Posts

Windows 2019, NPS and broken firewall rules (good job Microsoft...)

Image
I have a love and hate relationship with Microsoft products. In one hand they integrate well to each other, they cover most of real life use cases and some products are even the best you can find from the field. On the other hand, the quality of documentation can vary a "bit" too much, logging varies from great to awful and there are really weird design decisions here and there. One of these issues hit me hard a while ago when I was configuring a new environment for a customer. Win 2019 servers, Active Directory, Network Policy Server (NPS) and RADIUS authentication for accessing network devices. Sounds simple and easy, right?? Just install the NPS role to the server, create some rules who can authenticate and that's it. Well.... As you already might guess, things aren't so easy in this land of ICT misery. I actually once said to a friend of mine that I'm not sure if my job leans more on to comical or tragical side.... But, let's move on. After carefully veri...

Disobey 2020 - Covid-19 edition

Image
Pathetic topic. I know. But still, I decided to include the Covid-19 to the topic. Just because I wanted to share that I'm donating some of my electricity (aka. computing powers) to the greater cause. Folding@Home project has some Covid-19 related projects where you can share your compute resources to fight Covid-19. Drug and virus related researches are today really compute intensive, and thus also funding intensive. Having access to those high performance crunching machines requires quite much funding, because it's not cheap. In the last twenty or so years there have been projects where this number crunching has been divided and distributed to smaller computers around the globe. Seti@Home has been probably the most known one, but they have shutdown the project a couple of weeks ago. In the late 90s or start of this century there also was some crypto related project where they tried to bruteforce open various encryption algorithms. I recall to participate in that for so...

Disobey 2020, First Edition

Disobey 2020 is now over. And it was marvelous two days around topics like hacking Boeing , getting grasp of logs , various hacking competitions, red teaming workshops , etc. This post is named 'First Edition' because of two reasons. Firstly, this was my first Disobey. Secondly, I don't yet know how many posts I will write around this topic. Most probably this first post will be a general introduction and include also competition stuff, and then there will be one or two posts about presentations and workshops. I've wanted to go to Disobey for many years, but previously it has not been possible, for various reasons. Luckily this year it finally happened. Disobey 2020 was also my first ICT conference, so I didn't really know what to expect. But I'm glad that I started from Disobey! Disobey is a hacker conference from hackers to hackers, if you want to summarize it somehow. Program is built around different infosec/cybersec/etc fields, but in generally the h...