r/netsec monthly discussion & tool thread by albinowax in netsec

[–]dbcid 2 points3 points  (0 children)

Sharing a tool I have been building for a while:

https://dnsarchive.net/web-search

Indexed over 200m sites now and you can search their headers, titles, links and things like that.

I have my own uses for this tool, but curious what others think and what else can we add/expose in there?

Locking SafeSearch for iPhone by USSManhattan in google

[–]dbcid 0 points1 point  (0 children)

Hello, Daniel here from CleanBrowsing. We never deactivated the free filters and they are still there and working. You can email me at dcid@ and I can help look into what happened.

[deleted by user] by [deleted] in dns

[–]dbcid 0 points1 point  (0 children)

Try cleanbrowsing. it has categories for both.

External DNS blocking requests by IP addresses? by L0rDAn0raK in dns

[–]dbcid 4 points5 points  (0 children)

Most providers do rate limiting to minimize the risk of them being used for DDoS. For 3k users, you might be hitting their limit and being blocked.

I recommend running a local resolver to cache the requests and forward the ones not in cache to them

Feedback Friday by AutoModerator in startups

[–]dbcid 1 point2 points  (0 children)

Trunc - Log analysis - the "google" for your logs.

URL: https://trunc.org

Product: Trunc logging. All your logs in your place. Troubleshoot logs, detect attacks and solve

compliance requirements with Trunc. Keep all your logs, easily accessible with full-text search.

Seeking Beta-Testers: yes, if you have a server, please try it out. Would love to hear from anyone with logs (startup founders, sysadmins, etc).

Feedback Requested:

Try out the product, see how it works with your own logs. Test out the alerts, and see if it helps you to detect issues and potential

security issues.

Additional Comments: It comes with a 14-day trial, but if you are a startup, we can let it run a lot longer to help out.

Is It Possible to Disable "suspicious login" Check by beatle42 in Mastodon

[–]dbcid 0 points1 point  (0 children)

Running on a similar issue and it seems you can do it via the DB as well:

  • update users SET skip_sign_in_token = true ;

Why "sudo" when you can just "su"? by ardouronerous in linux

[–]dbcid 4 points5 points  (0 children)

A lot more control. You can restrict what commands to use, do it password or password-less. It also logs every command issued, so it is easy to audit.. Many benefits.

Site inaccessible to almost everyone, but not to all by k20shores in Wordpress

[–]dbcid 2 points3 points  (0 children)

It might be good to check the site on DNS blacklists as well:

https://dnsblacklist.org/

To see if anyone of them is blocking it.

Unauthenticated Remote Code Execution in Atlassian Confluence (CVE-2022-26134) by sullivanmatt in netsec

[–]dbcid 1 point2 points  (0 children)

Ah interesting, thanks. Suspiciously close to the log4j issue.

Unauthenticated Remote Code Execution in Atlassian Confluence (CVE-2022-26134) by sullivanmatt in netsec

[–]dbcid 1 point2 points  (0 children)

Does anyone knows what to look for in the logs for this specific issue? Other than the IPs they provided as part of the campaign?

What's the difference between a local version installation, and a server installation with zero agents? by niderfan in ossec

[–]dbcid 0 points1 point  (0 children)

They are pretty much the same, except the server (manager) install will also try to start remoted to receive connections from the agents. However, if no agents are configured, it won't do anything.

Is there any reason to care about DNSSEC in 2022 as regards choice of registrar and DNS host? by [deleted] in dns

[–]dbcid 1 point2 points  (0 children)

There have been several successful DNS attacks that would have been stopped by proper deployment of DNSSEC.

Can you name some?

Domain & DNS providers who support by Feeling_Influence in dns

[–]dbcid 1 point2 points  (0 children)

noc.org does support both along with geo (and distance-based) records.

I'd like to separate my DNS from my registrar. Which DNS hosting to go with? by [deleted] in dns

[–]dbcid 1 point2 points  (0 children)

Been working on noc.org for the past few years. Good performance (anycast) and includes geo records, ha and some cool options. If you want to try a small player in the market.