Uncategorised

GeoFirewall for RDP

What? A Geography based firewall blocks access to/from entire countries. Why? Useful on a RDP server to reduce risk by ignoring entire chunks of the internet. (RDP has been targeted recently with wormable exploits) Verigio makes a cool little software firewall, that is super simple and free. (free for 5 areas or less, still waiting …

GeoFirewall for RDP Read More »

2FA Hardware Keys

Hello All; I was curious about 2FA hardware keys popularized by Yubikey. Recently the FIDO standard has been published, which incentivizes cheaper hardware through competition. I purchased this Mini HyperFido key to use for my testing. The unit came with ZERO documentation so I am creating a document here. Setup for Gmail: If your FidoKey …

2FA Hardware Keys Read More »

OpenVas on RasPi

What? OpenVas is a network vulnerability scanner that is free. It is a fork of the last free version of Nessus. It can automatically scan your entire network and give a lovely report of vulnerabilites found and suggested fixes. GreenBone makes this easy via a Web Gui. Why? OpenVas could be installed as a virtual …

OpenVas on RasPi Read More »

Non-Domain Networks

I support some schools and small businesses without Windows domains. If cost is an issue i would normally recommend a Synology NAS as a domain controller. https://www.youtube.com/watch?v=rNRtOTNfjnk Generic Troubleshooting: -Make sure the windows firewall is OFF on the PC you are trying to get to, firewall setting on the local PC doesn’t matter. There are …

Non-Domain Networks Read More »

School Environment

I have been working on a private school project, I haven’t finalized any solutions yet but i hope my notes will guide others in similar predicaments. Server: A Synology NAS makes a good turn-key file server that is easy to use, supports add-in software, supports cloud sync. Alternates are OpenMediaVault running on Rock64, NextCloud running …

School Environment Read More »

WPAD Disable

WPAD is an old method Windows uses to automatically configure a proxy server in a corporate environment. Recently it has been exploited to spy on traffic in-flight, it can bypass encryption. I recommend disabling it on your personal computer. If you are concerned about a work computer you might just forward this article to your …

WPAD Disable Read More »

Disk Space Cleanup

Empty recycle bin, after backup of course Verify De-duplication stats; PowerShell as AdminGet-DedupStatus c: | flpay attention to LastOptimizationTime : 5/13/2020 12:45:07 PM Manually run the Deduplication garbage collection in case the scheduled task has stopped: Start-DedupJob -Type GarbageCollection -Priority High -Volume “c:” Get-DedupJob -Volume “c:” Download Mass Image Compressor (req DotNet) and run it. …

Disk Space Cleanup Read More »