Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Geoff

Edu Supporters
  • Posts

    13,543
  • Joined

Everything posted by Geoff

  1. I will come have a look. My username is 'EvilGrin'.
  2. Ok, I just looked. O365 Pro Plus is £7.80/month/user. Google Apps w/Vault is £6.60/month/user. These are business prices.
  3. Isn't Google Apps half the price of the equivalent O365 subscription anyway?
  4. Just leave a few copies of this in the school library. http://www.amazon.com/Violent-Python-Cookbook-Penetration-Engineers/dp/1597499579
  5. Honestly I would do a fresh install. There's far too many gotchas trying to migrate.
  6. I would highly encourage everyone to learn Powershell and automate it themselves.
  7. Most consumer grade padlocks are easily picked. Anyone with a reasonable amount of practice can open them in seconds. Note that carrying the tools about when you aren't a locksmith will mean you are guilty of 'Going equipped for theft' unless you can convince the police otherwise. Actually popping a lock that isn't yours or without the owners permission is 'unlawful entry/breaking and entering' or 'theft' depending if the lock is attached to a door or not.
  8. I'd count up what it is costing in time / money / lesson disruption and then kick the problem up the food chain to the SMT.
  9. The Powershell team have announced their first code release. This is a fully ported OpenSSH to windows. They outline the milestones going into 2016 as well. OpenSSH for Windows Update - Windows PowerShell Blog - Site Home - MSDN Blogs You can get the code from Github. https://github.com/PowerShell/Win32-OpenSSH
  10. Yeah, it's a security system used to define access control policies. So you can say Apache only has access to these files and devices. It's really handy in stopping exploits and rootkits. For an internal server I would not bother unless there is a compliance reason to have it.
  11. I don't work in a school any more (although I imagine our system would work). We have a separate HR database in MS SQL. There's a bunch of Powershell scripts that create, rename, move, delete users based on what HR says. So it's completely hands off from our point of view. I fully expect you could do something similar based on what your MIS says.
  12. Are you running selinux? As it might be getting in the way.
  13. You can't do anything about the banner as it's not your SMTP server. You can do dmarc, spf and domainkeys though if you have control over your dns records.
  14. MXtoolbox have a good testing tool. halstead-school.org.uk Domain Health
  15. We are using request tracker: https://www.bestpractical.com/rt/ There is a demo you can try here: Login
  16. Which reminds me, this script will get the last login user and the basic system details and update the computer description in AD. If you run this as a login script you will need to give authenticated users access to update the description field on computer objects. Set WshNetwork = WScript.CreateObject("WScript.Network") Set objWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2") ' Get service tag and computer manufacturer For Each objSMBIOS in objWMI.ExecQuery("Select * from Win32_SystemEnclosure") serviceTag = replace(objSMBIOS.SerialNumber, ",", ".") manufacturer = replace(objSMBIOS.Manufacturer, ",", ".") Next ' Get computer model For Each objComputer in objWMI.ExecQuery("Select * from Win32_ComputerSystem") model = trim(replace(objComputer.Model, ",", ".")) Next ' Get computer object in AD Set objSysInfo = CreateObject("ADSystemInfo") Set objComputer = GetObject("LDAP://" & objSysInfo.ComputerName) ' Build up description field data and save into computer object if different from current description ' We also do not update computers with a description that starts with an underscore (_) newDescription = WshNetwork.UserName & " (" & serviceTag & " – " & manufacturer & " " & model & ")" if not objComputer.Description = newDescription and not left(objComputer.Description,1) = "_" then objComputer.Description = newDescription objComputer.SetInfo end if
  17. Get the Windows Product Key of a specified machine via WMI. function get-windowsproductkey([string]$computer) { $Reg = [WMIClass] ("\\" + $computer + "\root\default:StdRegProv") $values = [byte[]]($reg.getbinaryvalue(2147483650,"SOFTWARE\Microsoft\Windows NT\CurrentVersion","DigitalProductId").uvalue) $lookup = [char[]]("B","C","D","F","G","H","J","K","M","P","Q","R","T","V","W","X","Y","2","3","4","6","7","8","9") $keyStartIndex = [int]52; $keyEndIndex = [int]($keyStartIndex + 15); $decodeLength = [int]29 $decodeStringLength = [int]15 $decodedChars = new-object char[] $decodeLength $hexPid = new-object System.Collections.ArrayList for ($i = $keyStartIndex; $i -le $keyEndIndex; $i++){ [void]$hexPid.Add($values[$i]) } for ( $i = $decodeLength - 1; $i -ge 0; $i--) { if (($i + 1) % 6 -eq 0){$decodedChars[$i] = '-'} else { $digitMapIndex = [int]0 for ($j = $decodeStringLength - 1; $j -ge 0; $j--) { $byteValue = [int](($digitMapIndex * [int]256) -bor [byte]$hexPid[$j]); $hexPid[$j] = [byte] ([math]::Floor($byteValue / 24)); $digitMapIndex = $byteValue % 24; $decodedChars[$i] = $lookup[$digitMapIndex]; } } } $STR = '' $decodedChars | % { $str+=$_} $STR } get-windowsproductkey .
  18. Exactly. It's dead easy once you have got your head round it.
  19. As long as you are using a currently supported OS you should be fine. Granted yes, you have to roll out DNS and probably DHCP6 too. I would hope everyone reading this had a thorough grasp of IPv6 already, as IPv6 is probably running on your network to some degree already. Both my ISPs talk IPv6. I have an issue with our current firewall and IPv6, but that is getting replaced this side of Crimbo.
  20. I find it amusing people in wider tech circles than Edugeek are sticking their head in the sand and ignoring this issue. We are going to run out of publicly addressable IPv4 space. You will have to be able to speak to an IPv6 only Internet host at some time in the future. Our internal network understands IPv6 and has done for some time. It was simply a case of making sure any kit we bought understood IPv6 when it was up for renewal. The whole IPv6 NAT thing is a red herring. There's no need for it on the IPv6 Internet. You simply have an IPv6 enabled firewall and use acls to control what traffic goes where. 6to4 tunnelling I can understand ofc, there will be a need for ISP customers who only get a IPv6 IP (due to IPv4 address exhaustion) to access the legacy IPv4 Internet.
  21. The 'VMware way' is to to setup a couple of vSwitches and allocate the NIC(s) to them, then allow each VM access to the relevant vSwitch. https://www.youtube.com/watch?v=80IgFaBaNco The alternative is to directly expose the VM to the hardware NIC and use the OS tools. However this is less 'VMWarey' and will confuse anyone who comes along and looks at your setup. VMware KB: Configuring VMDirectPath I/O pass-through devices on a VMware ESX or VMware ESXi host
  22. Because I'm pulling the security logs from all my DCs I can see what users are logging in with ELK. The Citrix Metrics / Logging can tell me what apps are being used (see my previous screenshots).
  23. If you cannot handle storing and processing *everything* just be selective. You should also think about what you would need realistically store. There's little point storing logs that will never see the light of day (other than for compliance or regulatory reasons). Production nodes I'm probably looking at 8 vCPU and 64Gb Ram with 1 Tb index storage. The client node can have less ram and storage obviously. I'd template all this so I can spin up extra VMs as required.
  24. One shard per node is optimal. There's plenty of reading on the subject here. I only have about 20 servers forwarding logs at the moment. This is still in development so I'm not covering everything (around 80 devices/servers). 250k log lines/hour A VM with 2 vCPU, 8Gb Ram, 300Gb VHD for my indexes. It's important to tune the Java VM to your memory sizes. If you are using ubuntu you need to edit /etc/default/elasticsearch. Also consider adding more nodes (I'd probably go for 3 + 1 client node), this system is designed to scale horizontally. As I originally indicated more elasticsearch nodes should be used in a production setup as you have no fault tolerance with a single node. Additionally consider having the node running kibana in client mode as this will load balance the kibana requests between the nodes in your cluster. You will also have to reshard (by re-indexing), see above for that. Finally with a multi-node setup you should use RabbitMQ or Redis between your logstash clients and your logstash servers. This will load balance the log data as it comes into the cluster. RabbitMQ and Logstash - Dopey's Corner How to Setup Logstash on Linux with ElasticSearch, Redis, Nginx If this is too much for your internal infrastructure to handle. Put the Redis/RabbitMQ onsite and put the Elasticsearch cluster on Amazon S3 or similar. In the event of a link failure your Redis/RabbitMQ will buffer the logs until your elasticsearch cluster is available. Bonus points if you use elastic compute on Amazon, so you can size your cluster up and down based on load (eg, the firewall gets hammered whenever we or our customers do PCI scans, which causes a lot of logging to be produced. It would be awsome to spin up extra elasticsearch and logstash nodes to handle these spikes).
  25. Oh it is small beer, but every little helps and all those 1% improvements start to add up.
×
×
  • Create New...