@kajer I've said it before and I'll say it again: Ubiquiti is the Tesla of network gear.
Notices by cR0w (cr0w@infosec.exchange)
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 20-Nov-2024 06:19:18 JST cR0w -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 19-Nov-2024 10:09:57 JST cR0w @jornane @The_Turtle_Moves @dalias "You must click this link to learn why you must never click links."
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 19-Nov-2024 05:03:30 JST cR0w @edolnx I don't know of an existing reliable solution, but I think @ryanc deployed one in the past. Maybe they have some pointers.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 15-Nov-2024 09:12:15 JST cR0w PAN Then: We don't know that there is a vulnerability. It's all rumors.
PAN Now: There's an unauth RCE that we have observed and do not have a fix for, but we told you to segment so it's your fault if you get pwned.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Wednesday, 13-Nov-2024 09:25:56 JST cR0w @danrubins @GossiTheDog If you have older logs, it may be worth looking back further. I've seen it going since at least July with my tenants.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 29-Oct-2024 08:15:43 JST cR0w @ryanc You mean the same way they already do their geo lookups? Seems simple enough to me when you already have the update mechanism in place.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 29-Oct-2024 08:10:30 JST cR0w @ryanc It's maddening how few security appliances have this basic feature.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 29-Oct-2024 08:08:54 JST cR0w @ryanc :flan_set_fire:
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Saturday, 26-Oct-2024 06:13:43 JST cR0w @patrickcmiller I am the 14%. That's a sad number. :-(
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 11-Oct-2024 23:36:32 JST cR0w @ryanc git ret
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Thursday, 10-Oct-2024 21:14:25 JST cR0w @ryanc That makes sense. I was more thinking about how it's nice to get a little bit of insight into some of the inner workings of a device before you purchase it.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 27-Sep-2024 02:56:55 JST cR0w -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Monday, 23-Sep-2024 23:49:06 JST cR0w Has anyone ever seen anything legitimate coming out of Stark Industries ( AS44477 )? It's been over a year of "don't block, just in case" at a couple sites, but I have yet to see anything worth allowing from them. And with more of their IPs geolocating to the US, they're getting around geoblocks.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Saturday, 21-Sep-2024 00:01:28 JST cR0w -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Thursday, 19-Sep-2024 23:42:21 JST cR0w Someone woke up and chose violence and I'm here for it.
https://www.fox13seattle.com/news/seattle-top-pizza-city-study
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Tuesday, 17-Sep-2024 00:04:02 JST cR0w @mattly Honestly, why even stop at three digits per octet?
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Monday, 16-Sep-2024 23:58:45 JST cR0w Y'all realize the whole IPv4 shortage is just manufactured scarcity to allow ISPs and cloud hosting companies to charge more, right? If IANA would allow us to go above 255 in each octet, we would have more than enough addresses to go around and not have to mess around with NAT and IPv6.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Saturday, 14-Sep-2024 22:19:32 JST cR0w -
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 13-Sep-2024 22:55:13 JST cR0w @GossiTheDog In before the 1337 INFOSEC nerds denigrate them as "script kiddies" again despite being more effective than the "professionals" ever will be.
-
Embed this notice
cR0w (cr0w@infosec.exchange)'s status on Friday, 13-Sep-2024 02:14:58 JST cR0w @ryanc When I worked in PHYSEC, we only used Axis in high risk and high value locations. That was nearly a decade ago so grain of salt, but I agree that they're generally worth it. Just keep them off the damn Internet. 😆