wop

joined 2 years ago
MODERATOR OF
 

I've decided to self-host yet another service. This time it is NTFY. Simple HTTP based push notifications for your devices.

https://ntfy.brrl.net/

Feel free to use it. Feedback is welcome.

I use it to notify me about successful logins on one of my servers, failed backups, results of cron jobs and so on. One simple HTTP request is all you need.

 

Sometimes I just need a simple whiteboard for troubleshooting or brainstorming sessions. I've decided to self-host a whiteboard with collaboration function. I am going to give whitebophir a try.

Feel free to use it too!

  • free
  • no ads
  • no tracking

Disclaimer: the data is not encrypted and I - as provider - could look into them.

Not optimal for permanent boards as I plan to reset it once a month (not sure yet).

 

Rsync is one of my most used tools and I am happy to share this guide with you. I've learned a lot doing the research and I hope to share some tipps with you.

 

Thanks to Jerry for bringing this community back to life. I'll be playing moderator for a while and may tweak the design a bit.

Enjoy!

 

I've added a status page with #uptimekuma. I want to get used to it for now. It is currently running on the same server as the rest of the services, which is not optimal. Additionally adding some more sensors at some point.

 

Just created an overview of the services I host.

 

I've decided to add an email newsletter to my blog. It is still 'work in progress', but I make progress and the first 'issue' will be sent next Monday.

GDPR-compliant, no tracking, lightweight, and nothing special.

Feel free to check out the following link for additional information.

https://ittavern.com/newsletter/

 

I am happy to share my revised SSH server hardening guide.

Feedback is very welcome.

 

I've created a new article about Port Knocking in preparation of my rework of the SSH Hardening guide.

I'd like to hear your opinion about port knocking.

 

haven't shared my backup guide here yet - your feedback would be greatly appreciated

[–] [email protected] 1 points 2 years ago

Haven't found my perfect solution. The current goal is get everything together and see what I really need. Most likely a single .md file that I can encrypt and sync in my machines, but not sure yet.

[–] [email protected] 4 points 2 years ago (8 children)

I am currently trying to organize my notes. The old 'system' is a pain, and getting everything centralized makes it easier to find things. Notes, snippets, bookmarks, and so on.

[–] [email protected] 4 points 2 years ago* (last edited 2 years ago) (3 children)

Thank you for the AMA.

Do you regularly feel overwhelmed? - Keeping up with the sec news and patch accordingly, firewall/ips and endpoint alarms, logs, meetings, and more. It shouldn't be the case, but it seems that everything in security is prio 1.

EDIT: and being the party pooper and saying no to everything, bc people do not think about security.

[–] [email protected] 2 points 2 years ago (2 children)

Added the Update 2. Still some things to do, but we know a little bit more now. Feedback and questions are still welcome.

[–] [email protected] 2 points 2 years ago

Ping - Update 2 Your numbers are are still missing since I havent had time to look into the pcaps yet. I hope I can get it done by the end of the week, but we are a little bit wiser.

[–] [email protected] 1 points 2 years ago

Ping - Update 2

[–] [email protected] 2 points 2 years ago (6 children)
[–] [email protected] 1 points 2 years ago
[–] [email protected] 2 points 2 years ago
[–] [email protected] 1 points 2 years ago (4 children)

I am hosting multiple services, but my application/web security knowledge is lacking. Is there a guide or framework to check for common or risky mistakes? Is there a list of things I should check every application for, or guide on how to harden hosted applications? That is a topic that I am going to tackle in the near future, and would appreciate some tips in advance.

[–] [email protected] 11 points 2 years ago

Thank you Jerry!

[–] [email protected] 1 points 2 years ago

Not yet. Just got access to the test clients and I have planned to do a troubleshooting session tomorrow in the morning. Not a big fan of stress testing the network on a working day haha

view more: ‹ prev next ›