ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. notverypunny
    3. Topics
    • Profile
    • Following 0
    • Followers 0
    • Topics 45
    • Posts 685
    • Groups 0

    Topics

    • notverypunnyN

      HelpWire: legit or no?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      4
      1 Votes
      4 Posts
      860 Views
      yar_with_helpwireY

      Thank you so much for considering giving HelpWire a try! We truly appreciate your interest. I'm here not to spam, but to address your concerns directly.

      Concerning the "too good to be true" perception, I understand that this often stems from privacy concerns related to using a free (and new) product. So, what's the catch, you might wonder?

      Initially, we launched HelpWire as a free service to establish a foothold in a market where competitors offer a broader range of features. That's the entire story.

      I assure you, we do not sell any private information to third parties to cover our expenses. Instead, HelpWire is supported by our parent company, Electronic Team, Inc., which has a range of successful products generating revenue to support HelpWire's post-launch phase.

      Will there be a paid tier in the future? Yes, but that's still a long way off. Even then, HelpWire will continue to offer a comprehensive set of features for free. Currently, every feature and functionality is available for extensive use, free of any limitations.

      I hope this clears up any concerns! If you have more questions or need further clarification, feel free to post them here (I'll keep an eye on this thread) or contact our support team at support(at)electronic(dot)us.

    • notverypunnyN

      GLPI: 9.5 to 10.0.5 | FusionInventory plugin to GLPI Inventory Plugin

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      1
      1 Votes
      1 Posts
      745 Views
      No one has replied
    • notverypunnyN

      FortiGate + PRTG

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      1
      0 Votes
      1 Posts
      250 Views
      No one has replied
    • notverypunnyN

      ASR Rules - Some won't apply

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      1
      1 Votes
      1 Posts
      194 Views
      No one has replied
    • notverypunnyN

      Self-Signed certs for LDAPS

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      2
      0 Votes
      2 Posts
      345 Views
      ObsolesceO

      @notverypunny said in Self-Signed certs for LDAPS:

      So I'll start off by acknowledging that self-signed certs are less than ideal for most purposes.

      Right now my goal is to get rid of plain-text LDAP on the network and want to make sure that I'm not trading one security hole for another.

      I've found a couple of sets of instructions online and figured I'd run the idea past the assembled brain-power before going too far down the rabbit hole.

      https://anandthearchitect.com/2019/10/10/active-directory-self-signed-certificate-for-ldaps/

      https://social.technet.microsoft.com/Forums/en-US/667ec29d-d83a-49b4-9280-308964359154/best-way-to-enable-ldaps-self-signed-certificate?forum=winserversecurity

      https://www.javaxt.com/wiki/Tutorials/Windows/How_to_Enable_LDAPS_in_Active_Directory

      Open to other suggestions to move from LDAP to LDAPS, but I'm in an environment that has too much legacy stuff to scrap it and / or AD so that whole possible course of action is the non-starter to end all non-starters.

      In an on-prem only AD environment, no problem using self signed.

    • notverypunnyN

      HAPPY SYSADMIN DAY 2022

      Watching Ignoring Scheduled Pinned Locked Moved Water Closet
      5
      2 Votes
      5 Posts
      597 Views
      ITivan80I

      I missed the memo on this 😂

    • notverypunnyN

      OT / IoT asset management

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      5
      1 Votes
      5 Posts
      532 Views
      1

      @notverypunny said in OT / IoT asset management:

      My main concern for the present effort is getting an accurate picture of what SCADA / OT etc devices we've got in the environment so that I know if action has to be taken or flagged to the appropriate controls group when vulnerabilities are flagged online.

      Sounds like your needs are primarily security centric.

      Give cyberx a look then. It's now called Microsoft Defender for IoT but it covers SCADA and other OT tech as well. https://azure.microsoft.com/en-us/services/iot-defender/#features

      I do have a lot of experience with documentation of these kinds of system in a variety of industries, like manufacturing industry, pulp and paper, chemical plants etc.

      In a lot of cases automatic discovery can be problematic and won't work.

      If you have a lot of control systems, most of the manufacturers will have tools that can keep track of their own devices. Especially when it comes to DCS systems that you'll find in larger installations.

      You will likely need some kind of hybrid approach.

    • notverypunnyN

      ZeroTier & Security

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      15
      1 Votes
      15 Posts
      1k Views
      S

      @pete-s said in ZeroTier & Security:

      @scottalanmiller said in ZeroTier & Security:

      @pete-s said in ZeroTier & Security:

      @notverypunny

      If you assume that being connected to an ZeroTier network is the same as having the host sitting directly on the internet, you'll be fine.

      That is the basic premise of the zero trust security model - assuming that the network is hostile.

      Ding ding, exactly. It's a connectivity tool, not a security tool. The security has to be provided normally. Any ZT provided security, is purely extra.

      Yes, and when it comes to security ZeroTier, as any other VPN, shows up as a virtual network adapter. So you can apply the OS' firewall like you could on any network adapter.

      And the ZeroTier network itself also has some limited L2 rules to control the traffic, similar to a switch. It lacks tcp sessions and other things though so it's not like a real router/firewall.

      There is also the possibility to connect ZeroTier to a compatible firewall and not the host directly.

      I'm running OPNSense at home and have the plugin working and connected to a client's PC's from my house.

      Works great.

    • notverypunnyN

      Chrome OS Flex

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      5
      0 Votes
      5 Posts
      428 Views
      jclambertJ

      @gjacobse It is not compatible. There was another project out there that was ARM compatible. I think it fizzled or was bought by Google several years ago now. Sigh

    • notverypunnyN

      TacticalRMM issue today, anyone else?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      5
      0 Votes
      5 Posts
      497 Views
      notverypunnyN

      @dustinb3403 said in TacticalRMM issue today, anyone else?:

      Sounds like you're using this in production, correct?

      Truth. It's not the only remote tool that we're using, but it's a nice backup / complement to our other options.

    • notverypunnyN

      Wazuh goes bork?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      1
      0 Votes
      1 Posts
      147 Views
      No one has replied
    • notverypunnyN

      TacticalRMM - Security

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion tacticalrmm security block public
      1
      3 Votes
      1 Posts
      402 Views
      No one has replied
    • notverypunnyN

      NG AV / Endpoint Protection in 2021

      Watching Ignoring Scheduled Pinned Locked Moved Unsolved IT Discussion
      56
      0 Votes
      56 Posts
      4k Views
      scottalanmillerS

      @hobbit666 said in NG AV / Endpoint Protection in 2021:

      So in simple terms, people are saying dump the AV products like Webroot/Bitdefender/Eset and move over to a more SIEM orientated setup whether that's in house or externally managed (we wouldn't have the resources internally)

      By and large, just dump them. If you need SIEM, that's a different discussion. But definitely dump those. ESET is outright evil, they are an active threat. We've had actual criminal activity from them. They are nothing like the others.

      Bitdefender and Webroot, they just don't add value over what is included, but do have some pretty significant negatives (not only cost.) Performance and, especially with Bitdefender, all kinds of application breakages.

      The upside to customers who keep installing Bitdefender against our advice... boy does it rack up the billable hours to fix issues that it introduces.

    • notverypunnyN

      Wazuh Windows Folder Access Monitoring

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion wazuh
      1
      1 Votes
      1 Posts
      556 Views
      No one has replied
    • notverypunnyN

      Wazuh Setup

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      6
      0 Votes
      6 Posts
      522 Views
      scottalanmillerS

      @notverypunny said in Wazuh Setup:

      @scottalanmiller said in Wazuh Setup:

      ElasticSearch is no longer open. I won't touch them. Look at OpenSearch now instead.

      Looks like they're already using elasticsearch-oss and opendistroforelasticsearch instead of the closed source stuff. https://documentation.wazuh.com/current/installation-guide/open-distro/distributed-deployment/step-by-step-installation/elasticsearch-cluster/elasticsearch-single-node-cluster.html#elasticsearch-single-node-cluster

      That's good.

    • notverypunnyN

      FortiMail 7.0

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      4
      0 Votes
      4 Posts
      311 Views
      scottalanmillerS

      @notverypunny said in FortiMail 7.0:

      Damn, nobody else on here uses these guys?

      Nope, why would we? LOL I don't know anyone much running in house email anymore. Those that do just use a mail filtering service, not an appliance. This is a device for a very different era. Not the kind of thing you'd expect to see still deployed.

    • notverypunnyN

      FIM, FAAM, details & False Positives

      Watching Ignoring Scheduled Pinned Locked Moved Unsolved IT Discussion
      5
      1 Votes
      5 Posts
      353 Views
      scottalanmillerS

      @notverypunny said in FIM, FAAM, details & False Positives:

      The only commercial product that I've seen that discusses or seems to leverage this is Rapid7's InsightIDR.

      Keep in mind that Greylog is a commercial product and is not open source. It used to be open source, now it is not. They claim to be, but they don't qualify.

    • notverypunnyN

      Docushare: any experts here?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      4
      1 Votes
      4 Posts
      244 Views
      notverypunnyN

      f3ab13d3-c5d6-4e2d-802e-13e119a26dfe-image.png

    • notverypunnyN

      Discovery of the week

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      4
      2 Votes
      4 Posts
      585 Views
      coliverC

      @notverypunny said in Discovery of the week:

      @coliver said in Discovery of the week:

      @notverypunny said in Discovery of the week:

      If anyone else needs something for IPAM / network documentation I've just fallen in love with phpipam (https://phpipam.net/)

      I'd tried netbox in the past but this just seems to work better for me. You can also set up polling / discovery of the configured ranges (on a per-range basis) either from the central server or from remote agents.

      Anyways, it's rare that I'll advocate for something out of the blue, but I'm almost enjoying moving our horrible excel spreadsheet documentation over to this.

      Happy Friday all 🙂

      Yeah, we've been using it for a year or more. It has a nice API that @stacksofplates helped me dig into to automate DHCP reservations.

      That sounds sexy.... windows server DHCP or something else?

      dhcpd. The developers are working on built in Kea integration, although that's been on the table for a while.

    • notverypunnyN

      RDP Security / Hardening

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion
      7
      0 Votes
      7 Posts
      443 Views
      IRJI

      @scottalanmiller said in RDP Security / Hardening:

      Let's start with understanding the need. Why is RDP open at all? Is it only open to the LAN, or is it open to the world?

      Yeah that is a much bigger concern than simultaneous connections.

    • 1
    • 2
    • 3
    • 1 / 3