Skip to main content

Posts

Showing posts with the label [Network]

What is Firewall Rule (Policy) Review / Firewall Rule Review คืออะไร มาดูกัน

สามารถอ่าน version ภาษาไทยได้ด้านล่างเช่นเคยครับ Sometime it's call Firewall Rule Re-validate or Firewall Rule-base review . Firewall Rule review is part of Firewall audit process. Auditor will review Firewall Rule or ACLs on router that appropriate to network security no need rule will be removed for example permit ip any any : it's should not be placed in top of each segment of network. why ! firewall rule review From my experience, many organization will have firewall admin who is responsible for add, move, delete, modify rules but he never come back to see which rule is expired or no need, which rule can be merge or have to re-arrange sequence to improve performance and mitigate risk from attacker. what can we do 1. Duplicate object include host, ip, group, service must be removed. 2. Expired rule or no need rule must be removed. 3. Duplicate rule --> remove ^^ 4. There is rule that can be merge no bad impact to business...

ทำไมต้องมีการทดสอบเจาะระบบ (Why Penetration Testing !!)

คุณเคยสงสัยหรือป่าว เวลามีคนบอกว่าทำงาน Pentest มันคืออะไร ทำไรวะ มีด้วยเหรอ ผมจะมาเล่าให้ฟังคร่าวๆ แบบคนทั่วไปฟังรู้เรื่อง เหตุเกิดจากว่าผมจะเจอเป็นประจำเวลาเจอเพื่อน เจอคนรู้จักที่ไม่ได้ทำงานในสายนี้ มักมีคนถามว่า "มึงทำงานไรวะ Pentest ไม่เคยได้ยิน"  หรือ "เห็นบอกทำงานเจาะระบบช่วย hack เงินในเกมส์ให้หน่อย", "เฮ้ย hack เงินแทงบอล ให้กูหน่อยดิ" , บางคนก็ถามว่า "ทำ pentest กรณีคนลืม password เหรอ" หรือ "ทำไมต้องทำการทดสอบเจาะระบบ มันเป็นเรื่องผิดกฎหมายรึป่าว" บางคนว่าเป็นงานโจรก็ยังมี ก็อธิบายกันไป ^^  ไม่ว่าอะไร เพราะผมก็ไม่ได้รู้มาก่อนเหมือนกัน ก็เลยคิดว่าเขียน blog อันนี้ขึ้นมาเพื่อให้ผู้ที่ไม่รู้ได้ทราบแบบง่ายๆ เอาที่คนทั่วไปเข้าใจ -------------------------------------------------------------------------------------------------------------------------- คือเมื่อ พูดถึงการรักษาความปลอดภัยทางคอมพิวเตอร์และเครือข่าย เกือบทุกคนน่าจะคุ้นเคยเฉพาะด้านการป้องกัน หรือ Defensive Security เช่นการใช้ไฟล์วอลล์, ...

My First Post (Introduce myself)

  * ตั้งใจเขียนทั้งสองภาษาเพราะอยากฝึกภาษาอังกฤษด้วยครับ ถ้าใครเก่งภาษาอังกฤษ แนะนำเรื่อง grammar ได้นะครับ อ่านภาษาไทยได้ด้านล่างเลยครับ Penetrest  --> come from Penetrate + Interest I write this blog because I always forget some technique, how to, or knowledge and try to write about basic things when you work as penetration tester to help you more easy to begin. I write how to fix problem that I found in my penetration life. Hope it useful. I have working experience in system + network for 10 years,defensive sec, sec policy for 4 years and offensive sec just 1 year. About Me Former --> Network Security and System Engineer.              --> IT Security Consultant and Focal point for Network dept in IBM.  Currently --> I work as Penetration Tester in Thailand. Valid Certificates --> OSCP, ITILv3, CCNP Sec, CCNP r&s, CCDP, MCTS About content I intend to write w...