mindly.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mindly.Social is an English speaking, friendly Mastodon instance created for people who want to use their brains and their hearts to make social networking more social. 🧠💖

Administered by:

Server stats:

1.2K
active users

#dns

31 posts29 participants0 posts today

Mit der Rückkehr von Donald #Trump ins Weiße Haus wird die Abhängigkeit von #US-#Cloud-Diensten zu einem wachsenden Problem.
Denn der
#CloudAct zwingt US-amerikanische Firmen Anweisungen von US-Behörden Folge zu leisten, ganz gleich wo deren #Server stehen.

Nicht nur Staaten und Unternehmen, sondern auch Privatpersonen sind betroffen.

Angefangen bei #Datenspeichern über #Online-#Office-Anwendungen bis zu grundlegenden Internetdiensten wie #DNS oder Zertifizierungsstellen.

Es betrifft selbst smarte Geräte wie #WLAN-Steckdosen, wenn deren zentralen Dienste auf einem #Hyperscaler wie #Amazon #AWS oder #Microsoft #Azure liegen.

Doch es gibt Möglichkeiten, den #Datenabfluss zu minimieren und #Alternativen zu nutzen.


Welche das sind, erläutert c’t Redakteur Peter Siering. Die Optionen reichen von #Suchmaschinen über europäische Cloud-Speicher und Open-Source-Projekte bis zu dezentralen, sichereren #Messengern.

youtube.com/watch?v=5i2eLjLKl2

@switchingsoftware

@bfdi !!
@bsi !!

For those that run a homelab with DNS and DHCP, are you using IPv6? I'm running BIND and debating if I need to configure IPv6 just to future-proof myself. I'm not seeing any issues, at least any that I notice.

Also, I know little about IPv6, so I admit I need to do some learning.

#homelab#dns#dhcp

In case you're not up-to-speed on what #FastFlux #DNS is, it's part of the arms race between attackers and defenders:

THREAT ACTOR: This is my C2 IP
BLUE TEAMER: Blocked at the firewall

TA: Ok, well then, here's my C2 domain. I've rented 50k botnet nodes to use as proxies to my real C2 infrastructure, and I'm going to keep changing the IP the domain points to basically forever. Good luck blocking that. [FAST FLUX]
BT: Blocked the domain's nameserver's IPs at the firewall

🧵

Friendly reminder that you should be blocking all newly registered domains for your end users. Free lists like the NRD (github.com/xRuffKez/NRD) exist. Microsoft Defender for Endpoint also has a built in list you can enable via policy.

IMO everyone should do 365 days but even 30 or 90 will save you so much headache.
#DNS #ThreatIntel #FastFlux

A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis. - xRuffKez/NRD
GitHubGitHub - xRuffKez/NRD: A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis.A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis. - xRuffKez/NRD

This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).

The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here urlscan.io/result/0195ed8b-7a4 )

Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.

Here is a sample of the hundreds of domains we are detecting:
womivor[.]ru
nthecatepi[.]ru
toimlqdo[.]ru
dantherevin[.]ru
xptdieemy[.]ru

#dns#domains#phishing

It feels good in the curent situation to be fully free of any proprietary solution.

#Linux #Debian #FreeBSD on all systems only, own #public #DNS servers on own systems including management.

#Mastodon, #Matrix , #Bridges , #Email , #SOGo #Nextcloud #Owncloud #UnifiedPush #ntfy #HomeAssistant #WebSites mostly done with #Hugo, and far more all self hosted on own systems in the basement or in our housing rack.

Mobiles #GrapheneOS and #LineageOS

Whatever #Trump #Microsoft aso does i dont care

Replied to Joel Carnat ♑ 🤪 :runbsd:

@joel Mostly true, in summary yes. Hugely depends on the TLD though (and hence your registrar of choice should be the authoritative reply on this question, for a specific domain/TLD). But usually privacy laws apply to individuals, not moral entities. BTW your question is also not really #DNS :-) which doesn't deal with contact data. It is more related to domain names registrations in general. No idea of best tag for that.

Hey #DNS masters. Is it true that when you register a domain name as a Moral Person / Legal Entity, you can't have the personal details (address etc) hidden in the WHOIS database? To have those hidden, you would have to use a Physical Person / Individual account?