predictive analysis-by-synthesis coding. Para el codificador de high rate utiliza Multipulse Maximum Likelihood Quantization (MP-MLQ) y para el de low-rate usa Algebraic-Code-Excited Linear-Prediction (ACELP).
3.8-3.9
G.726ITU-T40, 32, 24, 16 kbit/s adaptive differential pulse code modulation (ADPCM)16/24/32/408MuestreadaADPCM; reemplaza a G.721 y G.723.
3.85
G.727ITU-T5-, 4-, 3- and 2-bit/sample embedded adaptive differential pulse code modulation (ADPCM)var. MuestreadaADPCM. Relacionada con G.726.
 
G.728ITU-TCoding of speech at 16 kbit/s using low-delay code excited linear prediction1682.5CELP.
3.61
G.729 **ITU-TCoding of speech at 8 kbit/s using conjugate-structure algebraic-code-excited linear-prediction (CS-ACELP)8810Bajo retardo (15 ms)
3.92
G.729.1ITU-TCoding of speech at 8 kbit/s using conjugate-structure algebraic-code-excited linear-prediction (CS-ACELP)8/12/14/16/
18/20/22/24/
26/28/30/32
810Ancho de banda desde 50Hz a 7 Khz Mas info
GSM 06.10ETSIRegular­Pulse Excitation Long­Term Predictor (RPE-LTP)13822.5Usado por la tecnología celular GSM
 
LPC10Gobierno de USALinear-predictive codec2.4822.510 coeficientes.La voz suena un poco "robotica"
 
Speex  8, 16, 322.15-24.6 (NB)
4-44.2 (WB)
30 ( NB )
34 ( WB )
 
 
iLBC  813.330 
 
DoD CELPAmerican Department of Defense (DoD) Gobierno de USA 4.8 30 
 
EVRC3GPP2Enhanced Variable Rate CODEC9.6/4.8/1.2820Se usa en redes CDMA
 
DVIInteractive Multimedia Association (IMA)DVI4 uses an adaptive delta pulse code modulation (ADPCM)32VariableMuestreada 
 
L16 Uncompressed audio data samples128VariableMuestreada 
 
SILKSkypeUncompressed audio data samplesDe 6 a 40 kbit/sVariable20El codec Harmony está basado en SILK
 


* El codec g711 tiene dos versiones conocidas como alaw (usado en Europa) y ulaw (usado en USA y Japón). U-law se corresponde con el estandar T1 usado en Estados Unidos y A-law con el estandar E1 usado en el resto del mundo. La diferencia es el método que se utiliza para muestrear la señal. La señal no se muestrea de forma lineal sino de forma logaritmica. A-law tiene un mayor rango. Para mas información de las diferencias ver G.711 Ley A vs Ley u

** existen varias versiones del codec g729 que es interesante explicar por su extendido uso
G729: es el códec original 
G729A o anexo A: es una simplificación de G729 y es compatible con G729. Es menos complejo pero tiene algo menos de calidad. 
G729B o anexo B: Es G729 pero con supresion de silencios y no es compatible con las anteriores. 
G729AB: Es g729A con supresión de silencios y sería compatible solo con G729B.
Aparte de esto G729 (todas las versiones) en general tienen un bit rate de 8Kbps pero existen versiones de 6.4 kbps (anexo D) y 11.4 Kbps (anexo E). 

martes, 30 de agosto de 2016

How to configure LACP on our Smart/ Managed Switch?

Introduction
LACP (Link Aggregation Control Protocol) is defined in IEEE802.3ad and enables the dynamic link aggregation and disaggregation by exchanging the LACP packets with its partner. The switch can dynamically group similar ports into a single logical link, which will highly extend the bandwidth and flexibly balance the load.

Application scenario
As is shown in the picture above, we take TL-SG5428 and T3700 as example and we will configure ports 26,27,28 on TL-SG5428 and ports 21,22,2 on T3700 correspondingly as LACP.

Note: For the member ports in an aggregation group, their basic configurations must be the same. The basic configuration includes STP, QOS, GVRP, VLAN, port attributes, MAC Address Learning mode and other associated settings. If you are not sure about these basic configurations, you can export the config file and reset the device and then try it again. We highly suggest you configure the LAG function before configuring any other function for member ports.

Configuration
Step1: login to the management interface of the TL-SG5428, and go to Switch--LAG--LACP, you can designate a System Priority for the TL-SG5428 or leave as default value, The default value is 32768. And then choose the ports 26/27/28, designate an Admin Key 2 for these ports. The ports with the same Admin Key will be aggregated to the same group. Choose the Mode as Active and Status as Enable. And then click Apply to take the setting into effect. The result will show as below:
5428E.JPG

Note:
1.A lower system priority value indicates a higher system priority. When exchanging information between systems, the system with higher priority determines which link aggregation a port belongs to, and the system with lower priority adds the proper ports to the link aggregation according to the selection of its partner. If the System Priority value is the same, the device with smaller MAC address owns higher priority.
2.There are two mode of the port, Active and Passive. In Active mode, the port can send LACP packets actively while in Passive mode, the port can only send LACP packets after it has received a LACP packet. It is suggested that set one side as Active mode and the other side as Passive mode.

Step2: almost the same settings as the T3700. Login to the management interface of the T3700, and go to Switch--LAG--LACP, you can designate a System Priority for the T3700 or leave as default value, The default value is 32768. And then choose the ports 21/22/23, designate an Admin Key 3 for these ports. Choose the Mode as Passive and Statusas Enable. And then click Apply to take the setting into effect. The configuration will show as below:
T3700G-28TQ.JPG

Now, the configuration is done, and we can check the result in the LAG Table. Since the lines are aggregated or disaggregated dynamically into the group, we can only see the ports that are added to the group at this moment in the Member.
5428E result.JPG