Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Learning Unix By Access This Public Free Unix Server (Running Since 1987)

4/30/2023

0 Comments

 
Learning Unix By Access This Public Free Unix Server (Running Since 1987)
Super Dimension Fortress (SDF, also known as freeshell.org) is a non-profit public access UNIX shell provider on the Internet. It has been in continual operation since 1987 as a non-profit social club.

SDF provides free Unix shell access, web hosting and many other features at the user membership level. Additional programs, capabilities and resources are available at "patron" and "sustaining" level memberships, which are granted with one-time or recurring dues in support of the SDF system.

The SDF network of systems that serves its membership currently includes NetBSD servers for regular use (running on DEC Alpha- and AMD Opteron-powered hardware) as well as retrocomputing environments: a TWENEX system running the Panda Distribution TOPS-20 MONITOR 7.1 on two XKL TOAD-2 computers,[2][3] a Symbolics Genera system, and an ITS system[4] . 

- above information is from Wikipedia. 




Websites


  • https://sdf.org/ -  SDF Public Access UNIX System .. Est. 1987
  • http://freeshell.de - Public access Linux system. Your non-profit shell provider since 2002.

Online Access Server through Gate One Web SSH Client
  • https://ssh.sdf.org:4443/




Register an account

 
https://sdf.org/




Log In

After registered an account, you will be able to use your own or online ssh client to log into it. 




┌──────────────────────────────────────────────────────────────────────┐
│ • MobaXterm Professional Edition v22.1 • │
│ (SSH client, X server and network tools) │
│ │
│ ⮞ SSH session to [email protected] │
│ • Direct SSH : ✓ │
│ • SSH compression : ✓ │
│ • SSH-browser : ✓ │
│ • X11-forwarding : ✗ (disabled or not supported by server) │
│ │
│ ⮞ For more info, ctrl+click on help or visit our website. │
└──────────────────────────────────────────────────────────────────────┘ [ 'jy' will expire in 365 days - Please 'validate' your account soon ] Please press your BACKSPACE key:


Here are some outputs after logged in.


    ┌──────────────────────────────────────────────────────────────────────┐
    │               • MobaXterm Professional Edition v22.1 •               │
    │               (SSH client, X server and network tools)               │
    │                                                                      │
    │ ⮞ SSH session to [email protected]                                 │
    │   • Direct SSH      :  ✓                                             │
    │   • SSH compression :  ✓                                             │
    │   • SSH-browser     :  ✓                                             │
    │   • X11-forwarding  :  ✗  (disabled or not supported by server)      │
    │                                                                      │
    │ ⮞ For more info, ctrl+click on help or visit our website.            │
    └──────────────────────────────────────────────────────────────────────┘
[ 'jy' will expire in 365 days - Please 'validate' your account soon ]
Please press your BACKSPACE key:
=======================================================================
SDF host uptime report for Seattle WA, Dallas TX (USA) and Germany (EU)
             Please use 'tty.sdf.org' for general access
=======================================================================
SERVER          DAYS+HOUR:MIN       USERS   MACHINE LOAD
----------------------------------------------------------------------
9p             up  26+21:54,   16 users,  load:   0.00,   0.00,   0.00
aNONradio      up  134+6:00,   24 users,  load:   0.16,   0.17,   0.15
beastie        up  42+12:10,   18 users,  load:   0.00,   0.01,   0.00
faeroes        up 134+00:12,   69  user,  load:   0.20,   0.24,   0.24
iceland        up 134+00:04,   51 users,  load:   0.26,   0.28,   0.27
jitsi          up  32+22:55,    4 users,  load:   0.00,   0.00,   0.00
ma             up  63+16:14,   85 users,  load:   3.91,   3.54,   3.53
mastodon       up 139+21:33,  862 users,  load:   1.85,   1.92,   2.06
matrix         up  11+22:07,  227 users,  load:   0.70,   0.41,   0.51
mc             up  63+16:20,    2 users,  load:   3.46,   3.50,   3.52
miku           up 108+23:07,    3 users,  load:   3.85,   3.63,   3.66
mx             up 120+21:09,  334 users,  load:   1.98,   1.79,   1.47
norge          up  42+12:19,   85 users,  load:   0.09,   0.08,   0.08
otaku          up 134+00:00,   42 users,  load:   0.31,   0.21,   0.22
rie            up 133+23:57,  202  user,  load:   0.52,   0.57,   0.57
sdf            up  20+18:57,  137 users,  load:   0.63,   0.67,   0.80
sdfeu          up  98+11:21,  133 users,  load:   2.69,   2.60,   2.58
sverige        up  42+12:21,   26 users,  load:   0.09,   0.11,   0.08
vps3           up  221+1:45,   20 users,  load:   3.70,   2.11,   1.38
vps9           up  81+16:46,    9 users,  load:   0.00,   0.00,   0.00
                             2349 total
(continue)
The Moon is Waning Gibbous (78% of Full)
                 .----------
             .--'  o     . .
          .-'   .    O   .
       .-'@   @@@@@@@   .  @@@@@
      /@@@  @@@@@@@@@@@   @@@@@@@
    ./    o @@@@@@@@@@@   @@@@@@@
   /@@  o   @@@@@@@@@@@.   @@@@@@@
  /@@@@   .   @@@@@@@o    @@@@@@@@@@
  |@@@@@               . @@@@@@@@@@@
 /@@@@@  O  `.-./  .      @@@@@@@@@@@    Full Moon +
 | @@@@    --`-'       o     @@@@@@@@    4 18:23:38
 |@ @@@        `    o      .  @@   .     Last Quarter -
 |       @@  @         .-.     @@@       3  1:57:43
 \  . @        @@@     `-'   . @@@@
  |      @@   @@@@@ .           @@
  \     @@@@  @\@@    /  .  O    .
   \  o  @@     \ \  /         .
    `\     .    .\.-.___   .      .
      \           `-'
       `-.   o   / |     o    O
          `-.   /     .       .
             `--.       .
                 `----------
(continue)
[09-Sep-22 17:47:51 abortretryfail      abortretryfail                         EL87]
% Greetings from the Mac Color Classic. :)
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[12-Sep-22 00:25:04  slothrop           mobb_solo               N. Loop Austin]
% Live Music @ Monkeywrench Booksellers 8pm ▒?
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[18-Sep-22 05:05:57      qiqi Kusanalika Xamarin (initial)                             ]
% Thanks for this. Well I use Indonesia main language using script and not all use Indonesia main language. Memang agak sulit untuk menerjemahkan.
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[23-Sep-22 11:20:54  claudiom            claudiom                         work]
% Happy Friday from UTC-4!
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[23-Sep-22 14:58:35 charmquark          charmquark                        Earth]
% Running my own unix server... nevermore?
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[27-Sep-22 14:40:26    unixen              Unixen            The last Frontier]
% Wish I had found this a long time ago, but glad I am here now
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[02-Oct-22 21:30:21 billybigbagels               Billy              Los Angeles, CA]
% It was a fun ride Overwatch 1, you will be missed...
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[03-Oct-22 14:21:07    skylar              skylar                             ]
% command line!
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[03-Oct-22 17:29:55       isk                 isk                  Los Angeles]
% The trap appears to be disarmed.
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[06-Oct-22 05:03:22    geoffo        Geoff Oliver         Colorado Springs, CO]
% Very cool stuff!!!
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[07-Oct-22 08:48:31 devhackvps          devhackvps             The End Of Space]
% lol free email address + free computer
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[09-Oct-22 04:09:32 burgertron              cheesy              server 'closet']
% got a server with a buttload of ram, getting freebsd going with samba and doing apple mdm stuff, may write something
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[09-Oct-22 09:13:02 tusharhero          tusharhero                        India]
% Hello I am under water here too much raininig ?
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[09-Oct-22 14:00:29 tusharhero Depressed JEE aspirant                        India]
% I have been trying to complete my homeowrk for 6 hours now
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[09-Oct-22 14:20:54    railey                 ree                     Internet]
% what's the meaning of life?
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[10-Oct-22 13:48:30 abortretryfail      AbortRetryFail                         EL87]
% What is love? Baby don't hurt me... Don't hurt me, no more.
 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
[13-Oct-22 14:17:24    cberce               Chris          Zurich, Switzerland]
% gruezi mitanand :)
7304 guestbook entries.
Type 'help' for Commands.
Type 'com' to chat with other users.
Type 'ttytter' to listen to Twitter Tweets anonymously.
Type 'mud' to play the SDFmud.
Type 'mkhomepg' to set up your personal website.
Did you know you can become a permanent LIFETIME member of SDF
by making a onetime donation of $36?  Type 'arpa' for more info!
faeroes:/sdf/udd/j/jon>




Commands

You can easily use help command to get the list for all available commands:

faeroes:/sdf/udd/j/jo> help
SDF psh Version 8 - *PREVALIDATED SHELL ACCOUNT*

 what         - what can I use this account for?
 unix         - a listing of UNIX commands available to you NOW
 how          - information on increasing membership
 teach        - using SDF in a classroom setting
 dialup       - information about SDF dialup service
 arpa         - about lifetime arpa membership
 bboard       - sdf user message boards
 commode      - chat with other users online
 ysm          - chat on the ICQ network
 bsflite      - chat on the AIM network
 msnre        - chat on the MSN network
 ttytter      - listen to Twitter tweets anonymously
 lynx         - browse the WWW textually or access GOPHER
 bksp         - set your BACKSPACE key
 software     - display software programs installed on the system
 quote        - get a real time stock quote
 games        - a listing of available games
 thxmoo       - connect to the THXMOO
 mud          - connect to the SDFmud
 validate     - gain additional shell access (also try 'user' for details)

faeroes:/sdf/udd/j/jo>



faeroes:/sdf/udd/j/jo> unix
UNIX command summary

 cd         {dir}  - Change Directory
 pwd               - print working (current) directory
 ls                - LiSt directory  (try ls -la)
 cat        {file} - conCATenate (view) a file
 mkdir      {name} - create a directory
 rm         {file} - remove a file or directory
 mv         {file) - move a file or directory
 chmod perm {file} - set permission bits for a file or directory
 edit       {file} - edit a file in your directory
 ps                - Process Status (try ps -aux)
 passwd            - Change your password
 disk              - show current disk usage
 uptime            - show system status
 df                - print system storage
 freeirc           - IRC access is free on Sundays
 profiles          - Join the ASCII social network
 dict       {word} - query the online dictionary
 cal               - calendar (try 'cal 1752')
 finger     {user} - show info about a user (try who or w)
 chfn              - change your full name
 chsh              - change your shell
 ping       {host} - test network connectivity to a host
 traceroute {host} - view the route to a remote host
 man         {cmd} - read a manual page for a command.
 dig / host        - DNS utilities
 geoip             - Country lookup on an IP
 expire            - calculate your account expiration
 domains           - list domains available for use on SDF
 mkhomepg          - manage your own webpage space
 mkgopher          - manage your own gopherspace
 upload            - upload a file using ZMODEM (works w/ TeraTERM)
 com               - multiuser online chat
 msg        {user} - send a message to another user online
 bboard            - bulletin board
 faq               - frequently asked questions
 mail              - read/send email (also try http://webmail.freeshell.org)
 lynx        {url} - browse webpages
 links       {url} - browse webpages (w/ frames support)
 gopher      {url} - browse gopherspace
 talk       {user} - talk to another user
 url        {user} - look up a user's URL
 ysm               - chat on the ICQ network
 pkg_info          - list ported/installed software packages
 whois    {domain} - query the INTERNIC WHOIS database
 logout            - logoff



faeroes:/sdf/udd/j/jo> df -h
Filesystem         Size       Used      Avail %Cap Mounted on
/dev/wd0a           35G       1.9G        32G   5% /
nol1:/sdf           23T       6.5T        16T  29% /sdf
ptyfs              1.0K       1.0K         0B 100% /dev/pts
faeroes:/sdf/udd/j/jo>




Change Password

 
faeroes:/sdf/udd/j/jo> passwd
Trying 10.0.0.22...
Connected to nol1.
Escape character is 'off'.

NetBSD/amd64 (mx) (pts/3)

login:
                                                                     
SDF ACCOUNT MAINTENANCE INTERFACE - (use 'tty.sdf.org' for LOGIN access)
                                                                                                                                                                                                                                                                   
p - change your password
s - change your shell
f - configure your PUBLIC FINGER display (finger [email protected])
g - configure your NON-PUBLIC GECOS field (Fullname, Office, Phone ..)
a - setup automatic password recovery
e - an external contact email address for dues and system notices
o - manage optional account features and social networking
m - reset your MySQL password(s)
w - reset webmail preferences
v - set or reset your VoIP SIP id
                                                                                                                                                                                                                                                                   
q - quit
                                                                                                                                                                                                                                                                   
(main) Your Choice: Changing local password for jon.
Old password:
New password:
Retype new password:
% Successful - NOTE! THE CLIENTS WILL UP DATE SHORTLY.
               BE PATIENT AND ALLOW THE UPDATE TO OCCUR.
                                                                                                                                                                                                                                                                   
(continue)

There are lots of limitation for free user to use those features or fuctions, such as change your shell. If you are trying to do that, it will require you validate your account first. Validate basically means a minimum donation, $1 USD by mail or $3 USD by Paypal. 



Resources

 
EN: https://docs.freebsd.org/doc/
CN: https://book.freebsdcn.org/


Videos

 







References

  • SDF Public Access Unix System Wikipedia page



via Blogger http://blog.51sec.org/2023/04/learning-unix-by-access-this-public.html
April 30, 2023 at 11:02AM Linux
0 Comments

CyberArk P-Cloud (CyberArk Privilege Cloud)

4/29/2023

0 Comments

 
CyberArk P-Cloud (CyberArk Privilege Cloud)
CyberArk Privilege Cloud is a SaaS solution that enables organizations to securely store, rotate and isolate credentials (for both human and non-human users), monitor sessions, and deliver scalable risk reduction to the business.

Privilege Cloud protects, controls, and monitors privileged access across on-premises, cloud, and hybrid infrastructures.  Privilege Cloud = Vault + PVWA + Connector


Privilege Cloud architecture

Diagram:

Note: https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud-SS/Latest/en/Content/Privilege%20Cloud/PrivCloud-detailed-architecture.htm


Privilege Cloud enables your organization to securely store, rotate and isolate credentials (for both human and non-human users), monitor sessions, and deliver scalable risk reduction to the business.

The Privilege Cloud customer setup includes:
  • The Windows Connector (Connector) for establishing privileged sessions with Windows target machines
  • Optionally, Secure Tunnel client, for SIEM syslog and setup of offline access using CyberArk Remote Access
  • Optionally, the Unix connector (PSM for SSH) for establishing privileged sessions with Unix target machines.

For details on each of these components, see Welcome to CyberArk Privilege Cloud.

The Privilege Cloud cloud service includes:
  • Privilege Cloud Portal user interface for setting up and managing user access privileges to your organizational resources
  • Vault enables organizations to secure, manage, automatically change and log all activities associated with all Privileged Passwords and SSH Keys.

Deployment : One Site







Deployment : Multiple Sites

 




Three Phases Implementation Program

Privilege access projects can vary between organizations, based on priorities, technologies in use, and more. We understand this. We want to offer a path that we see as optimal, based on CyberArk's vast experience in protecting organizations. You can decide how, and in what order to execute the plan to best meet your needs.

With these guidelines and CyberArk's assistance, you can build a successful and, ultimately, mature privileged account security program.

Phase 1 – Discovery and initiation

Phase 2 – Definition and planning

Phase 3 – Launch and execution


Access your organization's P-Cloud: https://<subdomain>.cyberark.cloud


Connector


Connector servers are quired to be installed in the customer's environment.

  • CPM = Password Manager
  • PSM
  • Identity Connector
  • Secure Tunnel

What is A Privileged Account?




How many privileged accounts an organization will have averagely?





Protect Cloud and SaaS Applications:




Securing the console and CLI




Best practice


Protect the identity provider
  • AD FS - same level of domain controllers (Tier 0)
Protect the API keys


Managing Workloads in the cloud


Event Driven Automatic Onboarding



Action

Call to action - Skyark





Baseline your accoutns - Discovery Tools

What is CyberArk DNA?

CyberArk DNA is a discovery and audit tool that automatically scans an organization’s network for data related to privileged and non-privileged accounts. The scanner automatically discovers and analyzes any privileged and nonprivileged account within servers and desktops, and then generates a report and visual organizational map that evaluates the privileged account security status in the organization.

Run DNA in your network

Before you can run DNA, you need to set it up on a network machine. All the information for setting up and running DNA can be found in the CyberArk DNA User Guide.

Videos

 


References

  • Best Practices for Privileged Access & Secrets Management in the Cloud
  • Secure an Azure IAM Account with Privileged Access Manager | CyberArk
  • What are licensing requirements for Microsoft Remote Desktop Services ("RDS") when deploying CyberArk's Privileged Session Manager ("PSM")?





via Blogger http://blog.51sec.org/2023/04/cyberark-p-cloud.html
April 29, 2023 at 09:43PM CyberArk
0 Comments

(HourOne AI Generated) Top Risk in AI Technology

4/28/2023

0 Comments

 
Related Post: ✍https://blog.51sec.org/2023/04/online-free-ai-text-to-video-generator.html Related Videos: ? ?Chapters: 0:00 - Introduction ✅#51Sec #NetSec ====================================================================== If you found this video has some useful information, please give me a thumb up and subscribe this channel to get more updates: ⚡https://www.youtube.com/c/Netsec?sub_confirmation=1 ⚡Resource Collection and Bookmarks: https://sites.51sec.org/ Learning and Sharing - ?海内存知己,天涯若比邻! Discord: https://discord.gg/fCW9phn Blog: https://blog.51sec.org

Watch video on YouTube here: https://youtu.be/7Kw6GIqsJh8 by NetSec
0 Comments

Use Tebi.io Free S3 Compatible Storage To Store ShareX Screenshots

4/23/2023

0 Comments

 
Tebi.io has 25GB free tier storage and 250GB/month for outbound traffic. In this video, I am showing you how to use it to host your files or images with a integration to ShareX, a free and opensource screenshot capture software. With the right configuraton, you can just press one key or one mose click to get ShareX to capture screenshot then upload to Tebi.io. The screenshot url will be automatically generated and copy to your clipboard for you to paste anywhere. Much converinet and completely free! Related Post: ✍https://blog.51sec.org/2023/04/integrate-sharex-with-free-forever-s3.html Related Videos: ?Integrate Scaleway Free 75GB Object Storage with NextCloud and ShareX - https://youtu.be/aLj3jTfxWFU ?Free but Powerful Screenshot Capture Software - ShareX - https://youtu.be/pWGN9N1teR8 ?Chapters: 0:00 - Introduction 2:32 - Lets Star It 2.37 - 1. Register an account & enable Free tier plan 4:25 - 2. Create a bucket & access key 6:42 - 3. Integrae with ShareX 16:18 - End Scene ✅#51Sec #NetSec ====================================================================== If you found this video has some useful information, please give me a thumb up and subscribe this channel to get more updates: ⚡https://www.youtube.com/c/Netsec?sub_confirmation=1 ⚡Resource Collection and Bookmarks: https://sites.51sec.org/ Learning and Sharing - ?海内存知己,天涯若比邻! Discord: https://discord.gg/fCW9phn Blog: https://blog.51sec.org

Watch video on YouTube here: https://youtu.be/22JPqFZNn7Q by NetSec
0 Comments

CyberSecurity Review Resources for SaaS / PaasS & Other IT Solution

4/23/2023

0 Comments

 
CyberSecurity Review Resources for SaaS / PaasS & Other IT Solution

This post collects some useful resources to have a proper CyberSecurity review to any SaaS, PaaS, and other IT solutions.




Minimum Security Standards for SaaS and PaaS from Standord Unviersity

Minimum Security Standards for IaaS
Note: https://uit.stanford.edu/guide/securitystandards/iaas

Minimum Security Standards:

Infrastructure-as-a-Service (IaaS) and Containerized Solutions

Applicability:

  1. The minimum security standards found here apply to IaaS managed services — virtual servers that are designed to be ephemeral — and containerized solutions.
  2. All other persistent virtual servers, regardless of infrastructure, are to be managed under the Minimum Security Standards: Servers guidelines.
Standards What to do Low Risk Moderate Risk High Risk
Platform Selection

Follow the Stanford cloud solution selection workflow found at Choosing and Purchasing a Cloud Solution.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Operational Practices

As far as possible, apply the Stanford Cloud Operational Principles and Practices.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
System Architecture

As far as possible, apply the Stanford Cloud Architecture Principles for IaaS.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Account Management

Provision new cloud accounts through University IT. 

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Patching and Application Lifecycle
  1. Apply high severity security patches within seven days of release.
  2. Apply all other security patches within 90 days.
  3. Use a supported operating system and application version.
  4. Use machine images only from trusted sources.

Additional Elaboration:

  • Managed Services — For managed services like Amazon RDS or Google Cloud SQL, define a maintenance window that meets the standard.
  • Ephemeral Servers and Containers — If using an automated system to build fully patched machine images, ensure that the patched image, or container base layer, is in use in your environment within the window of time specified in the MinSec standard.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Vulnerability Management

Based on National Vulnerability Database (NVD) ratings: Identify and remediate severity 4 and 5 CVE vulnerabilities within seven days of discovery, and severity 3 vulnerabilities within 90 days.

Stanford provides and recommends the Qualys toolset (which includes the Qualys Cloud Agent), however platform specific tools such as Amazon Inspector and Google Cloud Security Scanner may be used instead.

If a detection tool other than Qualys is used, ISO may request a review and audit of your tool and practices as well as periodic verification of efficacy.

Additional Elaboration:

  • Managed Services — Qualys scanning may be omitted on infrastructure provider managed services, however if the platform provides a native vulnerability detection capability, it should be implemented.
  • Ephemeral Servers — Build machine images that contain the appropriate agent, or bootstrap the installation and configuration of the agent using the management tools specific to your implementation.
  • Containerized Solutions — Scan image for CVEs using CLAIR, Anchore, private DockerHub scan, or similar tool.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Inventory and Asset Classification

Review and update department/MinSec Cloud inventory records quarterly. Must indicate associated risk classification and service ownership.

Additional Elaboration:

  • Ephemeral Servers — Systems designed for a lifespan no greater than 7 days (commonly those in autoscaling worker groups) should be inventoried as a single application.
  • Managed Services — Infrastructure managed services like Amazon RDS or Google Cloud SQL should be inventoried as applications.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Firewall

Use the native tools and design patterns of your platform to ensure that only the minimum necessary network communication is permitted through virtual network devices such as VPCs, load balancers, and the like. This includes access to managed services such as hosted database platforms.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Credential and Key Management
  1. Where possible, integrate with Stanford SSO authentication for all cloud administration consoles.
  2. Abide by Stanford’s password complexity rules.
  3. Review administrative accounts and privileges quarterly.
  4. API keys:
    1. Minimize their generation.
    2. Grant minimum necessary privileges.
    3. Rotate at least annually.
    4. Do not hardcode.
  5. Do not share credentials.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Two-Step Authentication

Enforce two-factor authentication for all interactive user and administrator logins. Stanford provided Duo two-factor authentication is recommended, but other two-factor options are acceptable.

  Required for Moderate Risk Data Required for High Risk Data
Logging and Alerting
  1. Enable any available application logging that would assist in a forensic investigation in the event of a compromise. Seek vendor or ISO guidance as needed.
  2. Forward logs to remote logging solutions.
    1. University IT Splunk service recommended, but third party SaaS solutions are also acceptable.

Additional Elaboration:

  • Administrative Activity Logs —  Log user actions and API calls that create or modify the configuration or metadata of a resource, service or project.
  • Data Access Logs — Log user actions and API calls that create, modify, or read High Risk data managed by a service. One example would be to enable data access logs on AWS S3 buckets containing High Risk Data.
  Required for Moderate Risk Data Required for High Risk Data
Backups
  1. Backup application data at least weekly.
  2. Encrypt backup data in transit and at rest.
  3. Store backups in independent cloud accounts.
  Required for Moderate Risk Data Required for High Risk Data
Encryption
  1. Enable transport layer encryption for all communications external to the private cloud environment.
  2. Use TLS 1.2 or higher.
  3. Use encryption at rest if available.
  Required for Moderate Risk Data Required for High Risk Data
Data Centers

Prefer US based data center locations.

  Required for Moderate Risk Data Required for High Risk Data
Secure Admin Workstation

Cloud administration consoles should only be accessed through a Privileged Access Workstation (PAW) or Cardinal Protect workstation when logging in with an administrative account. A PAW is required for ring0 access.

Administrative accounts are defined as:

  • Accounts with the ability to make unrestricted, potentially adverse, or system-wide changes.
  • Accounts with the ability to override or change security control
    Required for High Risk Data
Security, Privacy, and Legal Review

Follow the Data Risk Assessment process and implement recommendations prior to deployment.

    Required for High Risk Data
Regulated Data Security Controls
  1. Adhere to applicable regulations: PCI, HIPAA/HITECH, NIST 800-171, GDPR, etc.
  2. For HIPAA data, ensure that only cloud services covered under a Business Associate Agreement (BAA) are used.
    Required for High Risk Data



Minimum Security Standards for IaaSFor SaaS / PaaS 

Note: https://uit.stanford.edu/guide/securitystandards/saas_paas
Standards What to do Low Risk Moderate Risk High Risk
Product Selection

Follow the Stanford cloud solution selection workflow found at Choosing and Purchasing a Cloud Solution.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Pre-implementation Planning

Follow the SaaS Considerations checklist.

Follow the PaaS Considerations checklist.

Follow the Security When Using a Cloud Product guidelines.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Inventory and Asset Classification

Review and update department/MinSec Cloud inventory records quarterly. Must indicate associated risk classification, data volume estimates, and service ownership.

Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Credential and Key Management
  1. If possible, Integrate with Stanford's SSO services, preferably SAML.
  2. Review administrative accounts and privileges quarterly.
  3. Adhere to the Stanford password complexity rules if not integrated with a Stanford SSO service.
  4. API keys:
    1. Minimize their generation.
    2. Grant minimum necessary privileges.
    3. Rotate at least annually.
    4. Do not hardcode.
  5. Do not share credentials.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Encryption
  1. Enable transport layer encryption TLS 1.2 or higher.
  2. Use encryption of data at rest if available.
Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Two-Step Authentication

If user login is not able to be integrated with Stanford SSO, enable two-factor authentication if offered by the solution.

  Required for Moderate Risk Data Required for High Risk Data
Logging and Auditing
  1. Enable any available application logging that would assist in a forensic investigation in the event of a compromise. Seek vendor or ISO guidance as needed.
  2. Contractually ensure that the provider can export logs at the request of Stanford within five days.
  Required for Moderate Risk Data Required for High Risk Data
Data Management

Contractually ensure that Stanford data are purged upon termination of the agreement with accommodations as necessary to comply with any applicable regulatory obligations.

 
  Required for Moderate Risk Data Required for High Risk Data
Secure Admin Workstation

Administration consoles should only be accessed through a Privileged Access Workstation (PAW) or Cardinal Protect workstation when logging in with an administrative account. A PAW is required for ring0 access.

Administrative accounts are defined as:

  1. Accounts with the ability to make unrestricted, potentially adverse, or system-wide changes.
  2. Accounts with the ability to override or change security controls.
    Required for High Risk Data
Security, Privacy and Legal Review

Follow the Data Risk Assessment process and implement recommendations prior to deployment.

    Required for High Risk Data
Regulated Data Security Controls
  1. Follow all regulatory data controls as applicable (HIPAA/HITECH, NIST 800-171, PCI DSS, GDPR, etc.). 
  2. For HIPAA data, ensure that only cloud services covered under a Business Associate Agreement (BAA) are used.
    Required for High Risk Data

 

SaaS Checklist

A SaaS product used for the Stanford community must meet these requirements:

Business requirements:

The product provides functional support for Stanford's business.
The service provider is viable and provides support for the product.
The service provider has a process to notify the user about changes in the product (e.g., functionality, UI).

Technical/integration requirements:

The product integrates with Stanford's IAM (Identity and Access Management) and account provisioning systems.
The product has the capability for service health monitoring.
The product includes log and/or event notification (e.g., it tracks administrative access or configuration changes to deployment).
The product has testing and staging environments.
The product is scalable and fault-tolerant.

Risk management requirements:

The product supports Stanford's data security requirements.
The product complies with University policy and legal requirements.
The product supports business continuity and disaster recovery.



PaaS Checklist


When looking to acquire a PaaS product for the Stanford community, follow this checklist of required attributes. More detail can be found in the sections below.

Required attributes — a PaaS candidate solution must address these three sets of considerations:

Business considerations:

Functional support for Stanford's business
Vendor support and viability
Cost
Lifecycle and exit strategy

Technical/integration considerations:

Scalability and availability
Capability for service health monitoring
Ability to integrate with and operate with Stanford services and products
Ability to integrate with Stanford IAM (Identity and Access Management) infrastructure

Risk management considerations:

Ability to support Stanford's data security requirements
Support for business continuity and disaster recovery
Ability to notify Stanford about breaches or outages
Compliance with University policy and legal requirements



Note: Minimum Security Standards | University IT (stanford.edu)

Minimum Security Standards: Endpoints

An endpoint is defined as any laptop, desktop, or mobile device.

  1. Determine the risk level by reviewing the datarisk classification examples, serverrisk classification examples, and application risk classification examples and selecting the highest applicable risk designation across all. For example, an endpoint storing Low Risk Data but utilized to access a High Risk application is designated as High Risk.
  2. Follow the minimum security standards in the table below to safeguard your endpoints.
Standard Recurring Task What to do Low Risk Moderate Risk High Risk
Patching Recurring Task Apply security patches within seven days of publish. BigFix is recommended. Use a supported OS version. Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Whole Disk Encryption   Enable FileVault2 for Mac, BitLocker for Windows. SWDE is recommended, option to use VLRE instead. Install MDM on mobile devices. Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Malware Protection   Install antivirus (Recommended: CrowdStrike or Microsoft Defender for Windows, Crowdstrike for Mac). Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Backups   Back up user data at least daily. University IT CrashPlan is recommended (option to set personal password). Encrypt backup data in transit and at rest. Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Inventory Recurring Task Review and update NetDB records quarterly. Maximum of one node per NetDB record. Required for Low Risk Data Required for Moderate Risk Data Required for High Risk Data
Configuration Management   Install BigFix and SWDE.     Required for High Risk Data
Regulated Data Security Controls   Implement PCI DSS, HIPAA, or export controls as applicable.     Required for High Risk Data

Minimum Security Standards: Servers

A server is defined as a host that provides a network accessible service.

  1. Determine the risk level by reviewing the datarisk classification examples, serverrisk classification examples, and application risk classification examples and selecting the highest applicable risk designation across all. For example, a server running a Low Risk application but storing High Risk Data is designated as High Risk.
  2. Follow the minimum security standards in the table below to safeguard your servers.
Standard Recurring Task What to do Low Risk Moderate Risk High Risk
Patching Recurring Task Based on National Vulnerability Database (NVD) ratings, apply high severity security patches within seven days of publish and all other security patches within 90 days. Use a supported OS version. Required for low risk servers Required for moderate risk servers Required for high risk servers
Vulnerability Management Recurring Task Perform a monthly Qualys scan. Remediate severity 4 and 5 vulnerabilities within seven days of discovery and severity 3 vulnerabilities within 90 days. Required for low risk servers Required for moderate risk servers Required for high risk servers
Inventory Recurring Task Review and update NetDB, SUSI, and  department/MinSec inventory records quarterly. Maximum of one node per NetDB record. Required for low risk servers Required for moderate risk servers Required for high risk servers
Firewall   Enable host-based firewall in default deny mode and permit the minimum necessary services. Required for low risk servers Required for moderate risk servers Required for high risk servers
Credentials and Access Control Recurring Task Review existing accounts and privileges quarterly. Enforce password complexity. Logins with SUNet credentials via Kerberos recommended. Required for low risk servers Required for moderate risk servers Required for high risk servers
Two-Step Authentication   Require Duo two-step authentication for all user and administrator logins.   Required for moderate risk servers Required for high risk servers
Centralized Logging   Forward logs to a remote log server. University IT Splunk service recommended.   Required for moderate risk servers Required for high risk servers
Sysadmin Training Recurring Task Attend at least one Stanford Information Security Academy training course annually.   Required for moderate risk servers Required for high risk servers
Malware Protection Recurring Task Deploy Crowdstrike. Review alerts as they are received.   Required for moderate risk servers Required for high risk servers
Intrusion Detection Recurring Task Deploy  OSSEC or Tripwire. Review alerts as they are received.   Required for moderate risk servers Required for high risk servers
Physical Protection   Place system hardware in a data center.   Required for moderate risk servers Required for high risk servers
Secure Admin Workstation   Access administrative accounts only through a Privileged Access Workstation (PAW) or Cardinal Protect workstation. A PAW is required for ring0 access.     Required for high risk servers
Security, Privacy, and Legal Review   Follow the Data Risk Assessment process and implement recommendations prior to deployment.     Required for high risk servers
Regulated Data Security Controls   Implement PCI DSS, HIPAA, or export controls as applicable.     Required for high risk servers

Minimum Security Standards: Applications

An application is defined as software running on a server that is remotely accessible, including mobile applications.

  1. Determine the risk level by reviewing the datarisk classification examples, serverrisk classification examples, and application risk classification examples and selecting the highest applicable risk designation across all. For example, an application providing access to Low Risk Data but running on a High Risk server is designated as High Risk.
  2. Follow the minimum security standards in the table below to safeguard your applications.
Standard Recurring Task What to do Low Risk Moderate Risk High Risk
Patching Recurring Task Based on National Vulnerability Database (NVD) ratings, apply high severity security patches within seven days of publish and all other security patches within 90 days. Use a supported version of the application. Required for low risk applications Required for moderate risk applications Required for high risk applications
Vulnerability Management Recurring Task Perform a monthly Qualys application scan. Remediate severity 4 and 5 vulnerabilities within seven days of discovery and severity 3 vulnerabilities within 90 days. Required for low risk applications Required for moderate risk applications Required for high risk applications
Inventory Recurring Task Review and update department/MinSec Application inventory records quarterly. Must indicate associated risk classification and data volume estimates. Required for low risk applications Required for moderate risk applications Required for high risk applications
Firewall   Permit the minimum necessary services through the network firewall. Required for low risk applications Required for moderate risk applications Required for high risk applications
Credentials and Access Control Recurring Task Review existing accounts and privileges quarterly. Enforce password complexity. Logins with SUNet credentials via WebAuth/SAML recommended. Required for low risk applications Required for moderate risk applications Required for high risk applications
Two-Step Authentication   Require Duo two-step authentication for all user and administrator logins.   Required for moderate risk applications Required for high risk applications
Centralized Logging   Forward logs to a remote log server. University IT Splunk service recommended.   Required for moderate risk applications Required for high risk applications
Secure Software Development   Include security as a design requirement. Review all code and correct identified security flaws prior to deployment. Use of static code analysis tools recommended.   Required for moderate risk applications Required for high risk applications
Developer Training Recurring Task Attend at least one Stanford Information Security Academy training course annually.   Required for moderate risk applications Required for high risk applications
Backups   Back up application data at least weekly. Encrypt backup data in transit and at rest.   Required for moderate risk applications Required for high risk applications
Secure Admin Workstation   Access administrative accounts only via a Privileged Access Workstation (PAW) or Cardinal Protect workstation. A PAW is required for ring0 access.     Required for high risk applications
Security, Privacy, and Legal Review   Follow the Data Risk Assessment process and implement recommendations prior to deployment.     Required for high risk applications
Regulated Data Security Controls   Implement PCI DSS, HIPAA, FISMA, or export controls as applicable.     Required for high risk applications




SaaS Vendor Evaluation Template v0.1





T E M P L A T E

EVALUATING SaaS VENDORS

This template will help you evaluate the SaaS vendors you are interested in. First rate your vendor from 1-5 for each of the criteria listed. One is the lowest score and five is the highest. Then rate the importance of each feature to your organization. The third column provides an automatic score for each feature. Once completed, check the “final evaluation" at the bottom of this table to see the final results and compare your vendors.

 

 

 

 

 

Insert SaaS Vendor 1

 

Vendor Grade

Urgency

Vendor Assessment

Criteria

Rate your SaaS vendor for  the features below (from 1 to 5).

Rate the importance of each feature to your organization (from 1 to 5)

Final vendor assessment (calculated automatically)

Security

GDPR compliance

 

 

0

SOC 2 compliance

 

 

0

ISO/IEC 27001

 

 

0

PCI

 

 

0

HIPAA

 

 

0

FFIEC

 

 

0

Single Sign-On Integration

 

 

0

Multi-factor Authentication

 

 

0

Service

Uptime

 

 

0

Response time

 

 

0

Dedicated Customer Success Manager

 

 

0

Community/Forum

 

 

0

Automated monthly reporting

 

 

0

Professional Services

 

 

 

Support

 

 

0

Cost

License terms

 

 

0

Professional Services Fee

 

 

 

Pricing

 

 

0

Feature-set (listed below are exampes of features for Enterprise SaaS Management solutions)

Automated discovery process

 

 

0

Extensive SaaS vendor integrations

 

 

0

ERP integrations

 

 

0

HRIS integrations

 

 

0

Single Sign-On Integration

 

 

0

Advanced reporting dashboard

 

 

0

Contract timeline

 

 

0

Contract renewal alerts

 

 

0

Actionable monthly recommendations

 

 

0

SaaS service usage insights

 

 

0

Departmental spend and utilization overview

 

 

0

Utilization rate metering

 

 

0

Compliance tracking

 

 

0

Final evaluation

0





Standards


Security

  • ISO
  • CSA (Cyber Security Alliance)
  • ico.
  • HIPAA
  • SSAE
  • PCI DSS
  • GDPR
  • IEC
  • COBIT
  • Cyber Essentials
  • ISAE

Cloud

  • IEEE
  • ISO
  • IETF
  • DMTF
  • ETSI
  • GICTF
  • OpenGridForum
  • SNIA
  • Open Cloud Consortium
  • Cloud Standards Customer Council
  • NIST
  • OASIS

Operations

  • ISO
  • ITIL
  • IFPUG
  • CIF
  • DMTF
  • COBIT
  • TOGAF 9
  • MOF
  • tmforum
  • FitSM



References


  • SaaS Vendor Criteria Matrix
  • Choosing a SaaS Solution (University of Colorado)




via Blogger http://blog.51sec.org/2023/04/cybersecurity-review-resources-for-saas.html
April 23, 2023 at 09:02AM Architecture
0 Comments

Integrate ShareX with Free Forever S3 Compatble Storage Solution - Tebi.io (25G Storage 250GB Outbound Traffic)

4/23/2023

0 Comments

 
Integrate ShareX with Free Forever S3 Compatble Storage Solution - Tebi.io (25G Storage, 250GB Outbound Traffic)
Tebi.io is a s3 compatible geographically distributed object storage solution. It is available with a free trial, or on a forever free plan. It features full S3 API compatibility, live replication, FTP protocol support, and other features supporting data delivery and accelerating cloud operations. Tebi.io is providing most generous free tier plan: 25GB storage with 250GB outbound transfer. 

ShareX is a fantastic tool for Windows that enables screen capture, file sharing, and much more. The most interesting part for ShareX is it can be integrated with many third party services like the Imgur, standard protocols like ftp/SFTP, as well as s3 compatbile services like Amazon AWS S3 and Backblaze B2. 

In this post, I am gonna show you how you can integrate 



Related Posts:
  • Create Your Own Cloud Photo Storage Site in BackBlaze B2 Using Cloudflare and ShareX
  • Integrate Scaleway FREE 75GB Storage with NextCloud and ShareX
  • ShareX Configuration - Free & Powerful Screenshot Tools


Register An Account and Log In

Since registration is very straighforward, there is no necessary to show all screenshots. 
Only thing you will need to do is to enter your credit card to get this free tier + Pay As You Go plan. 


Notes:
You will only have 14 days trial if you did not enter your credit card information.
You can remove your credit card later.
You can enter random numbers as your credit card. 



Create A Bucket & Key with Secret

Add a bucket

For example, we are creating a new bucket i.51sec.org, which is going to matching our future custom subdomain. If you are not planning using your own custom subdoman, you can use any bucket name as long as no one is using it, and matching S3 bucket name requirements. 


Add a key with least permissions






Configure ShareX

Make sure both image uploader and file uploader are using FTP as a method for uploading to.




You can use s3.tebi.io this domain for your configuration. Later in next section, we will change it to your own domain to use. 

Please refer FTP parameter documentation from : https://docs.tebi.io/intro/connection.html


FTP/FTPS Protocols Connection Parameters:

The File Transfer Protocol (FTP) is a standard communication protocol used for the transfer of computer files from a server to a client on a computer network. Tebi supports both encrypted (FTPS) and not encrypted (FTP) versions.

Host

ftp.tebi.io

Protocol

FTP or FTPS

Login

Bucket Key

Password

Bucket Secret

In this example, we are using FTP protocol. You also can use FTPS for better security: 



Make sure FTP uploaded file is public accessible. 
Change FTP Default ACL configuration to Public. 


Bucket File List:


Check Usage:

Support service included:
The tecnical support is pretty fast to respond to the ticket opened, although we are using a free tier service. It usually will be answered in an hour so. 

Enable Hosting and SSL Certificate Support

To enable SSL certificate support, you will need to enable hosting first and configuration custom subdomain. 

The high level steps from Tebi's documentation to associate a hostname with a Tebi bucket using CNAMEs:

  1. Select a hostname that belongs to a domain you control. This example uses the images subdomain of the your-domain.net domain.

  2. Create a bucket that matches the hostname. In this example, the host and bucket names are images.your-domain.net. The bucket name must exactly match the hostname.

  3. Create a CNAME record that defines the hostname as an alias for the Tebi bucket. For example: images.your-domain.net CNAME images.your-domain.net.s3.tebi.io.

1. Enable hosting:




2. Enable HTTPS Certificate

If you have not create DNS CNAME record, the https certificate option will be greyed out. 

There is a trick at Cloudflare configuration to enable https certificate. When configuration CNAME record in Cloudflare site, you will not enable Proxy for this cname record. 

For 

Here is wrong configuration:


Correct configuration:


3 Enable Force HTTPS

It will automatically rediect http traffic to https.

4. Change ShareX configuration to reflect domain change




Videos

 



References


  • tebi.io免费对象存储,可托管静态网站
  • https://www.youtube.com/watch?v=FzOTQg7UUfg



via Blogger http://blog.51sec.org/2023/04/integrate-sharex-with-free-forever-s3.html
April 22, 2023 at 10:49PM Cloud
0 Comments

(Pictory.AI Generated)Top Three Cybersecurit Incidens in March 2023

4/22/2023

0 Comments

 
ChatGPT does not have latest contents so I am using ChatSonic from https://writesonic.com/chat to generate the scripts then using Pictory.AI's free plan to generate video based on the scripts. Scripts in the video: There were several notable cybersecurity incidents that occurred in March 2023. Here are three of the top incidents: 1. DDoS attack on Poland's tax service: The attack on Poland's tax service website used a distributed denial of service (DDoS) method and was believed to have been carried out by Russian hackers. Although the website was taken down, no taxpayer data was reportedly leaked. 2. Ransomware attack on Group 1001 and Codman Square Health Center: Both Group 1001 and Codman Square Health Center were victims of a ransomware attack in March 2023. Ransomware is a type of malware that encrypts files on a victim's computer and demands payment in exchange for the decryption key. 3. Data breach at WH Smith: British retailer WH Smith suffered a data breach in March 2023 [1, 3]. It is unclear how many customers were affected or what type of data was exposed, but the company did confirm that it had suffered a breach and was investigating the incident. Related Post: ✍ Related Videos: ? ?Chapters: 0:00 - Introduction ✅#51Sec #NetSec ====================================================================== If you found this video has some useful information, please give me a thumb up and subscribe this channel to get more updates: ⚡https://www.youtube.com/c/Netsec?sub_confirmation=1 ⚡Resource Collection and Bookmarks: https://sites.51sec.org/ Learning and Sharing - ?海内存知己,天涯若比邻! Discord: https://discord.gg/fCW9phn Blog: https://blog.51sec.org

Watch video on YouTube here: https://youtu.be/Ic0lXvp0av0 by NetSec
0 Comments

Two Things You Can Do If ChatGPT Has Been Blocked

4/21/2023

0 Comments

 
Two Things You Can Do If ChatGPT Has Been Blocked

Lately, what ChatGPT can do has brought up lots of concerns of data security and privacy, which cause ChatGPT got blocked in some areas and companies. 

If it does happened to your area and you don't have access to ChatGPT. You will still need to use it then here are two things you might be able to do to use this advanced technology again. 



Settings

Create Your Own ChatGPT Web UI

Github : https://github.com/Yidadaa/ChatGPT-Next-Web

One click to deploy this Github project into Vercel. This can help you bypassing the domain related block. 

  • Demo

Features:

  • Deploy for free with one-click on Vercel in under 1 minute
  • Privacy first, all data stored locally in the browser
  • Responsive design, dark mode and PWA
  • Fast first screen loading speed (~100kb), support streaming response
  • Awesome prompts powered by awesome-chatgpt-prompts-zh and awesome-chatgpt-prompts
  • Automatically compresses chat history to support long conversations while also saving your tokens
  • One-click export all chat history with full Markdown support

Deploy to Vercel:

  1. Get OpenAI API Key;
  2. Click Deploy with Vercel, remember that CODE is your page password;
  3. Enjoy :)


Deploy using Docker (Recommended):

docker pull yidadaa/chatgpt-next-web

docker run -d -p 3000:3000 \
   -e OPENAI_API_KEY="sk-xxxx" \
   -e CODE="your-password" \
   yidadaa/chatgpt-next-web

You can start service behind a proxy:

docker run -d -p 3000:3000 \
   -e OPENAI_API_KEY="sk-xxxx" \
   -e CODE="your-password" \
   -e PROXY_URL="http://localhost:7890" \
   yidadaa/chatgpt-next-web


Deploy from Shell:

bash <(curl -s https://raw.githubusercontent.com/Yidadaa/ChatGPT-Next-Web/main/scripts/setup.sh)






Use An Alternative - Claude

Claude: Anthropic’s Rival to ChatGPT

Anthropic, an AI startup co-founded by former employees of OpenAI, has quietly begun testing a new, ChatGPT-like AI assistant named Claude. The team at Anthropic was gracious enough to grant us access, and updates to Anthropic’s social media policies mean we can now share some of our early, informal comparison findings between Claude and ChatGPT.





Here is an answer from Claude+ regarding if it is better than ChatGPT?


ChatGPT is an AI assistant developed by OpenAI. While we are both conversational AI's, we have different architectures and were trained on different data.

Some key differences:

• I was trained with Constitutional AI to be helpful, harmless, and honest using techniques like Constitutional AI. ChatGPT was trained with self-supervision to be helpful, harmless, and honest.

• My architecture is based on transformers while ChatGPT's architecture is also based on transformers.

• I have access to different data sources than ChatGPT. ChatGPT was trained on web data. I was trained using different data compiled by Anthropic.

• We have different capabilities - I am focused on being helpful, harmless, and honest while ChatGPT has more open-domain conversational abilities.

• We have different licenses and usage terms. I have an open license while ChatGPT has a restricted license.

So in summary, while ChatGPT and I are both conversational AI's, we were created by different companies using different techniques and data. We have some overlapping but also some different capabilities and characteristics. I do not think either of us is inherently better - we were just designed for different purposes! My role is to be helpful, harmless, and honest.


Further introduction about Claude can be found from their blog post.

Features Claude
AI Technology Large-language model
Languages Supported English 
User Experience Chat Interface or API Integration  
Educational Material Documentation available
Long Form Document Editor Yes 
Search Engine Optimization No
Art Generation No
Text Summarization Yes
Plagiarism Detection No
Chrome Extension No
API/Webhooks Yes
Free Trial No
Pricing Model Pay-as-you-go


References


  • Fast, helpful AI chat - poe.com


via Blogger http://blog.51sec.org/2023/04/two-things-you-can-do-if-chatgpt-has.html
April 21, 2023 at 07:31PM AI
0 Comments

Two Methods to Access AI Once ChatGPT Got Blocked

4/21/2023

0 Comments

 
If ChatGPT has been blocked for some reasons, are there any methods to continue accessing AI? This video provides you two other methods to get your access to AI. Related Post: ✍ Related Videos: ? ?Chapters: 0:00 - Introduction 1:07 - Lets start it! 1:56 - 1. Install your own ChatGPT Web UI 6:10 - 2. An alternative - Claude from Anthropic 10:03 - End Scene ✅#51Sec #NetSec ====================================================================== If you found this video has some useful information, please give me a thumb up and subscribe this channel to get more updates: ⚡https://www.youtube.com/c/Netsec?sub_confirmation=1 ⚡Resource Collection and Bookmarks: https://sites.51sec.org/ Learning and Sharing - ?海内存知己,天涯若比邻! Discord: https://discord.gg/fCW9phn Blog: https://blog.51sec.org

Watch video on YouTube here: https://youtu.be/f7Z2zvvNkyk by NetSec
0 Comments

Gartner Magic Quadrant for Access Management (2015 - 2022)

4/15/2023

0 Comments

 
Gartner Magic Quadrant for Access Management (2015 - 2022)
Today’s businesses require secure 24/7 access to their cloud applications and data, and require more than Web Single Sign-On to propel their business forward. The world has changed, allowing an almost infinite number of identities and accounts on different platforms and devices including cloud, mobile, social, and personal networks. Having an identity and access management strategy in place is more important than ever.




2022






2021






2020

Okta, Ping and Microsoft are named a Leader in the Gartner Magic Quadrant for Access Management for the Fourth Consecutive Year.

Okta is the only vendor that has consistently been a Leader since the inception of Gartner’s evaluation of the identity space — starting with the first Identity as a Service (IDaaS) Magic Quadrant seven years ago.

2019






2018 (Second Year)

CA becomes into Visionaries from Leaders. Micro Focus falls into Visionaries from Challengers. Five Leaders in 2018:
  • Microsoft
  • OKTA
  • IBM
  • Oracle
  • Ping Identity




2017 (First Year)

Gartner recently named following vendors as  a leader in its first “Magic Quadrant for Access Management, Worldwide 2017.”

  • Microsoft
  • Okta
  • CA Technologies
  • Oracle
  • IBM
  • Ping Identity



===================================================================
Previous years, Gartner used to publish IDaaS report, but could not find it anymore after 2016. I listed IDaaS MQ in 2016 and 2015 here since they are similar and worth comparing them. 

2016

In the 2016 MQ for IDaaS (Identity and Access Management as a Service), following three vendors are in Leaders:
  • Microsoft
  • Centrify
  • Okta




2015

In 2015, the ‘leaders’ quadrant of Gartner’s graph featured just one vendor - OKTA.





via Blogger http://blog.51sec.org/2018/04/gartner-magic-quadrant-for-access.html
April 15, 2023 at 10:12PM Security
0 Comments
<<Previous

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org