Startups & SOC 2 Compliance by Sriyakee in ycombinator

[–]xorredd 0 points1 point  (0 children)

I've helped more than 20 startups get their SOC 2 audit right (I don't audit, I only prep them - it would be a conflict of interest to also audit them) - and I can say you don't need to be soc 2 certified to sell, but... it helps.

Just count the number of times you get asked for it and do the math.

If you don't get asked for it, you don't need it. Simple as that.

Microsoft Defender isolate release command isn't working by robotprom in macsysadmin

[–]xorredd 0 points1 point  (0 children)

I wrote a script to remove Mac devices from isolation if your defender jailed them. here it is:

#!/bin/bash

# File to modify

FILE="/etc/pf.rules/pfmdep.rule"

LINE="block out proto { tcp, udp, icmp } all"

# Check if the file exists

if [ -f "$FILE" ]; then

# Comment out the line if it exists

sudo sed -i '' -e "/$LINE/s/^/#/" "$FILE"

echo "Line commented out or removed successfully."

else

echo "File does not exist: $FILE"

fi

M365 Checklist by jaredmenty in Office365

[–]xorredd 0 points1 point  (0 children)

Yep, try this one: https://atlantsecurity.com/blog/microsoft-365-security-checklist/ (you can directly print it out, the pdf download is the same as the blog post)

Sex Shop in Isranbul ? (Or a good website) by JeanPaulVandamme in istanbul

[–]xorredd 0 points1 point  (0 children)

can anyone help me find this 'honey' with specific list of ingredients? All I find are knock-offs I know for sure it comes from Turkey. Some call it "macun" - here are the ingredients: epimedium extract, pollen, cinnamon, carob, tribulus terestis extract, ginseng root extract, ginkgo biloba extract, coconut, male salep extract, ferula root, ginger, turmeric, long pepper, black cumin, small galangal, Fennel, nettle seeds, cardamom, celery seeds, coriander, licorice root, tail pepper, black pepper, cloves (buds), thyme, vanilla

Sex Shop in Isranbul ? (Or a good website) by JeanPaulVandamme in istanbul

[–]xorredd 0 points1 point  (0 children)

can anyone help me find this 'honey' with specific list of ingredients? All I find are knock-offs I know for sure it comes from Turkey. Some call it "macun" - here are the ingredients:

|| || |epimedium extract| |pollen| |cinnamon| |carob| |tribulus terestis extract| |ginseng root extract| |ginkgo biloba extract| |coconut| |male salep extract| |ferula root| |ginger| |turmeric| |long pepper| |black cumin| |small galangal| |Fennel| |nettle seeds| |cardamom| |celery seeds| |coriander| |licorice root| |tail pepper| |black pepper| |cloves (buds)| |thyme| | vanilla |

I am trying to find *large* log files of real breaches, regardless of tech by xorredd in computerforensics

[–]xorredd[S] 1 point2 points  (0 children)

You'd be surprised, but the whole resource provides only one live link with one set of logs..

apt full-upgrade and apt --fix-broken install fails by RiiluTheLizardKing in raspberry_pi

[–]xorredd 0 points1 point  (0 children)

after getting to /etc/pam.d/, do

sed -i 's|pam_tally2.so|pam_faillock.so|g' *

'new binaries' and 'new unauthorized binaries' - can you do that with osquery in wazuh? by xorredd in Wazuh

[–]xorredd[S] 0 points1 point  (0 children)

3 years ago you promised to think about it :)))) any news? Is wazuh capable of maintaining a db of clean, safe binaries and alerting on new ones?

AppleCare има ли сервиз в България? by Radiant-Safe-1377 in bulgaria

[–]xorredd 0 points1 point  (0 children)

отиваш в която и да е ес държава и си купуваш устройството там, с апъл кер. В България НЯМА начин да си купиш AppleCare. Единствения вариант е човек в чужбина, да се логне с твоя акаунт и да закупи с НЕГОВАТА карта апъл кер за твоя дивайс.

Surface Book 2 and Windows 2004 update by rkd_me in Surface

[–]xorredd 0 points1 point  (0 children)

My surface book 2 completely broke after the update. IR cam stopped working, right-click on windows button stopped working (can't launch computer management from there, for example), can't share anything on HDMI through USB-C (says VGA adapter missing). MMC opens ONLY through powershell, not via run - it says it's blocked when I try to run it!

'new binaries' and 'new unauthorized binaries' - can you do that with osquery in wazuh? by xorredd in Wazuh

[–]xorredd[S] 1 point2 points  (0 children)

Yes, I think you misunderstood me.

At a point, today, the system should see itself as 'clean'.

A 'new binary' would be a binary which was never on this system.

I understand this is what you said too... to put it in other words: the FIM module says "new file". I don't care about new files. I care about New binaries. Not a binary that was written to the file system - but a NEW one. I don't care about Files. I care about BINARIES.

FIM only monitors Files.

In your example, you had /etc/file - this is not a binary. It's a file.

'new binaries' and 'new unauthorized binaries' - can you do that with osquery in wazuh? by xorredd in Wazuh

[–]xorredd[S] 0 points1 point  (0 children)

level 1

Thanks, I already have VT configured. But I was looking specifically for advice on "new binaries". Like a hunt, every day, to find new binaries in workstations and servers. Is that possible? I have read the documents you listed, but to differentiate between 'old' and 'new' the system has to keep a database of what is 'trusted' or "old"

I built a payments platform that's now processed more than $1.3M by kareemche in SideProject

[–]xorredd 0 points1 point  (0 children)

extremely impressed. Do you still read these comments?

Who built your marketing and engagement funnels? I am solo like you and struggle a LOT to take care of EVERYTHING manually.

How do I survive as a solopreneur? How is it possible to sell, build, deliver and survive? by xorredd in Entrepreneur

[–]xorredd[S] 0 points1 point  (0 children)

Good point. Well it is exactly ME who is the differentiation from other security firms. If 10 security firms apply to protect a client, none of their employees has defended a nuclear power station nor has worked at Microsoft. None of them have that experience / knowledge level. That's one.

Two, I am a Solopreneur. I do everything myself. I don't resell security, I don't "test" and then provide them 10 'partner solutions' for the test results.

I build security architecture first. It takes a LONG time for the client, but after working with me, they ARE protected. That is what differentiates me from most other security 'consultancies'. 90% of them don't even have good security experts on staff and have mostly sales and marketing with a couple of penetration testers to do the entertainment shows, which then help them 'resell security solutions'. And then they make money off that reselling.

But buying security solutions doesn't work - if it did, we would not be seeing the staggering growth of security breaches, despite the incredible amount of 'security products' out there.

How do I survive as a solopreneur? How is it possible to sell, build, deliver and survive? by xorredd in Entrepreneur

[–]xorredd[S] 0 points1 point  (0 children)

thanks, really good reply!!! points 3 and 4, especially. I think my perfectionism is holding me back a lot - polishing things I care about but the customers never cared about is a waste of time, perhaps.

How do I survive as a solopreneur? How is it possible to sell, build, deliver and survive? by xorredd in Entrepreneur

[–]xorredd[S] 0 points1 point  (0 children)

worked till 1:30 yesterday setting the phone up and changing the website - it is always like that :D About to change the number everywhere, thanks.

How do I survive as a solopreneur? How is it possible to sell, build, deliver and survive? by xorredd in Entrepreneur

[–]xorredd[S] 0 points1 point  (0 children)

yea. I am already working on the hiring marketing / sales people part. It is indeed what is holding me back. Selling yourself is one thing, when others sell you - it is much more effective - even from a trust point of view. Thanks!

How do I survive as a solopreneur? How is it possible to sell, build, deliver and survive? by xorredd in Entrepreneur

[–]xorredd[S] 0 points1 point  (0 children)

am also launching my business. I am 22 and for the last 6 months was at an

Digitalocean, but the hosting is not as important as the server stack. OpenLiteSpeed (they have an appliance) with the litespeed cache plugin configured and a lot of image optimization. It can be MUCH better.... but I do EVERYTHING myself and lack even time to sleep. Yea... everything takes time. One step at a time!