Oct 26, 2022

Moving from Operations to GitOps

After the article on Operation Hates Agile, here comes next, how to move from Operations to GitOps.

IaC is the replacement of traditional operation. It allows enterprises to control changes and manage the configuration settings in cloud environments more efficiently.

First, we need to know what contained inside "Infrastructure as Code" or IaC. There are 3 characteristics in IaC:

  1. Imperative and Declarative
  2. Mutable and Immutable
  3. DevOps

Imperative Vs. Declarative

Most IaC is declarative in nature. However, we can always make changes to the cloud environment with both imperative or declarative automation.

To make imperative automation changes to cloud infra, we use cmdline interface (CLI). It directs changes to the cloud first within a container, then virtual machine (VM), and then virtual private cloud, through a script. This is a detailed checklist, but if the configuration needs to be changed after the push to multiple machines, the steps and the script would have to be repeat.

A declarative automation approach requires goal creation. For example, rather than using the CLI and listing the exact step-by-step configuration for a VM, you’d simply state that you want a VM with, say, a domain attached, and then let the automation take over. The declarative approach (most of the time in YAML) enables you to more easily state what needs to be accomplished by the automation tools.

Mutable Vs. Immutable

Mutable means that it is prone to change. A virtual machine is an example of mutable infrastructure.

Immutable infrastructure cannot be changed once deployed, such as container/docker. Changes will still occur, but they are made to the original declarative statements. Once the changes are ready, all like devices or configurations are changed consistently.

Most of the time, we use both imperative and declarative automation methods interchangeably to manage IaC. This may raise an issue called Configuration Drift.

Oct 25, 2022

MHDDoS - DDoS Attack Script

MHDDoS is a DDoS Attack Script written in Python3. It includes 56 attack methods (DoS/DDoS). 


Installation (1st way)

$ git clone https://github.com/MHProDev/MHDDoS.git
$ cd MHDDoS
$ pip install -r requirements.txt

 Installation (2nd way)

$ docker pull ghcr.io/mhprodev/mhddos:latest


Links:

Oct 24, 2022

Multipass Private SSH Key is Exposing to Everyone

It is so convenience to use the command 'multipass shell jimny' whenever we need to access to VM created. 

But, how can we login without password? Where is the SSH private key?

Actually it is using SSH public key authentication for login to VM. 

Oct 23, 2022

Windows Event Log Analysis

Configuring logging on Windows systems, and aggregating those logs into a SIEM, is a critical step toward ensuring that your environment is able to support effective incident response using Incident response tools.

Events can be logged in the Security, System and Application event logs. 

Log NameEvent Log where the event is stored. Useful when processing numerous logs pulled from the same system.
SourceThe service, Microsoft component or application that generated the event.
Event IDA code assigned to each type of audited activity.
LevelThe severity assigned to the event in question.
User
The user account involved in triggering the activity or the user context that the source was running as when it logged the event.
OpCodeAssigned by the source generating the log.
LoggedThe local system date and time when the event was logged.
Task CategoryAssigned by the source generating the log.
KeywordsAssigned by the source and used to group or sort events.
ComputerThe computer on which the event was logged. This is useful when examining logs collected from multiple systems, but should not be considered to be the device that caused an event (remote workstation).
DescriptionA text block where additional information specific to the event being logged is recorded.

 

Types of Windows Event Log Analysis – Guide

  •     Account Management Events
  •     Account Logon and Logon Events
  •     Common Event ID 4768 result codes
  •     Logon event type code descriptions
  •     Common logon failure status codes
  •     Access to Shared Objects
  •     Scheduled Task Logging
  •     Object Access Auditing
  •     Audit Policy Changes
  •     Auditing Windows Services
  •     Wireless LAN Auditing
  •     Process Tracking
  •     Additional Program Execution Logging
  •     Auditing PowerShell Use


Go thru the complete incident response guide with the following link.


Links:

Oct 22, 2022

Couldn't open a raw socket. Error: Permission denied (13)

With Multipass, do I still need VMware Player to run Linux with full privilege, under Windows OS ?

WSL is more common choice of running virtual machine nowadays comparing to VMware Player.

With Multipass, everything seems more easier/faster now. 😇 

Here's my story today, on how I need to run nmap port scan to a router.

PS> multipass launch -n scanner

PS> multipass shell scanner

ubuntu@scanner:~$ sudo snap install nmap

ubuntu@scanner:~$ sudo nmap -sU -p 53 192.168.31.1
Starting Nmap 7.93 ( https://nmap.org ) at 2022-10-21 23:17 +08
Couldn't open a raw socket. Error: Permission denied (13)

ubuntu@scanner:~$ sudo snap connect nmap:network-control

ubuntu@suzuki:~$ sudo nmap -sU -p 53 192.168.31.1
Starting Nmap 7.93 ( https://nmap.org ) at 2022-10-21 23:18 +08
Nmap scan report for XiaoQiang (192.168.31.1)
Host is up (0.0027s latency).

PORT   STATE SERVICE
53/udp open  domain

Nmap done: 1 IP address (1 host up) scanned in 0.06 seconds

ubuntu@scanner:~$ sudo nmap -n -sS -p 1-1024 192.168.31.1
Starting Nmap 7.93 ( https://nmap.org ) at 2022-10-21 23:35 +08
Nmap scan report for 192.168.31.1
Host is up (0.0075s latency).
Not shown: 1020 closed tcp ports (reset)
PORT    STATE SERVICE
53/tcp  open  domain
80/tcp  open  http
443/tcp open  https
784/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 0.34 seconds
ubuntu@scanner:~$

With this, I have more confidence with Multipass now. 😉