TeamAU Overclocking

3.9K posts

TeamAU Overclocking

TeamAU Overclocking

@teamau

Team Australia overclocking group, systems administrator, security aficionado, blogger, technical writer, dodgy coder, lover of all things tech

Australia Katılım Temmuz 2009
755 Takip Edilen642 Takipçiler
EZ
EZ@IAMERICAbooted·
@Bluewall It should be fido2 hard key authn as primary auth and stored in the company safe with a procedure to get them out, critical alerts when they login, and excluded from all CAPs
English
1
2
2
160
EZ
EZ@IAMERICAbooted·
This is you uncomfortable reminder that if a Global Admin gets popped, they can create another Global Admin account and delete all the others :p
English
2
4
52
3.2K
Aura
Aura@SecurityAura·
Whenever I have clients that talk about DLP to prevent exfil and so on I ask them to do one test: Go on a random server, download the portable version of WinSCP or FileZilla, connect to an outbound SFTP or FTP server and transfer files. Neither DLP or EDR will do anything here
Steve Borosh@rvrsh3ll

@T3chFalcon Can say that DLP has not once prevented me from exfiltrating data from a network.

English
20
22
174
25.7K
spencer
spencer@techspence·
Famous last words by IT admins: I’m just testing…
English
28
5
83
5K
slovak_killer - XOC HWBot
slovak_killer - XOC HWBot@slovak_killer·
Another day, another leak. ASTRAL RTX 5090 2000W XOC V2 leaked, its the newer version of the bios, which should include fixed power limit, with GPU able to reach 2000W now. Link in the comments.
slovak_killer - XOC HWBot tweet media
English
6
3
20
1.4K
TheDataBunny
TheDataBunny@thedatabunny·
Fully migrated the OpenVPN server to the De-Militarized Zone (DMZ). Any servers that will have ports open to the internet will sit on the DMZ network and on this DMZ switch. Now, I’m going to clean up for tonight.
English
21
41
614
72.2K
avvyx
avvyx@avvyxcs·
@iamcs2kitchen @CounterStrike This exact affinity set had my best results. Disabling 0 had some improvement, disabling 1, 3, 5, 7, 9, 11, 13 and 15 had even more and having them all disabled had the best. Both AVG and P1 improved a lot.
avvyx tweet media
English
6
1
15
5.1K
CS2 Kitchen
CS2 Kitchen@iamcs2kitchen·
Disabling core 0 can boost your 1% low FPS by upto 17% on many CPUS ( doesn't work on all cpus). Good thing is this performance benefit is not limited to @CounterStrike . CPU's tested ( Works on: 7800x3d, 9800x3d... maybe your cpu as well.)
English
50
24
927
198.3K
TeamAU Overclocking
TeamAU Overclocking@teamau·
@MyNameIsMurray I think PacketFence is what you want. I just finished POC, SCEP server built in, captive portal with saml, tls authentication, ad authorisation, guest registration workflows, firewall sso integrations, self onboarding certificates for macOS windows, it’s identical to Clearpass
English
0
0
1
31
Murray
Murray@MyNameIsMurray·
@teamau It seems like not many have actually tried to do both device and user authentication, or if they have they are wealthy schools/enterprises that can use Cisco ISE, Aruba ClearPass, or similar ludicrously expensive options. I just want a budget-friendly modern Wi-Fi auth. Sigh!
English
1
0
0
101
TeamAU Overclocking
TeamAU Overclocking@teamau·
@MyNameIsMurray have you looked into packetfence for your use cases? Just starting to build our PoC and it looks promising but a lot of work to go
English
1
0
0
61
TeamAU Overclocking
TeamAU Overclocking@teamau·
@techspence These are the exact files I leave around the place, backdated with canary credentials. Vmdk or vhd are juicy targets too.
English
1
0
2
149
spencer
spencer@techspence·
Ultimate internal pentest cred-hunting cheat sheet (steal these) .kdbx | unattend(dot)xml | web(dot)config | .ini | .env | appsettings(dot)json | .git-credentials | .ps1 | .bat | .cmd | .vbs | .vba | .sql | connections(dot)xml Also check… BCDR docs, logon scripts, Notepad++ temp, browser vaults, anything with “secret” in the name, log files, vmdks, readme’s, install guides, new user setup docs, powershell history, source code repos What did I miss?
English
3
15
131
7.4K
TeamAU Overclocking
TeamAU Overclocking@teamau·
@MyNameIsMurray I like it, I’m trying to work towards passwordless, wifi is the last hurdle, so trying to work out a wifi onboarding method that supports modern auth mechanisms
English
1
0
0
28
Murray
Murray@MyNameIsMurray·
@teamau And that is why modernising the old and not very secure PEAP/MSCHAPv2 solution with a secure tunnel and then performing user auth (backed by Entra users/groups) is my current plan.. this EAP-TTLS/PAP.
English
1
0
1
77
Murray
Murray@MyNameIsMurray·
@teamau There are a few options that rely on browser initiated user authentication, but these tend to not provide network access at the login window, not trigger auth for apps/sockets. It's a bit "meh" as a solution compared to EAP-TTLS/PAP and eventually TEAP...
English
2
0
0
223
TeamAU Overclocking
TeamAU Overclocking@teamau·
@MyNameIsMurray Nah I’m thinking more the auth mechanism than fw vs NPS. Have you considered open network with OWE and captive portal OIDC to Entra? Support for passkeys and modern auth and you can configure in a way that if the user is logged into Entra in browser it’ll auth automatically l
English
1
0
0
15
Murray
Murray@MyNameIsMurray·
@teamau Modernise authentication to provide (filtered) internet access more securely. We already have a firewall to protect internal assets and provide web access policy configuration that satisfies our duty of care requirements: So we just need an NPS replacement, not a new firewall.
English
1
0
0
30
Murray
Murray@MyNameIsMurray·
@teamau I've used it in the past, mostly to help isolate VMs needed for testing where we couldn't physically isolate or configure VLANs. It was fine. The main thing I need to solve at the moment is RADIUS, and PF includes FreeRADIUS, so I'm just going with FreeRADIUS directly for now.
English
1
0
0
37
TeamAU Overclocking
TeamAU Overclocking@teamau·
@NathanMcNulty is it your understanding that WH passkeys should be supported in syncable passkey preview? I can get password manager keys enrolled but WH is failing.
English
0
0
0
9
TeamAU Overclocking
TeamAU Overclocking@teamau·
@IAMERICAbooted We’re using Prisma for some edge cases and it’s working really well. Users generally arnt happy with the extra control’s though.
English
1
0
1
101
EZ
EZ@IAMERICAbooted·
Best RBI solution? Please RT
English
7
1
3
3K