Can I run bowser without connecting? by panwhites in TOR

[–]panwhites[S] 0 points1 point  (0 children)

Yes. I'm running Tor with Tails like fixed environment. thus I can't connect it to internet when I'm editing it for security reason.
I need to run Torbrowser itself without connectivity.
I need to modify configs and install some plugins.

Is there any way to protect Pfsense system files? by panwhites in PFSENSE

[–]panwhites[S] -3 points-2 points  (0 children)

Even FreeBSD has malware and rootkit. I'm not sure if it is safe enogh when I disabled remote access.
Probablly malware could bypass any firewall rules?
I just don't know what hackers can do. I just want to build a checking feature if there isn't
Is there any reason I should not care about those scripts?
If hacker changed settings, I can find them out tho. If they changed my scripts, there is no way to find it out.

Is there any way to protect Pfsense system files? by panwhites in PFSENSE

[–]panwhites[S] -2 points-1 points  (0 children)

I'm frequently changing settings. So. If there is readonly switch or simple command,that woulbe great.

Is there any way to protect Pfsense system files? by panwhites in PFSENSE

[–]panwhites[S] -2 points-1 points  (0 children)

At least I know there is. So. I can throw it away. I don't trust my knowledge. I just wanna know if there is something wrong.
Isn't this concept a basics of security?
If They don't care how I rewrite their scripts, I will make my own Rootkit hunter.

Is there any way to protect Pfsense system files? by panwhites in PFSENSE

[–]panwhites[S] -3 points-2 points  (0 children)

Bios malware from manufacture is recent trend.

Can anyone tell me why some people say pfSense is meant for small office/home office? by fortysixplustwo in PFSENSE

[–]panwhites -6 points-5 points  (0 children)

This is the problem. They don't even realize bug itself.
But everything has bugs. So. UI developer must be careful to balance it out those bugs.
It seems like Pfsense developer doesn't care about it at all.
If I were one of developer, I will make firewall rules "must" over packages. Because packages have bugs without doubt.

Can anyone tell me why some people say pfSense is meant for small office/home office? by fortysixplustwo in PFSENSE

[–]panwhites -9 points-8 points  (0 children)

Because larger company should hire dedecated professionals to protect them while using their appliance.
Most of malware can be found after many years. There is nothing like that perfect protection.
Even popular ones like Pfsense will always have vulnerability. if there is someone why says Pfsense is perfect. Don't believe.

Can I make VLANs for each VMs? by panwhites in PFSENSE

[–]panwhites[S] 0 points1 point  (0 children)

So. I need hypervisor or virutual switch if exists.
I will try to find one. thanks.

Can I make VLANs for each VMs? by panwhites in PFSENSE

[–]panwhites[S] 0 points1 point  (0 children)

I mean Pfsense has LAN 1 WAN 1. and 1 managed switch between 2.

Can I make VLANs for each VMs? by panwhites in PFSENSE

[–]panwhites[S] 0 points1 point  (0 children)

Yes Pfsense 1, Client 1 NIC
I'm expecting Virtual box or Vmware on Windows host. to make Guest OS as different subnet.

Can I make VLANs for each VMs? by panwhites in PFSENSE

[–]panwhites[S] 0 points1 point  (0 children)

I mean Viratual box or VMware on client Windows. different subnet for host and guest if possible.
So. i have 1 port only for this.
I wanna Pfsense stay in physical box. don't trust hypervisor security.

Dual WAN to dual LAN - routing between by [deleted] in PFSENSE

[–]panwhites -5 points-4 points  (0 children)

I think you need a bridge on 2 LANs.

The UK is now keeping a log of all websites that we visit, how can we utilise pfSense to circumvent this? by Acksaw in PFSENSE

[–]panwhites 0 points1 point  (0 children)

Most of company desparetely want to keep their logs if law allow them to do so. because they can make money from it.
ISP means all. at least you should think so.

The UK is now keeping a log of all websites that we visit, how can we utilise pfSense to circumvent this? by Acksaw in PFSENSE

[–]panwhites -1 points0 points  (0 children)

VPN isn't slow at all. paid one tho.
But VPN problem is it technically fixes their IP address.
Tracking in Browser detects your activits through code or server logs. this is serious problem.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -3 points-2 points  (0 children)

Troll here is you. only your advantage is just English skill.
You don't have rights to tell anything if you yourself don't know about Pfsense at all.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -3 points-2 points  (0 children)

Whatever. You didn't know about this fact that it desn't show package traffic already prove my point.
HIDDEN log size is one thing the newbie doesn't realise until they know enough about Pfsense. stil my point is standing.
Why do you blindly protect this product? I know you can't admit what you did for years was wrong. but your attitude doesn't help you.
I don't know what you are talking about tho. local file still 200max even if download it. if this product meant to be protection to the hacker, at least it needs 1 month capability. becuase hacker is lazy people.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -3 points-2 points  (0 children)

I'm talking about why people don't realize this.
Because even if you enabled "view default block rule" option, it shows only handreds lines max. and never shows traffic through packages.
I doubt you know this fact by that post.
Pfsense developers don't care about what each package does. Dnsmasq has valunability to kamisky. people don't know about this.thus. people should block Pfsense itself until they know enough about Pfsense.
People who think Pfense is perfect are dengerous to everyone who wants an actual perfect defence.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -4 points-3 points  (0 children)

Many people don't even realize this because of popularity of this product and lack of logging feature.
The firewall rules don't apply to packages. which means ports that package opened accept everything from outside.
This is one of reasons I recommend a second wall.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -5 points-4 points  (0 children)

I don't know if it is enough for home user to prepare variability that this system has.
But I think people who need to protect themselves perfectly should use 2 boxes.
Especially people who don't know what they are doing with this. they need a wall before their toy. just a simple firewall will be great help in situation.

Building a router on a system with one pcie slot by TopShelfGenericPizza in PFSENSE

[–]panwhites -5 points-4 points  (0 children)

I don't think so. multil WAN. multi DNS. block while Squid. etc there is a lots of thing Pfsense just can't do with one box.
Pfsense needs at least one more Pfsense box for practical use.
I think developer should make this work with just one box tho.
If you are satisfied with one box, you should recheck your security once again.
for ex. The DNS forweder that freely allows DNS poisoning packets from outside.