Category: Security

Tailscale VPN: Connect Your Own Services on Your Own Infrastructure

Proxmox in the data center, a laptop in the home office, a Raspberry Pi at the edge of a field, and a DGX Spark for inference: your own hardware is rarely in one place. NAT, firewalls, and dynamic IPs separate the devices. Manual WireGuard means: exchanging keys, maintaining IPs, updating firewall rules. Tailscale builds on

Securely Connected Remote Work

Connecting Distributed Nodes with a Nebula VPN Remote work has become the norm in the current situation. In a digital working environment, this should actually offer optimal possibilities. But one thing can become a problem: essential systems required for the daily workflow often cannot be used in a remote-work context. Not every company has set

Distributed Trust – Reputation Systems in the Blockchain

Distributed Reputation Systems in the Blockchain Almost every project that serves the interaction of people uses a concept for evaluating the reputation of its participants. If the implementation is still simple and clear at the beginning of a project, often even a bit naive, the demands grow over the further life cycle of a system.

How to disable the www-data user to send emails with postfix

Sometimes an insecure configuration allows spammer to use the www-data user to send emails with you postfix server. Normally this is the case, when you get a bunch of error email from your mailserver, that some emails from www-data@hostname.tld could not be delivered. To be sure, that this situation cannot exist, you can add the

black handled key on key hole

solving Security Error while starting Java WebStart (e.g. IPMI Remote)

Most of the IPMI Systems out there still using good old Java based Remote Applications to connect to the remote console. Sine Java 8 update 111, the MD5 singing algorithm was marked as insecure (aka disabled) by Oracale (see Relase Notes for that Release ” Restrict JARs signed with weak algorithms and keys”). You will

Jenkins/Hudson Password Hash Format

Nice to know: The Build-In Security Realm of Jenkins/Hudson is based on acegisecurity. The Hash is Sha256 based. For a Salt foo and a password bar , you have to Hash bar{foo} , that’s then 77ce9123f864f6749a2b2c99b988089c21d33e39247f7b1276dfad01a112f038 (via hashgenerator.de) You find the Hashes in <Jenkins-Dir>/users/<username>/config.xml it is then storred as   <?xml version=”1.0″ encoding=”UTF-8″ standalone=”yes”?> <user>

setup your public SSH key to another UNIX Host

Normally you would prefer to use your public ssh key for login into a remote linux machine. I created a script to perform the basic steps for inserting your public key into the hosts authorized_keys files. The script looks like this: #!/bin/bash HOST=$1; echo “>> setup your ssh keys for $HOST” echo “” echo “>>

tatsächlich….

…. fast schon wieder n Jahr rum 😉 Also irgendwie komme ich gar nicht mehr dazu hier was zu posten.Hat sich schon eine ganze Menge ereignet in letzter Zeit :-)Achja… heute dann mal in Deutsch wieder, irgendwie ist das Englische grade entfallen.Zuallererst:Ich habe endlich ein Macbook und es ist soooo schön! Zwar in weiß (und langsam

Die Sache mit den Emails (vorsicht, hoher Geek Faktor!)

Da einem Kollegen von mir Namentlich Bartosz, regelmäßig teilweise wirklich unglaubliche Dinge passieren, habe ich mal angefragt, und werde jetzt hin und wieder daraus etwas schildern…. tada…. *Tusch oder so* Bartosz Welt: Neulich beim abendlichen Chat mit einem Bekannten: < 23:21:19 xxxxxxxxx: die uni bei uns hat jetzt nen neuen spamfilter - exchange spam irgendwas,