Infosec

Home Lab Part I : Approaches and Why

This will be a multiple part post outlining my opinions of homelabs and what you should consider when building your lab. I will also include a few resources I can vouch for and have used. Furthermore, I do not claim to have all the answers and your setup/needs will be different from mine. That being said, I will start off in a general sense and narrow done as these posts go on.

This Isn't a Lifestyle Blog but These are Awesome

Many of my bigger projects have been placed on the back-burner as I have been focusing more on work, classes and spending time with my family. Although, I am not grokking down into the weeds on new technologies, I have stumbled across some nuggets worth sharing, even at the risk of sounding like a “lifestyle” blog. Infosec Think-Piece This essay has been making it’s rounds on infosec twitter however, I think it is worth reading to all those who are in infosec or are even curious about infosec/”cyber security”.

The Real Cybersecurity News: The Ukrainan Power Plant Attacks and Why You Should Care

Recently, there has been an overwhelming amount of discussion over WhatApp’s non-existent “Government backdoor”, which can easily be debunked with the following statement: If Facebook wanted to allow any government to have a back door, they own the code base, they could just code one in. You wouldn’t know it. Additionally, the end points are still soft, you have to de-crypt the message to read it, which provides a much easier attack vector.

Ransomware: The New Massively Disruptive Market?

Ransomware, malicious software designed to encrypt a victim’s hard drive and charge a ransom for the recovered files, has been reigning terror or organizations and users for a number of years now. The business model has always been simple, infect the user through spam e-mail or other vectors of infection (i.e. online droppers), encrypt the hard drive and hold it hostage until the user pays the ransom in Bitcoin. Rinse and repeat.

How Infosec is Creating More Problems for Infosec

Information Security, cybersecurity or any flavor of security plus technology interest has skyrocketed and expected to grow exponentially. The reason is justified, criminals have moved into this section and been successful in exploiting victims for money then cycling those funds into developing more profitable ways to exploit targets. Furthermore, the domain of information technology provides a great return on their investment just by the scale at which these criminals can attack.

Calm Down, It's Just DNS

Last month Dyn, an “internet performance management company” or a DNS provider, was attacked by what looks to be some flavor of the Mirai botnet. If you remember, the Mirai source code was dumped after the original users spread it to get rid of some law enforcement pressure. Furthermore, this botnet targets weak security in the form of backdoors/passwords put into the firmware of “internet of things” devices, like webcams and DVRs.