home.social

#egress — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #egress, aggregated by home.social.

  1. Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].

    "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"

    They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.

    While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.

    [1] gov.uk/government/publications
    [2] web-assets.esetstatic.com/wls/

  2. Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].

    "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"

    They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.

    While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.

    [1] gov.uk/government/publications
    [2] web-assets.esetstatic.com/wls/

  3. Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].

    "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"

    They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.

    While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.

    [1] gov.uk/government/publications
    [2] web-assets.esetstatic.com/wls/

  4. Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].

    "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"

    They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.

    While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.

    [1] gov.uk/government/publications
    [2] web-assets.esetstatic.com/wls/

  5. Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].

    "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"

    They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.

    While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.

    [1] gov.uk/government/publications
    [2] web-assets.esetstatic.com/wls/

  6. 65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering.

    Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯

    securityblueprints.io/posts/th

  7. 65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering.

    Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯

    securityblueprints.io/posts/th

  8. 65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering.

    Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯

    securityblueprints.io/posts/th

  9. VPC Endpoint Bucket Policies are completely ineffectual in preventing exfiltration if the workload has access to the Internet. Just upload to the $otherCloud's storage endpoint.

    This is where #egress filtering at the NAT gateway layer prevents a compromise.

  10. VPC Endpoint Bucket Policies are completely ineffectual in preventing exfiltration if the workload has access to the Internet. Just upload to the $otherCloud's storage endpoint.

    This is where #egress filtering at the NAT gateway layer prevents a compromise.

  11. VPC Endpoint Bucket Policies are completely ineffectual in preventing exfiltration if the workload has access to the Internet. Just upload to the $otherCloud's storage endpoint.

    This is where #egress filtering at the NAT gateway layer prevents a compromise.

  12. Регион выхода — это инфраструктура, а не настройка у пользователя

    Сервис открывается, отвечает, всё работает — но цены в другой валюте, половина функций спрятана, а платёжный шаг падает с невнятной ошибкой. Через час выясняется, что выдача зависит от того, из какого региона пришёл запрос, а вы ходите из «неправильного». Знакомо всем, кто проверял локализацию продукта или подключался к региональному B2B‑порталу из другой страны. Дальше обычно появляется VPN до нужного региона, и на этом задача считается решённой. На практике решённой она не считается — просто проблема переезжает в то место, где её не видно.

    habr.com/ru/articles/1051676/

    #policybased_routing #маршрутизация_трафика #egress #Squid #CDN #SNI #прокси

  13. Регион выхода — это инфраструктура, а не настройка у пользователя

    Сервис открывается, отвечает, всё работает — но цены в другой валюте, половина функций спрятана, а платёжный шаг падает с невнятной ошибкой. Через час выясняется, что выдача зависит от того, из какого региона пришёл запрос, а вы ходите из «неправильного». Знакомо всем, кто проверял локализацию продукта или подключался к региональному B2B‑порталу из другой страны. Дальше обычно появляется VPN до нужного региона, и на этом задача считается решённой. На практике решённой она не считается — просто проблема переезжает в то место, где её не видно.

    habr.com/ru/articles/1051676/

    #policybased_routing #маршрутизация_трафика #egress #Squid #CDN #SNI #прокси

  14. Регион выхода — это инфраструктура, а не настройка у пользователя

    Сервис открывается, отвечает, всё работает — но цены в другой валюте, половина функций спрятана, а платёжный шаг падает с невнятной ошибкой. Через час выясняется, что выдача зависит от того, из какого региона пришёл запрос, а вы ходите из «неправильного». Знакомо всем, кто проверял локализацию продукта или подключался к региональному B2B‑порталу из другой страны. Дальше обычно появляется VPN до нужного региона, и на этом задача считается решённой. На практике решённой она не считается — просто проблема переезжает в то место, где её не видно.

    habr.com/ru/articles/1051676/

    #policybased_routing #маршрутизация_трафика #egress #Squid #CDN #SNI #прокси

  15. 8 PoPs по миру за €46/мес: реальная экономика pet privacy-DNS в цифрах

    Я полгода в одиночку пилю VantageDNS, privacy-focused recursive DNS с фильтрацией. Аналог NextDNS, юрисдикция EU. Ниже честный построчный разбор того, во что мне на самом деле обходится сеть из 8 нод по миру и контрол-плейн. Не маркетинговое «около ста евро», а реальная цифра, которая каждый месяц списывается с карты: €46.27. В конце таблица расходов и прикидка, сколько платных юзеров надо, чтобы это перестало быть хобби. Показать счёт

    habr.com/ru/articles/1035616/

    #VPS #инфраструктура #egress #DNSпровайдер #lowcost #индихакерство #биллинг #EU #экономика #soлоSaaS

  16. 8 PoPs по миру за €46/мес: реальная экономика pet privacy-DNS в цифрах

    Я полгода в одиночку пилю VantageDNS, privacy-focused recursive DNS с фильтрацией. Аналог NextDNS, юрисдикция EU. Ниже честный построчный разбор того, во что мне на самом деле обходится сеть из 8 нод по миру и контрол-плейн. Не маркетинговое «около ста евро», а реальная цифра, которая каждый месяц списывается с карты: €46.27. В конце таблица расходов и прикидка, сколько платных юзеров надо, чтобы это перестало быть хобби. Показать счёт

    habr.com/ru/articles/1035616/

    #VPS #инфраструктура #egress #DNSпровайдер #lowcost #индихакерство #биллинг #EU #экономика #soлоSaaS

  17. 8 PoPs по миру за €46/мес: реальная экономика pet privacy-DNS в цифрах

    Я полгода в одиночку пилю VantageDNS, privacy-focused recursive DNS с фильтрацией. Аналог NextDNS, юрисдикция EU. Ниже честный построчный разбор того, во что мне на самом деле обходится сеть из 8 нод по миру и контрол-плейн. Не маркетинговое «около ста евро», а реальная цифра, которая каждый месяц списывается с карты: €46.27. В конце таблица расходов и прикидка, сколько платных юзеров надо, чтобы это перестало быть хобби. Показать счёт

    habr.com/ru/articles/1035616/

    #VPS #инфраструктура #egress #DNSпровайдер #lowcost #индихакерство #биллинг #EU #экономика #soлоSaaS

  18. RE: infosec.exchange/@ChaserSystem

    Our #egress filtering solution for containing agent behaviour in the cloud appears to be hardened enough as of today 🤞 . Of course, it is not a system you log into or get shell access during the course of work. And all input is first sanitised by the cloud APIs and then our own logic.

  19. RE: infosec.exchange/@ChaserSystem

    Our #egress filtering solution for containing agent behaviour in the cloud appears to be hardened enough as of today 🤞 . Of course, it is not a system you log into or get shell access during the course of work. And all input is first sanitised by the cloud APIs and then our own logic.

  20. RE: infosec.exchange/@ChaserSystem

    Our #egress filtering solution for containing agent behaviour in the cloud appears to be hardened enough as of today 🤞 . Of course, it is not a system you log into or get shell access during the course of work. And all input is first sanitised by the cloud APIs and then our own logic.

  21. Agentic red teaming (or malicious activity) have lowered the bar for their human actors when it comes to #evasion around #egress #filtering tech; and raised the bar for vendors making such tech 🙋‍♂️

    <insert bittersweet meme>

  22. Agentic red teaming (or malicious activity) have lowered the bar for their human actors when it comes to #evasion around #egress #filtering tech; and raised the bar for vendors making such tech 🙋‍♂️

    <insert bittersweet meme>

  23. Agentic red teaming (or malicious activity) have lowered the bar for their human actors when it comes to #evasion around #egress #filtering tech; and raised the bar for vendors making such tech 🙋‍♂️

    <insert bittersweet meme>

  24. Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs?

    New feature in the works that'll let you capture your progress with updating the crypto libs

    #DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement

  25. Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs?

    New feature in the works that'll let you capture your progress with updating the crypto libs

    #DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement

  26. Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs?

    New feature in the works that'll let you capture your progress with updating the crypto libs

    #DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement

  27. Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: chasersystems.com/

    Link to review: g2.com/products/discriminat-fi

  28. Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: chasersystems.com/

    Link to review: g2.com/products/discriminat-fi

  29. Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: chasersystems.com/

    Link to review: g2.com/products/discriminat-fi

  30. 🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
    interlaye.red/kubernetes_002de #Egress #RetroTech #CloudComputing #HackerNews #ngated

  31. 🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
    interlaye.red/kubernetes_002de #Egress #RetroTech #CloudComputing #HackerNews #ngated

  32. 🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
    interlaye.red/kubernetes_002de #Egress #RetroTech #CloudComputing #HackerNews #ngated

  33. 🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
    interlaye.red/kubernetes_002de #Egress #RetroTech #CloudComputing #HackerNews #ngated

  34. 🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
    loopholelabs.io/blog/xdp-for-e #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated

  35. 🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
    loopholelabs.io/blog/xdp-for-e #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated

  36. 🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
    loopholelabs.io/blog/xdp-for-e #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated

  37. 🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
    loopholelabs.io/blog/xdp-for-e #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated

  38. Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing in the Peak District or his local gym.

    (screenshot of MitMed Cursor)

  39. Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing in the Peak District or his local gym.

    (screenshot of MitMed Cursor)

  40. Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing in the Peak District or his local gym.

    (screenshot of MitMed Cursor)

  41. We make it easier for you to enable an outbound network traffic firewall in full allowlist enforcement mode -- with discovery, dry run and micro-segmentation.

    Available on AWS and GCP. Search for DiscrimiNAT Firewall in your cloud web console.

    #egress #filtering