Security

Free Security Training

20th September 2019

Wizer is offering free security training. Their videos are only a few minutes long and in an entertaining hand-drawn style. The site will also keep score if you need that…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

2FA Hardware Keys

16th September 2019

Hello All; I was curious about 2FA hardware keys popularized by Yubikey. Recently the FIDO standard has been published, which incentivizes cheaper hardware through competition. I purchased this Mini HyperFido…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Hackers mount attacks on Webmin servers, Pulse Secure, and Fortinet VPNs

27th August 2019

Fortinet Problems with SSL VPN which was fixed in May. Use IPSec VPN and set firewall and other security devices to auto-update. More info here

๐Ÿ“Œ
0๐Ÿ’ฌ read more

WPAD Disable

22nd August 2019

WPAD is an old method Windows uses to automatically configure a proxy server in a corporate environment. Recently it has been exploited to spy on traffic in-flight, it can bypass…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

PfSense/OpnSense Firewall Hardware

20th August 2019

NewEgg has Protectli hardware $250ca, fanless, 4x Gig eth ports, 0 Ram, 0 HDD. USB Wifi is an option. May have a free m.2 socket onboard. https://www.newegg.ca/p/2DS-001U-00002?Description=2%20nics&cm_re=2_nics–9SIA6XD5UV1629–Product Pfsense does sell…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Win7 Ext Support ends Jan2020

6th August 2019

Just a reminder that Windows 7 extended support ends January 2020. Micro$oft will not make software updates after that date. It will quickly accumulate security holes and every bad guy…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

VxWorks and Sonicwall woes

Armis has discovered 11 security vulnerabilities in VxWorks real-time operating system TCP stack. VxWorks powers many IoT devices as it requires minimal hardware but it also is the base for…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Why Cyber-Insurance Doesn’t Work

16th June 2019

As Ransomware become more prevalent, Insurance companies will add more requirements and stipulations for payout. If your company didn’t have the mitigations in place that they promised, there will be…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Secure Alternatives

14th June 2019

Here I explore some alternatives to Insecure social media. Social media makes their money from selling your browsing history and brand preferences. Some counties have restrictions that personal data needs…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Simple Security Tests

Some Simple Security Tests to get Small Businesses started Thycotic Weak Password finder; tests for LanMan, Weak hashes etc. and shows which of those accounts have Administrator privilege. https://thycotic.com/solutions/free-it-tools/weak-password-finder/ Wireshark…

๐Ÿ“Œ
0๐Ÿ’ฌ read more