Security

Hackers mount attacks on Webmin servers, Pulse Secure, and Fortinet VPNs

27th August 2019

Fortinet Problems with SSL VPN which was fixed in May. Use IPSec VPN and set firewall and other security devices to auto-update. More info here

๐Ÿ“Œ
0๐Ÿ’ฌ read more

WPAD Disable

22nd August 2019

WPAD is an old method Windows uses to automatically configure a proxy server in a corporate environment. Recently it has been exploited to spy on traffic in-flight, it can bypass…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

PfSense/OpnSense Firewall Hardware

20th August 2019

NewEgg has Protectli hardware $250ca, fanless, 4x Gig eth ports, 0 Ram, 0 HDD. USB Wifi is an option. May have a free m.2 socket onboard. https://www.newegg.ca/p/2DS-001U-00002?Description=2%20nics&cm_re=2_nics–9SIA6XD5UV1629–Product Pfsense does sell…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Win7 Ext Support ends Jan2020

6th August 2019

Just a reminder that Windows 7 extended support ends January 2020. Micro$oft will not make software updates after that date. It will quickly accumulate security holes and every bad guy…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

VxWorks and Sonicwall woes

Armis has discovered 11 security vulnerabilities in VxWorks real-time operating system TCP stack. VxWorks powers many IoT devices as it requires minimal hardware but it also is the base for…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Why Cyber-Insurance Doesn’t Work

16th June 2019

As Ransomware become more prevalent, Insurance companies will add more requirements and stipulations for payout. If your company didn’t have the mitigations in place that they promised, there will be…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Secure Alternatives

14th June 2019

Here I explore some alternatives to Insecure social media. Social media makes their money from selling your browsing history and brand preferences. Some counties have restrictions that personal data needs…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Simple Security Tests

Some Simple Security Tests to get Small Businesses started Thycotic Weak Password finder; tests for LanMan, Weak hashes etc. and shows which of those accounts have Administrator privilege. https://thycotic.com/solutions/free-it-tools/weak-password-finder/ Wireshark…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Increase Your Personal Security

It’s Tricky Tricking people is much easier than actual hacking, security professionals like to call this Social Engineering. Their best trick is to convince websites or companies to reset your…

๐Ÿ“Œ
0๐Ÿ’ฌ read more

Security Via DNS

Article DNS security filtering Quad9 is a free offering from an IBM led group of security organizations. OpenDNS made this type of service popular and Quad9 builds on that by…

๐Ÿ“Œ
0๐Ÿ’ฌ read more