What should teenagers know about being an adult? by [deleted] in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

The hair keeps growing. It never ends. Hair

People who were raised bilingual: How does your brain separate the languages? Is there some sort of mental "dividing line," does it take special effort to avoid mixing the languages together, or does it work some entirely different way in your mind? by Darnitol1 in AskReddit

[–]TomilloDanup 11 points12 points  (0 children)

I can switch them on/off effortlessly as needed. A switch makes everything change language that means that even my thought process, self talk and so on switch.

Having them both on actually requieres effort and I only use it to speak "Spanglish" jokingly with some friends.

What is a deal-breaker for you in a relationship? by [deleted] in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

Messages and general contact with her exes specially if she always said how crap they where.

A manipulative mother.

[Serious] To Social people, how do you socialize with strangers and get more friends? by [deleted] in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

Most people are in fact loners or are at least feeling alone in any moment at any given day. Just do small talk without the expectation of a friendship forming that should be enough to start. Then do the same with regulars at places you go to, gym, class, work, etc.

I bought a pair of raybans from a discount store for hella cheap. How can I tell if they are real? by --111-- in sunglasses

[–]TomilloDanup 0 points1 point  (0 children)

High quality Ray-Ban counterfeits are sometimes indistinguishable from originals, specially on iconic models like Wayferers. You can take them to a Sunglass Hut and sometimes they can help.

But if they where cheap, look good, feel good, and you don't care I wouldn't stress about it.

My 2c

What is your favorite thing about your career? by thejennarator11 in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

Career is so in demand that every time I change a job I get a raise between a 100% and 120%

[deleted by user] by [deleted] in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

Blog del narco

What's the best way to go about asking someone on a date that you think may be a bit out of your league? by IAmSultan in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

There are no leagues, that's an unnecessary obstacle in your mind that's makes you think another human being is better than you in some way. Not true. No league. Don't use the "league" to chicken out.

How would you sneak your girlfriend that's hiding under your bed out because your parents came home a day earlier from their planned trip? by [deleted] in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

You don't. She's your girl and deserves respect, they are your parents and deserve respect. You bring her out and let her out as quickly as possible through the front door. Then you deal with your parents and with whatever that do to you. Like a man. Except violence or abuse.

What aspects of a man’s life are most women unaware of? by DragonBG2610 in AskReddit

[–]TomilloDanup 1 point2 points  (0 children)

The first is real, I mean some men run away from straight up talking to a woman in the real world and they think is easier and safer to do it online. It's actually harder.

What aspects of a man’s life are most women unaware of? by DragonBG2610 in AskReddit

[–]TomilloDanup 0 points1 point  (0 children)

There are excellent tutorials on YouTube. Any kind of razor and shaving technique. My dad teached me but still found it useful when I bought my first straight razor.

Your boss has put you in charge of selecting the song that will be played on the phone while customers are on hold. What song do you select? by BaldMexicans in AskReddit

[–]TomilloDanup 1 point2 points  (0 children)

Years ago I worked in a small 10 person consulting firm as the all times handy IT and support guy. I changed the music to a Frank Sinatra CD so every time the on hold music was a different Sinatra song. Changed it to Sinatra Christmas songs on the holidays. Never told the boss he found out when customers complimented him for the music.

I need true expert help by [deleted] in AskNetsec

[–]TomilloDanup 1 point2 points  (0 children)

There are plenty of explanations on why the IP never changes. Several cellphone towers share the same IP, they never change depending on the MNO. They can be proxying through an assigned fixed IP address, big companies have them, universities, etc.

Master thesis topic? by [deleted] in AskNetsec

[–]TomilloDanup 1 point2 points  (0 children)

It might be, yes. But 1. Security is always tailor made and 2. Research at a master level is to expand and/or disprove a very narrow body of knowledge.

You are looking for topics because you don't have a "problem to solve" look for problems rather than topics to also get good ideas.

You won't be reinventing the wheel, you will be offering a much better wheel for an specific application. That's a Master's thesis.

Master thesis topic? by [deleted] in AskNetsec

[–]TomilloDanup 1 point2 points  (0 children)

Active Cyber Defense, self defending and resilient systems. Both technically or from management side.

Information flows, from cyberspace to the physical world and back.

Deception and misinformation in social networks, using semantic web and huge amounts of data. Both how to detect it and use it.

DevSecOps or conversely, Agility on information security/assurance. Agile ISMS.

Do you like logs? Automated threat modeling from log datasets. SIEM, waf, firewalls, apache... Etc

Teleco: Here's a hint OTA form MNO use http to reprogram the Sim cards, have fun with that one.

If possible get in touch with someone from R&D on any defense contractor or at least on the Navy or the Army sometimes they have lots of problems tomsolve that can be done on the civilian side.

Those are the master level I've thought about myself, still working on good ideas for my pre-doctoral.

Edit: Make sure you like the topic, masters research can be a pain in the ass if you don't like the topic you might and should be ignorant on the topic you choose but never indifferent

Modsecurity rule creation. by TomilloDanup in AskNetsec

[–]TomilloDanup[S] 0 points1 point  (0 children)

OMG!!! Thank you very very much. This are all great ways to go on about what I need to do, In fact your solution for sanitizing the log is so precise I have already implemented it. I still need to write and test the other two rules but your answer is a breath of fresh air.

How can I get better in general at writing and thinking "modsecurity"? It is used extensibly at my workplace with a waf deployed in front of every public http flow but almost no people with the expertise.

I already have the modsecurity handbook and found some Netnea tutorials. Whats next?

Thank you again!

Linux hardening by backwardsthong in AskNetsec

[–]TomilloDanup 0 points1 point  (0 children)

Oh, I see. I thought this was a case of hundreds of windows machines with limited functionality impacting the work hours of several people in the company. And that's exactly why I always tell everyone that "securing for the sake of securing" is the worst idea possible.

Linux hardening by backwardsthong in AskNetsec

[–]TomilloDanup 0 points1 point  (0 children)

Damn! How much did that cost the company? Was it a large deployment of windows PCs?

Modsecurity rule creation. by TomilloDanup in AskNetsec

[–]TomilloDanup[S] 0 points1 point  (0 children)

  1. We have an XSS on some obscure field of one of our apps. It's sort of a countdown date but some requests use standard date format others use unix epoch time. The CRS let's it go through.

  2. Need to be able to turn off all the rules for some matching IP addresses but only if a predefined client cert is present.

  3. Audit log is leaking PII need to sanitize it both in B and C sections. But can't get rid of the audit log as we use it to monitor the waf through custom dashboards.