[-] [email protected] 2 points 1 year ago

So, let's assume that you are in an international company and the first and only security person. What are your first steps and projects? It is like really vague, but I'd assume like a SIEM, inventory of the network and all devices, backup situation, maybe even honeypots?

What are your high-prio things that every company should have? Is there even a framework for it?

Feeling kinda lost and I hope you get some guidance in the right direction.

4
submitted 1 year ago by [email protected] to c/[email protected]

Set up new #FreshRSS instance for now. I want to read more and stay up to date on certain topics and I figured I could give RSS another chance. Stays invite-only for now, but feel free to hit me up if you want to have an account.

2
submitted 1 year ago by [email protected] to c/[email protected]
1
submitted 1 year ago by [email protected] to c/[email protected]

Focus on decoding unknown strings.

4
submitted 1 year ago by [email protected] to c/[email protected]

I am happy to share some Thoughts & Ideas about forum.ittavern.com in this article.

Feedback is welcome.

https://ittavern.com/forum.ittavern.com-thoughts-and-ideas/

[-] [email protected] 3 points 1 year ago

Testing a few CTF platforms to learn more about pentesting. It is interesting, but the learning curve is quite steep.

2
submitted 1 year ago by [email protected] to c/[email protected]

Not gonna lie, wasn't that fun. Learned a lot, but felt lost multiple times. Probably gets better over time.

4
submitted 1 year ago by [email protected] to c/[email protected]

Doing some rooms on TryHackMe. Decided to create a write up of one room. Have to work on the format, but it should be fine for now.

Feedback is welcome!

22
submitted 1 year ago by [email protected] to c/[email protected]

I think I've never share one of my favorite articles with you.

Creating this was great and it has been a great resource ever since. I use SSH tunnel a lot in troubleshooting sessions and security demonstrations.

3
submitted 1 year ago by [email protected] to c/[email protected]

I am pleased to announce the launch of: forum.ittavern.com

More information can be found in this thread, but in short I miss the forum culture and want to create an open-minded and sustainable community.

I welcome you and look forward to great discussions.

[-] [email protected] 3 points 1 year ago
2
submitted 1 year ago by [email protected] to c/[email protected]
3
submitted 1 year ago by [email protected] to c/[email protected]

I am happy to share with you the new design of my blog.

New logo, new thumbnails, lots of CSS changes and everything is now hosted in a German DC.

The goal was to create a clean design and reduce the loading time even further.

Feedback is welcome.

6
submitted 1 year ago by [email protected] to c/[email protected]

Sending files over the internet. Been a pain in the past and I finally decided to host my own instance. It should be 'production' ready, but let me know if you encounter any problems.

[-] [email protected] 2 points 1 year ago

Currently using HedgeDoc for taking notes, but it is lacking some features, so I am trying to find and host some alternatives and compare them. And I hope I can find some time to play with my Flipper Zero....

1
submitted 1 year ago by [email protected] to c/[email protected]

So, every network engineer knows it: everyone else will blame the network and you have to prove them wrong.

There are multiple reason:

  • lack of knowledge
  • ignorance
  • passing on responsibility
  • laziness
  • ... There are more.

I am interested in how you react to 'The network is causing the problems' requests.

  • do you request certain information?
  • need an explanation?
  • what are you first steps?
  • do you have a runbook or some policy in place?

Without getting into too much detail, I request some or all of the following information before I start looking:

  • what are they trying to do? What is the desired outcome?
  • what is the error message? *(pref a screenshot!) *+ timestamp (for logs)
  • has it ever worked before?
  • since when isn't it working?
  • can you resolve domains?
  • Source Host > Destination Host:Port
  • Results of Ping + Powershell Test-NetConnection on Windows and Netcat on Linux (to test general connection, assuming TCP connection)

What I ask for and in what order depends on the person I am talking to. By the way, monitoring is my friend. If it says everything is fine, it usually is.

Side note Describing the actual proof that it is not the network depends heavily on the infrastructure and the problem, so this may be a discussion for another thread.


What are your first steps?

[-] [email protected] 2 points 2 years ago

I want to get into Ansible and I am building a testing env for it - home lab with various switches and routers, Fortinet, Palo, and a proxmox host server and some remote VPS. One of my goals for Q1 '24. Today I am going to prep the switches.

Besides that, I want to host my own NFTY server and I hope that I can get it online within this week.

[-] [email protected] 5 points 2 years ago

I am currently transitioning into a Security role at work. One question would be: what are the must-have tools for every blue team?

  • Vuln-Scanner
  • Logging/ SIEM-Server
  • ...
[-] [email protected] 3 points 2 years ago

Learning things about Wireguard and implement it to secure my internet facing servers.

[-] [email protected] 2 points 2 years ago

Added the Update 2. Still some things to do, but we know a little bit more now. Feedback and questions are still welcome.

[-] [email protected] 2 points 2 years ago

Ping - Update 2 Your numbers are are still missing since I havent had time to look into the pcaps yet. I hope I can get it done by the end of the week, but we are a little bit wiser.

[-] [email protected] 11 points 2 years ago

Thank you Jerry!

[-] [email protected] 1 points 2 years ago

Not yet. Just got access to the test clients and I have planned to do a troubleshooting session tomorrow in the morning. Not a big fan of stress testing the network on a working day haha

[-] [email protected] 1 points 2 years ago

Gotcha! - I thought Wireguard might has some logging features that could provide some insights. Thank you.

view more: next ›

wop

0 post score
0 comment score
joined 2 years ago
MODERATOR OF