Wednesday, 8 July 2020

copy (tftp) files to each switch in a cisco switch stack

copy tftp: flash1:
copy tftp: flash2:
copy tftp: flash3:

etc

On the master set the boot var for all switches
boot system switch all flash:image.bin


https://community.cisco.com/t5/switching/boot-system-command-for-quot-switch-2-quot-of-stack/td-p/1119357

Thursday, 11 June 2020

reset cisco 2960

https://www.cisco.com/c/en/us/support/docs/switches/catalyst-2950-series-switches/12040-pswdrec-2900xl.html#topic1

Wednesday, 10 June 2020

download packet capture (pcap) file from FMC / FTD / firepower



connect to the sensor of the FTD

use "system support diagnostic-cli" to go into ASA CLI

setup your capture as normal and capture your traffic.

Once complete "copy /pcap capture: disk0:"

now type exit twice to get out of ASA CLI

type "expert"

cd to "/mnt/disk0"

cp MYCAP.pcap /ngfw/var/common

On the FMC web interface

Devices -> hammer + wrech icon -> advanced 

Go into advanced troubleshooting -> File download

Enter MYCAP.pcap and click download.

Saturday, 6 June 2020

Deploying a Defensive Raspberry Pi



Raspberry pi

BroIDS (6:18)
Dependence

Doing the make on Bro takes a long time like 45 mins
Then make install

GW
Span / mirror port

Critical stack plugs into bro

Logstash (ELK stack)
inputs
filters
outputs

elastic search (database)

Kibana
Visualization engine (pie charts)

https://github.com/travisfsmith/sweetsecurity


Updated 


Watching to make sure we are receiving packets
watch ifconfig eth0


We can use BPF to whitelist certain traffic like netflix traffic for example.

Mikrotik routers can capture packets on it.

We need a 64bit OS to install RITA

Looks like we can get a vdsl SFP for mikrotik

Tuesday, 19 May 2020

can't RDP to server authentication error due to CredSSP encryption oracle remediation

The server is using this update but the client is not

Update both hosts to latest

On client gpedit.msc -> computer conf -> admin templates -> system -> credential delegation

Set Encryption oracle remediation
to enabled
drop down to vulnerable

https://weblogs.asp.net/dixin/remote-desktop-connection-authentication-error-due-to-credssp-encryption-oracle-remediation

Tuesday, 12 May 2020

cisco umbrella firewall rules

object-group network UmbrellaVAs
network-object host 10.53.0.71
network-object host 10.53.0.72


object-group network UmbrellaVA_Destination
network-object host 208.67.220.220
network-object host 208.67.222.222
network-object host 208.67.222.220
network-object host 208.67.220.222
network-object host 67.215.71.201
network-object host 146.112.255.155
network-object host 91.189.94.4
network-object host 91.189.89.199
network-object host 91.189.91.157
network-object host 91.189.89.198
network-object 67.215.92.0 255.255.255.0
network-object object ocsp.digicert.com
network-object object crl4.digicert.com
network-object object disthost.opendns.com
network-object object disthost.umbrella.com
network-object object s.tunnels.ironport.com

object-group service Umbrella_Ports tcp-udp
port-object eq domain
port-object eq 443
port-object eq www
port-object eq 123
port-object eq 22
port-object eq 25
port-object eq 5353
how is this even working?