Blog: ittavern.com Feedback is appreciated
Learning things about Wireguard and implement it to secure my internet facing servers.
Yeah, after more testing, we can say that the second IPStunnel was the issue. Re-worked the route over a single tunnel and the whole 100 Mbps are available again. Users are happy, I am happy. Even tho a little bit frustrating.
Thank you for your input!
Ping - Update 2 @Avian_Carrier@infosec.pub @jharrison@infosec.pub @SgtKetchup@infosec.pub
Ping - Update 3 @Avian_Carrier@infosec.pub @jharrison@infosec.pub @SgtKetchup@infosec.pub
Yeah, notifications are really unreliable here. I’ve got another window for more stress test today. Going to post update later, or tomorrow. Focus on MTU/MSS
The ISPs are slow to answer if there is no active outage. Will take some time anyway.
Packets are dropped in bot directions. I am currently looking through the pcaps and will do another stress test later - got another window. MTU/MSS is the prio today.
Good points and thank you for your input. What kind of TaskManager do you use? Any system, or just simple list?
Do you know https://logseq.com/ ? - I think it is considered an alternative to Obisidian. Had been using it for a while, was great, but it was almost too much work to organize everything.
Haven’t found my perfect solution. The current goal is get everything together and see what I really need. Most likely a single .md file that I can encrypt and sync in my machines, but not sure yet.
I am currently trying to organize my notes. The old ‘system’ is a pain, and getting everything centralized makes it easier to find things. Notes, snippets, bookmarks, and so on.
Thank you for the AMA.
Do you regularly feel overwhelmed? - Keeping up with the sec news and patch accordingly, firewall/ips and endpoint alarms, logs, meetings, and more. It shouldn’t be the case, but it seems that everything in security is prio 1.
EDIT: and being the party pooper and saying no to everything, bc people do not think about security.
Added the Update 2. Still some things to do, but we know a little bit more now. Feedback and questions are still welcome.
Ping - Update 2 Your numbers are are still missing since I havent had time to look into the pcaps yet. I hope I can get it done by the end of the week, but we are a little bit wiser.
Ping - Update 2
Ping - Update 2 @Avian_Carrier@infosec.pub @jharrison@infosec.pub @SgtKetchup@infosec.pub
I hope it is ok to ping you.
Thank you!
Thank you!
I am hosting multiple services, but my application/web security knowledge is lacking. Is there a guide or framework to check for common or risky mistakes? Is there a list of things I should check every application for, or guide on how to harden hosted applications? That is a topic that I am going to tackle in the near future, and would appreciate some tips in advance.
Thank you Jerry!
Not yet. Just got access to the test clients and I have planned to do a troubleshooting session tomorrow in the morning. Not a big fan of stress testing the network on a working day haha
So, let’s assume that you are in an international company and the first and only security person. What are your first steps and projects? It is like really vague, but I’d assume like a SIEM, inventory of the network and all devices, backup situation, maybe even honeypots?
What are your high-prio things that every company should have? Is there even a framework for it?
Feeling kinda lost and I hope you get some guidance in the right direction.