Category: Administration

Configuring the main settings on Huawei CloudEngine switches (using the 6865 as an example)

We have been using Huawei equipment in the production environment of our public cloud for quite some time. Recently, we put the CloudEngine 6865 model into operation, and while adding new devices, the idea emerged to share a checklist or a collection of basic configurations with examples. There are many similar instructions available online for users of Cisco equipment. However, there are few such articles for Huawei, and sometimes it is necessary to search […]

Honeypot vs Deception using Xello as an example

There are already several articles on Habr about Honeypot and Deception technologies (1 article, 2 articles). However, we still encounter a lack of understanding regarding the difference between these classes of protection tools. For this reason, our colleagues from Xello Deception (the first Russian developer of Deception platforms) decided to thoroughly describe the distinctions, advantages, and architectural features of these solutions. Let's explore what […]

A Hole as a Security Tool – 2, or How to Catch APT 'Live'

(Thanks to Sergey G. Brester for the title idea) Colleagues, the goal of this article is to share our experience from a year of testing a new class of IDS solutions based on Deception technologies. To maintain the logical coherence of the material, I believe it's necessary to start with the premises. So, the problem statement: Targeted attacks are the most dangerous type of attacks, despite comprising a small portion of the total number of threats […]

Immensely attractive: how we created a honeypot that can't be exposed

Antivirus companies, cybersecurity experts, and simply enthusiasts post honeypot systems online to 'catch' fresh strains of viruses or detect unusual hacking tactics. Honeypots are so common that cybercriminals have developed a kind of immunity: they quickly recognize that they are faced with a trap and simply ignore it. To study the tactics of modern hackers, we created a realistic honeypot that […]

Why don't the letters in EBCDIC appear consecutively?

The ASCII standard was adopted in 1963, and it is unlikely that anyone still uses a character encoding where the first 128 characters differ from ASCII. Nonetheless, until the end of the last century, EBCDIC was actively used—the standard encoding for IBM mainframes and their Soviet clones ES EVM. EBCDIC remains the primary encoding in z/OS, the standard OS for modern mainframes […]

ipipou: more than just an unencrypted tunnel

What do we say to the God of IPv6? Indeed, today we say the same to the God of encryption. This will cover unencrypted IPv4 tunnels, but not the old-fashioned kind; rather, the modern 'LED' type. Raw sockets will also be mentioned, and there will be work done with packets in user space. There are N tunneling protocols to suit every taste and style: the trendy and youthful WireGuard […]

Remote work or a review of VPN in Sophos XG Firewall

Hello everyone! This article will focus on reviewing the VPN functionality in the Sophos XG Firewall product. In the previous article, we discussed how to obtain this home network protection solution for free with a full license. Today, we'll talk about the VPN features built into Sophos XG. I'll try to explain what this product can do, and I'll also provide examples of IPSec configuration […]

The Battle of Jenkins and GitLab CI/CD

In the last decade, significant progress has been made in the development of continuous integration (CI) and continuous delivery (CD) tools. The advancement of development and operations (DevOps) integration technologies has led to a rapid increase in the demand for CI/CD tools. Existing solutions are constantly improving, striving to keep up with the times, and new versions are being released, as the world of control […]

Industrial trends in mass data storage systems

Today we will discuss how to better store data in a world where fifth-generation networks, genome scanners, and autonomous vehicles produce more data in a day than all of humanity generated before the industrial revolution. Our world is generating more and more information. Some of it is fleeting and lost just as quickly as it is collected. Other parts need to be stored longer […]

Introduction to Semaphores in Linux

This article's translation has been prepared in anticipation of the launch of the "Administrator Linux.Basic" course. A semaphore is a mechanism that allows competing processes and threads to work with shared resources and helps solve various synchronization issues such as race conditions, deadlocks, and incorrect thread behavior. To address these problems, the kernel includes tools such as mutexes, semaphores, signals, and barriers. […]

These crazy KPIs

Do you love KPIs? Probably not. It's hard to find someone who hasn't been affected by KPIs in one way or another: some have failed to meet targets, others faced subjective assessments, and some worked, left, but never learned what those very KPIs were, which were even feared to be mentioned in the company. And […]

Creating Optimized Docker Images for a Spring Boot Application

Containers have become the preferred method for packaging an application with all its software and operating system dependencies, and then delivering them across various environments. This article explores different ways to containerize a Spring Boot application: creating a Docker image using a Dockerfile, building an OCI image from source code using Cloud-Native Buildpack, and optimizing the image at runtime by […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster