Category: Administration

Two-factor authentication for VPN users via MikroTik and SMS

Hello colleagues! Now that the excitement around remote work has calmed down a bit, and most admins have successfully enabled remote access for employees to the corporate network, it's time to share my long-standing approach to enhancing VPN security. This article will not cover the currently popular IPSec IKEv2 and xAuth. Instead, we'll discuss building a two-factor authentication (2FA) system for VPN users, with MikroTik serving as the […]

Comparison of platforms for 1C development and Client Communicator

In this article, I will discuss 1C and КлиК not as ready-to-implement solutions, but as platforms for creating customized solutions. 1C Client Communicator Free versions are not available. A free educational version is available with many different limitations. Any configuration can be used in single-user mode for free and without restrictions. Installation File version (not recommended for network use): […]

Overview of the Okerr Hybrid Monitoring System

Two years ago, I already made a post about a simple failover for the okerr website. Now there has been some development of the project, and I also published the source code of the okerr server part under an open license, so I decided to write this small overview on Habr. [ full size ] Who might be interested This may be of interest to you if you […]

Simple failover for a website (monitoring + dynamic DNS)

In this article, I want to show how easy and free it is to create a failover scheme for a website (or any other internet service) using a combination of Okerr monitoring and a dynamic DNS service. That is, in case of any issues with the main site (ranging from a "PHP Error" on the page to lack of space or a suspiciously low number of orders […]

We accelerate internet requests and sleep soundly

Netflix is the market leader in internet television, a company that has created and actively developed this segment. Netflix is known not only for its extensive catalog of films and series available from almost any corner of the planet and on any device with a display, but also for its reliable infrastructure and unique engineering culture. A clear example of Netflix's approach to developing and supporting complex systems was presented at DevOops 2019 […]

What Has Changed in Capacity Tier Since Veeam Became v10

The Capacity Tier (or as we refer to it internally at Veeam — cap tier) first appeared in Veeam Backup and Replication 9.5 Update 4 under the name Archive Tier. Its underlying idea is to allow backups that have fallen outside the so-called operational restore window to be moved to object storage. This helped free up disk space for those backups.

How Time Synchronization Became Secure

How to Ensure Time Itself Doesn't Lie When You Have Millions of Large and Small Devices Interacting via TCP/IP? Each of them has a clock, and the time must be correct on all of them. This problem cannot be solved without NTP. Let's imagine for a moment that difficulties arose in one segment of industrial IT infrastructure.

The problem of outdated root certificates. Let's Encrypt and smart TVs are next in line.

For a browser to authenticate a website, it presents a valid certificate chain. A typical chain is shown above, which may contain more than one intermediate certificate. The minimum number of certificates in a valid chain is three. The root certificate is the heart of the certification authority. It is literally embedded in your OS or browser and physically exists on your device. It cannot be changed with […]

10 common mistakes when using Kubernetes

Note from the authors: the authors of this article are engineers from a small Czech company, Pipetail. They managed to compile a remarkable list of [somewhat trivial yet still] highly relevant issues and misconceptions related to the operation of Kubernetes clusters. Over the years of using Kubernetes, we have had the opportunity to work with a large number of clusters (both managed and unmanaged — on GCP, AWS, and Azure). […]

In-memory architecture for web services: fundamentals of technology and principles

In-Memory — a set of data storage concepts where data is stored in the application’s RAM, while the disk is used for backup. In traditional approaches, data is stored on the disk, and memory is used for caching. For instance, a web application with a backend for processing data requests them from the storage: retrieves, transforms, and transmits a large amount of data over the network. In In-Memory computing, processing occurs closer to the data — […]

Elastic Under Lock: Enabling Security Options for Elasticsearch Cluster Access from Inside and Outside

Elastic Stack is a well-known tool in the SIEM systems market (indeed, not just for them). It can gather diverse data, both sensitive and non-sensitive. It is not entirely correct if access to the Elastic Stack components themselves is not secured. By default, all out-of-the-box Elastic components (Elasticsearch, Logstash, Kibana, and Beats collectors) operate over open protocols. And […]

Remote Desktop from the attacker's perspective

1. Introduction Companies that had not organized remote access systems were urgently deploying them a couple of months ago. Not all administrators were prepared for such "heat"; as a consequence, there were security oversights: incorrect service configurations or even the installation of outdated software versions with previously known vulnerabilities. Some of these oversights have already come back to haunt them, while others have been luckier, […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster