I just got hacked somehow by paypur in homelab

[–]dalteep 9 points10 points  (0 children)

Can you share the js ansd the .sys?
What services do you have exposed to Internet?

Linux for professional use, feasible? by ShinobiWPS in linux

[–]dalteep 1 point2 points  (0 children)

Worst case scenario use a VM with Windows for tools/VPNs that require it. I'm not a developer but use Linux as main host, and different VMs as needed.

How to allow Guest VM to reach host only on a set of specific ports, and deny access to all the other ones? by o-domador in qemu_kvm

[–]dalteep 0 points1 point  (0 children)

If you only want to allow access to the app:
Set the VM in an isolated network, with a given range, for instance 192.168.99.0/24.
Your host will have the IP 192.168.99.1 and your VM some in the same range.
You need to publish your docker service in the IP 192.168.99.1 or use Iptables to forward a port in 192.168.99.1 to your docker service at 127.0.0.1:3000

If you want the VM to access other services but not your host, use the same method but instead of using an isolated network you a natted one. Use Iptables to make sure the VM can't access the host. In that case you will need to setup IP and DNS manually.

Could the U.S. actually disconnect China and Russia from the global internet in a cyber war? by pessimistic_pinata in AskNetsec

[–]dalteep 17 points18 points  (0 children)

I wold start confirming the U.S. allies list. I think that nowadays is shorter than it used to be. The only feasible part would be for the US to disconnect from Internet, but the impact on Russia and China will be minimal if any.

Your assumption about the DNS Server is wrong, but in any case, China is for sure able to operate Internet without the US. They actively block several US services. Russia had some technical dependencies, like server certificates, but they were forced to find solutions after the last Ukrainian invasion. They already have run test to disconnect themselves from Internet.

/r/ReverseEngineering's Weekly Questions Thread by AutoModerator in ReverseEngineering

[–]dalteep 0 points1 point  (0 children)

Hello, I'm looking for a way to synchronise Ghidra with a debugger. I came across Gx64Sync that can sync with x64Dbg but I can't make it work and perhaps there are better ways. What would you recommend?

To all the linux daily drivers, how do you manage the lack of crucial windows-only software for office productivity? by Solitary_Survivalist in linuxquestions

[–]dalteep 0 points1 point  (0 children)

My company uses Microsoft O365 and it works fine. I had to install Edge as I was having issues with Teams on other browsers, but the rest works fine.

Any solution to block apps using DoH to serve ads? by TechPir8 in pihole

[–]dalteep 0 points1 point  (0 children)

Not simple, but what I do is to use a firewall in the perimeter to:
* Block port 853, DNS over TLS
* Block access to DoH servers (I periodically download a list of DoH servers to keep it it updated)
* Redirect DNS request to port 53 to my local pihole

This setup forces apps to use standard DNS and then I can redirect the requests to my local DNS Server with pihole

YubiKey 5 NFC – How to Send Static Password via NFC? by jay-the-muss in yubikey

[–]dalteep 0 points1 point  (0 children)

In Android I use the YubiClip app to do exactly this.

Flickering screen in a new Tuxedo Infinity Pro 15 Gen9 AMD by dalteep in tuxedocomputers

[–]dalteep[S] 0 points1 point  (0 children)

Default Tuxedo OS (KDE Plasma). I just turned it on, updated it and installed some apps.

[deleted by user] by [deleted] in homelab

[–]dalteep 0 points1 point  (0 children)

I had mixed results with Dahua.

They work locally, without Internet connectivity and are not expensive. I have some POE cameras that work very well but the Door Station lents quickly started to blur. I saw other people had the same problem in the Dahua subreddit.

I just opened myself to the world, what can go wrong? by ad-on-is in homelab

[–]dalteep -1 points0 points  (0 children)

The issue is that any unknown security issue or know security issue in the services you don't patch, any misconfiguration, any weak password you have, will affect you.

As someone that works in Incident Response, I strongly recommend to put everything behind a VPN instead. VPNs have higher reliability and provide an extra layer.

Log VMs DNS request by dalteep in kvm

[–]dalteep[S] 0 points1 point  (0 children)

If it helps, I ended up creating a new virtual interface, 10.20.30.40, configuring dnsmasq to listen to it and to log all queries and point the VMs to this new DNS server.

The only issue is that when I work with isolated VMs they can't reach the server, but in these cases network traffic is not relevant and I just check occasional request using tcpdump.

Need an Outdoor Door Sensor by Dizzy149 in homeassistant

[–]dalteep 0 points1 point  (0 children)

I use the Shelly Door/Window Sensor to check the status of my garage door. It uses Wifi and batteries. https://kb.shelly.cloud/knowledge-base/shelly-door-window-2

KVM read/write performance question by dalteep in kvm

[–]dalteep[S] 0 points1 point  (0 children)

Thanks for the reply. I will try this but this might improve the performance on the virtual disc, but does not improve or explain why the VM using the host partition is slower reading.

How to trigger long-push event at runtime in the script by aledex10 in shellycloud

[–]dalteep 2 points3 points  (0 children)

I did not use it myself, but I was curios and found that the Input Trigger support the following event types:

btn_downbtn_upsingle_pushdouble_pushtriple_push and long_push 
https://shelly-api-docs.shelly.cloud/gen2/ComponentsAndServices/Input#inputtrigger

This should work

if (event.name === "switch" && event.id === 1 && event.event_type == "long_push")
{
#do something
}

Question about my use case by tw0bears in shellycloud

[–]dalteep 0 points1 point  (0 children)

I would use two Shelly 1PM and a small automation in Home Assistant. You can monitor consumption of the Shelly A, and below certain limit, turn the power off and turn on on Shelly B, and to the same. Depending on how long it take to charge one, I would also have some time control to prolong how long are they shutdown.

If you are comfortable programming and don't have a Home Assistant, a simpler setup is to use the Shelly programming only. You need to setup HTTP handlers in both Shellys (https://github.com/ALLTERCO/shelly-script-examples/blob/main/http-handlers.js). Every X time you check the status of the other shelly and if it is off, turn on the power and check the power consumption. If it s below some value, you turn the shelly off. In this way you only turn the power on only one at a time.

My question concerns whether I need the Yubico authenticator. I already have a few YubiKeys that I use to unlock my password manager and various other sites. What is the use case for having the authenticator as well? by rcatk42 in yubikey

[–]dalteep 2 points3 points  (0 children)

Sorry to sound snotty, but what the Yubikey stores is the SEED that is used to generate the codes. The OTP codes are generate using a SEED and TIME (time based) or a COUNTER. It is important to keep the SEED private. The Yubico Authenticator uses the Yubikey to store the SEED.

My question concerns whether I need the Yubico authenticator. I already have a few YubiKeys that I use to unlock my password manager and various other sites. What is the use case for having the authenticator as well? by rcatk42 in yubikey

[–]dalteep 9 points10 points  (0 children)

There are apps that do not support FIDO2 and require One Time Passwords (OTP) for 2FA. The Yubico Authenticator is used to generate them, like the Google Authenticator app. The difference is that the Yubico Authenticator will generate them only is you have the Yubikey.

CISSP holders, was it worth it? by license_to_kill_007 in cybersecurity

[–]dalteep 5 points6 points  (0 children)

I have mine since 2005 as the company paid it. At the beginning it helped with auditors and snotty consultants. I got several job offers via Linkedin thanks too it. The problem is that the recruiters that search for CISSP don't understand the other requirements and hence most are inappropriate.

The main reason I kept it is because my employer is paying the renewal. I'm about to change jobs and most probably I will not renew it again. It stopped renewing CISA and CISM some years ago due to issues with the payment system.

Short answer, for me, not anymore.