daily "top" for spam and malware

it’s interesting to take a look. and then a second look - as a lot of well known networks and hosts appear on those maps: SenderBase malware SenderBase spam and for general SenderBase reports, biggest threat intelligence network go here: SenderBase

May 13, 2015 · Łukasz Bromirski

use keys, not passwords

it’s subject old as world (password-protected world, that is). i had to do some of cleanup on my devices and i hit a problem with 4096 bit keys. so, just as a reference that may be helpful somewhere for someone - you import keys to Cisco IOS without any special problems: router#conf t Enter configuration commands, one per line. End with CNTL/Z. router(config)#ip ssh pubkey-chain router(conf-ssh-pubkey)#username TEST router(conf-ssh-pubkey-user)#key-string router(conf-ssh-pubkey-data)#AAAAB3NzaC1yc2EAAAADAQABAAACAQDCiLBaopUwsFb9YJNhGqVYqBajlrH S/zwD6/yR6N8VcRzrpqMMNCFXe1q5GMGM[...]ANWInd9GHBjTzbJWVwavxy1ooQewii8ErofZuv1l/SXSdXLzfL p0zMoZ0L+BNPS0j4XBS0N3t8Vl8oVixqIeG2BNTCNaDDt6hx2Q== lukasz@bromirski.net router(conf-ssh-pubkey-user)#exit router(conf-ssh-pubkey)#exit for Cisco ASA, keys that are longer than 2048 bits need to be prepared using pkf format, as command line has limit of 512 bytes. so, to move key in OpenSSH compliant format like this one: ...

April 1, 2015 · Łukasz Bromirski

deploy SIDR

google again dropped out of the internet because of failure to filter prefixes. SIDR configuration on Cisco gear is really simple - for IOS-XE, IOS-XR. if you have Juniper it takes like half a second of searching. of course configuring is one thing, visiting RIPE and cerfifying your own resources is another thing. then it’s all done. every prefix signed, and every autonomous system checking for certification data is helping. every single one.

March 15, 2015 · Łukasz Bromirski

christmas cleaning part 1

it seems that F-35 can’t end it’s failure series. despite GAO audits, model of building military equipment for biggest army in the world didn’t change a bit since end of second world war. they’re still ordering and building things that will bring maximum revenue to military vendors and not what military customers actually need. i immediately got back to one of the articles i’ve read recently in ACM Queue - responsive enterprise: embracing the hacker way. it’s great piece and synthezies todays world - not only corporations are dinosaurs of our current times. a big portion of industry is. on normal market, companies that can adapt or use feedback loop tu build better and better products thrive. and those, who need years and still are not able to produce competitive products should vanish in history books. ...

December 27, 2014 · Łukasz Bromirski

canvas fingerprinting... and unbound

some time ago I changed my BIND at home to Unbound, due to the change of the default DNS server in FreeBSD (yes, I do have my own DNS server at home, and it serves all local queries). actually, I have four right now ;) back in BIND times, i used a lot of scripts to add zones containing 127.0.0.1 for domains serving ads. after switching to Unbound - i forgot about it completely. ...

July 24, 2014 · Łukasz Bromirski

ASA 9.2(1)

…supports BGP and it’s already out. do you like BGP on your firewalls? i don’t. should we have the tool in hand, just in case? well, sometimes it’s handy. but going back again - do you like BGP on your firewalls? ;)

April 27, 2014 · Łukasz Bromirski

some weekend reading...

in 2002 it was calculated that to reach closest star (Proxima Centauri), multigenerational crew would need to start with at least 150 to 180 men and women. latest simulations show however, that to guarantee gen variance you’d need to take between 10000 and 40000 people onboard. it would be interesting to see how those plans will end up - we will stay on Earth until Sun burns out, we’ll kill each other or maybe we’ll start finally intergalactic travels? ...

April 5, 2014 · Łukasz Bromirski

ipv6... once again in bad spotlight

all memory and CPU related features in IPv6 world is major challenge even for modern hardware. unfortunately this is emphasized with lack of best practices followed by developers writing code. i just noticed there’s Microsoft Windows problem with IPv6 RA. it seems that actual problem is not limited only to RA, but actually - to the whole networking stack when working with link-local addresses. under Microsoft Windows code is allocating memory pretty recklessly. ...

April 1, 2014 · Łukasz Bromirski

just bunch of posts to read...

Jennifer Lawrence phenomenon (i can’t quite get Hunger Games popularity, but i love Silver Linings Playbook. how you should do proper conference badges (oh yeah, we’re learning!), Department of Defense outsources to private company management of their own images and movies archive for 10 years, RSA accepted 10M$ of bribe from NSA to promote weaker encryption algorithm and last but not least - DARPA vision of autonomic SkyNet network from eightees. and to sum it up - how to deal with the fact that what you do in your daily job, may not be the thing you love. from my own experience i can attest, that you should strive to find job you’ll love and treat it as a hobby (while this may lead to blurring time between work and private life, and in effect - turning into workaholic). ...

December 23, 2013 · Łukasz Bromirski

there's nothing interesting in TV...

…so I decided to use youtube to find my favorite Monty Python series, Program will resume soon (quite specific Polish series - BTW, never published on DVD!). i was also able to find archive of our old polish IT magazines - Bajtek, Top Secret and Secret Service. my own archive, collected over years and protected from everyone fell prey one day to suprise ‘cleaning’ organized in the basement where it was stored. i’m still looking for Gambler and Komputer magazines. i strongly believe that there’s no comparision between those articles and magazines that you’ve read from first to last page and todays worthless ‘magazines’ that compete with number of colorful photos and zero interesting content. ...

November 3, 2013 · Łukasz Bromirski