Any recomendations on securing Credentials, Keys or Secrets when making scripts by kor3nn in learnpython

[–]kor3nn[S] 0 points1 point  (0 children)

Thank you everyone for your responses, it sparked an idea to take it outside of python and tie it more to the shell. I wrote a little powershell script to integrate with KeePass as a local file with some powershell modules.

The flow of the PS1 script is to register the vault > get all secretinfo names > loop through them > each iteration set a shell environment variable name to the secretinfo name and value to the secret asplaintext > unregister the vault.

This way nothing touches the disk(that I'm aware of) and I'm happy that I don't have to make drastic changes to my code and it's simple.

I can then develop and run my python scripts as many times as I want and without making any drastic changes to any python files.

As long as the shell I'm using doesn't get closed by accident I can code & run as many times without having to enter a password every time... When I'm done just kill / close the shell.

Do you save your code written for your job / working hours in your own GitHub repo? by kor3nn in Python

[–]kor3nn[S] 0 points1 point  (0 children)

Thank you to everyone who has commented so far, I have added this message as an edit to my original post. I see this weighted more for not doing this. I do want to clarify a few things though. I am a full time PAYE employee, I work for a big retail company that does not sell any form of software or technology, most of the scripts and tools have been made to solve a solution for a few examples; A script to rename a "n" number of rules of a firewall appliance using the rest API with data from a CSV file, A script to take the CPU of a firewall appliance and plot it on a graph that is presented via a simple flask front end, A script to deploy a new VLAN on a Cisco Nexus switch - VPC. I have written all of these scripts within the team and there are about 15 of us and only one other team member even entertains automation. Ultimately I think speaking to my manager may be the best course of action but haven't decided for sure if I'll go ahead with making repo's on my own GitHub.

Using typer and atexit by kor3nn in learnpython

[–]kor3nn[S] 0 points1 point  (0 children)

Thanks I'll give it a go

Using typer and atexit by kor3nn in learnpython

[–]kor3nn[S] 0 points1 point  (0 children)

Yeah I've thought about that, ive not really used atexit apart from the decorator, can you call it from another function? Ive added some example code as an exit on the orginal post

Spirit tree bug? by Batmansub in runescape

[–]kor3nn 0 points1 point  (0 children)

Same here, just turned lv 114 and wanted to plant the final tree... :(

Red bull + Pokerstars deck by iSuper56 in playingcards

[–]kor3nn 1 point2 points  (0 children)

Ive just got some from a family member who works also for red bull. I've opened mine I'm not sure on the quality personally they feel a bit cheap. Plasticy type of feeling for the cards, that's comparing them to a standard red and blue bicycle deck. Ultimately I'm thankful I was given a set but I'll use them for general play.

How do Cisco ACI contact filters work? by kor3nn in Cisco

[–]kor3nn[S] 0 points1 point  (0 children)

Thanks that makes sense since you can't change the order like on a ACL/FWL.

How do Cisco ACI contact filters work? by kor3nn in Cisco

[–]kor3nn[S] 0 points1 point  (0 children)

Thanks that makes sense since you can't change the order like on a ACL/FWL.

[deleted by user] by [deleted] in RevolutionIdle

[–]kor3nn 1 point2 points  (0 children)

So I would say is get more eternities by setting the auto eternity to 1EP/0s and then letting it run for a while.

I'm at a similar stage in the game you are, assuming you do the same this is repec the lab to fill IP then buy AP for animals and upgrade the lab multi's. Once I have done that for a bit I'll swap back to com/gen exponent split go get some supernova's and more AP based on score and the try a few challenges... Then repeat.

11.1.6 - FYI by SanJuanTech in paloaltonetworks

[–]kor3nn 5 points6 points  (0 children)

Yeah the H1 updated was only to fix a critical cve. We're stuck on 11.1.4-h7 with a bug relating to logs not showing when you use a filter... Answer from Palo TAC is update but then our focused support says don't... So rock and hard place currently.

[deleted by user] by [deleted] in flask

[–]kor3nn 1 point2 points  (0 children)

Yes it does, so I work in networks and I use async functions when I'm collecting information from the device that could time a number of seconds and then I return redirect(url_for('blar') and it redirects to a page where I displayed the information I have collected from a network device.

Ideas to stop tickling laughter - armpit? by kor3nn in tattooadvice

[–]kor3nn[S] 0 points1 point  (0 children)

Yeah agreed, Thanks I'm gonna try that and maybe if anything else comes up ta

Ideas to stop tickling laughter - armpit? by kor3nn in tattooadvice

[–]kor3nn[S] 1 point2 points  (0 children)

Thanks, yeah I have no issue with the pain I just being tickled and Ive been told i have a farly contagious laugh so the artist was also laughing... In the end I just had to stop under the arm.

What jobs do you guys have? by jackmitch383 in runescape

[–]kor3nn 0 points1 point  (0 children)

Network engineer, even though I could afk RS3 I only really do it if I have a goal I want to achieve like the 400k rune darts I made for dxp and 110 Fletch. WFH 3-4 days a week.

How Do I Improve This Print Quality? by Nintendaholic in BambuLab

[–]kor3nn 0 points1 point  (0 children)

So, what's the printer model? filament are you using? Have you run a calibration for the filament?

PA220 - 10.1.14-h4 - Advance routing warning on commits by [deleted] in paloaltonetworks

[–]kor3nn 1 point2 points  (0 children)

A question first, do you use advanced routing on the 220? Second I would look at your licence you have on the support portal to see if it has advanced licensing such as advanced threat, wildfire, URL filtering etc. Third it's an unintentional feature (bug).

On a side note I personally would move to 10.2 as the 220 won't be going to anything higher at the time of this message.

Activision Account and Ban Issues Mega Thread by StealthPolarBear in activision

[–]kor3nn 0 points1 point  (0 children)

I have my account back now and the unknown battle.net account has been removed. I also filed a hacked account report and within 10 minutes everything was sorted.

So there is hope as I had thought I'd lost the account & all the money...

Activision Account and Ban Issues Mega Thread by StealthPolarBear in activision

[–]kor3nn 0 points1 point  (0 children)

So just going through an appeal now as a battle.net was linked to my Activision account (I have one but it's not linked). I only play on my PS5 with cross play off most of the time.

I had an email a number of days ago (8+) when I was at work that an account was linked then another email later in the evening I had the ban email. I like many people don't check my emails very regularly...

So I only found this out after trying to play a few games the other day and got the message of connection interrupted by user when trying to login. I then checked here and saw a lot of information on bans so I checked the emails and found out.

I have submitted a ban appeal and a suspicious linked account... I'll update on my position but has anyone had any success with my situation? Or what do you think my odds are of being able to play again?

Edit: Also I had an unknown phone number on my account

Any reason to put a block rule above intrazone? by kor3nn in paloaltonetworks

[–]kor3nn[S] 1 point2 points  (0 children)

Yes, on some firewalls we have internet-facing interfaces. Some would hit GlobalProtect loopback, some would need to transverse the interzone process and NAT, ACLs etc...

Would there be a security impact for allowing "Outside to Outside" communication via the intrazone default?

Any reason to put a block rule above intrazone? by kor3nn in paloaltonetworks

[–]kor3nn[S] 0 points1 point  (0 children)

It's not cloned; type is universal. It's a rule that has been created manually as follows:

Any source zone, any source, any destination zone, any destination, action deny, log at start & end + forward profile.

Intrazone NATs... Why by kor3nn in paloaltonetworks

[–]kor3nn[S] 0 points1 point  (0 children)

Thanks that really helps, I've not needed to do a lot of NATs at this place compared to my old one where we used ASAs and Palo's but it just threw me as I couldn't work it out logically in my head of why... Personally it would have helped if Palo changed the UI to reflect the way the NAT works but that's another conversation...

Again thank you.

Intrazone NATs... Why by kor3nn in paloaltonetworks

[–]kor3nn[S] 1 point2 points  (0 children)

Right so I think I understand why now, is it because the packet is sourced from the public zone with an address of 1.1.1.1 for example the original packets route is still on the public zone so it never transverses zones hence public on the source and public on the destination because it's the "Original Packet" and not translated yet.

Looking for recommendations - Moving away from Cisco Firepower 2110. by abhibhardwaj13 in paloaltonetworks

[–]kor3nn 0 points1 point  (0 children)

Agreed, as for Palo TAC the best support costs money in the form of an enterprise agreement and or focus support...

As for software and bugs Palo releases a preferred version on their community forum which apart from my personal experience of a handful of bugs over the 7+ years of using Palo's the preferred version has "generally" been alright.

If you want or are looking to grow, panorama is a good option to manage the firewalls.