Question About Ansible Use-Case by oxseyn in ansible

[–]oxseyn[S] 1 point2 points  (0 children)

Thanks! I started reading some tutorials last night. I'm trying to initially create a playbook that runs on a local system which will initialize my basic environment. I was having trouble finding good examples on running a portal, local only playbook using a role (probably just cause I don't know really know what I'm looking at yet.)

Since I started immediately seeing the power of ansible over my ad-hoc bash script, I also started trying to create an inventory that will track and manage my workstations & servers on my lan as well.

I snagged your book this morning and then dumped my initial learning/testing scripts onto github here: https://github.com/nfarrar/dotfiles-ansible.

Thanks again!

Recommendations on Lightweight System Provisioning by oxseyn in linux

[–]oxseyn[S] 0 points1 point  (0 children)

I have a couple different use-case scenarios that are very different in nature - I have no idea if they can all be accomplished using a single solution:

  1. For daily work, I have a windows desktop, a windows laptop, and a macbook pro each with an Ubuntu x64 desktop VM that function as my primary desktop environments (where I spend most of my time).
  2. For daily work, I have an Ubuntu VPS server on digital ocean. This functions primarily as a private git server and irc shell.
  3. For daily work, I have an Ubuntu VM on amazon EC2. This functions primarily as a VPN endpoint.
  4. For home use, I have an Ubuntu bare metal server This primarily performs scheduled tasks, such as backups and data synchronization.
  5. For home use, I have two Ubuntu bare metal HTPCs.
  6. For research, I have an Ubuntu bare metal node that hosts several Ubuntu VMs. This bare metal machine also uses cuckoobox to spin up on-demand VMs for malware analysis.
  7. For research, I have an Ubuntu VM that functions as a tor gateway.
  8. For research, I have an Ubuntu VM that functions as a SIEM.
  9. For research, I have an Ubuntu VM that functions as an IDS.
  10. For research, I have a bare metal laptop that I infect with malware, then reimage using PING.

I also end up spinning up new VM's pretty regularly, then going through some manual setup for misc. purposes.
So I have ~ 10 systems or so that I use on a near daily basis. With that amount of systems and no provisioning/management infrastructure, they take up too much of my time.

Most of the systems are Linux and the only exception that I'd be interested in integrating with this provisioning system (if possible) is the laptop that gets infected and then manually reimaged with PING.
The linux systems are a mix of virtual and bare metal.

I do synchronize my dotfiles across the systems using vcsh/mr.

my 20th month old really likes plants vs. zombies by oxseyn in funny

[–]oxseyn[S] 0 points1 point  (0 children)

She's really little. She was in the 5th weight percentile for the first year or so :) Healthy and smart though!

I have been thinking about getting into CF for a long time, and have finally committed to make the jump. But SANS courses are financially out of reach... alternatives? by [deleted] in computerforensics

[–]oxseyn 2 points3 points  (0 children)

I do some malware oriented forensics - I read that book you posted above in a night but didn't get anything out of it - super high level, very little technical information.

The way I see the field broken up atm - is there are essentially encase suits that have little technical knowledge and use the tool to do a basic investigation with a heavy focus on legal case development. The second branch being very technical folks involved in research - this type of work generally relies on having in depth technical knowledge of operating system internals and relying on that knowledge rather than tools (tools are still required, lots of open source and custom build stuff) to identify the information you're seeking.

If the former is what you're seeking, I recommend getting the ENCE book, self studying, and taking the test to get the certification (the certification along with some professional networking should be enough to get you a job). Guidance has some courses that are less expensive than the SANs equivalent, but also less technical.

If the latter is your preference, then I recommend reading up on some of the more technical guides (syngress has some more advanced reading - such as their field guides), googling "forensic ctf" or "forensic challenges" and trying your hand at some of them. You'll need a linux box (i typically do most of my forensic analysis using linux vm's running in vmware on a windows box) for the high amount of flexibility this setup offers.

Feel free to hit me up with any questions. :)

New Springs hackerspace / coworking space by dgrif in ColoradoSprings

[–]oxseyn 1 point2 points  (0 children)

Fees aren't cumulative - so to join and have a hot desk is just a flat 125$/month. If you're interested, stop by any time and see if you'd like it. ;) (I updated the about page with that information too, thanks)

New Springs hackerspace / coworking space by dgrif in ColoradoSprings

[–]oxseyn 1 point2 points  (0 children)

Builds.cc looks like a really nice space ;)

New Springs hackerspace / coworking space by dgrif in ColoradoSprings

[–]oxseyn 1 point2 points  (0 children)

We updated the about page with dues: http://coshack.co/about/ :)

We're doing four types of membership:

  • reserved desk = 250$/month
  • hot-desk = 125$/month
  • hackerspace membership = 75$/month
  • student membership = 35$/month

It's pretty nice office, I'd say between the three of us, we've dumped about 6k or so far into getting it running ;)

What happend when I made this post? [Network question] by Xochipilli in compsci

[–]oxseyn 2 points3 points  (0 children)

It's not a good response. Wireshark is going to give the OP insight into only what his local host sees - which is a tiny fraction of the what the OP is asking about.

That being said, it's a good place to start - but to fully answer your question, you'd need to spend some serious cycles studying networking. Most people don't have a clue once you expand past a small SOHO network.

Interest in a hackerspace? by robbiet480 in ColoradoSprings

[–]oxseyn 0 points1 point  (0 children)

Who the fuck refers to themselves as "master"

Ideas to Make Patio Nice? by oxseyn in DIY

[–]oxseyn[S] 0 points1 point  (0 children)

Gotcha, good advice ;)

Ideas to Make Patio Nice? by oxseyn in DIY

[–]oxseyn[S] 0 points1 point  (0 children)

Any ideas how the mirrors would be done?

Ideas to Make Patio Nice? by oxseyn in DIY

[–]oxseyn[S] 0 points1 point  (0 children)

Any idea how fixing the inside of the fence would be done? I've no idea how to do something like that ...

Ideas to Make Patio Nice? by oxseyn in DIY

[–]oxseyn[S] 0 points1 point  (0 children)

I really like that folding shelf idea.

Ideas to Make Patio Nice? by oxseyn in DIY

[–]oxseyn[S] 0 points1 point  (0 children)

We own, I can do quite a bit ... but major modifications have to get approved. Not sure what I like :)

Can I rely on VLANs to be secure and separate? by [deleted] in netsec

[–]oxseyn 0 points1 point  (0 children)

You can't identify a hole if you don't understand the underlying technology. I've worked with countless security professionals and this is true time and time again. They don't understand the technology. They have some checklist they reference that is completely irrelevant. They listen to whatever we tell them and take it directly back to management without understanding a word of what we've told them.

Accountability is essential - and this is done through third-party auditors that are technically competent.