View Full Version : win hand is cool.
ir803
07-07-2004, 09:30 AM
winhand for palm is amazing, using my T630 mobile phone I can remote control my home pc, I can check or send out emails and much more and the screen res is fantastic and the speed is very impresive.
I just have one query for anyone else trying it, I have norton internet security pro and without any alteration to any settings after installation windhand worked first tiem, on installation norton asked if i wanted to allow or block the winhand server app so I OK'ed it, my query is Does this leave a port vulnerable to hackers/ viruses etc.
BTW here's a screen shot.
http://www.itsmy-space.co.uk/cliemax/screenshots/winhand.jpg
th1nm1nt
07-07-2004, 09:36 AM
I like that format!
winhand for palm is amazing
Oooh! Link please! - this looks very nifty - a possible vnc-killer!
I just have one query for anyone else trying it, I have norton internet security pro and without any alteration to any settings after installation windhand worked first tiem, on installation norton asked if i wanted to allow or block the winhand server app so I OK'ed it, my query is Does this leave a port vulnerable to hackers/ viruses etc.
Simple answer - Yep.
Norton most probably picked up the listen request to the OS and that caused it to prompt whether or not to open that port to the outside world.
In increasing order of security (and madness) here's some options (For maximum security and maximum insanity, do them all):
You can hope that the app is secure enough that it's listening on an open port won't create a vulnerability. I wouldn't recommend this if it's important to you that your PC doesn't get hacked.
I'd suggest you limit the possible IPs that can connect to it down to the range your ISP gives to it's clients - that way only you and connect to that port (and anyone else that uses your ISP :D)
Perhaps include some time of day limits as well (pehaps set so that at times you are normally at home, the port is locked down as you'd not need it)?
Keep the port locked and set something to unlock it when you send a particular email to your home PC (something with a rolling set of passwords that you know the sequence of would protect against sniffers) and lock it down again when you finish each time.
You could go crazy and set up a VPN server on your PC (and have only that port open). Then force connections to authenticate to that (you can get VPN clients for palmos).
ir803
07-07-2004, 03:05 PM
OK you scared me now, I've had win-hand running for two days and this morning I left it running on my PC while I was out so I could do another test.
I have now (for now) set Norton to block win hand in the programs list until I have looked into this further, I cannot afford to get hacked, there is a more secure version but it costs about $40 which I cannot justify at the moment. I tried Palm VNC a while ago and Win hand blows it out of the water and into deep space. here's the link http://www.win-hand.com the basic version is free, I am a bit ignorant when it comes to iP's ISP's and server settings I'm afraid so alot of what you suggested is over my head. If you try this app let me know how you get on and if you find a good way of securing it with having to pay for the full version.
GeoffreyDC
07-07-2004, 03:13 PM
If you're using the free version of Win-Hand, anyone else with the program and your IP address can completely control your PC--generally speaking this is not a good thing.
If you buy the software, the security, from what I can tell, is excellent.
Geoffrey
No password protection at all Geoffrey? Yeah, probably a good thing you've got it locked down again ir803 :D :D :D
I'll definatly be giving it a go, but I doubt I'll open it to the internet :)
The IP stuff is actually not too hard - you can ask your ISP for the range (it'll be something of the form <blah>.<blah>.<blah>.<low number> - <blah>.<blah>.<blah>.<higher number>, they may have more than one range depending on the number of users and dial in lines they have. Any firewall software worth the plastic it's written on will allow you to specify a list of addresses that may connect to a given port. With a bit of luck, you should be able to view a list of 'open ports' and then list some IP addresses and/or ranges of IP addresses for a given port. It's worth playing with if you have any other ports open as it gives a substantial gain in security (screens out the majority of script kiddies) without too much hassle on your part.
Even with that security though, in light of GeoffreyDC's comment I'd still not recommend opening that port to the internet again :(
I'll have a think about ways to protect it, but nothing simple is leaping to mind straight away...
Might not be an entirely bad idea to have run a quick check of your system for spyware, worms, viruses or back doors seeing as it's been open for a couple of days. I wouldn't stress too much though, you'd probably already be seeing the results if you'd been hit - most black-hats are a long way from subtle these days. Do the checks to be sure though - never hurts to be a bit careful :)
If you want to learn a bit more about internet security, check out Gibson Research (http://www.grc.com/default.htm). He's got some useful resources (including Shield UP (https://www.grc.com/x/ne.dll?bh0bkyd2) which is a nifty little online security tester thing).
They guy's a bit of a lunatic in that he's perhaps unrealisticly paranoid but is also damned clever (He's written a really interesting article (http://www.grc.com/dos/grcdos.htm) about a Denial of Service attack he experianced a few years back).
ir803
07-07-2004, 04:49 PM
ok, I have opted for the dyndns option to hopefully minimize risk a little at the same time the desktop server will not be running all the time and my norton is set to pick up attacks on the set ports. So I will see how this goes.
How would using dyndns help?
If you mean you've got norton logging connections to the ports used by Win-Hand then that could be quite useful. Unfortunatly, it'll only help you detect a security breach rather than prevent it in the first place :(
Having the server running only at certain times will also help but you are taking a bit of a risk here by leaving the whole world able to connect - hope it's worth it.
TheRealZero
07-07-2004, 06:37 PM
I've been using this for a while. Reports say it's about 45 times faster than VNC. Dunno caus ei've never used it. Win-hand (even the free version) is really neat, but I can only use it when my Cliés plugged into the computer cause i only have a TJ-27.
vBulletin v3.0.3, Copyright ©2000-2012, Jelsoft Enterprises Ltd.