Tuesday, April 24, 2018

P3n-T3st

To learn about Penetration Testing:

http://www.securitytube.net

https://www.offensive-security.com

Wednesday, September 14, 2016

AWS Cloudwatch to S3


I've been researching on how to move Cloudwatch logs to S3 Bucket for archiving purposes. Cloudwatch logs can be manually exported as one of its Action menu. Maybe in the future it can be one of its feature to automate but right now I need to create a solution to automate it.

Good thing there is an AWS CLI we can use to automate it. First you need to install the python AWS plugin in able to use it.

https://pypi.python.org/pypi/awscli-cwlogs/1.4.0

Once installed, in may case, I use a linux box for my automation tool (e.g. Puppet, git, ansible, etc.). I just created a cron job that will export the logs to S3 bucket.

0 0 * * * /usr/local/bin/aws logs create-export-task --task-name "LogExport1" --log-group-name "Windows" --destination "prod-os-logs1" --destination-prefix "WindowsLogs/$(date)" --from "$(($(date +\%s\%3N) - 86400000))"  --to "$(date +\%s\%3N)"

Where "Windows" is Cloudwatch log group and "prod-os-logs1" is S3 Bucket

Saturday, July 9, 2016

Kali Linux - PenTest

"Need to keep on Learning or else you'll get obsolete"


Learning Kali Linux



Tuesday, March 29, 2016

Packet Generator

Good application for testing and analysing packets

http://ostinato.org

Tuesday, March 8, 2016

IETF best current practices (BCP) (Link/s)

For Reference:

https://www.ietf.org/rfc/bcp-index.txt

https://en.wikipedia.org/wiki/Best_current_practice

Thursday, November 20, 2014

Big Data

I'm currently learning what this Big Data specifically using Apache's Hadoop is all about and I can say its a a Big WOW just by imagining how much data it can process. If you're an IT guys like me that has Database administration background using MS-SQL, MySQL, Oracle, etc, you would ask how those all the data (syslog, weblog, sales, etc.) can be imported to a database and make use of it or produce information that can help the business or customers.

Big Data can use or import using Pig (can eat anything) or if you're not much of a java programmer, a Hive can be use to create a MapReduce jobs. There are also tools like Sqoop and Flume that can help importing file or streaming data.

Good thing also about Hadoop is that the License is under Apache, which means no one OWNS it and the public community can use it, for Free.

Link:

http://hadoop.apache.org

Monday, September 8, 2014

Python 101

With SDN on the rise, network engineer should know how to use either Java or Python in able to manage the Controller to talk to the API.

Google has a basic Python class available to begin with:

https://developers.google.com/edu/python/


Happy Scripting!!!


UPDATE: Playing with Python..

With the recent Earthquake in the Philippines last January 11, 2015 at around 3:30AM (Phil. Time) that reach 5.9 Magnitude, I though maybe I can create an image (Data Visualisation) on where is the centre of the earthquake. So here's python to the rescue. Since I been reading for awhile regarding what other modules can do, I ended up using Basemap. The script below has 2 parts. First is to grab dataset from the cvs file. The columns are Latitude, Longitude and Magnitude. The second part is the engine for the script where Baseman is being used to create the image.

For the result, the red dot will got bigger if the magnitude is higher.

----------------------------------------------------------------

# Import Dataset
import csv

filename ='DS.csv'

lats, lons = [], []
mags = []

with open(filename) as f:
    # Create a csv reader object.
    reader = csv.reader(f)

    # Ignore the header row.
    #next(reader)

    # Store the latitudes and longitudes in the appropriate lists.
    for row in reader:
        lats.append(float(row[0]))
        lons.append(float(row[1]))
        mags.append(float(row[2]))

#----------------------------------------------------------------

from mpl_toolkits.basemap import Basemap
import matplotlib.pyplot as plt
import numpy as np

## Philippine Map coordinates
m = Basemap(resolution='f',projection='merc',                                        
            lat_0=13, lon_0=122,
            llcrnrlat=5.0,                                                         
            urcrnrlat=19.0,                                                          
            llcrnrlon=114.,                                                          
            urcrnrlon=130.0,                                                         
            ) 

m.drawmapboundary(fill_color='white')                                                
m.fillcontinents(color='#F5DEB3',lake_color='#85A6D9')                               
m.drawcoastlines(color='black', linewidth=.4)                                        
m.drawcountries(color='#6D5F47', linewidth=.4)                                       

min_marker_size= 2.5
for lon, lat, mag in zip(lons, lats, mags):
    x,y = m(lon, lat)
    msize = mag * min_marker_size 
    m.plot(x,y, 'ro', markersize=msize)

figsize=(50, 18)

plt.show()

DS.csv
09.97,124.17,2.6
11.64,126.10,3.2
11.55,126.31,3.1
11.59,126.23,4.9
04.87,127.19,3.7
06.17,126.02,2.5
14.79,120.00,2.3
05.69,126.26,4.2
14.74,119.91,5.9


Final image:


Sunday, September 7, 2014

I'm Back.....

Wow, it's been years since I last blog. Since then, I finished my CCNP for Routing and Switching as well as for Security. I'm also been active CISSP since then.

Now for my biggest challenge of all..CCIE. I can say that this exam is a Beast. I've built my ccie home lab from old Cisco routers and switches and it's been a year since I started studying. The good thing about it is that the more I study, the more I know that there are lots of things to learn, and the the more things I've learn, the more I can design network efficiently and securely.

I'll be posting more configuration setup here for me to refresh my memory and hopefully help others as well.....

Happy Studying.....

Friday, December 23, 2011

Whoohaa

Finally got my CISSP exam result after a month of waiting, now time for endorsement. Also need 1 more exam for my CCNP..

Friday, October 21, 2011

iperf server

It's been a while since I last post. I've been busy designing and implementing our BGP routers and Core switches. Also, I've been studying for my CCNP and CISSP exams. (Whew!!).
Anyway, I just want to share the tool I used to test your network bandwidth (Internet, Site to site, etc.). I used iPerf in a linux box. It uses a client/server type of testing.

If you want an iPerf server to test your Internet link, send me your email so I can provide you the details...

Monday, May 16, 2011

Security Awareness 101

This is a good source of information for basic IT security awareness. It was used to educate people during APEC summit though it was old, the information is still relevant for today's technology.

Thursday, May 12, 2011

How to start your Security Awareness Program?

I must say I'm still in the process of learning and practising IT Security but I know I got a good background in securing an environment as I worked on every aspect of Information Technology. In a usual IT environment, the company has Active directory for Identity and Access control, Firewall and router for Network Connectivity, Antivirus, Mail, Backup and File servers. Now how would you start your security program? You cannot just start mandating all your employees to do this and that. In able to have a successful security program, at least to start, is to have the Top executive back you up in the program. You must get their approval on why security is needed and how will the company benefit. The program should also align with the company's mission and vision statement. A program would be hard to implement if there is no budget allocated. In able to get the figures, you can start with Risk Assessment. This will give you an overall view on what your assets (Data, Information, Process, etc) are and which one needs to be secure. The assessment is a long process but it would be able to give you a figure on how much to secure the company's assets.

Now how would you direct the program to the end-user?. For me I started it by putting Posters at the common area. I printed on an A4 paper regarding how valuable a strong password are and how to create a strong and complex password.

Wednesday, July 21, 2010

Generating keystore

To generate keystore file, a tool called keytool by Java is used to generate certificates. Make sure to use the latest java release to use the latest security library.

Check Java version:

#java -version

Generating keystore:

keytool -genkey -alias -keyalg -keysize -keystore keystorefile

Example:

#keytool -genkey -alias myalias -keyalg RSA -keysize 2048 -keystore mykeystore.

Note: it will ask for the password to the keystore and alias. It can be the same.


Generate CSR:

keytool -certreq -alias -keystore -file

Example:

#keytool -certreq -alias myalias -keystore mykeystore -file mycsr.csr.

Note: it will prompt you for the keystore password specified above procedure.


Send the CSR to Public CA like TPP Internet, Thawte, etc. . After sending the file, download the corresponding CRT file for the domain created.

Importing CRT:

#keytool -import -trustcacerts -alias -file -keystore

Example:

keytool -import -trustcacerts -alias myalias -file certfromca.crt -keystore mykeystore

Thursday, July 8, 2010

Redhat - Reduce size of root file system

The default file system layout from the Red Hat Enterprise Linux 5 installation process includes a special space for /boot and swap space then gives all left space to one logical volume and used the logical volume as root / volume.

Integrating all data files and system files in one file system is not always an ideal choice for production systems. If the system cannot be reinstalled, it is possible to reduce the size of the root file system and the logical volume on which it resides.

Reducing the logical volume on the root / volume must be done in rescue mode.

First, boot the system from Red Hat Enterprise Linux 5 Disc 1, and at the prompt, type linux rescue and press enter. When prompted for language, and keyboard, provide the pertinent information for the system. When prompted to enable the network devices on the system, select "No." Finally, select "Skip" when prompted to allow the rescue environment to mount Red Hat Enterprise Linux installation under the /mnt/sysimage directory. The filesystems MUST NOT be mounted to carry out the following steps.

Next run following commands to scan all disks LVM2 volume groups:

# lvm.static vgscan

Next, activate the logical volume to reduce. In this example, /dev/VolGroup00/LogVol00 was made available with the following command:

 # lvm.static lvchange -ay /dev/VolGroup00/LogVol00  

Next, reduce the size of file system and logical volume on /dev/VolGroup00/LogVol00. Please make sure there is enough space left on the root / file system and that the logical volume is large enough to contain all the data that was previously present. If the file system is at close to being full, for example, this may not work. Before resizing file system, run e2fsck to check file system first.

 # e2fsck -f /dev/VolGroup00/LogVol00 # resize2fs /dev/VolGroup00/LogVol00 3000M # lvm.static lvreduce -L 3000M /dev/VolGroup00/LogVol00  

Please note that this is done on /dev/VolGroup00/LogVol00. The number at the end is the final size of the file system, not the amount it is reduced by.

Finally, verify the modification then reboot the system.

 # lvm.static vgdisplay VolGroup00 # exit  

Wednesday, July 7, 2010

Mobile Device Management & Wireless Expense Management | MobileIron

People nowadays are using their mobile phone to access their corporate emails but the concern is how they could provide security for both end-user as well as the company.

Now the company can put into their own infrastructure or hosted one to provide this kinda of security. The product is called MobileIron.

Mobile Device Management & Wireless Expense Management | MobileIron

The company based in Sydney Australia called ManageNET can provide this kinda of service. link: http://www.managenet.com.au/solutions/mobile_device_management

Friday, July 2, 2010

Manual: CIS benchmark tests

This is a great tool to use if you want to benchmark your Linux box prior to deployment or audit the system against CIS Security benchmarks. Aside from this rootcheck, OSSEC can provide a server-client setup to run the file system integrity check (or other HIDS) to comply with PCI Compliance.

Reference: Manual: CIS benchmark tests

Manual: CIS benchmark tests

We just included support in the OSSEC Policy monitor to audit if a system is in compliance with the CIS Security Benchmarks (as of right now, only RHEL2-5, Fedora 1-5 and Debian/Ubuntu are supported - the other versions will be soon).

If you want to try it out manually and provide some feedback to us, please follow the instructions bellow to test:

First, grab the latest CVS snapshot and compile it (it will be included on v1.6 and above):

# wget http://www.ossec.net/files/snapshots/ossec-hids-080710.tar.gz
# tar -zxvf ossec-hids-080710.tar.gz
# cd ossec-hids-080710/src/
# make clean
# make libs
# cd rootcheck
# make binary

The binary ossec-rootcheck will be created on the current directory and we can start using it. A simple scan on my Ubuntu box looked like this: (note, that it will do all the normal rootcheck tests plus the CIS scans — just grep for CIS if you don’t want to see the rest):

# ./ossec-rootcheck
..

[INFO]: System Audit: CIS - Testing against the CIS Debian Linux Benchmark v1.0. File: /proc/sys/kernel/ostype. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 1.4 - Robust partition scheme - /tmp is not on its own partition. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 1.4 - Robust partition scheme - /var is not on its own partition. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 2.3 - SSH Configuration - Root login allowed. File: /etc/ssh/sshd_config. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 2.4 - System Accounting - Sysstat not enabled. File: /etc/default/sysstat. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 4.18 - Disable standard boot services - Squid Enabled. File: /etc/init.d/squid. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 7.2 - Removable partition /media without ‘nodev’ set. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 7.2 - Removable partition /media without ‘nosuid’ set. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 7.3 - User-mounted removable partition /media. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

[INFO]: System Audit: CIS - Debian Linux 8.8 - GRUB Password not set. File: /boot/grub/menu.lst. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .

..


Wednesday, June 30, 2010

Creating bootable USB using UNetbootin

This is a cool tool in creating a bootable USB drive

Reference: UNetbootin - Homepage and Downloads

Monday, June 28, 2010

MCITP: Enterprise Administrator certified

Finally passed my last exam to become an MCITP: Enterprise Administrator certified..

How do I use Problem Steps Recorder?

This is a very cool tool called Problem Steps Recorder for a Call support to see what is happening on their client's PCs during troubleshooting. Basically what it does is it takes a screenshots of every steps the client made on the PC. After it record, a zip file will be generated and can be send out to support for troubleshooting.

Here is the link to the Microsoft Website: How do I use Problem Steps Recorder?


  1. Open Problem Steps Recorder by clicking the Start button Picture of the Start button, and then typingpsr. In the list of results, click psr.

  2. Click Start Record. On your computer, go through the steps on your computer to reproduce the problem. You can pause the recording at any time, and then resume it later.

  3. Click Stop Record.

  4. In the Save As dialog box, type a name for the file, and then click Save (the file is saved with the .zip file name extension).

    To view the record of the steps you recorded, open the .zip file you just saved, and then double-click the file. The document will open in your browser.

  • After recording and saving a .zip file, click the help down arrow Picture of help down arrow, and then click Send to E‑mail recipient. This will open an e‑mail message in your default e‑mail program with the last recorded file attached to it.

    Note

    Note

    You won't be able to click the Send to e‑mail recipient option until you've recorded and saved a file.

  1. Open Problem Steps Recorder by clicking the Start button Picture of the Start button, and then typingpsr. In the list of results, click psr.

  2. Click Start Record.

  3. When you want to add a comment, click Add Comment.

  4. Use your mouse to highlight the part of the screen that you want to comment on, type your text in the Highlight Problem and Comment box, and then click OK.

  5. Click Stop Record.

  6. In the Save As dialog box, type a name for the file, and then click Save.

    To view the record of the steps you recorded, open the .zip file you just saved, and then double-click the file. The document will open in your browser.

When you adjust settings for Problem Steps Recorder, they're only saved for your current session. After you close and reopen Problem Steps Recorder, it will return to the regular settings.

  1. Open Problem Steps Recorder by clicking the Start button Picture of the Start button, and then typingpsr. In the list of results, click psr.

  2. Click the help down arrow Picture of help down arrow, and then click Settings.

  3. You can change the following settings for Problem Steps Recorder:

    • Output Location. If you don't want to be prompted to save a file after recording, click the Browse button to set a default output file name.

    • Enable screen capture. If you don't want to capture the screen shots along with the click information, select No. This might be a consideration if you are taking screen shots of a program that contains personal information, such as bank statements, and you are sharing the screen shots with someone else.

    • Number of recent screen captures to store. While the default is 25 screens, you can increase or decrease the number of screen shots. Problem Steps Recorder only records the default number of screen shots. For example, if you took 30 screen shots during a recording but only had 25 screen shots as the default, you would be missing the first five screen shots. In this case, you would want to increase the number of default screen shots.