Hernán M. Racciatti

     Information Security + Research + Fun

 

TOOLS: IPFront

Download

- IPFront.zip [a8ffad4b44e0cab23a83db2fe3084350] Size 24 kb

About

IPFront is a small tool developed for administrators in charge of WIndows 2000/2003 hardening.

Although it is certain that both platforms have a certain amount of utilities to do this task (GPOs, Groups of Baseline, etc.), administrators of systems Windows often are seen in the necessity to navigate different windows from its graphical interface at the time of establishing simple filtering rules of traffic by means of IPSec policies, that accompany the correct process by Hardening of their platform.

There are in Windows 2003, and in the Resource Kit for Windows 2000, command line utilities to make powerful scripts to implement IPSec rules, but its syntax i probably not well-known by inexperienced administrators, or they may even be, sadly, not interested in learning them.

In short, IPFront is nothing more that a small * Front End * that receives direction on the behalf of the user, and then creating small script that one can later execute from IPFront or be transferred and executed in other servers.

IPFront also has two buttons that make possible to make some changes in the registry of Windows, with the object of hardening some aspects of the treatment of packets by the TCP/IP stack, and removing existing exceptions in the implementation of IPSec in Windows (Please refer to IPFronts help to know more about this).

Installation Requeriments

Although IPfront does not require installation, its total functionality in systems Windows 2000, is obtained with the implementation of component IPSECPOL.EXE developed by Microsoft, which is included in the Resource Kit, or through Microsoft's Web site. Please review the documentation of IPSECPOL.EXE in order to make the correct installation of this component if you require to execute the application or script resulting in the system to assure.

At the time of writing these lines, is available in the following URL:

http://www.microsoft.com/windows2000/techinfo/reskit/tools/

existing/ipsecpol-o.asp

- Windows 2000 Professional SP 4
- Windows 2000 Server SP 4
- Windows 2000 Advance Server SP 4
- Windows Server 2003

- Internet Explorer 5,5 SP 1 or Later

- Usuary with privileges of Administrator and component IPSECPOL.EXE of the Windows 2000 Resource Kit, in case of requiring TO APPLY the rules created by means of IPFront (In this case IPSECPOL.EXE it will have to be in path or the same directory that IPFront.hta).

Aknowledgements

Vero, Nico, Sofy thks for supporting me... I Love u All... I want to thank my friends too... you know who you are... (Special thks to Diego, Buanzo, Shadown, Rebel, Gaby Zabal, Chacal, Kero, Vampii, Insomnia, Quark and all guy in 2600 .ar / SJ05 meets)

Screenshots

- IPFront Website