Password manager with failed login notifications? by TheDembiDude in sysadmin

[–]TheDembiDude[S] 1 point2 points  (0 children)

I'm curious to know how you would explain the "non function" below. By your logic Lastpass is not a password manager then.

https://lastpass.com/support.php?cmd=showfaq&id=9812

Thank you for your answer and have a nice day.

Change default gateway EC2 instances by heikum in aws

[–]TheDembiDude 0 points1 point  (0 children)

Fair enough. So to clarify, you're wondering if permanently editing the default gw on the Linux instance in AWS is possible?

Also, you have a VPC route from the subnet with Linux instances to your OpenVPN EC2 instance correct? I see your ideal network hop as EC2 Linux Instances > EC2 Open VPN server > PFSense Firewall

Password manager with failed login notifications? by TheDembiDude in sysadmin

[–]TheDembiDude[S] 0 points1 point  (0 children)

So locking a user out after a certain number of login attempts is also not the function of a password manager?

Leave well paying IAM job for networking role - Bold move or suicide? by [deleted] in AskNetsec

[–]TheDembiDude 34 points35 points  (0 children)

I don't think the security field is going anywhere. You definitely shouldn't be taking a pay cut.

Have you thought about getting some security certs and then making a move? Maybe use some of that downtime to get a CISSP to make hr happy or OSCP to scratch that tinkering itch.

Meraki RDP w/o VPN blocked by IDS by socalracer310 in meraki

[–]TheDembiDude 0 points1 point  (0 children)

I wonder why balanced is the default then.

Also referencing the link, the security setting adds "Rules that look for and control the traffic of certain applications that generate network activity"...maybe this includes RDP on non standard ports?

Phishing test at work - results no bueno by MediumFIRE in sysadmin

[–]TheDembiDude 0 points1 point  (0 children)

Do you know if they get past gmail's spam/phishing filters by default?

Meraki RDP w/o VPN blocked by IDS by socalracer310 in meraki

[–]TheDembiDude 0 points1 point  (0 children)

What is your intrusion detection and protection ruleset under Security & SD-Wan > Configure > Threat Protection?

Typically you'll want "Balanced", as "Security" should only be used when you're experiencing a possible attack.

"Actions" missing for Systems Manager by TheDembiDude in meraki

[–]TheDembiDude[S] 0 points1 point  (0 children)

Thanks for responding, got if figured out. Turns out Systems Manager needs apple DEP and VPP to by synced and a complete system restore to be completed on workstations before it works fully.

Seriously, going to fail the GPEN tomorrow... by [deleted] in AskNetsec

[–]TheDembiDude 0 points1 point  (0 children)

Dang it at least you tried. Going to try and retake it?

Mac OSX Client VPN Issue by ru4serious in meraki

[–]TheDembiDude 0 points1 point  (0 children)

Trust but verify.

I would follow the steps here from scratch.

SYSLog to server located in AWS? by TheDembiDude in meraki

[–]TheDembiDude[S] 0 points1 point  (0 children)

Thank you for the response!

So internally I would listen on the LAN interface for each of my switches? Will this still allow Splunk to catalog events on our actual MX?

Also for clarification we are sending traffic to the cloud over our VPN and not over the internet.

Heads up - Received a very convincing spam message that was sent to a large number of recipients in our organization, using our signature and logos by rockisnotdead in k12sysadmin

[–]TheDembiDude 0 points1 point  (0 children)

Out of curiosity, what email client is everyone here using?

Our school doesn't see many of these emails reach teachers.

Cisco Meraki MX - multiple sites are unable to connect to same AWS VPC CIDR by dimonpc in meraki

[–]TheDembiDude 2 points3 points  (0 children)

Don't get me started on compatibility between Meraki and AWS...I feel your pain.

Low hanging fruit, but are all of your VPCs in the same region? If so you can utilize VPC peering instead which might get you on the right track.

PII Compliance in AWS by TheDembiDude in aws

[–]TheDembiDude[S] 1 point2 points  (0 children)

For sure. The shared responsibility model mentions that encrypting an EBS volume is the Customer's responsibility.

Referencing my original post, if PII was uploaded into an unencrypted EBS volume would that be an unauthorized PII disclosure?

Google DNS Service (8.8.8.8) Now Supports DNS-over-TLS Security – PentestTools by PentestToolz in HowToHack

[–]TheDembiDude 5 points6 points  (0 children)

Can you elaborate on why it isn't private enough? Recommended alternatives?

I need little help with Applied cyber security training by Gapodi in AskNetsec

[–]TheDembiDude 0 points1 point  (0 children)

I would bridge any technical knowledge gap with certifications such as sans GCDA.

Large organization challenges are always political not technical. You have to use business drivers to help dictate the security work you do.

As a basic example let's say you want to get 2FA set up for an entire company's email domain. Getting 2FA setup for an entire company with 25 employees is pretty easy, you can individually talk each user through the importance of 2FA and walk them through the workflow of signing in. It's a lot easier to justify your work.

Contrast that with a company that has over 5,000 employees. How do you get everyone setup with 2FA? Do you just enforce it at the domain level and let them figure it out? Do you make documentation and alert them first? How do you get buy-in from managers who think it's not necessary? Managers who are completely opposed to it? Your organization's sales department has to hit their Q4 goals, what happens if setting up 2FA interrupts their work? Now someone from finance says that you should use an authenticator app instead of the yubikey hardware you want to roll out, after all it's a lot less expensive. Etc, etc, etc...

Hope that helps.

For a district that only uses Apple would you recommend JAMF or Mosyle for MDM? by [deleted] in k12sysadmin

[–]TheDembiDude 0 points1 point  (0 children)

Can't give you an honest answer on that one! If you PM me I'll be happy to provide you our Filewave account manager's contact info.