You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

177 lines
10 KiB

<!DOCTYPE html>
<html lang=""><link rel="stylesheet" href="../../css/style.css" type="text/css" media="all" />
<meta property="og:locale" content="en_US">
<meta property="og:type" content="article">
<meta property="og:title" content="Weekly Roundup #1: December 12-19th 2021 &middot; Graham Helton">
<meta property="og:description" content="What is this? This is the first of a weekly &amp;amp;ldquo;round up&amp;amp;rdquo; that aims to summarize the security or IT related concepts I have worked on this week during my free time. My goal is to create a footprint for others to follow in if they so desire. When I was first learning the basics of security I struggled to find projects that I could work on to help me learn useful security practices and techniques.">
<meta property="og:url" content="">
<meta property="og:site_name" content="Graham Helton">
<meta property="og:image" content="">
<meta property="og:image:secure_url" content="">
<script type="application/javascript">
var doNotTrack = false;
if (!doNotTrack) {
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
ga('create', 'UA-211014781-1', 'auto');
ga('send', 'pageview');
<meta property="article:published_time" content="2021-12-19T00:00:00Z">
<nav class="navbar" role="navigation">
<div class="navbar__left">
<a href="../../">Graham Helton</a>
<div class="">
<a href="../../roundup">Roundup</a>
<span class ="nav-item navbar-text mx-1">&emsp;/&emsp;</span>
<a href="../../blog">Blogs</a>
<span class ="nav-item navbar-text mx-1">&emsp;/&emsp;</span>
<a href="../../tags/">Tags</a>
<span class ="nav-item navbar-text mx-1">&emsp;/&emsp;</span>
<a href="../../pages/">Other</a>
<section class="section">
<div class="blog__container">
<h1 class="blog__title">Weekly Roundup #1: December 12-19th 2021</h1>
<p> The first roundup! </p>
<p>Published: December 19, 2021</p>
<p>Reading Time: 3 minutes <p>
<div class="blog__details">
<div class="blog__info">
<div class="content">
<h1 id="what-is-this">What is this?</h1>
<p>This is the first of a weekly &ldquo;round up&rdquo; that aims to summarize the security or IT related concepts I have worked on this week during my free time. My goal is to create a <em>footprint</em> for others to follow in if they so desire. When I was first learning the basics of security I struggled to find projects that I could work on to help me learn useful security practices and techniques. Some weeks will have have more content than others depending on the amount of free time I have.</p>
<h1 id="12122021">12/12/2021</h1>
<li>Went over SANS GSEC certification notes</li>
<li>Spent entirely too long getting <a href=""></a> and <a href=""></a> to point to my twitter and github using DNS&hellip;</li>
<li>Rebuilt homelab into a snazzy new case.</li>
<p><img src="../../Pasted-image-20211214203659.png" alt=""></p>
<li>Compiled some information about how to get started with docker to go through once I finish my SANS GSEC material</li>
<div class="highlight"><pre tabindex="0" style="color:#ebdbb2;background-color:#282828;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">1</span><span><span style="color:#928374;font-style:italic"># Docker learning resources</span>
</span></span><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">2</span><span><span style="color:#fe8019">=</span>wCTTHhehJbU
</span></span><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">3</span><span>
</span></span><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">4</span><span><span style="color:#fe8019">=</span>3c-iBn73dDE&amp;feature<span style="color:#fe8019">=</span>
</span></span><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">5</span><span>
</span></span><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">6</span><span><span style="color:#fe8019">=</span>MnUtHSpcdLQ&amp;feature<span style="color:#fe8019">=</span>
</span></span></code></pre></div><h1 id="12132021">12/13/2021</h1>
<li>Watched Black hills information security&rsquo;s <a href="">emergency log4j webcast</a></li>
<li>Studied SANS GSEC notes</li>
<li>Spent forever researching <a href="">searx</a> and borking installs.</li>
<li>Fiddled with my <a href="">recipe website</a> to fix some formatting issues.</li>
<h1 id="12142021">12/14/2021</h1>
<li>Studied SANS GSEC notes</li>
<li>Fixed searx install from previous day</li>
<li>Wrote <a href="">Thou Shall Not Snoop Our Searches - Searx Installation and Discussion</a></li>
<li>Added some android VMs to my lab for future projects</li>
<h1 id="12152021">12/15/2021</h1>
<p>Discovered <a href="">Unsupervised Learning</a> by <a href="">Daniel Miessler</a></p>
<p>Watched <a href="">A Tale of Two Johns (John hammond and John strand interview)</a></p>
<p>Set up rsyslog server in my home lab via <a href="">this tutorial</a> (This was very easy)</p>
<li>Noticed some weird things going on in my network. The first being some very strange pings every few minutes to some random IPs. After some researching I found a reddit post where someone described the same problem. Looks like its a part of <a href="">PIA&rsquo;s code</a> to check the latency to their servers.</li>
<p><img src="../../Pasted-image-20211215161851.png" alt=""></p>
<li>Noticed UFW was blocking some more traffic that happened to beacon every 2 minutes and 6 seconds&hellip;
<img src="../../Pasted-image-20211215162540.png" alt=""></li>
<p>Investigated further with wireshark and found out it was an IGMP query packet to refresh the IPs of multicast group memberships. This was sent out by my router.</p>
<div class="highlight"><pre tabindex="0" style="color:#ebdbb2;background-color:#282828;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span style="white-space:pre;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#756d59">1</span><span>sudo tcpdump -i &lt;interface&gt; -s <span style="color:#d3869b">65535</span> -w sketchy.pcap
<li>Added <a href=""></a> to my <a href="">smallScripts github repot</a></li>
<h1 id="12162021">12/16/2021</h1>
<li>Listened to <a href="">The Privacy, Security, and OSINT show</a> episodes 242 and 243</li>
<li>Discovered <a href=""></a> which is a collection of scripts to disable windows / mac features that reduce privacy</li>
<li>Verified with PIA VPN that they do send out pings to all their servers every couple minutes to &ldquo;verify connectivity&rdquo; (This still makes me feel uneasy&hellip;)</li>
<p><img src="../../Pasted-image-20211219153745.png" alt=""></p>
<li>Went over GSEC notes.</li>
<h1 id="12172021">12/17/2021</h1>
<li>Studied GSEC
<li>Finished indexing GSEC books</li>
<li>Formally accepted the agreement for the SANS Masters degree program (🎉 🎉🎉)</li>
<h1 id="12182021">12/18/2021</h1>
<li>Got sick :/</li>
<li>Binged like 20 <a href="">John Hammond videos</a></li>
<li>Learned a little bit about <a href=";t">web3</a>, <a href="">filecoin</a>, and <a href=";t">IPFS</a></li>
<h1 id="12192021">12/19/2021</h1>
<li>Listened to <a href="">darknet diaries #106</a></li>
<li>Published this round-up</li>
<li>Began looking for some open source asset management tool.
<li><a href="">@snipeyhead</a> on twitter linked me to <a href="">snipe-it</a></li>
<h1 id="have-any-questions">Have any questions</h1>
<p>Do you have any questions? Feel free to <a href="">reach out to me on twitter</a>. See you next Sunday. :)</p>
<div class="footer_class">
<a href="" title="Reach out to me">Have Questions? Reach out to me.</a>