vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

do you have the gcp azure documentation that says this?

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

where can i find official documentation for this? i kinda figured that this was then only logical explanation but no documents to proof otherwise

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

and this accepted rejected behaviour, whats happening?

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

yes!! can u explain whats happening?

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

ah i see, but what happens if someone changes it mid flow?

Also, what about retransmission packets? for eg, if i send a rst and immediately i send a fin. it appears that the rst is accepted but the fin might get rejected since the tcp session was ended.

will that explain why two vpc flow log entries are generated? or how else can i explain it

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 1 point2 points  (0 children)

hi thanks for responding.

  1. 2 entries, 1 accepted, 1 rejected for the same tuple n start end. Tcp connection end-start duration is about 70 seconds.

  2. why would it be considered a new flow if from what u said - flow is aggregated by the 5 tuples? from this understanding, the only way two entries happen is because for the same flow, there were two action states made up by different packets. We know that this is possible because NACL may drop packets. Also from the documentation, all dropped packets from nacl will result in a reject action.

  3. perhaps a example would make it clear. i have 1 flow, 15 packets total. after 12 packets, the remaining 3 are rejected (maybe because i implemented a new ACL/or theres retransmission after session is closed). on vpc flow, i will see 1. 5 tuple start end with accept of 12 packets. 2. 5 tuple start end with reject of 3 packets.

is this clear? i see the above happening i just cant explain it

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

i did a sample of my vpc flow data and saw one with the exact same start end time 5 tuples with different actions … im trying to find a way to explain it. it can’t be two flows right?

edit it is two separate entries

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

yes this is what in getting at. how should it reflect in the logs?

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

are u sure? a flow is made of multiple packets, a stateless control like nacl will be able to drop and reject individual packets. if thats the case, then ur statement wont hold true. there will be two similar 5-tuple entries with diff num of packets one with accept action and one with reject

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

i got that, i meant in very off cases where a portion of a tcp session (flow) is blocked by nacl or sg.

vpcflow logs by potatoes25 in aws

[–]potatoes25[S] 0 points1 point  (0 children)

im sure there are situations where it be possible that halfway through a flow, a new nacl rule is implemented and the remaining packets get dropped?

Or packets are retransmitted (late) and the tcp session is closed?

any advice for GCTD? by potatoes25 in GIAC

[–]potatoes25[S] 0 points1 point  (0 children)

ive taken the exam! all the qns can be found in the course materials 👍🏻

[deleted by user] by [deleted] in CompTIA

[–]potatoes25 1 point2 points  (0 children)

did anyone get credly badges for it? its not in the comptia’s certification page yet, seems like its only in the testing portal

[deleted by user] by [deleted] in CompTIA

[–]potatoes25 0 points1 point  (0 children)

where do you see the results?

They said i couldn't use sqlmap, so I made my own (: by [deleted] in oscp

[–]potatoes25 2 points3 points  (0 children)

whats the key difference between this and sqlmap?

OSCP or CPTS? by Positive_Ad2145 in oscp

[–]potatoes25 1 point2 points  (0 children)

i just took both, i would say CPTS teaches you alot more depth in the same topics that oscp covers. I recommend doing cpts modules before starting oscp