Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Forwarded from Sys-Admin InfoSec
 
BLD DNS: One more server received as a gift from X-rdp.co

Hey, several days ago I published post (En denoscription) about the new server that was added to the BLD DNS infrastructure.

Today, I glad to present to you new server provided for BLD DNS from X-RDP.CO, located in Canada, I am really very happy, now I tested this server and want to present to you some information about of him:

- Speedtest - Download 940Mbps / Upload 236Mbps
- Storage IO - Write 1.1GB/s / Read7.1 GB/s
- CPU - AMD EPYC, 2395 MHz, KVM (AMD-V), 5 CPU Cores, 2 GB RAM

This server provided minimum on one year, I hope this service will bring a lot of benefits to the users of the service.

And I have another news - I requested from x-rdp.co discount coupon code and now I glad to present yo you
- Code: SYS10
- Discoint: 10%

I want to express my gratitude to the hosting, thank you, success to you and prosperity!

Take you care and safety. PEACE ✌️

#bld #dns #thanks
Sys-Admin Up pinned «  BLD DNS: One more server received as a gift from X-rdp.co Hey, several days ago I published post (En denoscription) about the new server that was added to the BLD DNS infrastructure. Today, I glad to present to you new server provided for BLD DNS from X…»
What Data Do The Google Dialer and Messages
Apps On Android Send to Google?

https://www.scss.tcd.ie/doug.leith/privacyofdialerandsmsapps.pdf
2022_ThreatDetectionReport_RedCanary.pdf
10.8 MB
Red Canary’s 2022 Threat Detection Report

Based on in-depth analysis of over 30,000 confirmed threats detected across our customers’ environments, this research arms security leaders and their teams with actionable insight into the threats we observe, techniques adversaries most commonly leverage, and trends that help you understand what is changing and why. This is our most expansive report to date, but our intention remains the same: The Threat Detection Report exists to help you understand and detect threats
Forwarded from Sys-Admin InfoSec
Secure BLD: Защита от оверлимитных запросов

За последнее время было замечено злоупотребление ресурсами BLD DNS, как это выглядит:
1. Штатное состояние - Опытным путем выявлено: 10к-20к запросов в час, это штатная работа средней организации.
2. Злоупотребление - Превышение максимально-допустимого количества запросов, например 20к+ запросов в час.

Как пример - NextDNS платная подписка начинается с 300к запросов в месяц. Штатное состояние BLD DNS покрывает месячный лимит NextDNS менее, чем за двое суток 🤘

Есть клиенты сервиса генерирующие по 100к запросов в час‼️, пропускная способность BLD DNS позволяет выдерживать хорошие нагрузки. Несколько миллионов в сутки - штатная работа BLD на сегодняшний день, но благодаря злоупотреблению суточная норма, легко превращается в часовой показатель, это не есть хорошо.

Возражений нет - задонать, уведомь и будем решать, если надо сделаем выделенный инстанс, не проблема (донаты вообще не воспрещаются, а даже приветсвуются, так как поддержка сервиса идет за счет внутренних ресурсов проекта).

Так же есть BLD+ (об этом пару месяцев назад был анонс), поэтому - welcome.

Превентивные меры
Вчера прилетело ~300к запросов за час сразу с нескольких IP адресов, стало понятно, что нужно что-то делать:
- Был разработан механизм автоматической блокировки абьюсеров 🎉
- На сегодня (пока) работает по формуле - 20000k запров в 1 час = бан 10 минут (кто будет отваливаться, сразу ко мне @sysadminkz, будем решать)
- Решение имеет "белые списки", так что оверлимитчикам welcome to donate area
- Решение полностью автономное, работает в автоматическом режиме.

Note: Кто знает, что у него генерится большое количество запросов и знает свой IP, можно заблаговременно обратиться ко мне.

~~~ EN

Recently, abuse of BLD DNS resources has been noticed, how it looks like:
1. Legitimate state - Experimentally revealed: 10k-20k requests per hour, this is the regular work of an medium organization.
2. Abuse - Exceeding the maximum allowable number of requests, for example 20k+ requests per hour.

As an example - NextDNS paid subnoscription starts with 300k requests per month. The regular state of BLD DNS covers the monthly NextDNS limit in less than two days 🤘

Today, there are clients of the service generating 100k requests per hour‼️, the bandwidth of BLD DNS allows to work with hight loads. Several million per day is the regular work of BLD today, but thanks to the abuse of the daily norm, it easily turns into an hourly norm, this is not good.

No objections - donate, and notify me and we will decide what we need to do, no problem(donations are not prohibited at all, but even welcome, since the support of the service comes at the expense of the internal resources of the project).

BLD+ mode specifically created for overlimits (there was an announcement about this a couple of months ago (https://news.1rj.ru/str/sysadm_in_channel/3740 )), therefore - welcome.

Preventive measures
Yesterday BLD received ~300k requests arrived in an hour from several IP addresses at once, it became clear that something needed to be done:
- The mechanism of automatic blocking of abusers was developed 🎉
- Today (so far) it works according to the formula - 20000k requests in 1 hour = ban 10 minutes (who will fall off, immediately contact me @sysadminkz, we will decide)
- The solution has "whitelists", so the are welcome to donate area and then welcome to BLD back.
- The blocking solution is completely autonomous, works in automatic mode.

Note: Who knows that he generates a large number of requests and knows own IP, you can contact me in advance.

Take you care. PEACE ✌️
Assessing Security and Privacy Controls in Information Systems and Organizations from NIST (Jan, 2022)

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar5.pdf