starkzarn

joined 2 years ago
[โ€“] starkzarn@infosec.pub 1 points 6 days ago

Yes! Qsl cards are very much still alive and well. Some traditions will never die. The special event stations are fun to get cards from.

Super cool anecdote on the telescope thing, I've never heard of that.

I hope you get back on the radio, it's a great hobby. It's a nice stress relief outlet for me these days too.

[โ€“] starkzarn@infosec.pub 2 points 6 days ago (2 children)

Love to hear things like that! When I first got licensed the solar cycle was utter trash. We're past the peak now, but band conditions are still pretty good generally. A few watts and a wire will still get you somewhere with CW and some other forward error corrected modes (like FT8). I have a lot of fun with the digital stuff like AREDN, but it's definitely a different ball game and the old school SSB-based radio still has its place in my heart.

[โ€“] starkzarn@infosec.pub 2 points 1 week ago

False positive what? I didn't give any specific examples of alerts, just simply monitoring metrics. Are you referring to the note on the Dnsmasq memory leak?

[โ€“] starkzarn@infosec.pub 6 points 1 week ago

For any hams here, maybe this blog post will be up your alley. 73!

 
[โ€“] starkzarn@infosec.pub 8 points 2 weeks ago

I write a tech and radio blog, if that's your schtick. If not, no worries. Post your rss feed when you're done!

https://roguesecurity.dev/

[โ€“] starkzarn@infosec.pub 16 points 2 weeks ago

They misspelled "backdoors."

 

This one is less focused on self-hosting a homelab service, but I thought might be interesting for the homelabbers here. I got into this hobby through my career in cybersecurity, and decided to write up a little post about a tool I frequently use, mitmproxy!

[โ€“] starkzarn@infosec.pub 1 points 4 weeks ago

The OIDC settings in the Authelia config reference were the most nebulous to me, but they weren't entirely stumping. The hard part was interpreting whether my errors stemmed from an issue on the client application side or on the Authelia side.

I would imagine you could likely extend the config snippets from my post to work in your situation with a few tweaks. The big lift, the OIDC provider is covered, so I'd be curious to hear what else you have to tweak!

 

If you've followed any of my self-hosted headscale with Podman series, I wrote up another "bonus" post talking about OIDC configuration with Authelia. Took some trial and error, so I figured I'd document it in the public notebook.

[โ€“] starkzarn@infosec.pub 6 points 1 month ago

Hey good for you, that's awesome! My home network is also dual stacked.

You're right about the apples to oranges comparison, but it's not so wildly off, because the commentary is on adoption of new standards, regardless of bolt-on "fixes." Unauthenticated SNMP went through three revisions prior to adding authentication and encryption support.

[โ€“] starkzarn@infosec.pub 6 points 1 month ago (2 children)

And IPv6 was codified in RFCs and first addresses issued in 1999 but look where we are now. I'd bet your corporate network doesn't use IPv6 still. It's unfortunate, but sometimes the wheels of change are slow.

[โ€“] starkzarn@infosec.pub 5 points 1 month ago

Nagios is a premium offering. They have some open source components, but the software model is absolutely not built around the spirit of GPL.

Zabbix is the obvious alternative in my mind, and it is AGPLv3, so absolutely in the same spirit as the LibreNMS license. It's a slightly different tool though, and less network-specific. Having used both, I prefer LibreNMS for specifically network monitoring, it's laid out to cater more to an ISP-type entity running it, and I like that. Zabbix still gets my wholehearted stamp of approval though.

[โ€“] starkzarn@infosec.pub 5 points 1 month ago

Updated the post to reflect your feedback here. Thank you!

 

Another post in the records for the tech blog, this time all about opensource network monitoring with LibreNMS!

 

For those that were interested in my PART 1 post of the Grafana Loki OPNSense firewall log monitoring, I present you: PART 2! This one is the good one (albeit less technical) where we get the eye candy after getting the log ingestion pipeline already setup in part 1.

 

My first blog series on headscale with traefik through podman quadlets was pretty well received on here. I'm just getting started with this blog, and thought the second topic I recently worked on might be popular in this crowd too: a lower resource method of centralizing logs for OPNSense with Grafana Loki (and Alloy) including geoIP!

 

Part 1 of my Headscale and Traefik blog post seems to have gotten some good traction, so I just wanted to share with the community that I just published part 2!

 

Shameless self-plug here. I wrote a blog post to document my methodology after having some issues with publicly available examples of using Podman and traefik in a best-practices config. Hopefully this finds the one other person that was in my shoes and helps them out. Super happy for feedback if others care to share.

view more: next โ€บ