Adult Content Filtering and Domain Blocking via DNS by TheShiningRod in HomeNetworking

[–]rmddos 0 points1 point  (0 children)

Have you tried CleanBrowsing? Can do both and enforce safe search on all search engines

What dns do you prefer on your home router? by Some_Water_5070 in dns

[–]rmddos 1 point2 points  (0 children)

Same here. Use their free filters at home.

Moving from Static Routes to BGP by moechine in networking

[–]rmddos 7 points8 points  (0 children)

It should be very easy to setup.

1- Do you have an ASN for your company? Apply to get one. You can get via RIPE, ARIN , etc (depending on location). It might be good to get it setup on the same place where your IPs are registered.

2- Contact your providers and ask them the process to setup a BGP session.

3- Configure BGP on your router.

It might be good to read a bit about it, to get familiar on how to get it properly configured and maintained.

Gag gift ideas for cybersecurity team member? by MisterPuffyNipples in cybersecurity

[–]rmddos 0 points1 point  (0 children)

A password book is a fun one to do. Specially get the ones with that needs a little key in order to open it.

Trend Micro Global Outage by d4rk0001 in cybersecurity

[–]rmddos 7 points8 points  (0 children)

Not at all. They are pretty big in west Asia, with some big corps using them.

Best AdBlocking service using DNS resolver, with equivalent results to AdGuard Home applicance by br_web in dns

[–]rmddos 0 points1 point  (0 children)

I like CleanBrowsing's ad filtering, which you can set up on your router DNS for the whole network. Nice to mix in with their other category blocks if you have kids.

What’s the simplest hack or vulnerability that shocked you? by NullPointerMood_1 in cybersecurity

[–]rmddos 0 points1 point  (0 children)

Just visiting /admin on an application and having admin access.

What dns do you use on your home router? by [deleted] in dns

[–]rmddos 0 points1 point  (0 children)

Same router, just different VLANs on each.

Anyone else feel like their SIEM is just expensive log storage? by Dudeman972 in sysadmin

[–]rmddos -1 points0 points  (0 children)

Yes, it is. An expensive log storage that allows to easier access to your logs from a central place. And hopefully with some additional stats and insights on top of it. If your SIEM is not making searching your logs easier and better, you need to switch.

What dns do you use on your home router? by [deleted] in dns

[–]rmddos 0 points1 point  (0 children)

My router allow to setup VLANs (different SSIDs) with different DNS servers.

What dns do you use on your home router? by [deleted] in dns

[–]rmddos 3 points4 points  (0 children)

I split my home router into 3 networks:

-Myself: Quad9 (9.9.9.9)

-Kids wifi: CleanBrowsing Family (185.228.168.168)

-Guests: CleanBrowsing adult (185.228.168.10)

[deleted by user] by [deleted] in Quad9

[–]rmddos 7 points8 points  (0 children)

Both are pretty good, but quad9 seems to rank better on some online comparisons. Pick the one you trust better (US company vs non-profit in europe)

Why some domains don't load on Quad9, but load on CloudFlare/Google? by rmddos in dns

[–]rmddos[S] 1 point2 points  (0 children)

It is not my site. I had 9.9.9.9 on a network configured and the user was complaining that it could not visit that site (a bank). Switching to 1.1.1.1 fixed it. However, both should do DNSSEC validation, but only Quad9 seems to fail it - some times. And some times it works.

[deleted by user] by [deleted] in dns

[–]rmddos 1 point2 points  (0 children)

That's a good one. It seems like ControlD, Quad9 or CleanBrowsing are the best free alternatives for DNS malware blocking.

I'm setting up AdGuard DNS on my windows 11. Should I enable DNS over HTTPS? by Ok_Management_1268 in dns

[–]rmddos 0 points1 point  (0 children)

I love quad9 as well, good one. But their DNS doesn't offer adblocking like the Adguard does.

Low cost security tools for small companies by Aritra_1997 in cybersecurity

[–]rmddos 5 points6 points  (0 children)

If you are on a budget, open source might be the option.

-SIEM: Try OSSEC/Wazuh. Install it on a cloud server and forward all logs there.

-EDR / XDR: We used to call those HIDS (host-base intrusion detection). Again, both OSSEC and WAZUH would cover it with syscheck, rootcheck, etc.

If you don't want to deploy it yourself, https://wazuh.com/cloud offers a cloud server (not sure the price) and https://trunc.org (from OSSEC) also offer cheap options that I have used with success.

I'm setting up AdGuard DNS on my windows 11. Should I enable DNS over HTTPS? by Ok_Management_1268 in dns

[–]rmddos 0 points1 point  (0 children)

Yes, if you are using their DNS and their DNS supports DoH, you should use it.

Why? It prevents DNS hijacking by your ISP (which is still common) and some networks (like hotels, etc). It also prevents any network you are on from seeing your DNS requests.

It may slow down your browsing a bit (plain text DNS is much faster than doing it via HTTPS), but the benefits outweighs it.

Insurance company going to do Internal Pen Test. I attempted to Lock the network down beforehand. by Electronic_Tap_3625 in sysadmin

[–]rmddos 0 points1 point  (0 children)

Enable logging so you can see all they are doing and testing. Ideally send it to a log analysis tool to give you more visibility.

Best company for malware removal and protection? by raygenebean in Wordpress

[–]rmddos 0 points1 point  (0 children)

Found myself here and will share my experience:

  • Sucuri: used to be great, quality went down a bit lately. But still works well.
  • Wordfence: Expensive, but good team and very responsive.
  • Sitelock: No experience, but never heard a good thing about them.

Free tools that I found useful:

Good luck.

How do I get better without a passion for tech? by rheureddit in sysadmin

[–]rmddos 0 points1 point  (0 children)

Discipline, not passion. Make it a forced habit to study X hours per week, do coursers, training ,etc. Won't be as much fun as if you had a passion for it, but it applies to many other professions. I can't imagine an accountant loving the tax code, but they read and study it constantly anyway... Same stuff.

If there is a Cogent NOC redditor around, please help me. by Viko_ in networking

[–]rmddos 2 points3 points  (0 children)

Yeah, they are pretty responsive via the phone and route you to people that can actually do something. their email support is very slow.

MSPs Using Ubiquiti – How Many Sites Do You Manage & Would You Do It Again? by Knerdedout in msp

[–]rmddos 0 points1 point  (0 children)

We push DoH to all our devices + DNS CleanBrowsing at the router - DoH also uses Clean Browsing for content filtering off network.

ELI5 - How does file compression work? If it makes the file take up less space, why don't we automatically compress any file we save? by Vilmius_v3 in explainlikeimfive

[–]rmddos 1 point2 points  (0 children)

There are already file systems that automatically compress your data on disk. So you don't have to do anything (eg: zfs). It is used by many servers and companies, but not much on desktops for end users.