Configuring Kerberos for IP Address | Microsoft Docs
So SMB using IP's downgrades to NTLM, but if you set up W10/2016 with this, can use IP SPN's and kerberos to halt some of the pass-the-hash stuff. Unfortunately the IP SPN's don't autoupdate so you're boned in a DHCP environment...
security  kerberos  windows  10  2016  SMB  SPN  IP  address  NTLM 
june 2019 by asteroza
using custom TCP/IP stacks to assist bypassing UTM firewalls
custom  TCP  IP  stack  software  evasion  exfiltration  security  hacking  pentesting 
october 2018 by asteroza
LAteral Movement Encryption technique (a.k.a. The "LAME" technique)
I wonder why let's encrypt didn't isolate the internal IP range DNS entry SSL certificates to a child CA cert that enterprises could explicitly distrust, which would quash this in a heartbeat.
internal  IP  range  SSL  TLS  certificate  letsencrypt  lateral  movement  encryption  security  hacking  pentesting 
september 2018 by asteroza
AWS Developer Forums: Configurable Reverse DNS Records for Elastic IPs
Because many allegedly third party email blacklists are basically a shakedown...
AWS  EC2  TrendMicro  DUL  MAPS  SMTP  email  blacklist  exception  rDNS  reverse  DNS  elastic  IP  registration  antispam 
july 2018 by asteroza
Отслеживание количества актуальных IP адресов из выгрузки Роскомнадзора
SHowing number of IP's blocked by russian federal censors. Sudden jump to over 16 million IP's is due to spat with Telegram, which is domain fronting from google and AWS.
russia  IP  block  live  statistics  dashboard  censorship 
april 2018 by asteroza
Convenience rollup update for Windows 7 SP1 and Windows Server 2008 R2 SP1
Apparently a bug with this patch nukes VMware VMXNET3 adapters by replacing them with an identical network card but returned to default settings. Which means any static IP servers just went DHCP. Plus a VBscript to fix this seems lame... but this is the major rollup patch you should have so...
bug  fail  microsoft  windows  7  2008R2  VMware  NIC  network  card  static  IP  DHCP  VMXNET3  sysadmin  tips  tricks  networking  rollup  patch 
march 2018 by asteroza
Amaryllo, Your Security Robot Company
lightbulb socket based wifi home security video camera, new Atom R2 has LED in embedded lightbulb socket adapter so you don't lose the lighting
wifi  wireless  IP  video  camera  webcam  surveillance  Delicious 
june 2016 by asteroza
IP check
Uh, just connecting to this service is an OPSEC violation though...
privacy  security  IP  network  proxy  testing  checker  service  check  test  online  Delicious 
february 2016 by asteroza
AWS Fishing Panel
Reused elastic IP's with dangling DNS entires without short TTL's means I can potentially grab an IP for a major site, quickly deploy a phishing site emulating such site, and grab logins. Short TTL's and proper domain management will mitigate this though.
AWS  elastic  IP  dangling  domain  DNS  TTL  security  hacking  phishing  attack  Delicious 
october 2015 by asteroza
Rhino Security Labs | Ironclad Security for a Dangerous World
So this guy is going to make ProxyHam, an IP repeater box of sorts so you are not within line of sight of the AP you are stealing internet access from.
ProxyHam  wireless  IP  relay  hardware  electronics  devices  wifi  accesspoint  AP  security  privacy  bounce  repeater  Delicious 
july 2015 by asteroza
IPdeny IP country blocks
I don't advocate blocking a whole country, but if one has reason to, this is a reasonable start for collecting the requisite information (because blocking by DNS country code is dumb).
country  IP  address  block  listing  IPv6  security  reference  information  Delicious 
january 2015 by asteroza
Interesting, used by a 3D printer, but what are the merits compared to say something like CANnet or some other ethernet capable protocol?
Bowler  industrial  machinery  robot  robotic  control  protocol  design  concept  IP  software  Delicious 
may 2014 by asteroza
for Data Breach Management | Guardtime
Apparently KSI can somehow be leveraged to secure a streamed build file for a 3D printable object as it is streamed to a printer, to protect intellectual property in the build file from leaking.
KSI  security  keyless  digital  asset  tagging  management  signature  software  3D  printing  fabbing  build  file  DRM  IP  copyright  auditing  Delicious 
may 2014 by asteroza
iphone - ituneconnect using application loader behind a firewall - Stack Overflow 443 n/a 443* n/a 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 33001 33001-33500 44001 44001-44500
upload  tricks  tips  sysadmin  networking  network  permission  firewall  range  port  IP  UDP  TCP  submission  app  iPad  iPhone  iOS  xcode  apple  Delicious 
november 2012 by asteroza
Looks like the ZigBee Alliance is punting using the 920MHz band for IEEE 802.15.4g compatible PHY/MAC layer services for ECHONETlite, the new japanese standard for electric appliance/equipment energy management and connectivity to HEMS applications.
ECHONET  ECHONETlite  ZigBee  802.15.4  802.15.4g  HEMS  home  energy  management  smart  appliance  electric  equipment  IP  layer  application  SmartHome  SmartMeter  SmartGrid  green  japan  Delicious 
august 2012 by asteroza
Block China Web Traffic IP Addresses and Chinese Hackers
While I feel using country specific netblock blocking is like using a bazooka to kill a fly, some people feel it does have its usefulness...
tricks  tips  sysadmin  security  nigeria  russia  china  country  netblock  address  list  block  IP  network  blacklist  Delicious 
april 2012 by asteroza
Chinese Bullet Trains Carry "Black Box" Controls - IEEE Spectrum
The fact that certain control equipment supplied by Hitachi was used, potentially blindly, in both the high speed trains that crashed as well as in the new nuclear reactors is a cause for concern...
system  control  blackbox  IP  protection  china  Hitachi  japan  Delicious 
october 2011 by asteroza
Rapid DHCP: Or, how do Macs get on the network so fast? : Caffeinated Bitstream
Interesting info about the differences between Apple and linux DHCP client operation when connecting to a network, which may be a known known network.
fast  DHCP  discovery  reconnect  IP  address  allocation  configuration  mac  OSX  linux  networking  network  performance  Delicious 
july 2011 by asteroza
Chatroulette Map
A site doing geoIP mapping of anonymous Chatroulette users, effectively deanonymizing the users.
NSFW  Chatroulette  webcam  IP  address  geoIP  geolocation  mapping  chart  map  googlemaps  information  data  visualization  heatmap  privacy  anonymous  deanonymizer  Delicious 
march 2010 by asteroza
