Category: Administration

Everything you wanted to know about secure password resets. Part 1

Recently, I had the time to reconsider how the password reset function should work, first while embedding this functionality into ASafaWeb, and then when I helped someone else create something similar. In the second case, I wanted to provide him with a link to a canonical resource with all the details about securely implementing the reset function. However, the problem is that, […]

Minimizing risks of using DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH)

Minimizing the risks of using DoH and DoT Protecting against DoH and DoT Do you control your DNS traffic? Organizations invest a lot of time, money, and effort into securing their networks. However, one area that often doesn't receive adequate attention is DNS. A good overview of the risks associated with DNS is presented in Verisign's presentation at the Infosecurity conference. 31% of respondents […]

Key Milestones in the Evolution of Video Surveillance Systems

The capabilities of modern surveillance systems have long gone beyond mere video recording. Detecting movement in the area of interest, counting and identifying people and vehicles, tracking an object in motion—today, even the most affordable IP cameras can accomplish all this. With a sufficiently powerful server and the right software, the possibilities for security infrastructure become virtually limitless. And yet, […]

I automated the testing of Dr. Web. Can you?

I have never used Dr. Web. I have no idea how it works. But that didn't stop me from writing a series of automated tests for it (only my laziness prevented me from writing a hundred more): Installation test for Dr. Web; Access restriction test for removable devices (flash drives); Directory access segregation test between programs; Test […]

Sorry, OpenShift, we didn't appreciate you enough and took you for granted.

This post is written because our employees have had quite a few conversations with clients about application development on Kubernetes and the specifics of such development on OpenShift. We usually start with the thesis that Kubernetes is just Kubernetes, while OpenShift is already a Kubernetes platform, like Microsoft AKS or Amazon EKS. Each of these platforms has its own […]

Preparing a DRP — don't forget to consider a meteorite

Even during a disaster, there's always time for a cup of tea. A disaster recovery plan (DRP) is something that ideally you'll never need. But if suddenly beavers migrating during mating season chew through the main fiber optic line or a junior admin drops the production database, you definitely want to be sure you have a pre-prepared plan for what to do about all this […]

Installation and operation of 'Rudder'

Foreword Our 'friendship' began two years ago. I started a new job where the previous admin casually left me this software as an inheritance. I couldn't find anything online apart from the official documentation. Even now, if you Google 'rudder', in 99% of the cases, you will get results about ship steering wheels and drones. I managed to find an approach to it. Since the Community […]

Introduction to Debezium — CDC for Apache Kafka

In my work, I often encounter new technical solutions/software products for which there is very little information available in Russian online. This article aims to fill one such gap with an example from my recent practice when it was necessary to set up CDC event sending from two popular DBMS (PostgreSQL and MongoDB) to a Kafka cluster using Debezium. I hope this overview article, which has appeared due to […]

Provider, install my antivirus on VDI

Among our clients, there are companies that use Kaspersky solutions as their corporate standard and manage antivirus protection independently. It might seem that the virtual desktop service, where the provider monitors the antivirus, wouldn't fit them at all. Today, I'll show how clients can manage protection themselves without compromising the security of virtual desktops. In the last post, we already shared in […]

How we protect client virtual desktops from viruses, spyware, and attacks

This year, many companies rushed to transition to remote work. We helped some clients set up over a hundred remote workstations in one week. It was important to do this quickly but also safely. VDI technology came to the rescue: it allows for easy distribution of security policies across all workstations and helps protect against data leaks. In this article […]

We are checking the capabilities of the Intel Xeon Gold 6254 for working with 1C in the cloud based on the Gilev test.

Earlier this spring, we upgraded the infrastructure of the cloud mClouds.ru to the latest Xeon Gold 6254. It's too late for a detailed overview of the processor — over a year has passed since its release, and its specifications are well-known. However, one noteworthy feature is that the processor has a base frequency of 3.1 GHz and 18 cores, which can boost with turbo […]

Packet Tracer. Laboratory Work: Configuring Floating Static Routes

Network Topology Tasks Create a primary static default route Deploy a floating static route Verify failover to the floating static route when the primary route fails Overview To start, let's clarify what a static route, and even a floating route, is. Unlike dynamic routing, static routing requires building the route manually to a specific network. A floating […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster