Security

Subscribe via RSS →
8 min read

The Anatomy of an AWS Key Leak to a Public Code Repository

Many of us working with any cloud provider know that you should never ever commit access keys to a public github repo. Some really bad things can happen if you do. AWS (and I assume all the cloud …

  • Security
  • Developer
  • git
  • AWS
6 min read

Separate VPC's can do More Harm Than Good

I have come across this a number of times of the past couple of months. Environments that were born in the datacenter, have grown in the datacenter - in short people who are used to certain (shall we …

  • legacy
  • Network
  • Security
  • culture
3 min read

M&M's, Snickers and Security in the Cloud

I cannot take credit for this one - I heard it last week at a very interesting talk by Adrian Cockroft at the Speed and Scale Meetup last week in Herzeliya. The analogy was a very simple one, but very …

  • Security
  • Cloud
3 min read

Security in VMware Virtual Appliances

Today I got a reminder of a post I have been meaning to write about security best practices and VMware Virtual Appliances. A question was raised on the VMTN community VCSA - what is the default …

  • Security
  • Appliances
  • VMware
  • vCenter
4 min read

The SSH Key Problem With Cloned Linux VM’s

First let me start off this by saying – the way this is effects you will differ entirely on your organizational procedures and security requirements. We all love templates – don’t we? I mean they are …

  • Design
  • Linux
  • Security
  • vSphere
5 min read

Should You Patch the vCenter Server Virtual Appliance?

With vCenter 5 came the release of the the vCenter Server Virtual Appliance. This move was applauded by many due to the fact that VMware made the first step in the direction of removing their …

  • Security
  • Appliances
  • VMware
  • vCenter
1 min read

New Patch released - VMSA-2010-0016

This was just released. KB 1027027 (ESX) and KB 1027753 (ESXi) I wanted to point out that is should deal with several issues that include a patch to solve this Host crash because of ESX Active …

  • Security
  • vSphere
  • 4.1
  • VMware
3 min read

Stuxnet & Virtualization Targeted DOS

Stuxnet for those of you have been unaware to the what has been happening with one of the most talked about worms since Conficker is an industrial rootkit targeted at Siemens software. Now conspiracy …

  • Security
  • Virtualization
  • Miscellaneous
  • Administration
4 min read

Set a Time Limit on Group Membership

One of the most surprising things that Microsoft have not yet provided in Active Directory management - is allowing you to set a time limit on assigning membership of a user to a group. Let me explain …

  • Active Directory
  • Tools
  • Security
  • Scripting
2 min read

Generate a Random Password - Powershell

A task that I do quite often when building a new System is to create random password a local user on the machine – Don’t ask – it is a an OPSEC requirement from way before my time. So instead of …

  • Tools
  • Security
  • Powershell
  • Administration