packetmischief.ca
Monitoring Direct Attached Storage Under ESXi | packetmischief.ca
https://www.packetmischief.ca/2011/03/31/monitoring-direct-attached-storage-under-esxi
Monitoring Direct Attached Storage Under ESXi. Mar 31, 2011. My home ESXi box has two drives in a mirror set connected to an LSI 9260-4i. These tests were all done with the default LSI CIM provider that comes with ESXi 4.1u1. I simulated a drive failure by pulling out one of the hot swap drive trays. This is the view within the vSphere Client when there are no failures. Drive 0 and 1 on enclosure 252 (the LSI 9260-4i) are both ONLINE; the RAID 1 logical volume is OPTIMAL. VMWare Sensors All Green. Even t...
packetmischief.ca
BRKSEC-2010: Emerging Threats – The State of Cyber Security | packetmischief.ca
https://www.packetmischief.ca/2015/06/09/brksec-2010-emerging-threats-the-state-of-cyber-security
BRKSEC-2010: Emerging Threats – The State of Cyber Security. Jun 9, 2015. Presenter: Craig Williams (@security craig) – Sr Technical Leader / Security Outreach Manager, Cisco TALOS. I’m from Talos. We love to stop bad guys. Talos by the numbers:. Incoming malware samples per day. Sender Base reputation queries per day. Talos has a serious amount of data. For serious. Data is key. It allows generation of real threat intel. We basically have a bottomless pit of data. Talos vuln dev team:. Http:/ blogs....
packetmischief.ca
Virtualizing the OpenBSD Routing Table | packetmischief.ca
https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table
Virtualizing the OpenBSD Routing Table. Sep 20, 2011. The OpenBSD routing table can be carved into multiple virtual routing tables allowing complete logical separation of attached networks. This article gives a brief overview of rtables and explains how to successfully leak traffic between virtual routing domains. The ability to virtualize the routing table in OpenBSD first appeared in version 4.6. Using separate routing tables is similar to using VRFs. In Cisco IOS or routing instances. By default, all ...
packetmischief.ca
Juniper Olive | packetmischief.ca
https://www.packetmischief.ca/juniper-olive
Mar 22, 2011. Olive refers to a regular PC or virtual machine that is running Juniper Networks’. JUNOS software. Juniper created Olive early on so they could perform testing of JUNOS during development. These days Olive is deprecated in favor of cheap, low-end M and J-series routers but is still used by people wanting to evaluate/test JUNOS or those who are studying for Juniper certifications. And known to not work. So I won’t reproduce a separate list here. My Olive Related Posts. 4 Types of Port Channe...
packetmischief.ca
BRKSEC-2139: Advanced Malware Protection | packetmischief.ca
https://www.packetmischief.ca/2015/06/10/brksec-2139-advanced-malware-protection
BRKSEC-2139: Advanced Malware Protection. Jun 10, 2015. Presenter: Eric Howard, Techincal Marketing Engineer. Why aren’t we stopping all the malware? The term “APT” has become the boogey man of cyber security. :-). You don’t need to know squat about writing malware in order to launch malware. Malware as a Service (swipe CC, pay bitcoin). Why aren’t we stopping all the malware? There’s no silver bullet. If you knew you were going to be compromised, would you do security differently? Fuzzy fingerprinting: ...
packetmischief.ca
BRKSEC-2137 – Snort Implementation in Cisco Products | packetmischief.ca
https://www.packetmischief.ca/2015/06/11/brksec-2137-snort-implementation-in-cisco-products
BRKSEC-2137 – Snort Implementation in Cisco Products. Jun 11, 2015. Presenter: Eric Kostlan, Technical Marketing Engineer, Cisco Security Technologies Group. Above all, Snort is a community –Eric. Over 4 million downloads. Nearly 500,000 registered users. Snort was created in 1998 (! Sourcefire founded in 2001. DAQ – packet acquisition library(ies? Detection engine – various performance settings (eg, how long to spend on regex). Two components: rule builder and inspection component. Rule bu...Output modu...
packetmischief.ca
The Correct Mask for a PE’s Loopback0 | packetmischief.ca
https://www.packetmischief.ca/2015/07/29/the-correct-mask-for-a-pes-loopback0
The Correct Mask for a PE’s Loopback0. Jul 29, 2015. As I’ve written about previously ( The Importance of BGP NEXT HOP in L3VPNs. Here’s the example network:. First thing to test is whether R50 can reach R8 at 192.168.100.8. R50# ping 192.168.100.8 timeout 1 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 192.168.100.8, timeout is 1 seconds: . Success rate is 0 percent (0/5). R2# show bgp vpnv4 unicast vrf BRANCHES 192.168.100.8 . Local 10.1.7.7. Metric 31) from 10.1.7.7 (10&...The RIB h...
packetmischief.ca
AirPlay, VLANs, and an Open Source Solution | packetmischief.ca
https://www.packetmischief.ca/2012/09/20/airplay-vlans-and-an-open-source-solution
AirPlay, VLANs, and an Open Source Solution. Sep 20, 2012. As I’ve written about in the past ( here. That’s fine and dandy but what my earlier article focused on was how Bonjour broke down in a network where what I’ll call the “server” and the “client” are not in the same Layer 2 domain/VLAN. This is because the service discovery aspect of Bonjour relies on link-local scope multicast. These packets will not cross Layer 3 boundaries in the network. Bonjour packets will not pass a Layer 3 boundary. It also...
packetmischief.ca
Installing Olive 10.4R1 under VMware | packetmischief.ca
https://www.packetmischief.ca/2011/03/24/installing-olive-10-4r1-under-vmware
Installing Olive 10.4R1 under VMware. Mar 24, 2011. It’s been a long time since I’ve taken a run at getting Olive up and working. I wanted to take another stab at it and document how to get a working Olive installation using the latest JUNOS code. I also wanted to document how to get Olive up inside VMware ESXi since I hadn’t actually done that before. Update June 3 2011:. Mention that it’s ESXi that I’m working with. The installation breaks down into four major steps:. FreeBSD 4.11 mini-iso. I found tha...
packetmischief.ca
Monitoring BIND9 | packetmischief.ca
https://www.packetmischief.ca/monitoring-bind9
Sep 16, 2004. The goal here is to monitor DNS servers running BIND. Version 9 and graph the various statistics that it records about itself. The statistics will be made available to the Net-SNMP daemon. By a script. From there, the data can be polled by whatever NMS you choose to use. Getting Stats from BIND. Serving Stats via SNMP. Download for BIND 9.4. Download for BIND 9.6 and Newer. Getting Stats from BIND. A quick look at the statistics file from BIND version 9.4:. Var/named/tmp/named.stats /tm...
SOCIAL ENGAGEMENT