Wed, 16 Dec 2020 00:48:03 +0100
What happens when you loose your red team tools
#^fireeye/red_team_tool_countermeasures

#^fireeye/red_team_tool_countermeasures
FireEye Red Team Tool Countermeasures
These rules are provided freely to the community without warranty.
In this GitHub repository you will find rules in multiple languages:
* Snort
* Yara
* ClamAV
* HXIOC
authsch
Mon, 09 Nov 2020 14:48:00 +0100
Oh Jenkins
#^Jenkins Security Advisory 2020-11-04


#^Jenkins Security Advisory 2020-11-04
This advisory announces vulnerabilities in the following Jenkins deliverables:
* Active Directory Plugin
...

Login allowed with hardcoded password by Active Directory Plugin
Login allowed with empty password by Active Directory Plugin
Authentication cache in Active Directory Plugin allows logging in with any password
Missing permission check in Active Directory Plugin allows accessing domain health check page
CSRF vulnerability in Active Directory Plugin
Dieting
Thu, 24 Sep 2020 17:56:50 +0200
#^DockerSlim - Lean and mean Docker containers. Smaller, faster, more secure and frictionless!


Optimize Your Docker Containers.
Don't change anything in your Docker container image and minify it by up to 30x making it secure too! Optimizing images isn't the only thing it can do though. It can also help you understand and author better container images.
Keep doing what you are doing. No need to change anything. Use the base image you want. Use the package manager you want. Don't worry about hand optimizing your Dockerfile. You shouldn't have to throw away your tools and your workflow to have small container images.
Don't worry about manually creating Seccomp and AppArmor security profiles. You shouldn't have to become an expert in Linux syscalls, Seccomp and AppArmor to have secure containers. Even if you do know enough about it wasting time reverse engineering your application behavior can be time-consuming.
docker-slim will optimize and secure your containers by understanding your application and what it needs using various analysis techniques. It will throw away what you don't need, reducing the attack surface of your container. What if you need some of those extra things to debug your container? You can use dedicated debugging side-car containers for that (more details below).
IT-Mitarbeiter
Sat, 05 Sep 2020 01:50:49 +0200
#^Schleppende Digitalisierung - Schulen brauchen IT-Mitarbeiter | Deutschlandfunk


Schul-IT ist eine komplexe Aufgabe. Derzeit übernehmen diese oft Lehrkräfte nebenher - ein Grund, warum der digitale Unterricht nicht vom Fleck kommt. Gebraucht werden Mitarbeiter, die sich Vollzeit um die IT kümmern. Denkbar sind auch IT-Abteilungen, die für mehrere Schulen zuständig sind.
VAMT
Tue, 25 Aug 2020 20:42:29 +0200
We used a local KMS for M$ Windows Enterprise volume activation. Unfortunately we do not fulfil the required activation thresholds anymore, so we had to switch to MAK activation.
I discovered VAMT from the Windows ADK tools. That is a really handy tool. Overview over your keys and easy mass key changes and activation for all your computers.
#^Use the Volume Activation Management Tool (Windows 10) - Windows Deployment
Well... like most of the time with Micro$oft it sounds nice and good, until you start using it and reach disillusion.
I discovered VAMT from the Windows ADK tools. That is a really handy tool. Overview over your keys and easy mass key changes and activation for all your computers.
#^Use the Volume Activation Management Tool (Windows 10) - Windows Deployment
The Volume Activation Management Tool (VAMT) provides several useful features, including the ability to track and monitor several types of product keys.
Well... like most of the time with Micro$oft it sounds nice and good, until you start using it and reach disillusion.

Klimablase
Bonn, Germany, Mon, 10 Aug 2020 21:33:22 +0200
Bah ist das heute ekelhaft wenn man wieder aus dem Serverraum kommt.
Bonn, Germany, Fri, 17 Apr 2020 01:11:05 +0200
There was an interesting talk at Bonn Security Nights last evening.
It is not available (yet?) but the topics have been amongst others:
#^The Web Infrastructure Model (WIM) | Institute of Information Security | University of Stuttgart
#^New OAuth Security Recommendations - danielfett.de
It is not available (yet?) but the topics have been amongst others:
#^The Web Infrastructure Model (WIM) | Institute of Information Security | University of Stuttgart
The most comprehensive, expressive and precise model of the web infrastructure to date.
#^New OAuth Security Recommendations - danielfett.de
The OAuth Security BCP contains a number of new and updated recommendations on the usage of OAuth 2.0. I recommend reading the whole document to understand the threats and attacks that lead to these guidelines. As a quick reference, the following table shows an overview of the most important new recommendations:
This list is based on version -12 of the draft and will be updated in the future.
Kubernetes Managed Container Plattform
Mon, 06 Apr 2020 18:47:54 +0200
Ziemlich interessantes Angebot. Leider nur B2B und nicht für mein privates Hosting-Dilemma.
#^Kubernetes - Managed Container Plattform | NETWAYS Web Services
#K8s
#^Kubernetes - Managed Container Plattform | NETWAYS Web Services
Maßgeschneiderte Container Plattform basierend auf Kubernetes. Bei Bedarf administriert durch MyEngineer. Bezahlung nach Nutzung und in wenigen Minuten bereit.
#K8s
msodbcsql17 Buster
Fri, 21 Feb 2020 19:26:12 +0100
After a recent php:7.3-apache Docker image rebuild we were not able to connect to the M$SQL server anymore from our PHP application inside the docker container. Seems to be related with the Debian 9 (Stretch) --> Debian 10 (Buster) update of the official PHP base image.
The error message with the new container was:
Too lazy to find a proper solution right now, but a quick fix is to add following code to our Dockerfile:
Another lessons learned is to use the right base image tag e.g.: php:7.3-apache-stretch
The error message with the new container was:
[Microsoft][ODBC Driver 17 for SQL Server]TCP Provider: Error code 0x2746
[Microsoft][ODBC Driver 17 for SQL Server]Client unable to establish connection
Too lazy to find a proper solution right now, but a quick fix is to add following code to our Dockerfile:
RUN sed -i 's/SECLEVEL=2/SECLEVEL=1/g' /etc/ssl/openssl.cnf
Another lessons learned is to use the right base image tag e.g.: php:7.3-apache-stretch
lightmeter
Fri, 31 Jan 2020 17:38:00 +0100
#^Lightmeter
Funny project. If you look at the code #^https://gitlab.com/lightmeter it is just R
Getting mail reliably and quickly in the inbox of recipients is hard. Lightmeter shows where the bottlenecks are so you don't waste time.
Funny project. If you look at the code #^https://gitlab.com/lightmeter it is just R

spiffe
Fri, 31 Jan 2020 17:16:34 +0100
Recently saw in a certificate under Subject Alternative Name a spiffe:// URI. 
#^SPIFFE – Secure Production Identity Framework for Everyone

#CNCF

#^SPIFFE – Secure Production Identity Framework for Everyone

Secure Production Identity Framework for Everyone Inspired by the production infrastructure of Google and others, SPIFFE is a set of open-source standards for securely identifying software systems in dynamic and heterogeneous environments.
What is SPIFFE?
SPIFFE, the Secure Production Identity Framework For Everyone, provides a secure identity, in the form of a specially crafted X.509 certificate, to every workload in a modern production environment. SPIFFE removes the need for application-level authentication and complex network-level ACL configuration.
#CNCF
GLPI Inventory Agent for Android
Wed, 08 Jan 2020 17:44:11 +0100
#^glpi-project/android-inventory-agent

GLPI Android Inventory Agent allows your company to maintain control of all mobile devices, whilst providing comprehensive protection and enhanced security for sensitive corporate data, via a centralized management console.
Jenkinsfile in GitLab CI
Tue, 07 Jan 2020 17:57:48 +0100
Tempting...
#^Running Jenkins Files inside GitLab CI
#^Running Jenkins Files inside GitLab CI
Learn how to lift and shift your Jenkins jobs over to GitLab CI while you migrate.
First, I want to set some ground rules for this. For starters, this process is not meant for long term use. There are many downsides to this - Such as it only runs in one GitLab Stage and isn’t asyncronous. However this process can be used to run your Jenkins builds in GitLab CI, While you’re migrating your Jenkinsfile to GitLab CI Syntax. Make no mistake - This doesn’t solve your migration woes, But it does allow you to run your Jenkinsfile inside GitLab for the time being. It’s a stop-gap measure.
Log file Navigator
Tue, 07 Jan 2020 17:53:06 +0100
nice!!!
#^The Log File Navigator

#^The Log File Navigator

Many logging tools, like Splunk, provide great features but are optimized for large-scale deployments. They require installing and configuring servers before they can be effectively used. There is still a need for a robust log file analyzer for the terminal.
Just point lnav to a directory and it will take care of the rest. File formats are automatically detected and compressed files are unpacked on the fly.
Log files are a wealth of information, lnav can help highlight the parts that are important and filter out the noise.
Zero Trusted Networks
Wed, 11 Dec 2019 18:29:03 +0100
Interesting talk from #OSMC about micro-perimeter, least privileges, zero trust architectures, etc.
Modern Lifecycle Policy?
Mon, 25 Nov 2019 15:49:26 +0100

As a modern online service, the Microsoft Teams client auto-updates every two weeks. Because Teams is governed by the Modern Lifecycle Policy, it is expected that users remain on the most up to date version of the desktop client. This ensures that users have the latest capabilities, performance enhancements, security, and service reliability.

Users on Teams desktop clients that are more than three months old will encounter a blocking page giving the options to update now, reach out to their IT admin, or continue to Teams on the web.

The behaviour how this software installs automatically on every computer with M$ Office365 feels a lot like malware. It installs the Micro$oft Teams desktop client on the regular office update. In addition it installs a program that will reinstall the Micro$oft Teams Desktop client on next reboot if just the client was uninstalled.

Who will ever want to install the Micro$oft Teams client for Linux that will be released next month.
Handlungsempfehlungen zum Support-Ende von Windows Server 2008
Sat, 16 Nov 2019 23:51:39 +0100

#^Microsoft rät Kunden mit Windows Server 2008 zum schnellen Umstieg auf Azure-Cloud | News Center Microsoft
Support-Ende für Windows Server 2008 und Windows Server 2008 R2 am 14. Januar 2020: Ohne Migration riskieren Unternehmen Sicherheitsprobleme und Compliance-Verstöße
Am 14. Januar 2020 endet der erweiterte Support für Windows Server 2008 und Windows Server 2008 R2. Doch es gibt noch immer Unternehmen, die keine konkreten Pläne für die Migration auf ein neues Betriebssystem haben. Damit ab dem Stichtag keine Sicherheitslücken oder Verstöße gegen Compliance-Vorschriften zu riskieren sind, rät Microsoft zu einem Umzug der Server auf Azure. Die Migration in die Cloud gibt den Unternehmen mehr Zeit, um neue Lösungen für ihre Software-Anwendungen zu finden, die noch die Nutzung der alten Server erfordern.
in veralteten Server-Umgebungen die Einhaltung der EU-Datenschutzgrundverordnung (EU-DSGVO) nur schwer garantiert werden

Systeme vom Internet zu trennen ist keine Lösung

Microsoft empfiehlt Migration zu Azure

This website is tracked using the Piwik analytics tool. If you do not want that your visits are logged this way you can set a cookie to prevent Piwik from tracking further visits of the site (opt-out).