abq
Albuquerque, NM bless 6 months ago 100%
NM Highlands University Confirms Ransomware Incident

https://www.nmhu.edu/eoc/

4
2
newmexico
New Mexico bless 6 months ago 100%
NM Highlands University Confirms Ransomware Incident

https://www.nmhu.edu/eoc/

3
0
selfhosted Selfhosted question about self hosting SSO for multiple domains and services.
Jump
selfhosted Selfhosted Looking for help setting up an alternative to DuckDNS
Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    8 months ago 100%

    Who's your DNS provider? I use cloudflare and powershell script and hits their API. Works well

    6
  • selfhosted Selfhosted Best way to set up cloudflare dynamic DNS in late 2023?
    Jump
    selfhosted Selfhosted Access home server from anywhere
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    You can bound ufw rules to interfaces, so you can allow in only on the wg0 interface and not eth0 interface.

    Glad it's working! I love wireguard!

    1
  • selfhosted Selfhosted Access home server from anywhere
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    Hmm do a traceroute and see where it's dying. Can you ping inside IP of the tunnel on the wireguard server? What about outside?

    What did you deploy in docker, firezone or basic wireguard?

    Does your phone say connected and you see both incoming and outgoing packets? Is there a firewall in place on the wireguard host (ufw maybe)?

    If you have nmap available you can also check port status.

    2
  • cybersecurity Cybersecurity News Bluetooth security flaws reveals all devices launched after 2014 can be hacked
    Jump
    selfhosted Selfhosted Access home server from anywhere
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    Good thing about wireguard is it's really simple. Google should get it done, if you get stuck send me a DM. I started with basic wireguard, I now run firezone in docker as I like the frontend.

    2
  • cybersecurity Cybersecurity Bluetooth security flaws reveals all devices launched after 2014 can be hacked
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    It means they can impersonate the Bluetooth device connected. Input devices are particularly concerning (keyboards and mice) as well as BT IoT devices which already historically lack good security controls. A lot of vehicles have Bluetooth integrated as well these days.

    17
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearHA
    Hacking bless 10 months ago 100%
    Bluetooth security flaws reveals all devices launched after 2014 can be hacked

    Security researchers have discovered new Bluetooth security flaws that allow hackers to impersonate devices and perform man-in-the-middle attacks. The vulnerabilities impact all devices with Bluetooth 4.2 through Bluetooth 5.4, including laptops, PCs, smartphones, tablets, and others. Users can do nothing at the moment to fix the vulnerabilities, and the solution requires device manufacturers to make changes to the security mechanisms used by the technology. Research paper: https://dl.acm.org/doi/pdf/10.1145/3576915.3623066 Github: https://github.com/francozappa/bluffs CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-24023

    18
    0
    cybersecurity Cybersecurity News Bluetooth security flaws reveals all devices launched after 2014 can be hacked
    Jump
    cybersecurity
    Cybersecurity bless 10 months ago 97%
    Bluetooth security flaws reveals all devices launched after 2014 can be hacked

    Security researchers have discovered new Bluetooth security flaws that allow hackers to impersonate devices and perform man-in-the-middle attacks. The vulnerabilities impact all devices with Bluetooth 4.2 through Bluetooth 5.4, including laptops, PCs, smartphones, tablets, and others. Users can do nothing at the moment to fix the vulnerabilities, and the solution requires device manufacturers to make changes to the security mechanisms used by the technology. Research paper: https://dl.acm.org/doi/pdf/10.1145/3576915.3623066 Github: https://github.com/francozappa/bluffs CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-24023

    69
    5
    selfhosted Selfhosted Access home server from anywhere
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    I would go with wireguard VPN or something like cloudflare tunnels or tailscale. With wireguard you'll need to open up an external port and forward to your VPN host, but wireguard uses UDP so no one can probe it for responses. CF tunnels and tailscale you don't have to open up holes in your firewall which is nice.

    You also have the option of using a proxy and opening up 443 publicly on your firewall, but unless you know what you're doing I'd leave that closed until you learn more.

    44
  • cybersecurity
    Cybersecurity News bless 10 months ago 100%
    Bluetooth security flaws reveals all devices launched after 2014 can be hacked

    * Security researchers have discovered new Bluetooth security flaws that allow hackers to impersonate devices and perform man-in-the-middle attacks. * The vulnerabilities impact all devices with Bluetooth 4.2 through Bluetooth 5.4, including laptops, PCs, smartphones, tablets, and others. * Users can do nothing at the moment to fix the vulnerabilities, and the solution requires device manufacturers to make changes to the security mechanisms used by the technology. Research paper: https://dl.acm.org/doi/pdf/10.1145/3576915.3623066 Github: https://github.com/francozappa/bluffs CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-24023

    100
    16
    cybersecurity
    cybersecurity bless 10 months ago 97%
    Bluetooth security flaws reveals all devices launched after 2014 can be hacked

    * Security researchers have discovered new Bluetooth security flaws that allow hackers to impersonate devices and perform man-in-the-middle attacks. * The vulnerabilities impact all devices with Bluetooth 4.2 through Bluetooth 5.4, including laptops, PCs, smartphones, tablets, and others. * Users can do nothing at the moment to fix the vulnerabilities, and the solution requires device manufacturers to make changes to the security mechanisms used by the technology. Research paper: https://dl.acm.org/doi/pdf/10.1145/3576915.3623066 Github: https://github.com/francozappa/bluffs CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-24023

    35
    1
    selfhosted Selfhosted Setup a DNS server on a dynamic public ip
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    10 months ago 100%

    I would get a domain name and use ddns to update your rotating IP. Then I would setup wireguard VPN in split tunnel and have your parents network tunnel back to your piholes for dns resolution.

    I use cloudflare API for ddns updates but there are plenty of choices for that. If you're using cloudflare for DNS just keep in mind you can't proxy the DNS entry for the ip for your VPN host as CF only forwards traffic over certain ports and they are not configurable (on free plan anyway not sure about paid).

    5
  • selfhosted Selfhosted I finally figured out how to virtualize my OPNsense firewall. Suck it, Roku.
    Jump
    selfhosted Selfhosted Can you give me some hints? I have problems with Docker install
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    11 months ago 100%

    The error is telling you you already have something listening on port 80 so docker is unable to bind to 80 again until that is released. Try disabling nginx and apache as you stated.

    You can run

    netstat -pln

    to show you what's running on what port on your host is you want to verify

    2
  • selfhosted Selfhosted I’m about to throw my entire Pihole out the window
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    11 months ago 100%

    For infrastructure critical services I recommend reservations on the DHCP server and then set static assignment on the device for the IP reserved in DHCP. This way if the device ever fails over to DHCP for any reason the IP will not change. I'll usually also leave some small address space outside the DHCP scope available for static assignment if needed, usually at the front and usually around 20 IPs max as it's easier to let DHCP do the heavy lifting.

    Static IPs are important on infra critical devices if you ever find yourself in a situation where the DHCP services are not available, you don't want them to be a single point of failure.

    Just my 2 cents.

    1
  • cybersecurity Cybersecurity News security by no security?
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    12 months ago 100%

    Blank cred is like the first thing that is tried, right before 1234, admin, and password

    6
  • technology Technology Amazon To Start Running Ads In Prime Video Series and Movies, Will Launch Ad-Free Tier For Extra Fee
    Jump
    technology Technology Amazon To Start Running Ads In Prime Video Series and Movies, Will Launch Ad-Free Tier For Extra Fee
    Jump
    selfhosted Selfhosted Ideas wanted
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    1 year ago 100%

    So I run windows AD and have windows dns inside and cloudflare outside. I also run NPM for the web prox in my DMZ.

    On the inside DNS I point the A record for NPMProxy.domain.com to the IP of my npm server. I than setup service1.domain.com inside npm to forward requests to the web server setup for service1. I than setup the CNAME record for service1.domain.com to point to NPMProxy.domain.com. This should complete your inside.

    Outside I set the A record on cloudflare for service1.domain.com to my public IP address which will route again to NPM. This will complete the outside connectivity.

    Make sure your firewall rules are set and proper ports open and you should be golden.

    2
  • asklemmy Ask Lemmy People who prefer light theme over dark/night theme.. Why?
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    1 year ago 100%

    I primarily use dark themes but I do switch to light themes from time to time. To see better, give my eyes a break, or when in a dark room for too long are some examples. Also some apps just don't play nice in dark themes.

    2
  • asklemmy Ask Lemmy What are some of the best purchases of your life?
    Jump
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearBL
    bless
    1 year ago 100%

    We got lasik for my fiance and that was hands down the best money we ever spent. Life changing really.

    4
  • android Android Opinion - What are your thoughts on password managers? Do you use one? Would you recommend it to others?
    Jump