ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Some thoughts about Security

    IT Discussion
    11
    37
    10.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BRRABillB
      BRRABill @scottalanmiller
      last edited by

      @scottalanmiller said:

      Now you want to test out a few OSes. You might have a VM for 2012 R2, 2016, 2012, 2008 R2, 2008, 2003 R2, CentOS 6, CentOS 7, Suse Leap, Suse Tumbleweed, Ubuntu 14.04, Ubuntu 15.10, Fedora 23, Arch Linux, Debian Jessie, FreePBX, FreeBSD, NetBSD, DragonFly, Solaris, Windows 10 and Gentoo.

      That is "a few" OSes?

      Hey, to each their own. I have a hard time just managing my Xbox One.

      travisdh1T 1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        It's not many, really. All mainstream ones that you might want to have access to to test something or see how it installs or whatever. More than I test, but not many more. I don't test Arch or DragonFly, for example. But if you are testing appliances like FreeNAS and NAS4Free those will add up quickly too!

        1 Reply Last reply Reply Quote 0
        • A
          Alex Sage @scottalanmiller
          last edited by Alex Sage

          @scottalanmiller said:

          Well think about building a lab. You want a storage device, jump box and logging kind of at a minimum. That's three.

          I don't have a storage device or logging yet. What do you recommend? And what do you mean by a storage device? Like for shared /home?

          quicky2gQ 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Yeah, like a shared NFS or SMB for Windows. Or even ownCloud and stuff like that.

            Logging... ELK. Can't beat it.

            1 Reply Last reply Reply Quote 1
            • travisdh1T
              travisdh1 @BRRABill
              last edited by travisdh1

              @BRRABill said:

              @scottalanmiller said:

              Now you want to test out a few OSes. You might have a VM for 2012 R2, 2016, 2012, 2008 R2, 2008, 2003 R2, CentOS 6, CentOS 7, Suse Leap, Suse Tumbleweed, Ubuntu 14.04, Ubuntu 15.10, Fedora 23, Arch Linux, Debian Jessie, FreePBX, FreeBSD, NetBSD, DragonFly, Solaris, Windows 10 and Gentoo.

              That is "a few" OSes?

              Hey, to each their own. I have a hard time just managing my Xbox One.

              Oh, that's just a start. Much easier to manage today that it was "back in the day" as well! Over the whole Y2K thing I was interning, and had setup a computer to multi-boot Windows 95, 98, ME, XP, OS/2, OS/2 Warp, Red Hat 4, and I'm not sure how many different x86 compatible machine control things. I was ECSTATIC when that new thing called VirtualBox came around. Just thinking about what, and how easily, we can do things today compared to back then can make my head spin.

              Edit: I forgot NT3.5, 4.0 and Windows 2000 as well.

              1 Reply Last reply Reply Quote 0
              • A
                Alex Sage
                last edited by

                @scottalanmiller What about monitoring?

                dafyreD 1 Reply Last reply Reply Quote 0
                • dafyreD
                  dafyre @Alex Sage
                  last edited by

                  @anonymous said:

                  @scottalanmiller What about monitoring?

                  Zabbix!

                  A 1 Reply Last reply Reply Quote 1
                  • A
                    Alex Sage @dafyre
                    last edited by

                    @dafyre How hard is it to install for a noob like me?

                    dafyreD scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • dafyreD
                      dafyre @Alex Sage
                      last edited by

                      @anonymous said:

                      @dafyre How hard is it to install for a noob like me?

                      It takes a little bit of work to get it going, but it's not too bad. They have packages available at http://www.zabbix.com/download.php

                      Documentation is at that link too... just download the docs for whichever Distro you are using. I'll be happy to help if you hit any snags.

                      A 1 Reply Last reply Reply Quote 1
                      • A
                        Alex Sage @dafyre
                        last edited by

                        @dafyre Thanks!

                        1 Reply Last reply Reply Quote 0
                        • quicky2gQ
                          quicky2g @Dashrender
                          last edited by

                          @Dashrender said:

                          @anonymous said:

                          The funny thing is someone would that it has value, because of all the work you put into protecting it 🙂

                          While some people might think that because of your extreme protections it has value, the reality is that most hackers won't bother - they will move on to easier targets.

                          Those who would be willing to go to nearly any length are probably doing so because they Know it's value, and that value is greater than the cost of them getting the data.

                          How about the port forwarding a customer of mine had for RDP, FTP, SMTP, HTTP, and HTTPS to their exchange server? Sounds like an easy target.... Makes sense why I saw 10,000 sessions coming from Russia and Poland IP's through their router to the exchange server.

                          dafyreD 1 Reply Last reply Reply Quote 0
                          • dafyreD
                            dafyre @quicky2g
                            last edited by dafyre

                            @quicky2g said:

                            @Dashrender said:

                            @anonymous said:

                            The funny thing is someone would that it has value, because of all the work you put into protecting it 🙂

                            While some people might think that because of your extreme protections it has value, the reality is that most hackers won't bother - they will move on to easier targets.

                            Those who would be willing to go to nearly any length are probably doing so because they Know it's value, and that value is greater than the cost of them getting the data.

                            How about the port forwarding a customer of mine had for RDP, FTP, SMTP, HTTP, and HTTPS to their exchange server? Sounds like an easy target.... Makes sense why I saw 10,000 sessions coming from Russia and Poland IP's through their router to the exchange server.

                            cough it got hacked cough

                            1 Reply Last reply Reply Quote 2
                            • quicky2gQ
                              quicky2g @Alex Sage
                              last edited by quicky2g

                              @anonymous said:

                              @scottalanmiller said:

                              Well think about building a lab. You want a storage device, jump box and logging kind of at a minimum. That's three.

                              I don't have a storage device or logging yet. What do you recommend? And what do you mean by a storage device? Like for shared /home?

                              I do so much with syslog at home it's ridiculous. syslog-ng to MySQL database with custom written PHP front-end. Works like a charm. Have been using it for a few customers too. 0 cost to me or my company and way better than all those crappy Kiwi imitators logging to a flat text file with minimal searching. Try logging 10 ASA's to Kiwi for a week then searching for inbound/outbound connections for a single IP....not going to happen.

                              scottalanmillerS 1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @Alex Sage
                                last edited by

                                @anonymous said:

                                @dafyre How hard is it to install for a noob like me?

                                @Lakshmana set it up.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @quicky2g
                                  last edited by

                                  @quicky2g said:

                                  @anonymous said:

                                  @scottalanmiller said:

                                  Well think about building a lab. You want a storage device, jump box and logging kind of at a minimum. That's three.

                                  I don't have a storage device or logging yet. What do you recommend? And what do you mean by a storage device? Like for shared /home?

                                  I do so much with syslog at home it's ridiculous. syslog-ng to MySQL database with custom written PHP front-end. Works like a charm. Have been using it for a few customers too. 0 cost to me or my company and way better than all those crappy Kiwi imitators logging to a flat text file with minimal searching. Try logging 10 ASA's to Kiwi for a week then searching for inbound/outbound connections for a single IP....not going to happen.

                                  Yeah, can't imagine ever using Kiwi. What made you decide to not use ELK but to write something custom?

                                  quicky2gQ 1 Reply Last reply Reply Quote 0
                                  • quicky2gQ
                                    quicky2g @scottalanmiller
                                    last edited by

                                    @scottalanmiller said:

                                    @quicky2g said:

                                    @anonymous said:

                                    @scottalanmiller said:

                                    Well think about building a lab. You want a storage device, jump box and logging kind of at a minimum. That's three.

                                    I don't have a storage device or logging yet. What do you recommend? And what do you mean by a storage device? Like for shared /home?

                                    I do so much with syslog at home it's ridiculous. syslog-ng to MySQL database with custom written PHP front-end. Works like a charm. Have been using it for a few customers too. 0 cost to me or my company and way better than all those crappy Kiwi imitators logging to a flat text file with minimal searching. Try logging 10 ASA's to Kiwi for a week then searching for inbound/outbound connections for a single IP....not going to happen.

                                    Yeah, can't imagine ever using Kiwi. What made you decide to not use ELK but to write something custom?

                                    Never heard of ELK. Will have to check it out. Wrote the custom one a while ago and never found a reason to use anything else. Super lightweight and can export to Excel. Log analysis and visual stats would be nice though.

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @quicky2g
                                      last edited by

                                      @quicky2g http://mangolassi.it/topic/5364/showing-off-our-new-elk-install

                                      quicky2gQ 1 Reply Last reply Reply Quote 0
                                      • quicky2gQ
                                        quicky2g @scottalanmiller
                                        last edited by

                                        @scottalanmiller said:

                                        @quicky2g http://mangolassi.it/topic/5364/showing-off-our-new-elk-install

                                        Do you use the real-time dashboard from this guys article?

                                        http://operational.io/elk-for-network-operations/

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Not yet, ours is pretty basic right now, but going to be doing a lot more with it soon, hopefully.

                                          http://i.imgur.com/lydtCwn.png

                                          1 Reply Last reply Reply Quote 0
                                          • stacksofplatesS
                                            stacksofplates
                                            last edited by

                                            I'm currently installing mine again. I tried about 2 weeks ago and there were issues since they had just switched from the forwarder to filebeat.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post