Tools & Info for Sysadmins - SSH Library, Network Security Tip, Deployment Toolkit & More

Each week, I thought I'd post these SysAdmin tools, tips, tutorials etc.

To make sure I'm following the rules of r/sysadmin, rather than link directly to our website for sign up for the weekly email we're running reddit ads so:

You can sign up to get this in your inbox each week (with extras) by following this link. If the subscription link is not working for you from your computer, try from mobile phone.

Here are the most-interesting items that have come across our desks, laptops and phones this week. As always, Hornetsecurity has no known affiliation with any of these unless we explicitly state otherwise.

** We're looking for your favorite tools and resources to share with the community... the ones that help you do your job better and more easily. Please comment with your favorite(s) and we'll be featuring them over the following weeks.

A Free Tool

Parallel-SSH is an asynchronous parallel SSH library designed to simplify large-scale automation. Uses the least resources and runs fastest among all Python SSH libraries. thenumberfourtytwo likes it because "all you need is a file containing all your ssh hostsβ€”which in hindsight is quite similar to ansible, in its simplest form."

A Tip

kuldan5853 offers this advice to reduce security risks associated with network print servers: "[T]his is not for print servers only, but really look into Micro Segmentation of your network - there is no reason why printers need to be exposed to the clients directly for example, or why the print server should see your HPC cluster.

It is vastly more effort to manage if you divide your network in many small subnets that are segregated via firewall, but the gain in security is about the biggest you can imagine (if the firewall rules are implemented strictly as needed and not what is convenient)."

Another Free Tool

PDFescape is a surprisingly capable online PDF editor that allows you to annotate & modify PDFs, create forms, and more… entirely for free. Works with any modern browser, with no downloads or account required and no watermarks.

Yet Another Free Tool

Bulk Crap Uninstaller is an uninstaller for removing the vast majority of crap applications that weigh down Windows, with little user input or tech

... keep reading on reddit ➑

πŸ‘︎ 102
πŸ’¬︎
πŸ‘€︎ u/dojo_sensei
πŸ“…︎ Jan 04 2022
🚨︎ report
aau-network-security/richkit - Domain Enrichment Toolkit $ pip install richkit github.com/aau-network-se…
πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/LinkDropper
πŸ“…︎ Apr 23 2021
🚨︎ report
Network Security Toolkit Live Distro Is Now Based on Fedora Linux 32 9to5linux.com/network-sec…
πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/CrankyBear
πŸ“…︎ Jun 11 2020
🚨︎ report
An offensive security toolkit written in Rust github.com/kmanc/remote_c…
πŸ‘︎ 63
πŸ’¬︎
πŸ‘€︎ u/binaryfor
πŸ“…︎ Jan 29 2022
🚨︎ report
An offensive security toolkit written in Rust github.com/kmanc/remote_c…
πŸ‘︎ 8
πŸ’¬︎
πŸ‘€︎ u/binaryfor
πŸ“…︎ Jan 29 2022
🚨︎ report
Network Security professionals. What's in your hardware / software toolkit?
πŸ‘︎ 13
πŸ’¬︎
πŸ‘€︎ u/pextris
πŸ“…︎ Aug 18 2015
🚨︎ report
If I click OK, I lose. My mobile network operator abusing the SIM Toolkit popup to force me into subscribing to a useless service for R$4.99/week v.redd.it/chneejeqoyj71
πŸ‘︎ 4k
πŸ’¬︎
πŸ‘€︎ u/aofeo
πŸ“…︎ Aug 27 2021
🚨︎ report
Network Security Toolkit and Cygwin-X on Windows 7

Howdy! There are plenty of mentions of and recommendations for the incomparable Network Security Toolkit NST here on reddit, so I won't tell you how incredible it is, but I did want to share this.

Wireshark on NST displaying on Windows 7

I just finished setting up Cygwin-X to host remote X sessions on my Win7 machine.

While it's not difficult to setup, it's not exactly easy either.

The purpose of this post is to encourage folks to check out NST, and also take advantage of some of the functions it includes that aren't well suited to the Web Interface. (Wireshark for example).

I can post my steps if anyone is interested though I suspect my "How-To" would reveal my hack and whack noobtastic approach to Linux. it's more like "If I can get it working, so can you".

anyway TONS of great Network tools available in NST, I have it running on a P4 2.8 with a Gig of Ram and it just runs and runs and runs.

Running Port Replication from my Center Star switch and NST has a dedicated interface monitoring that, plus another NIC for connecting to the network.

If you've ever wanted to try Linux, or any Linux based network tools this is a great excuse.

πŸ‘︎ 5
πŸ’¬︎
πŸ‘€︎ u/StrangeCaptain
πŸ“…︎ Oct 18 2012
🚨︎ report
Modifying oauth-toolkit token refresh behaviour for better security in SPA

I keep finding myself, having to modify the View logic for packages like django-oauth-toolkit, djangorestframework-simplejwt, etc to make it so that refresh token is exchanged in a HttpOnly cookie to harden security aspects further. A little while ago I decided to make a package that modifies this behavior for django-oauth-toolkit so I don't have to keep doing it in every Django Project: https://github.com/oscarychen/django-oauth-toolkit-cookie-refresh

If you are curious about why I'm doing it, I provided the explanation in the ReadMe. However, I'm hoping someone can take a look and see if my logic and implementation are sound, it's possible that I missed something entire. All suggestions welcome. Thanks!

πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/airoscar
πŸ“…︎ Jan 18 2022
🚨︎ report
Trigger is a robust network automation toolkit written in Python that was designed for interfacing with network devices and managing network configuration and security policy trigger.readthedocs.org/e…
πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/sclo
πŸ“…︎ Mar 14 2015
🚨︎ report
DD rolls out new security toolkit for drivers… thoughts? techcrunch.com/2021/11/03…
πŸ‘︎ 3
πŸ’¬︎
πŸ‘€︎ u/Subadonic
πŸ“…︎ Nov 04 2021
🚨︎ report
We’re proud to announce a partnership with ExLocker CryptEx is a security platform for DeFi projects, founded in 2021 and backed by HashExOfficial. CryptEx offers a comprehensive toolkit for projects & has helped over 600 projects safeguard about 3B of user funds from a variety of threats
πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/danktim
πŸ“…︎ Nov 21 2021
🚨︎ report
DoorDash rolls out SafeDash, an in-app security toolkit for delivery people on the platform – TechCrunch techcrunch.com/2021/11/03…
πŸ‘︎ 4
πŸ’¬︎
πŸ“…︎ Nov 04 2021
🚨︎ report
My S10 just got the August Security Update and there's a new SIM toolkit icon. reddit.com/gallery/pr2iws
πŸ‘︎ 32
πŸ’¬︎
πŸ‘€︎ u/GalacticAir
πŸ“…︎ Sep 19 2021
🚨︎ report
New Application Security Toolkit Uncovers Dependency Confusion Attacks darkreading.com/dr-tech/n…
πŸ‘︎ 2
πŸ’¬︎
πŸ‘€︎ u/oaf357
πŸ“…︎ Nov 11 2021
🚨︎ report
Armenia may apply to UN Security Council if CSTO toolkit fails to settle the issue on Armenian-Azerbaijani border – Pashinyan aysor.am/en/news/2021/05/…
πŸ‘︎ 77
πŸ’¬︎
πŸ‘€︎ u/melikdavid
πŸ“…︎ May 26 2021
🚨︎ report
My Mom needed a weatherproof USB security camera. She doesn't have a wifi network but runs a desktop close to her front door. reddit.com/gallery/sfdm19
πŸ‘︎ 585
πŸ’¬︎
πŸ‘€︎ u/peppernickel
πŸ“…︎ Jan 29 2022
🚨︎ report
If I click OK, I lose. My mobile network operator abusing the SIM Toolkit popup to force me into subscribing to a useless service for R$4.99/week v.redd.it/chneejeqoyj71
πŸ‘︎ 12
πŸ’¬︎
πŸ‘€︎ u/mrchaotica
πŸ“…︎ Aug 28 2021
🚨︎ report
Canada has no choice but to bar Huawei from 5G mobile networks, security experts say nationalnewswatch.com/202…
πŸ‘︎ 6k
πŸ’¬︎
πŸ“…︎ Nov 14 2021
🚨︎ report
Anyone surprised about the lack of fundamental knowledge in network security? Not enough forward engineering knowledge it seems.

There seems to be a surprising lack of fundamental knowledge in network security. Has anyone else felt the same?

Here are some examples working with different teams:

  • Work heavily with Kibana servers, but lacked fundamental database knowledge
    • You would think someone managing a clusters would at least understand the basics of distributed systems
  • Heavily use SIEMs, but could not tell you what a the concept of an operating system process beyond "Yeah, it's a program that executes."
  • A serious lack of web development knowledge

A lot of people entering the field claiming they are knowledgeable in network security, but can't forward engineer a basic CRUD app, and yet they'll claim they know how to reverse engineer it and secure it. Yeah, you're able to successfully complete a basic SQL injection hackthebox, but you could barely construct a SQL query yourself. You just blindly put in a SQL query and hope you get back an error saying the web application is vulnerable and then blindly put in another SQL query.

πŸ‘︎ 46
πŸ’¬︎
πŸ‘€︎ u/me_hungry_and_sad
πŸ“…︎ Jan 21 2022
🚨︎ report
Canada has no choice but to bar Huawei from 5G mobile networks, security experts say nationalpost.com/news/can…
πŸ‘︎ 4k
πŸ’¬︎
πŸ‘€︎ u/LisaMck041
πŸ“…︎ Nov 14 2021
🚨︎ report
Abusing Public Infrastructure to Build Your Own VirusTotal for Email: An Open-Source Secure Email Gateway Evaluation Toolkit github.com/Rices/Phishiou…
πŸ‘︎ 115
πŸ’¬︎
πŸ“…︎ Oct 25 2021
🚨︎ report
Don't keep your crypto currency on exchanges, it devalues your investment and weakens network security.

Security isnt the only reason people tell you not to keep crypto on exchanges, one reason banks have so much power is because of the huge amount of our money they have at their disposal, to lend and invest. Exchanges are centralisation centres for a technology that is valued for not being centralised. At the least you shouldn't do it since you're essentially devaluing your own investment.

It is not that hard to own your keys, a couple of off-line backups of a series of words stored in a few safe places, if you have a small amount it's not too big a deal, but it's better to learn how it works when it is not much risk for you, and if it's a big investment then it's pretty silly not to take a little time, less than an hour really, to learn how to go about storing your large investment safely.

It's without a doubt the safest way to store your investment, so long as you aren't bragging to the neighbours about it, and you took an hour to learn how to store off-line backups securely.

It's best practice, and that was known back when it was mostly punks who understood the technology and purpose of crypto, when new guys started coming along they would inform them of this, but over time and with new investors who don't really understand anything more than its potential to be profitable becoming the norm, the explanations became less detailed and and the core message of "not your keys not your crypto" became a beneficial meme that worked to get people to follow the best practices for keeping cryptos decentralised and safe.

Not your keys not your crypto, is important for every crypto holder to follow, at the least not to devalue a technology they are invested in. Decentralisation is one of the core value drivers for all cryptocurrencies and a major attribute of another core value, network security.

πŸ‘︎ 2
πŸ’¬︎
πŸ“…︎ Jan 29 2022
🚨︎ report
HOUDINI: A web app with huge number of Docker Images for Network Security with run commands and cheatsheet (Hundreds of Offensive and Useful Docker Images for Network Intrusion ) github.com/cybersecsi/HOU…
πŸ‘︎ 236
πŸ’¬︎
πŸ‘€︎ u/deleee
πŸ“…︎ Jan 20 2022
🚨︎ report
Fully remote job with just Network+ and Security+?

I am wondering if it’s possible to get a fully remote job with Just A+, Network+ and Security+. I spend most of my time outside of the United States.

πŸ‘︎ 46
πŸ’¬︎
πŸ‘€︎ u/staplesz
πŸ“…︎ Jan 04 2022
🚨︎ report
IT Pro Tuesday #182 - SSH Library, Network Security Tip, Deployment Toolkit & More

Welcome back to IT Pro Tuesday!

We're looking for your favorite tips and tools we can share with the community... those that help you do your job better and more easily. Please reply or leave a comment with your suggestions, and we'll be featuring them in the coming weeks.

And as always, we’re updating the full list on our website here. Enjoy.

But on with this week's tools...! Here are the most-interesting items that have come across our desks, laptops and phones this week. Hornetsecurity has no known affiliation with any of these unless we explicitly state otherwise.

A Free Tool

Parallel-SSH is an asynchronous parallel SSH library designed to simplify large-scale automation. Uses the least resources and runs fastest among all Python SSH libraries. thenumberfourtytwo likes it because "all you need is a file containing all your ssh hostsβ€”which in hindsight is quite similar to ansible, in its simplest form."

A Tip

kuldan5853 offers this advice to reduce security risks associated with network print servers: "[T]his is not for print servers only, but really look into Micro Segmentation of your network - there is no reason why printers need to be exposed to the clients directly for example, or why the print server should see your HPC cluster.

It is vastly more effort to manage if you divide your network in many small subnets that are segregated via firewall, but the gain in security is about the biggest you can imagine (if the firewall rules are implemented strictly as needed and not what is convenient)."

Another Free Tool

PDFescape is a surprisingly capable online PDF editor that allows you to annotate & modify PDFs, create forms, and more… entirely for free. Works with any modern browser, with no downloads or account required and no watermarks.

Yet Another Free Tool

Bulk Crap Uninstaller is an uninstaller for removing the vast majority of crap applications that weigh down Windows, with little user input or technical knowledge required. Can detect most applications and games (even portable or unregistered), clean up leftovers, force uninstall, automatically uninstall according to premade lists, and more. IntelligentCanary902 says, "I'm a big fan of the portable version."

**One More Free Tool

... keep reading on reddit ➑

πŸ‘︎ 21
πŸ’¬︎
πŸ‘€︎ u/dojo_sensei
πŸ“…︎ Jan 04 2022
🚨︎ report
SSH Library, Network Security Tip, Deployment Toolkit & More

Just a few free tools, resources etc.Β that can make your tech life a little nicer.

But without further ado, here's the list… I have no known association with any of these unless stated otherwise.

A Free Tool

Parallel-SSH is an asynchronous parallel SSH library designed to simplify large-scale automation. Uses the least resources and runs fastest among all Python SSH libraries. thenumberfourtytwo likes it because "all you need is a file containing all your ssh hostsβ€”which in hindsight is quite similar to ansible, in its simplest form."

A Tip

kuldan5853 offers this advice to reduce security risks associated with network print servers: "[T]his is not for print servers only, but really look into Micro Segmentation of your network - there is no reason why printers need to be exposed to the clients directly for example, or why the print server should see your HPC cluster.

It is vastly more effort to manage if you divide your network in many small subnets that are segregated via firewall, but the gain in security is about the biggest you can imagine (if the firewall rules are implemented strictly as needed and not what is convenient)."

Another Free Tool

PDFescape is a surprisingly capable online PDF editor that allows you to annotate & modify PDFs, create forms, and more… entirely for free. Works with any modern browser, with no downloads or account required and no watermarks.

Yet Another Free Tool

Bulk Crap Uninstaller is an uninstaller for removing the vast majority of crap applications that weigh down Windows, with little user input or technical knowledge required. Can detect most applications and games (even portable or unregistered), clean up leftovers, force uninstall, automatically uninstall according to premade lists, and more. IntelligentCanary902 says, "I'm a big fan of the portable version."

One More Free Tool

PSAppDeployToolkit facilitates the performance of common application deployment tasks, including interacting with users. It offers functions that simplify the scripting needed for deploying applications in the enterprise and that help create a consistent, more-successful deployment experience. Can be used to replace your WiseScript, VBScript and Batch wrapper scripts with a single versatile, reusable, extensible tool. A shout out to knawlejj for pointing us to this one.

... keep reading on reddit ➑

πŸ‘︎ 4
πŸ’¬︎
πŸ‘€︎ u/dojo_sensei
πŸ“…︎ Jan 04 2022
🚨︎ report

Please note that this site uses cookies to personalise content and adverts, to provide social media features, and to analyse web traffic. Click here for more information.