ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. security
    Log in to post
    • All categories
    • dave247D

      Considering moving from SonicWall to Sophos XG (Looking for feedback on Sophos)

      IT Discussion
      • utm sonicwall sophos sophos xg networking security firewall • • dave247
      12
      2
      Votes
      12
      Posts
      1.5k
      Views

      scottalanmillerS

      Something to keep in mind is NGFW. Ubiquiti and Meraki, for example, are NGFW.

      It looks like much of the market is already starting to cool on the UTM crazy and NGFW is taking off as the "next stage" of popular approaches. Basically a reversal of direction or marketing at least, even from the big players in the UTM space like Palo Alto, Fortinet, Cisco, etc.

    • gjacobseG

      Security while Traveling -

      IT Discussion
      • firewall security securityawarenesstraining security while travelling linux linux mint fedora ubuntu • • gjacobse
      20
      0
      Votes
      20
      Posts
      1.9k
      Views

      scottalanmillerS

      @gjacobse said in Security while Traveling -:

      Could something like this or similar be supplemental?

      Seems pretty silly.

      So here is the question....

      What threat do you perceive there being? How do you feel this device addresses that thread?

      I don't really see any threat in the first place, and so that makes it extra hard to know how to assuage your fears. But how this device is supposed to help, I'm really unsure.

    • PhlipElderP

      D-Link DWR Series Vulnerability - Trivial Total Takeover

      IT Discussion
      • d-link security vulnerability d-link dwr router networking • • PhlipElder
      2
      1
      Votes
      2
      Posts
      495
      Views

      scottalanmillerS

      Only so serious, it's in D-Link gear. Bwahaha

    • mlnewsM

      Hackers breach US defense department travel records

      News
      • security breach dw • • mlnews
      1
      1
      Votes
      1
      Posts
      355
      Views

      No one has replied

    • EddieJenningsE

      Strange PBX CDR Entries

      IT Discussion
      • freepbx 14 security sip • • EddieJennings
      4
      0
      Votes
      4
      Posts
      632
      Views

      JaredBuschJ

      @eddiejennings said in Strange PBX CDR Entries:

      I've disallowed SIP guests. We'll see if I get future CDR entries like these.

      You won't.

    • EddieJenningsE

      Remote management of VMs hosted in colocation

      IT Discussion
      • remote management remote access virtualization colocation security • • EddieJennings
      40
      1
      Votes
      40
      Posts
      2.8k
      Views

      scottalanmillerS

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @dashrender said in Remote management of VMs hosted in colocation:

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @scottalanmiller said in Remote management of VMs hosted in colocation:

      @stacksofplates said in Remote management of VMs hosted in colocation:

      @scottalanmiller said in Remote management of VMs hosted in colocation:

      @eddiejennings said in Remote management of VMs hosted in colocation:

      Allowing an SSH connection to the managementVM from the Internet

      I have not tried this approach yet, and it appears more risky than the Screen Connect approach, since SSH to that VM would be open to the Internet. Unless I'm missing some benefit to this approach, I'll not be using it.

      Use a strong key, lock to your IP. Very safe. Add Fail2Ban, of course.

      Or add Salt and open/close based on need so it doesn't stay open.

      Fail2ban doesn't work with keys.

      But it would work normally with people attacking using non-keys, would it not? Or am I missing something about what it would do?

      Why would you not require keys? Not making them mandatory defeats the purpose of using them.

      I think he means - if a hacker is trying to use a password on a system setup to only allow keys - the fail2ban will block those users, or won't it?

      No. It's dropped before fail2ban even sees it.

      Oh, makes sense. There is no "attempt" like with a password, it is "already blocked."

    • 1

      SANS SEC401: Security Essentials - alternatives?

      IT Discussion
      • sans security • • 1337
      11
      1
      Votes
      11
      Posts
      1.9k
      Views

      IRJI

      @pete-s said in SANS SEC401: Security Essentials - alternatives?:

      @irj said in SANS SEC401: Security Essentials - alternatives?:

      @pete-s said in SANS SEC401: Security Essentials - alternatives?:

      @irj said in SANS SEC401: Security Essentials - alternatives?:

      I am curious to what SANS training costs?

      Around $6000 for the training.

      So after travel, etc, it is over budget?

      Well, since I'm in Europe it's makes sense to take the training here. With flights, travel costs, hotel, etc the total will be about 8250 EUR, which is $9650. Add to that the loss of billable hours and it adds up.

      Most of your standard cert training is like $3000 ,but most of the time it is just a bootcamp which really isnt what you want. I think you are going to be at that $5-6k range for the type of training you are looking at.

      I recently attended an O365 workshop that was $4k for 3 days and it was an absolute joke. Alot of time your training, is only as good as your instructor.

    • DustinB3403D

      Yealink Device Management Platform - Stores User Credentials in Plain-Text

      IT Discussion
      • yealink security blunder local on-premise security password privacy hell no ffs • • DustinB3403
      15
      0
      Votes
      15
      Posts
      1.6k
      Views

      DustinB3403D

      So this has been changed in their newest release 2.0.0.25 (not sure if it's publically available), and while the credentials are no longer in plain-text there are a few things you lose the ability to do.

      Namely to tell if any given used is logged into a device, and secondly to sign in/out as a user on any given device.

      I've provided my feedback to Yealink and hope to hear back soon. Neither of the above 2 issues are deal breakers, as the bigger goal is to be able to set configuration options, screensavers, time servers etc and have the user deal with the login.

      Especially since the "Web Sign in" functionality is so simple, there is little reason to need the ability to sign in for a user.

    • scottalanmillerS

      Microsoft Volume License Center Phishing Email from Insight Direct

      IT Discussion
      • security phishing scam spam licensing • • scottalanmiller
      32
      0
      Votes
      32
      Posts
      2.9k
      Views

      scottalanmillerS

      If you ever need to report a Microsoft partner for ethics breaches, you can email [email protected]

    • scottalanmillerS

      CredSSP and RDP in Windows 10

      IT Discussion
      • rdp windows 10 windows server credssp security oracle • • scottalanmiller
      19
      3
      Votes
      19
      Posts
      8.7k
      Views

      scottalanmillerS

      This might be useful for some people:

      https://mangolassi.it/topic/17197/disable-network-level-authentication-or-nla-remotely-via-powershell

    • nadnerBN

      Change your Twitter password

      News
      • twitter security password reset password • • nadnerB
      2
      4
      Votes
      2
      Posts
      759
      Views

      JaredBuschJ

      Changed, though I already had login verification setup so no way someone else would get in easily.
      0_1525401327754_d65c3f50-c905-47c5-b2b5-903e8bb692f5-image.png

    • mlnewsM

      Drupalgeddon2 Kicks Off

      News
      • drupal security content management system cms drupalgeddon ars technica • • mlnews
      8
      2
      Votes
      8
      Posts
      1.4k
      Views

      dbeatoD

      @dafyre said in Drupalgeddon2 Kicks Off:

      @dbeato said in Drupalgeddon2 Kicks Off:

      @dafyre said in Drupalgeddon2 Kicks Off:

      Has everybody else already patched their Drupal setups?

      Well, a new customer we needed to patch it 😞

      Hopefully it has been patched before they got pwned.

      Yeah hopefully .

    • mlnewsM

      Ripple Effect in Cambridge Analytica Privacy Scandal

      News
      • facebook privacy security cambridge analytica • • mlnews
      1
      2
      Votes
      1
      Posts
      613
      Views

      No one has replied

    • mlnewsM

      Cambridge Analytica May Have Had Access to Private Messages

      News
      • facebook security privacy cambridge analytica • • mlnews
      1
      0
      Votes
      1
      Posts
      593
      Views

      No one has replied

    • AdamFA

      IIS Security setup

      IT Discussion
      • iis powershell security ssl • • AdamF
      17
      0
      Votes
      17
      Posts
      2.5k
      Views

      AdamFA

      @psx_defector said in IIS Security setup:

      Best practice isn't up to date.

      Set it to PCI 1.2, that disables TLS1.0, all the AES stuff, etc. etc. You can also disable them manually in the first screen.

      Great, thanks.

    • mlnewsM

      Facebook Talked to Hospitals About Merging Anonymous User Profiles with Health Data Last Year

      News
      • facebook hipaa security privacy • • mlnews
      5
      1
      Votes
      5
      Posts
      954
      Views

      mlnewsM

      http://www.tomshardware.com/news/facebook-match-patient-data-profiles,36839.html#xtor=RSS-181

    • mlnewsM

      Delta Airlines and Sears Have Large Credit Card Breach Through Third Party Shared Service Firm

      News
      • security breach sears delta • • mlnews
      5
      2
      Votes
      5
      Posts
      926
      Views

      JaredBuschJ

      @aaronstuder said in Delta Airlines and Sears Have Large Credit Card Breach Through Third Party Shared Service Firm:

      @harry-lui It is accepted everywhere...

      Not true.

    • mlnewsM

      Facebook Refuses to Release Election Interference Information Until After Election

      News
      • facebook privacy democracy security • • mlnews
      1
      1
      Votes
      1
      Posts
      531
      Views

      No one has replied

    • mlnewsM

      In a Bid to Trick the US Judicial System, CenturyLink Claims to Not Have Customers

      News
      • centurylink isp security • • mlnews
      2
      3
      Votes
      2
      Posts
      733
      Views

      JaredBuschJ

      That is just funny to read.

    • mlnewsM

      Facebook and Cambridge Analytica: Everything We Know So Far

      News
      • facebook security privacy cambridge analytica toms hardware • • mlnews
      4
      2
      Votes
      4
      Posts
      771
      Views

      coliverC

      https://arstechnica.com/tech-policy/2018/04/facebook-now-says-87-million-people-affected-by-cambridge-analytica-breach/#p3

      Could be closer to 87M users. Wow.

    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 7
    • 8
    • 31
    • 32
    • 6 / 32