Security

  • Logging in with a domain account sends a push prompt in the Duo app

    Easy vCenter Server two-factor authentication without ADFS

    One of the new features added in vSphere 7 is the new identity federation component that allows organizations to point vCenter Server to an external identity source for the authentication workflow. This adds new possibilities for multi-factor authentication. However, currently,…

  • Running the Log4j remediation script on VMware Unified Access Gateways UAGs

    VMware Horizon Log4j patch workaround

    The fallout from the Log4j vulnerability continues to make ripples across organizations at the time of year when the last thing many want to hear about is a major security bug. Nonetheless, businesses are having to scramble to remediate and…

  • The VCSA Log4j patch remediation workaround Python script finishes successfully

    VMware vCenter Server Log4j patch script remediation process

    In case you haven’t heard, Apache Log4j is arguably the biggest vulnerability found across the board since Spectre/Meltdown vulnerabilities were disclosed, due to the sheer scope of the vulnerability. It is found everywhere and unfortunately, is found across a large…

  • The Pi hole webui is now viewable over SSL

    Configure Pi-hole SSL using a self-signed certificate

    I have been playing around a lot with Pi-hole lately. If you are new to Pi-hole and what it can do, take a look at my blog post here on how to Install Pi-hole in Ubuntu 21.04. If you are…

  • Pihole provides network level ad blocking

    Install Pi-hole in Ubuntu 21.04

    These days there are threats everywhere you turn when using electronic devices. Most of us are targeted for ads everywhere we go and every device we browse, search or place orders on. Aside from these threats to your privacy, there…

  • Critical Vulnerability in Apache Log4j CVE 2021 44228

    Critical Vulnerability in Apache Log4j CVE-2021-44228 is VMware affected?

    Well, unfortunately, it seems like we are ending the year on a dangerous critical vulnerability. Just a couple of days ago, a critical vulnerability in Apache Log4j identified by CVE-2021-44228 was posted. It is a bad one. We are going…

  • Network redesign using a privileged access workstation to administer vSphere

    Change your vSphere Management Network now!

    As part of the goals that I have set for myself, my home lab environment, and the production environments I work with, becoming more security conscious is on that list. I have found for myself personally that approaching my home…

  • Secured Core Server configuration using Windows Admin Center

    Windows Server 2022 Security Hardening best practices

    Hardening your Windows Servers is a great way, along with other security measures, that you have a strong security posture. What are the best ways to harden your Windows Servers in your environment? There are a few things you can…

  • SpinOne proactive ransomware detection

    Ransomware attack trends in 2022 – Double Extortion

    There is no question that ransomware attacks are on the rise and are wreaking havoc among enterprise organizations and their business-critical data today. This is in a large part due to the success that ransomware gangs are having using ransomware…

  • No IP mobile app download workaround

    No-IP mobile app download workaround

    If you are a No-IP user, like me, you may be frustrated when you take a look for a mobile app that provides the functionality you need as a dynamic update client or manage your No-IP account. I am not…