triskelion, to random
@triskelion@floss.social avatar

Why does podman has legacy iptables dependency? 🤔

lovisix, to random French
@lovisix@social.zdx.fr avatar

Hi foks,

Is there any specialist of ?

I install it on a computer at home.
Here in holidays I can see it with tailscale status. I also see it as connected machine on the web gui tailscale.

But I can't to it.

I can't remembrer if I enabled on my .

Help will be really appreciate.
Thanks in advance.

holm, to android German
@holm@social.saarland avatar

https://gnulinux.ch/datensparsames-android-mit-der-android-debug-bridge-teil1-samsung-phablet

wow! geiles verfahren. insbesondere rethink dns kannte ich noch nicht. aber da dieses mehrere wireguard endpunkte parallel verwalten kann wird das nun mal angetestet. happy hacking!

@gnulinux

bsi, to random German
@bsi@social.bund.de avatar

Ihr habt eine und fühlt euch vor allen Angriffen geschützt? Leider ist es nicht so einfach. Nur wenn die Firewall richtig konfiguriert ist, kann sie ihren Dienst tun und euer System sicherer machen. Denn Angriffe aus dem Internet nutzen jede in installierten Programmen wie auch in der Firewall selbst aus. Mehr zur Firewall-Konfiguration erfahrt ihr hier: https://www.bsi.bund.de/dok/131310

video/mp4

mikael, to wireguard
@mikael@hachyderm.io avatar

does it right: I configured hosted on my for my and my laptops, and it supports and out of the box without issues.

https://oxcrag.net/blog/2024/04/14/Connecting-to-Home-From-Abroad.html

HonkHase, to random German
@HonkHase@chaos.social avatar

Freitag Nachmittag, "Enterprise" Hersteller Geschenke fürs WE 🙄

Thnx an das BSI CERT Bund! 👌

Version 1.0: Networks 's: Aktive Ausnutzung einer ungepatchten
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-231856-1032

Widowild1, to opnsense French
@Widowild1@mastodon.xyz avatar
tux, to opnsense German

Eure Meinung ist gefragt:
Folgender grober Netzwerkaufbau:
VF-Kabelmodem --> FritzBox (Internettelefonie) --> OPNsense --> LAN und DMZ

Frage:
In der die als Exposed Host eintragen oder lieber doch einzelne Portfreigaben auf die OPNSense definieren auf dieser dann die gleichen für die jeweiligen Zielhosts existieren?

Bin mir da unschlüssig, ob durch den Exposed Host auf der FritzBox nicht irgendwelche Nachteile existieren. Auf der einen Seite habe ich ja dahinter die OPNSense als , die den weiteren Netzwerkverkehr regelt.

Was meint ihr?

@askfedi_de

jbzfn, to homelab
@jbzfn@mastodon.social avatar

🦾 INCTEL N100 fanless mini PC and micro firewall appliance comes with four 2.5GbE ports using Intel i226V controllers | CNX Software

「 The device supports up to 16GB DDR5 memory, can take an M.2 NVMe SSD and/or a 2.5-inch SATA drive for storage, and also provides two video outputs through HDMI and DisplayPort, as well as a few USB ports, an RJ45 console port, and optional support for WiFi and 4G LTE connectivity 」

https://www.cnx-software.com/2024/03/30/inctel-n100-fanless-mini-pc-and-micro-firewall-appliance-comes-with-four-2-5gbe-ports-using-intel-i226v-controllers/

foss_android, to android
@foss_android@mstdn.social avatar

Rethink
DNS + Firewall + VPN

#Rethink is a security app that combines multiple functionalities to protect your #Android device.

Download: https://rethinkdns.com/download

bsi, to random German
@bsi@social.bund.de avatar

Vorsicht vor dem Man-in-the-Middle-Angriff: Kriminelle können eure Verbindung ausspionieren und manipulieren. Neben einem sicheren helfen euch hier vor allem eine 2-FA, eine verschlüsselte Verbindung und eine .

kuketzblog, to security German
@kuketzblog@social.tchncs.de avatar

Das geplante Tutorial zu für das erste Quartal 2024 ist auf unbestimmte Zeit verschoben. Auch Version 0.5.5c ist mir persönlich noch zu buggy bzw. es treten seltsame Situationen/Schwierigkeiten im Betrieb auf. Da muss noch etwas Fleiß und Arbeit reinfließen, bevor ich dazu ein Tutorial erstelle.

linuxmagazine, to linux
@linuxmagazine@fosstodon.org avatar

The April issue has been released! This month we take a look at virtual memory in Linux. On the DVD: @elementary 7.1 and 9 https://shop.linuxnewmedia.com/shop/eh30281-linux-magazine-281-print-issue-256#attr=

gnulinux, to linux German
@gnulinux@social.anoxinon.de avatar

Sicher im Netz unterwegs mit der ufw Firewall

Ich zeige dir, wie du die ufw Firewall unter Linux einrichten kannst, um deinen PC vor Angriffen aus dem Internet zu schützen.

#Ufw #Firewall #SpaceFun #firewalld #TuxWiz #Linux

https://gnulinux.ch/sicher-im-netz-unterwegs-mit-der-ufw-firewall

stefano, to IT
@stefano@bsd.cafe avatar
vwbusguy, (edited ) to random
@vwbusguy@mastodon.online avatar

Pop quiz for . All things being equal, which of these determines the priority of which zone rules get applied if an IP source overlaps:

teriradichel, to AWS

A Firewall For AWS CloudShell
~~
ACM.446 Attempting to prevent outbound credential exfiltration via self-XSS
~~
#cloudshell #xss #credentials #container #aws #security #firewall

https://medium.com/cloud-security/a-firewall-for-aws-cloudshell-8c07bc026415

intelgraphy, to Cybersecurity
@intelgraphy@hachyderm.io avatar

The avahi-daemon duplicates are very suspicious. And both versions use the same port. So I blocked them.

nono2357, to random
weilawei, to random
@weilawei@mastodon.online avatar

If you are the owner/operator/admin of a public Internet service, I would implore you to report log errors to AbuseIPDB. This helps the rest of us automatically check for known attackers. Thank you.

https://abuseipdb.com

MacLemon, to Ansible
@MacLemon@chaos.social avatar

Looking for hints on how to properly setup the awall firewall on via . I'm aware of community.general.awall but that's only suitable for enabling/disabling existing policy/filter files.

So far my search-engine foo seems to be too weak to bring up anything substantially helpful. Hints are welcome!

skyfaller,
@skyfaller@jawns.club avatar

@MacLemon @ansible Good luck! This is what my friend and I found last time we looked into configuring the with Ansible: https://github.com/maximum-ethics/linode-caddy/issues/18#issuecomment-1146154646

We never got around to finishing the job but I really would like to figure it out.

stefano, to random
@stefano@bsd.cafe avatar

This morning, an e-commerce site (built on Laravel and well-developed, hence quite efficient) started showing signs of slowing down. This had also happened a few weeks ago, and we partially managed the situation by increasing the VPS power and freeing up the physical machine from other loads.
An analysis of the nginx log reveals that the server is being bombarded with requests from Bytedance. As often happens in these cases, I attempted to firewall the IPs associated with the bots.
However, as soon as I block one IP, (or entire class) the crawling resumes (violently, almost like triggering a DoS attack) from another IP on another class.
They don't respect the robots.txt file.
The IPs they use online don't match the ones from which the requests originate; they probably constantly acquire and change IP blocks.

It makes me wonder: if everyone online behaved like this, everything would collapse in a matter of minutes.

dusnm, to random
@dusnm@fosstodon.org avatar

Repeat after me:

👏 NAT 👏 IS 👏 NOT 👏 A 👏 FIREWALL

5am, to opnsense
@5am@fosstodon.org avatar

has now become a prized part of my home network and probably my favourite discovery of the last few years. + + DNS filtering + + VLANs, it all runs great on a repurposed x86 box, and the many hours of tinkering have been valuable learning experiences.

schenklklopfer, to windows German
@schenklklopfer@chaos.social avatar

Gibt es einen einfachen und zuverlässigen Weg nicht ins gesamte Internet zu lassen?

Nur auf einzelne IPs und Ports.

Die Windows eigene wird vermutlich nicht geeigent sein den Host vom nach Hause telefonieren abzuhalten...

Frage für

  • All
  • Subscribed
  • Moderated
  • Favorites
  • tester
  • osvaldo12
  • magazineikmin
  • cubers
  • thenastyranch
  • normalnudes
  • Youngstown
  • ngwrru68w68
  • slotface
  • mdbf
  • rosin
  • InstantRegret
  • kavyap
  • DreamBathrooms
  • JUstTest
  • khanakhh
  • anitta
  • modclub
  • Leos
  • everett
  • ethstaker
  • Durango
  • GTA5RPClips
  • provamag3
  • megavids
  • tacticalgear
  • cisconetworking
  • lostlight
  • All magazines