ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. security
    Log in to post
    • All categories
    • scottalanmillerS

      Security Theater Expained

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion security security theater
      3
      3 Votes
      3 Posts
      413 Views
      DonahueD

      haha

    • dave247D

      Considering moving from SonicWall to Sophos XG (Looking for feedback on Sophos)

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion utm sonicwall sophos sophos xg networking security firewall
      12
      2 Votes
      12 Posts
      2k Views
      scottalanmillerS

      Something to keep in mind is NGFW. Ubiquiti and Meraki, for example, are NGFW.

      It looks like much of the market is already starting to cool on the UTM crazy and NGFW is taking off as the "next stage" of popular approaches. Basically a reversal of direction or marketing at least, even from the big players in the UTM space like Palo Alto, Fortinet, Cisco, etc.

    • gjacobseG

      Security while Traveling -

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion firewall security securityawarenesstraining security while travelling linux linux mint fedora ubuntu
      20
      0 Votes
      20 Posts
      2k Views
      scottalanmillerS

      @gjacobse said in Security while Traveling -:

      Could something like this or similar be supplemental?

      Seems pretty silly.

      So here is the question....

      What threat do you perceive there being? How do you feel this device addresses that thread?

      I don't really see any threat in the first place, and so that makes it extra hard to know how to assuage your fears. But how this device is supposed to help, I'm really unsure.

    • PhlipElderP

      D-Link DWR Series Vulnerability - Trivial Total Takeover

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion d-link security vulnerability d-link dwr router networking
      2
      1 Votes
      2 Posts
      518 Views
      scottalanmillerS

      Only so serious, it's in D-Link gear. Bwahaha

    • mlnewsM

      Hackers breach US defense department travel records

      Watching Ignoring Scheduled Pinned Locked Moved News security breach dw
      1
      1 Votes
      1 Posts
      376 Views
      No one has replied
    • EddieJenningsE

      Strange PBX CDR Entries

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion freepbx 14 security sip
      4
      0 Votes
      4 Posts
      668 Views
      JaredBuschJ

      @eddiejennings said in Strange PBX CDR Entries:

      I've disallowed SIP guests. We'll see if I get future CDR entries like these.

      You won't.

    • EddieJenningsE

      Remote management of VMs hosted in colocation

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion remote management remote access virtualization colocation security
      40
      1 Votes
      40 Posts
      4k Views
      scottalanmillerS

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @dashrender said in Remote management of VMs hosted in colocation:

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @scottalanmiller said in Remote management of VMs hosted in colocation:

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @scottalanmiller said in Remote management of VMs hosted in colocation:

      @eddiejennings said in Remote management of VMs hosted in colocation:

      Allowing an SSH connection to the managementVM from the Internet

      I have not tried this approach yet, and it appears more risky than the Screen Connect approach, since SSH to that VM would be open to the Internet. Unless I'm missing some benefit to this approach, I'll not be using it.

      Use a strong key, lock to your IP. Very safe. Add Fail2Ban, of course.

      Or add Salt and open/close based on need so it doesn't stay open.

      Fail2ban doesn't work with keys.

      But it would work normally with people attacking using non-keys, would it not? Or am I missing something about what it would do?

      Why would you not require keys? Not making them mandatory defeats the purpose of using them.

      I think he means - if a hacker is trying to use a password on a system setup to only allow keys - the fail2ban will block those users, or won't it?

      No. It's dropped before fail2ban even sees it.

      Oh, makes sense. There is no "attempt" like with a password, it is "already blocked."

    • 1

      SANS SEC401: Security Essentials - alternatives?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion sans security
      11
      1 Votes
      11 Posts
      2k Views
      IRJI

      @pete-s said in SANS SEC401: Security Essentials - alternatives?:

      @irj said in SANS SEC401: Security Essentials - alternatives?:

      @pete-s said in SANS SEC401: Security Essentials - alternatives?:

      @irj said in SANS SEC401: Security Essentials - alternatives?:

      I am curious to what SANS training costs?

      Around $6000 for the training.

      So after travel, etc, it is over budget?

      Well, since I'm in Europe it's makes sense to take the training here. With flights, travel costs, hotel, etc the total will be about 8250 EUR, which is $9650. Add to that the loss of billable hours and it adds up.

      Most of your standard cert training is like $3000 ,but most of the time it is just a bootcamp which really isnt what you want. I think you are going to be at that $5-6k range for the type of training you are looking at.

      I recently attended an O365 workshop that was $4k for 3 days and it was an absolute joke. Alot of time your training, is only as good as your instructor.

    • DustinB3403D

      Yealink Device Management Platform - Stores User Credentials in Plain-Text

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion yealink security blunder local on-premise security password privacy hell no ffs
      15
      0 Votes
      15 Posts
      2k Views
      DustinB3403D

      So this has been changed in their newest release 2.0.0.25 (not sure if it's publically available), and while the credentials are no longer in plain-text there are a few things you lose the ability to do.

      Namely to tell if any given used is logged into a device, and secondly to sign in/out as a user on any given device.

      I've provided my feedback to Yealink and hope to hear back soon. Neither of the above 2 issues are deal breakers, as the bigger goal is to be able to set configuration options, screensavers, time servers etc and have the user deal with the login.

      Especially since the "Web Sign in" functionality is so simple, there is little reason to need the ability to sign in for a user.

    • scottalanmillerS

      Microsoft Volume License Center Phishing Email from Insight Direct

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion security phishing scam spam licensing
      32
      0 Votes
      32 Posts
      4k Views
      scottalanmillerS

      If you ever need to report a Microsoft partner for ethics breaches, you can email [email protected]

    • scottalanmillerS

      CredSSP and RDP in Windows 10

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion rdp windows 10 windows server credssp security oracle
      19
      3 Votes
      19 Posts
      9k Views
      scottalanmillerS

      This might be useful for some people:

      https://mangolassi.it/topic/17197/disable-network-level-authentication-or-nla-remotely-via-powershell

    • nadnerBN

      Change your Twitter password

      Watching Ignoring Scheduled Pinned Locked Moved News twitter security password reset password
      2
      4 Votes
      2 Posts
      785 Views
      JaredBuschJ

      Changed, though I already had login verification setup so no way someone else would get in easily.
      0_1525401327754_d65c3f50-c905-47c5-b2b5-903e8bb692f5-image.png

    • mlnewsM

      Drupalgeddon2 Kicks Off

      Watching Ignoring Scheduled Pinned Locked Moved News drupal security content management system cms drupalgeddon ars technica
      8
      2 Votes
      8 Posts
      1k Views
      dbeatoD

      @dafyre said in Drupalgeddon2 Kicks Off:

      @dbeato said in Drupalgeddon2 Kicks Off:

      @dafyre said in Drupalgeddon2 Kicks Off:

      Has everybody else already patched their Drupal setups?

      Well, a new customer we needed to patch it 😞

      Hopefully it has been patched before they got pwned.

      Yeah hopefully .

    • mlnewsM

      Ripple Effect in Cambridge Analytica Privacy Scandal

      Watching Ignoring Scheduled Pinned Locked Moved News facebook privacy security cambridge analytica
      1
      2 Votes
      1 Posts
      627 Views
      No one has replied
    • mlnewsM

      Cambridge Analytica May Have Had Access to Private Messages

      Watching Ignoring Scheduled Pinned Locked Moved News facebook security privacy cambridge analytica
      1
      0 Votes
      1 Posts
      608 Views
      No one has replied
    • AdamFA

      IIS Security setup

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion iis powershell security ssl
      17
      0 Votes
      17 Posts
      3k Views
      AdamFA

      @psx_defector said in IIS Security setup:

      Best practice isn't up to date.

      Set it to PCI 1.2, that disables TLS1.0, all the AES stuff, etc. etc. You can also disable them manually in the first screen.

      Great, thanks.

    • mlnewsM

      Facebook Talked to Hospitals About Merging Anonymous User Profiles with Health Data Last Year

      Watching Ignoring Scheduled Pinned Locked Moved News facebook hipaa security privacy
      5
      1 Votes
      5 Posts
      1k Views
      mlnewsM

      http://www.tomshardware.com/news/facebook-match-patient-data-profiles,36839.html#xtor=RSS-181

    • mlnewsM

      Delta Airlines and Sears Have Large Credit Card Breach Through Third Party Shared Service Firm

      Watching Ignoring Scheduled Pinned Locked Moved News security breach sears delta
      5
      2 Votes
      5 Posts
      967 Views
      JaredBuschJ

      @aaronstuder said in Delta Airlines and Sears Have Large Credit Card Breach Through Third Party Shared Service Firm:

      @harry-lui It is accepted everywhere...

      Not true.

    • mlnewsM

      Facebook Refuses to Release Election Interference Information Until After Election

      Watching Ignoring Scheduled Pinned Locked Moved News facebook privacy democracy security
      1
      1 Votes
      1 Posts
      554 Views
      No one has replied
    • mlnewsM

      In a Bid to Trick the US Judicial System, CenturyLink Claims to Not Have Customers

      Watching Ignoring Scheduled Pinned Locked Moved News centurylink isp security
      2
      3 Votes
      2 Posts
      763 Views
      JaredBuschJ

      That is just funny to read.

    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 7
    • 8
    • 31
    • 32
    • 6 / 32