Author: Yuri Gagarin

BPM Style Integration

Hello, Habr! Our company specializes in developing ERP-class software solutions, with transactional systems that carry a large share of business logic and document management like a document management system. Modern versions of our products are based on JavaEE technologies, but we are also actively experimenting with microservices. One of the most challenging aspects of such solutions is the integration of various subsystems related to […]

Configuring the main settings on Huawei CloudEngine switches (using the 6865 as an example)

We have been using Huawei equipment in the production environment of our public cloud for quite some time. Recently, we put the CloudEngine 6865 model into operation, and while adding new devices, the idea emerged to share a checklist or a collection of basic configurations with examples. There are many similar instructions available online for users of Cisco equipment. However, there are few such articles for Huawei, and sometimes it is necessary to search […]

Release of NTP servers NTPsec 1.2.0 and Chrony 4.0 with support for the secure protocol NTS

The IETF (Internet Engineering Task Force), which is responsible for the development of internet protocols and architecture, has completed the formation of the RFC for the NTS (Network Time Security) protocol and published the associated specification under RFC 8915. The RFC has received the status of "Proposed Standard," after which work will begin to elevate the RFC to the status of Draft Standard, effectively signifying full stabilization of the protocol and consideration of […]

Snek 1.5 is available, a Python-like programming language for embedded systems

Keith Packard, an active developer of Debian, leader of the X.Org project and creator of numerous X extensions, including XRender, XComposite, and XRandR, has released a new version of the Snek programming language 1.5, which can be seen as a simplified version of Python, tailored for use on embedded systems that lack sufficient resources for MicroPython and CircuitPython. Snek does not claim to provide complete support for […]

Honeypot vs Deception using Xello as an example

There are already several articles on Habr about Honeypot and Deception technologies (1 article, 2 articles). However, we still encounter a lack of understanding regarding the difference between these classes of protection tools. For this reason, our colleagues from Xello Deception (the first Russian developer of Deception platforms) decided to thoroughly describe the distinctions, advantages, and architectural features of these solutions. Let's explore what […]

A Hole as a Security Tool – 2, or How to Catch APT 'Live'

(Thanks to Sergey G. Brester for the title idea) Colleagues, the goal of this article is to share our experience from a year of testing a new class of IDS solutions based on Deception technologies. To maintain the logical coherence of the material, I believe it's necessary to start with the premises. So, the problem statement: Targeted attacks are the most dangerous type of attacks, despite comprising a small portion of the total number of threats […]

Immensely attractive: how we created a honeypot that can't be exposed

Antivirus companies, cybersecurity experts, and simply enthusiasts post honeypot systems online to 'catch' fresh strains of viruses or detect unusual hacking tactics. Honeypots are so common that cybercriminals have developed a kind of immunity: they quickly recognize that they are faced with a trap and simply ignore it. To study the tactics of modern hackers, we created a realistic honeypot that […]

Release of NGINX Unit application server 1.20.0

The release of the NGINX Unit 1.20 application server has taken place, within which a solution for running web applications in various programming languages (Python, PHP, Perl, Ruby, Go, JavaScript/Node.js, and Java) is being developed. Under NGINX Unit, multiple applications in different programming languages can run simultaneously, with launch parameters that can be dynamically changed without needing to edit configuration files or restart. Code […]

Release of the Suricata 6.0 attack detection system

After a year of development, the OISF (Open Information Security Foundation) announced the release of the Suricata 6.0 intrusion detection and prevention system, which provides tools for inspecting various types of traffic. Suricata configurations allow the use of the signature database developed by the Snort project, as well as the Emerging Threats and Emerging Threats Pro rule sets. The project's source code is distributed under the GPLv2 license. Key changes: […]

Suricata 6.0

The release of Suricata 6.0 has been announced, the result of a year of work by the OISF development team and the Suricata community. The developers focused on stability, reliability, performance, support for new protocols (HTTP/2, MQTT, and RFB), improved support for DCERPC, SSH, and extensibility. Some components have been rewritten in Rust. Suricata is an open-source intrusion detection and prevention system (IDS/IPS). The system is developed by Open […]

Why don't the letters in EBCDIC appear consecutively?

The ASCII standard was adopted in 1963, and it is unlikely that anyone still uses a character encoding where the first 128 characters differ from ASCII. Nonetheless, until the end of the last century, EBCDIC was actively used—the standard encoding for IBM mainframes and their Soviet clones ES EVM. EBCDIC remains the primary encoding in z/OS, the standard OS for modern mainframes […]

ipipou: more than just an unencrypted tunnel

What do we say to the God of IPv6? Indeed, today we say the same to the God of encryption. This will cover unencrypted IPv4 tunnels, but not the old-fashioned kind; rather, the modern 'LED' type. Raw sockets will also be mentioned, and there will be work done with packets in user space. There are N tunneling protocols to suit every taste and style: the trendy and youthful WireGuard […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster