Page 1 of 26 12311 ... LastLast
Results 1 to 10 of 251

Thread: Is there a knoppix Web Kiosk?

  1. #1
    Senior Member
    Join Date
    Oct 2003
    Location
    Canada
    Posts
    157

    Is there a knoppix Web Kiosk?

    Does anyone know of an internet kiosk version of knoppix that is able to be used on a business network (not allowed to browse the network) and only be able to access one or two sites? I am trying to find one for a friend that needs it for his customers. It will allow them to browse his internet page and see his products that aren't in the show room.

    If so...
    Which one
    How do I secure it from being an open door to the local lan
    How do I keep it from accessing the rest of the (windows) computers
    Make an install on the HDD so it will respond faster

    Thanks.

  2. #2
    Junior Member
    Join Date
    Feb 2004
    Location
    Switzerland
    Posts
    7
    have them in a different subnet...? and dont give users any administrative rights

    about the website: just adjust the router settings to only route to certain sites and not to any ip on the internet.

  3. #3
    Senior Member registered user
    Join Date
    Mar 2004
    Posts
    1,516
    hmm a remaster would be needed i guess.
    to begin you might make the "kioskuser" a separate group named "kioskuser" and allow that NOTHING eccept /home/"kioskuser" then as above make all directories not nesesarily read/write read only to kioskuser (as far as i know nothing outside /home), after that perhaps a chown -R root:root to several critical folders (such as /etc /usr/etc, /bin, /sbin, /usr/sbin...).
    hmmm, might as well do the reverse chown -R root:root / then open permisions as needed, would take longer but be as safe as could be made.

  4. #4
    Junior Member
    Join Date
    Feb 2004
    Location
    Switzerland
    Posts
    7
    agree with that. are these clients going to be used for anything else than surfing the mentioned websites? if not, you could just have an "empty" X with mozilla running.

  5. #5
    Senior Member registered user
    Join Date
    Mar 2003
    Posts
    872
    get a router that runs linux like the Linksys WRT54G and a number of iptable rules would be enough. Or just get an unused PC with 2 NIC and run a floppy based firewall.

    No need to remaster or whatever.

  6. #6
    Senior Member
    Join Date
    Oct 2003
    Location
    Canada
    Posts
    157
    He already has a router (D-Link DI-614)

    I myself am a windows admin (of sorts) and can manipulate windows like it was my own child. Linux is the hard part of this task. I am afraid that if I set up a Linux box, that it could give access to the rest of the network. You see I know that Linux is powerful, and it was born to live on the network (and internet). I have seen my own knoppix box attach to the internet and self detect all the NICs and router and IP information automatically (impressive!).

    Now that I know this, I am nervous about allowing a Linux version on the network because of how easy it (could) be to browse the LAN and possibly distroy anything on the rest of the network. Because of the fact that linux is so network amazing, how do I know that the Linux box is safe from the internet cracker jacks! Is linux an open door for them, especially if I don't know how to tinker with it to keep it closed?

    Remember I am still new to Linux and there was some things that were said that I can learn (I just don't know how to do them yet!) Te one thing I didn't understand is the "empty X server".

  7. #7
    Senior Member registered user
    Join Date
    Mar 2004
    Posts
    1,516
    to be honest, if you think anything can keep those really wanting to harm out you are deluded.
    the only way to reasonable safety is knowlege. there is always routes around ALL security.
    trouble is limiting holes... i would use a plain Debian and instal as little as possible (less risk of bugs, holes...) then i would alow the user to only read the bare minimum from /etc (as others)
    then NO KDE, NO gnome... just blackbox and mozilla installed. why? both KDE and Gnome (and some other WM's) have so many "builtins" that they themselves are security risks.
    The solution in MY eyes is configuring IPtables to allow acess to only the default gateway by blocking all other adresses on your network.
    If you then alow the user to only use mozilla and needed files, user would be even more crippled.
    if you wanted you could probably make a alias for logout, a script that empties the /home/user dir from all files then copy them back from a "mirror" somewhare on disk, and chown/chmod them to sensible values before actuall logout.

    if i was paranoid i would even remove/break other binaries. why apt-get is not needed to browse. nor is xterm, aterm, ping, wget, make, dpkg... cut everything not needed away.
    it might take a few days/weeks depending on your knowledge but it should be possible.

  8. #8
    Junior Member
    Join Date
    Jan 2004
    Posts
    4
    we do this commercially...email me directly zurk AT arbornet DOT org i interested.

  9. #9
    Member registered user
    Join Date
    Nov 2002
    Posts
    79

    Re: Is there a knoppix Web Kiosk?

    Quote Originally Posted by Hunkah
    Does anyone know of an internet kiosk version of knoppix that is able to be used on a business network (not allowed to browse the network) and only be able to access one or two sites? .
    Checkout KioskTool - Needs Kde 3.2, you may have to remaster Knoppix to use it. (Or try it with Kanotix)
    http://extragear.kde.org/apps/kiosktool.php
    http://www.kde-apps.org/content/show...204c047f209c83

    Cheers
    rob

  10. #10
    Senior Member registered user
    Join Date
    Jun 2003
    Posts
    611
    Couldn't you remove resolv.conf, and then edit /etc/hosts to be able top resolve the sites you want to their IP's....? Install a kiosk mode plugin to mozilla or firefox and set it to launch automatically when KDE starts. Then maybe some editing so that the user is not able to su or sudo.... and also disable KDE hotkeys.

    That would be a good start at least, right?

Page 1 of 26 12311 ... LastLast

Similar Threads

  1. knoppix for kiosk, how?
    By pinoylinux in forum General Support
    Replies: 2
    Last Post: 01-05-2005, 11:52 AM
  2. Kiosk Hardware
    By dragonwheels in forum Hardware & Booting
    Replies: 1
    Last Post: 11-22-2004, 07:17 PM
  3. hd-installed knoppix with kiosk mode twm
    By Eero in forum General Support
    Replies: 1
    Last Post: 09-29-2004, 01:23 AM
  4. Kiosk
    By sn0wflake in forum General Support
    Replies: 3
    Last Post: 12-05-2003, 04:13 AM
  5. Kiosk Knoppix for public libraries.
    By adamm in forum Customising & Remastering
    Replies: 30
    Last Post: 06-13-2003, 09:12 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram 2x 256GB SSD Quadro 2000 Linux GA picture

HP Workstation Z640 2x Xeon E5-2623V4 32GB Ram 2x 256GB SSD Quadro 2000 Linux GA

$212.49



HP Z420 Workstation Xeon E5-2690 v2 3ghz 10-Cores 64gb  512gb SSD  4TB  Win10 picture

HP Z420 Workstation Xeon E5-2690 v2 3ghz 10-Cores 64gb 512gb SSD 4TB Win10

$239.99



Dell Poweredge R630 2x Xeon E5-2680 v4 2.4ghz 28-Cores / 128gb / H330 / 2x 1TB picture

Dell Poweredge R630 2x Xeon E5-2680 v4 2.4ghz 28-Cores / 128gb / H330 / 2x 1TB

$334.99



HP Z440 Workstation 18Cores Xeon E5-2699 V3 128GB 1TB SSD 2TB WIFI WIN11 R5-340X picture

HP Z440 Workstation 18Cores Xeon E5-2699 V3 128GB 1TB SSD 2TB WIFI WIN11 R5-340X

$309.99



Intel Xeon E5-2680 v4 SR2N7 2.40GHz 35MB 14-Core LGA2011-3 CPU Processor picture

Intel Xeon E5-2680 v4 SR2N7 2.40GHz 35MB 14-Core LGA2011-3 CPU Processor

$14.99



SR1XP Intel Xeon E5-2680 v3 12 Core 30MB 2.5GHz LGA 2011-3 Grade A Processor picture

SR1XP Intel Xeon E5-2680 v3 12 Core 30MB 2.5GHz LGA 2011-3 Grade A Processor

$3.96



Dell Precision T5810 Xeon E5-1620 v4 (3.50GHz) 32GB RAM,  No OS, No Graphic Card picture

Dell Precision T5810 Xeon E5-1620 v4 (3.50GHz) 32GB RAM, No OS, No Graphic Card

$100.00



Intel Xeon E5-2667 V4 SR2P5 (3.2GHZ/8-CORE/25MB/135W) PROCESSOR CPU picture

Intel Xeon E5-2667 V4 SR2P5 (3.2GHZ/8-CORE/25MB/135W) PROCESSOR CPU

$29.95



Dell Precision T5600 Xeon E5-2603 1.80GHz 16GB RAM 1TB HDD Quadro 600 #27 picture

Dell Precision T5600 Xeon E5-2603 1.80GHz 16GB RAM 1TB HDD Quadro 600 #27

$76.99



Lenovo Thinkstation P510 E5-1620 V4 16GB RAM 512GB SSD DVD Quadro M2000 W10 Pro picture

Lenovo Thinkstation P510 E5-1620 V4 16GB RAM 512GB SSD DVD Quadro M2000 W10 Pro

$164.95