2
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub
1
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

Focus on decoding unknown strings.

4
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

I am happy to share some Thoughts & Ideas about forum.ittavern.com in this article.

Feedback is welcome.

https://ittavern.com/forum.ittavern.com-thoughts-and-ideas/

2
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

Not gonna lie, wasn't that fun. Learned a lot, but felt lost multiple times. Probably gets better over time.

4
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

Doing some rooms on TryHackMe. Decided to create a write up of one room. Have to work on the format, but it should be fine for now.

Feedback is welcome!

22
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

I think I've never share one of my favorite articles with you.

Creating this was great and it has been a great resource ever since. I use SSH tunnel a lot in troubleshooting sessions and security demonstrations.

3
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

I am pleased to announce the launch of: forum.ittavern.com

More information can be found in this thread, but in short I miss the forum culture and want to create an open-minded and sustainable community.

I welcome you and look forward to great discussions.

2
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub
3
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

I am happy to share with you the new design of my blog.

New logo, new thumbnails, lots of CSS changes and everything is now hosted in a German DC.

The goal was to create a clean design and reduce the loading time even further.

Feedback is welcome.

6
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

Sending files over the internet. Been a pain in the past and I finally decided to host my own instance. It should be 'production' ready, but let me know if you encounter any problems.

1
submitted 2 years ago by wop@infosec.pub to c/networking@infosec.pub

So, every network engineer knows it: everyone else will blame the network and you have to prove them wrong.

There are multiple reason:

  • lack of knowledge
  • ignorance
  • passing on responsibility
  • laziness
  • ... There are more.

I am interested in how you react to 'The network is causing the problems' requests.

  • do you request certain information?
  • need an explanation?
  • what are you first steps?
  • do you have a runbook or some policy in place?

Without getting into too much detail, I request some or all of the following information before I start looking:

  • what are they trying to do? What is the desired outcome?
  • what is the error message? *(pref a screenshot!) *+ timestamp (for logs)
  • has it ever worked before?
  • since when isn't it working?
  • can you resolve domains?
  • Source Host > Destination Host:Port
  • Results of Ping + Powershell Test-NetConnection on Windows and Netcat on Linux (to test general connection, assuming TCP connection)

What I ask for and in what order depends on the person I am talking to. By the way, monitoring is my friend. If it says everything is fine, it usually is.

Side note Describing the actual proof that it is not the network depends heavily on the infrastructure and the problem, so this may be a discussion for another thread.


What are your first steps?

4
submitted 2 years ago by wop@infosec.pub to c/ittavern@infosec.pub

A quick & dirty solution that is available on most Linux hosts.

[-] wop@infosec.pub 1 points 2 years ago

The ISPs are slow to answer if there is no active outage. Will take some time anyway.

Packets are dropped in bot directions. I am currently looking through the pcaps and will do another stress test later - got another window. MTU/MSS is the prio today.

[-] wop@infosec.pub 1 points 2 years ago

Ping - Update 2

[-] wop@infosec.pub 1 points 2 years ago

Getting a pcap of another client could bring some insight, yeah.

SSH is used for the data transfer. Without knowing it at this moment, I'd assume scp or rsync. You mean whether all their internet traffic is routed through the active SSH session?

[-] wop@infosec.pub 1 points 2 years ago

Fairly new too - why wouldn't you be able to answer if the post is set to 'Undetermined'. Haven't had any issues yet.

[-] wop@infosec.pub 1 points 2 years ago

Not yet. Wouldn't expect it tbh, but you'll never know. How would you utilize Wirehuard for it? I'd like to hear more about it.

[-] wop@infosec.pub 1 points 2 years ago

Valid question. We've checked it multiple times, on the client and via monitoring that it is 10 Mbits. Thank you.

view more: ‹ prev next ›

wop

0 post score
0 comment score
joined 2 years ago
MODERATOR OF