noUsernamesLef7

@noUsernamesLef7@infosec.pub

This profile is from a federated server and may be incomplete. Browse more on the original instance.

noUsernamesLef7,

And yet injection is still #3 in the OWASP Top 10

noUsernamesLef7,

You make it sound as if it’s a thing of the past when it is still a common problem.

noUsernamesLef7,

I set up Netbox recently at work to try and improve the abysmal documentation situation. I use an Ansible playbook to provision and set up the server, then copy a docker compose file and start the containers. So far I’m loving Netbox, I just wish my predecessors had documented things from the start.

noUsernamesLef7,

Namecheap + the dynamic DNS client in pfSense. No issues sinve I set it up years ago.

Before that it was a cron job that updated through the google domains api.

noUsernamesLef7,

Da Archive maybe? Most of my stuff has come from there.

noUsernamesLef7,

I recently set up and started using MediaTracker for this purpose. It’s kind of barebones, but functional. Seems like its biggest difference with movary is that it also covers TV, ebooks, audiobooks, and games.

I have a little section for movies and books on my website and i’ve been working on a script to automatically pull those lists and reviews from MediaTrackers api each time I build my site.

How does ransomware get into major networks, such as schools or other large public agencies?

I read an article about ransomware affecting the public transportation service in Kansas, and I wanted to ask how this can happen. Wikipedia says these are “are typically carried out using a Trojan, entering a system through, for example, a malicious attachment, embedded link in a phishing email, or a vulnerability in a...

noUsernamesLef7,

It is a great step but it’s rare to have enough buy in from upper managent to enforce any real consequences for repeat offenders. I’ve seen good initial results from this kind of phishing testing, but the repeat offenders never seem to change their habits and your click rate quickly plateaus.

noUsernamesLef7,

Stay suspicious. As a security guy, i’d way rather respond to 1,000 false positive reports than have an employee that doesn’t think about it and just clicks.

noUsernamesLef7,

A little late, but here is what I usually do when a ticket like that comes in:

  1. Check monitoring. It’s quick and easy to check so I’ll look before even asking any clarifying questions. If there is a real network problem at a site, 95% of the time its going to show up on our monitoring dashboard. Everything from ISP outages to device failures show up here.
  2. Ask for more details about what they are trying to do. What is the goal? What are you doing? What is happening? What should be happening? When was the last time it worked?
  3. Based on those details, I can usually put together a good guess as to what might be going on, so i’ll test that theory out and see if i’m right.
noUsernamesLef7,

Oh thanks, saved. Will break this image out next time it happens, though I usually end up dying from getting into desperate situations looking for antifungals before it gets to this point.

noUsernamesLef7,

I’m studying for CCSP right now. It’s fairly general and tries to be vendor neutral but Architecture is one of the knowledge domains on the exam. Might be worth it if you meet the work requirements or experience waiver requirements.

A lot of people also seem to conflate it with the CISSP when it comes up in conversation I’ve noticed.

noUsernamesLef7,

I just started my first official cybersecurity position at a medium size company in an industry that is currently being heavily targeted with ransomware.

I’m starting pretty much from scratch as they have not had a dedicated security role in over a year and my predecessor didn’t make much progress. So far i’ve been focused on inventory lists, policies, and procedures for hardware, software, and data. I think we’re doing okay with minimizing stuff thats internet facing and patching is in a good place (well, at least with the devices and os’s that are still supported).

Any suggestions on where to go from there or what to prioritize?

noUsernamesLef7,

Thanks! This is actually exactly what I have been basing my efforts on so far, it’s just sobering to look at how far away we are from completing implementation group 1.

What would be the best way for me to recover data from my old laptop's hard drive, which seems to have a bad superblock?

I got an external hard drive enclosure for the purpose of recovering some of the files from my old laptops hard drive. The hard drive and all of it’s partitions show up in both disks and gparted but it wont mount. When I tried to mount it manually, it gave the error message stating that it can’t read the superblock. I’ve...

noUsernamesLef7,

I swear by ddrescue. It’s a situation I strive to never be but i’ve been there before. I used it once to rescue an employees masters capstone project from their dead work laptop.

noUsernamesLef7,

As someone in the thick of it, it has been a nervewracking quarter for mortgage company IT and Infosec teams. There have been several very high profile breaches the last few months.

noUsernamesLef7,

I now want a roleplaying game set in village like this.

noUsernamesLef7,

Oh nice, have you read any of his other books? I keep meaning to get around to reading Bullshit Jobs.

noUsernamesLef7,

Oh I highly recommend it. As a kid I read a lot of his work and my favorites were the Cask of Amontillado and The Tell-tale Heart. I still love those ones but I feel like I can appreciate the poetry and other stories now.

Another series I’ve gotten a lot of mileage out of revisiting was Calvin and Hobbes funny enough.

noUsernamesLef7,

The shuttle SRB’s were really only reusable in the same sense that the engine from a wrecked car can be removed, stripped to a bare block, bored out, rebuilt, and placed into a new car is reusable. Hard to say exactly how long it took to turn around SRB segments, but just the rail transport between Utah and Florida was 12 days each way. SpaceX has turned around Falcon 9 boosters in under a month.

And even with all of that, the most reused reusable segments barely flew a dozen times. There is one Falcon 9 first stage that has now flown 18 times.

You’re not wrong about parts having been reused in the past but the scale of what has been done before really doesn’t compare to what SpaceX does now.

noUsernamesLef7,

Three things for me. One, I have no practical way of charging one at home. Two, they’re mostly outside my price range. Three, I have doubts about maintainability of the used ones in my price range.

I’ve owned 3 cars in the last six years, two of which I still have. All have been between 9 and 26 years old and cost between $2300 and $7000. Last time I looked around my area, there were only a few electric cars in that price range mostly 2012-2014ish Leafs and electric Focuses. I know the battery packs degrade over time and suspect the range at that age from that era of EV’s would be impractical for me. Replacement packs are expensive and if I factor them into the purchase cost it’s pushing all of them over $10,000.

Maybe in a few years when my living situation has changed and better EV’s are available in that price range?

noUsernamesLef7,

Do note though that for privacy purposes, a .us domain is not the best idea. You must be a U.S. citizen or business and registrars may try to verify your identity.

noUsernamesLef7,

Really depends on your scale and needs, but when we were in the process of transitioning from Ivanti to Intune we had a gap between them. I set up a FOG project server and a couple remote nodes and that worked really well as an interim solution. I actually started using it at home even though I don’t really need imaging too often.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • Durango
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • vwfavf
  • Youngstown
  • slotface
  • thenastyranch
  • ngwrru68w68
  • rosin
  • kavyap
  • PowerRangers
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • tacticalgear
  • ethstaker
  • modclub
  • osvaldo12
  • everett
  • tester
  • cubers
  • GTA5RPClips
  • normalnudes
  • Leos
  • provamag3
  • All magazines