Tuesday, April 24, 2018
P3n-T3st
http://www.securitytube.net
https://www.offensive-security.com
Wednesday, September 14, 2016
I've been researching on how to move Cloudwatch logs to S3 Bucket for archiving purposes. Cloudwatch logs can be manually exported as one of its Action menu. Maybe in the future it can be one of its feature to automate but right now I need to create a solution to automate it.
Good thing there is an AWS CLI we can use to automate it. First you need to install the python AWS plugin in able to use it.
https://pypi.python.org/pypi/awscli-cwlogs/1.4.0
Once installed, in may case, I use a linux box for my automation tool (e.g. Puppet, git, ansible, etc.). I just created a cron job that will export the logs to S3 bucket.
0 0 * * * /usr/local/bin/aws logs create-export-task --task-name "LogExport1" --log-group-name "Windows" --destination "prod-os-logs1" --destination-prefix "WindowsLogs/$(date)" --from "$(($(date +\%s\%3N) - 86400000))" --to "$(date +\%s\%3N)"
Where "Windows" is Cloudwatch log group and "prod-os-logs1" is S3 Bucket
Saturday, July 9, 2016
Tuesday, March 29, 2016
Tuesday, March 8, 2016
IETF best current practices (BCP) (Link/s)
https://www.ietf.org/rfc/bcp-index.txt
https://en.wikipedia.org/wiki/Best_current_practice
Thursday, November 20, 2014
Big Data
Big Data can use or import using Pig (can eat anything) or if you're not much of a java programmer, a Hive can be use to create a MapReduce jobs. There are also tools like Sqoop and Flume that can help importing file or streaming data.
Good thing also about Hadoop is that the License is under Apache, which means no one OWNS it and the public community can use it, for Free.
Link:
http://hadoop.apache.org
Monday, September 8, 2014
Python 101
Google has a basic Python class available to begin with:
https://developers.google.com/edu/python/
Happy Scripting!!!
UPDATE: Playing with Python..
With the recent Earthquake in the Philippines last January 11, 2015 at around 3:30AM (Phil. Time) that reach 5.9 Magnitude, I though maybe I can create an image (Data Visualisation) on where is the centre of the earthquake. So here's python to the rescue. Since I been reading for awhile regarding what other modules can do, I ended up using Basemap. The script below has 2 parts. First is to grab dataset from the cvs file. The columns are Latitude, Longitude and Magnitude. The second part is the engine for the script where Baseman is being used to create the image.
For the result, the red dot will got bigger if the magnitude is higher.
----------------------------------------------------------------
Sunday, September 7, 2014
I'm Back.....
Now for my biggest challenge of all..CCIE. I can say that this exam is a Beast. I've built my ccie home lab from old Cisco routers and switches and it's been a year since I started studying. The good thing about it is that the more I study, the more I know that there are lots of things to learn, and the the more things I've learn, the more I can design network efficiently and securely.
I'll be posting more configuration setup here for me to refresh my memory and hopefully help others as well.....
Happy Studying.....
Friday, December 23, 2011
Whoohaa
Friday, October 21, 2011
iperf server
Anyway, I just want to share the tool I used to test your network bandwidth (Internet, Site to site, etc.). I used iPerf in a linux box. It uses a client/server type of testing.
If you want an iPerf server to test your Internet link, send me your email so I can provide you the details...
Monday, May 16, 2011
Security Awareness 101
Thursday, May 12, 2011
How to start your Security Awareness Program?
Wednesday, July 21, 2010
Generating keystore
To generate keystore file, a tool called keytool by Java is used to generate certificates. Make sure to use the latest java release to use the latest security library.
Check Java version:
#java -version
Generating keystore:
keytool -genkey -alias
Example:
#keytool -genkey -alias myalias -keyalg RSA -keysize 2048 -keystore mykeystore.
Note: it will ask for the password to the keystore and alias. It can be the same.
Generate CSR:
keytool -certreq -alias
Example:
#keytool -certreq -alias myalias -keystore mykeystore -file mycsr.csr.
Note: it will prompt you for the keystore password specified above procedure.
Send the CSR to Public CA like TPP Internet, Thawte, etc. . After sending the file, download the corresponding CRT file for the domain created.
Importing CRT:
#keytool -import -trustcacerts -alias
Example:
keytool -import -trustcacerts -alias myalias -file certfromca.crt -keystore mykeystore
Thursday, July 8, 2010
Redhat - Reduce size of root file system
The default file system layout from the Red Hat Enterprise Linux 5 installation process includes a special space for /boot and swap space then gives all left space to one logical volume and used the logical volume as root / volume.
Integrating all data files and system files in one file system is not always an ideal choice for production systems. If the system cannot be reinstalled, it is possible to reduce the size of the root file system and the logical volume on which it resides.
Reducing the logical volume on the root / volume must be done in rescue mode.
First, boot the system from Red Hat Enterprise Linux 5 Disc 1, and at the prompt, type linux rescue and press enter. When prompted for language, and keyboard, provide the pertinent information for the system. When prompted to enable the network devices on the system, select "No." Finally, select "Skip" when prompted to allow the rescue environment to mount Red Hat Enterprise Linux installation under the /mnt/sysimage directory. The filesystems MUST NOT be mounted to carry out the following steps.
Next run following commands to scan all disks LVM2 volume groups:
# lvm.static vgscan
Next, activate the logical volume to reduce. In this example, /dev/VolGroup00/LogVol00 was made available with the following command:
# lvm.static lvchange -ay /dev/VolGroup00/LogVol00
Next, reduce the size of file system and logical volume on /dev/VolGroup00/LogVol00. Please make sure there is enough space left on the root / file system and that the logical volume is large enough to contain all the data that was previously present. If the file system is at close to being full, for example, this may not work. Before resizing file system, run e2fsck to check file system first.
# e2fsck -f /dev/VolGroup00/LogVol00 # resize2fs /dev/VolGroup00/LogVol00 3000M # lvm.static lvreduce -L 3000M /dev/VolGroup00/LogVol00
Please note that this is done on /dev/VolGroup00/LogVol00. The number at the end is the final size of the file system, not the amount it is reduced by.
Finally, verify the modification then reboot the system.
# lvm.static vgdisplay VolGroup00 # exit
Wednesday, July 7, 2010
Mobile Device Management & Wireless Expense Management | MobileIron
Friday, July 2, 2010
Manual: CIS benchmark tests
Manual: CIS benchmark tests
We just included support in the OSSEC Policy monitor to audit if a system is in compliance with the CIS Security Benchmarks (as of right now, only RHEL2-5, Fedora 1-5 and Debian/Ubuntu are supported - the other versions will be soon).
If you want to try it out manually and provide some feedback to us, please follow the instructions bellow to test:
First, grab the latest CVS snapshot and compile it (it will be included on v1.6 and above):
# wget http://www.ossec.net/files/snapshots/ossec-hids-080710.tar.gz
# tar -zxvf ossec-hids-080710.tar.gz
# cd ossec-hids-080710/src/
# make clean
# make libs
# cd rootcheck
# make binary
The binary ossec-rootcheck will be created on the current directory and we can start using it. A simple scan on my Ubuntu box looked like this: (note, that it will do all the normal rootcheck tests plus the CIS scans — just grep for CIS if you don’t want to see the rest):
# ./ossec-rootcheck
..[INFO]: System Audit: CIS - Testing against the CIS Debian Linux Benchmark v1.0. File: /proc/sys/kernel/ostype. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 1.4 - Robust partition scheme - /tmp is not on its own partition. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 1.4 - Robust partition scheme - /var is not on its own partition. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 2.3 - SSH Configuration - Root login allowed. File: /etc/ssh/sshd_config. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 2.4 - System Accounting - Sysstat not enabled. File: /etc/default/sysstat. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 4.18 - Disable standard boot services - Squid Enabled. File: /etc/init.d/squid. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 7.2 - Removable partition /media without ‘nodev’ set. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 7.2 - Removable partition /media without ‘nosuid’ set. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 7.3 - User-mounted removable partition /media. File: /etc/fstab. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
[INFO]: System Audit: CIS - Debian Linux 8.8 - GRUB Password not set. File: /boot/grub/menu.lst. Reference: http://www.ossec.net/wiki/index.php/CIS_DebianLinux .
..
Wednesday, June 30, 2010
Monday, June 28, 2010
MCITP: Enterprise Administrator certified
How do I use Problem Steps Recorder?
| To record and save steps on your computer |
Open Problem Steps Recorder by clicking the Start button
, and then typingpsr. In the list of results, click psr.
Click Start Record. On your computer, go through the steps on your computer to reproduce the problem. You can pause the recording at any time, and then resume it later.
Click Stop Record.
In the Save As dialog box, type a name for the file, and then click Save (the file is saved with the .zip file name extension).
To view the record of the steps you recorded, open the .zip file you just saved, and then double-click the file. The document will open in your browser.
| To send the problem steps in e‑mail |
After recording and saving a .zip file, click the help down arrow
, and then click Send to E‑mail recipient. This will open an e‑mail message in your default e‑mail program with the last recorded file attached to it.
Note
You won't be able to click the Send to e‑mail recipient option until you've recorded and saved a file.
| To annotate problem steps |
Open Problem Steps Recorder by clicking the Start button
, and then typingpsr. In the list of results, click psr.
Click Start Record.
When you want to add a comment, click Add Comment.
Use your mouse to highlight the part of the screen that you want to comment on, type your text in the Highlight Problem and Comment box, and then click OK.
Click Stop Record.
In the Save As dialog box, type a name for the file, and then click Save.
To view the record of the steps you recorded, open the .zip file you just saved, and then double-click the file. The document will open in your browser.
| To adjust settings |
When you adjust settings for Problem Steps Recorder, they're only saved for your current session. After you close and reopen Problem Steps Recorder, it will return to the regular settings.
Open Problem Steps Recorder by clicking the Start button
, and then typingpsr. In the list of results, click psr.
Click the help down arrow
, and then click Settings.
You can change the following settings for Problem Steps Recorder:
Output Location. If you don't want to be prompted to save a file after recording, click the Browse button to set a default output file name.
Enable screen capture. If you don't want to capture the screen shots along with the click information, select No. This might be a consideration if you are taking screen shots of a program that contains personal information, such as bank statements, and you are sharing the screen shots with someone else.
Number of recent screen captures to store. While the default is 25 screens, you can increase or decrease the number of screen shots. Problem Steps Recorder only records the default number of screen shots. For example, if you took 30 screen shots during a recording but only had 25 screen shots as the default, you would be missing the first five screen shots. In this case, you would want to increase the number of default screen shots.


