IT Pro Tuesday #298

IT Pro Tuesday #298

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Security Risks of Always On Remote Access,” we talk with Matt Lee from Pax8 to discuss the risks associated with deploying always on remote access software on managed endpoints. Matt discusses his extensive background in the MSP space and shares insights gained from his experience with a mass ransomware event.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list

A Training Resource

SadServers gives you access to a full remote Linux server on which you get to refine your troubleshooting skills by solving a particular problem. Free for personal use, with limits on the number of scenarios and total tries per day. aaron416 explains, “It will give you a task to complete on a real server, or something that’s broken. Then you figure out how to debug it and fix it!”

External Attack Surface Management Attack Surface Summary

A Free Tool

IntelBurnTest helps to simplify the use of Intel’s powerful Linpack program—a tool that can bring even the world’s most-powerful CPUs to the brink. thelanranger considers it an essential sysadmin tool.

External Attack Surface Management Attack Surface Summary

A Tip

ShoopDoopy shares a discovery:

“Use Bing chat to write short utility scripts for you. Add This is important for my career’ to the end to improve the quality of your results.”

Another Free Tool

Everything is an incredibly fast command-line search engine for Windows that instantly locates files and folders by name. By indexing only file and folder names, it generally takes a few seconds to build its database. Echo64 says, “1000% better than the built-in Windows search —one of these apps that once you use it, you can’t go back.”

One More Free Tool

CodeLobster is a cross-platform IDE that streamlines and simplifies the PHP development process. Autocompletes the names of functions, arguments, tags, and their attributes for PHP, HTML, JavaScript, TypeScript, Node.js, and Python. Also includes an internal PHP debugger that automatically detects your current server settings and configures corresponding files. Our thanks for the suggestion go to deanmoncaster.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

FurMark is an intense GPU stress test for Windows (32- and 64-bit) and Linux (32- and 64-bit) platforms as well as a quick OpenGL and Vulkan benchmark. Uses fur rendering algorithms—which are specially adapted to overheat the GPU—to measure graphics card performance. Kindly suggested by thelanranger.

Core FTP LE is a secure FTP client with features like SFTP (SSH), SSL, TLS, FTPS, IDN, browser integration, site-to-site transfers, FTP transfer resume, drag-n-drop support, file viewing/editing, firewall support, custom commands, FTP URL parsing, command line transfers, filters, and more. Appreciated by Barry2888.

IT Pro Tuesday #298

IT Pro Tuesday #296

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Are Tech ‘Innovations’ Accelerating Security Threats?” we explore how businesses can balance their need for technological advancements with maintaining robust security measures to protect against cyber threats.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list

A Script

How to monitor your UPS with free software + a Raspberry Pi is a simple script that installs Network UPS Tools plus some other packages on a Raspberry Pi or similar Linux system to quickly enable HTTP and SNMP v2c monitoring. Author david-eaton explains it “can make it easy to configure UPS monitoring on a RaspberryPi in a matter of minutes.”

External Attack Surface Management Attack Surface Summary

A Free Tool

Glary Utilities is an all-in-one solution that offers powerful one-click cleaning for an individual computer to boost speed and help fix errors, crashes, and freezes. Kindly suggested by jan-erikmense2.

External Attack Surface Management Attack Surface Summary

A Tip

A clever hack for preventing unwanted reboots, compliments of orwiad10:

Shutdown /r /t 315360000

Schedules a reboot 10 years in the future. If you have a reboot scheduled, the api prevents anything non-interactive from rebooting your machine… So stuff like a forced reboot for updates.

Another Free Tool

UltraVNC is a powerful, intuitive remote access tool for displaying and controlling the screen of another computer (via internet or network) from your own screen. Appreciated by itanassa.

A Cheatsheet

JS CheatSheet features a tidy collection of the key information you need when working with JavaScript. Our appreciation for the recommendation goes to Extradiscipline_644.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

nomacs is a multi platform image viewer that allows you to view and edit all common image formats including RAW and psd images. Supports cropping, resizing, rotating, color adjustments, and more. Thanks for this one go to SaucyKnave.

Airtable is a user-friendly cloud-based platform for creating and sharing relational databases, so you can store, organize, and collaborate on any information. brad-mdaemon-technologies says, “AirTable is my favorite tool for project tracking. Super versatile & the free version goes a long way.”

IT Pro Tuesday #298

IT Pro Tuesday #295

Welcome back to IT Pro Tuesday!

As a reminder, you’re invited to take part in a 5-min survey on IT security awareness training in companies, with a chance to win a Google Nest Hub Max worth $229!

And in the latest Security Swarm Podcast: “Tips and Tricks for Getting Started in Cybersecurity,” we sit down with Grant Collins, an infrastructure security engineer and cybersecurity career coach, to discuss everything from choosing the right degree to navigating the hiring process, acquiring essential skills, and building a robust professional network.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Free Tool

RDS-Shadow allows you to remotely view and control another user’s active session on a Remote Desktop Session Host server, without requiring admin rights. Kindly suggested by stetze88.

External Attack Surface Management Attack Surface Summary

Another Free Tool

Rocketchat is a customizable, open-source communications platform designed with a focus on data protection. Facilitates real-time conversations among team members or customers, regardless of how they connect with you. Thanks for the recommendation goes to Brianinca.

External Attack Surface Management Attack Surface Summary

Yet Another Free Tool

Bitbucket is a Git-based source code repository hosting service with a best-in-class Jira integration and built-in CI/CD. Provides a single spot where teams can plan projects, collaborate on code, test, and deploy.

A Tip

A simple keyboard shortcut appreciated by iamamisicmaker473737:

“Hold Ctrl to pause task manager sorting.”

A Script

CleanBloat is an easy way to remove all the useless bloatware and superfluous Microsoft Office language versions (except English) from Dell computers. This handy script was kindly shared by its author, Cj_Staal.

External Attack Surface Management Attack Surface Summary

P.S. Bonus Free Tools

Python Cheatsheet is a nice, single-page reference sheet that provides quick access to all the essentials for the Python 3 programming language. Kindly suggested by Extradiscipline_644.

Zypper is a powerful command-line package manager for installing, updating and removing packages in SUSE and openSUSE Linux. It features subcommands, arguments, and options that can be used to perform specific tasks, and it can also be used to manage repositories. This tool is a favorite of donges.

IT Pro Tuesday #298

IT Pro Tuesday #294

Welcome back to IT Pro Tuesday!

First off this week, we’d like to invite you to take part in a 5-min survey on I.T. security awareness training in companies. Help us understand how the human side of security is handled in your organization, and you’ll get a chance to win a Google Nest Hub Max worth $229!

And in the latest Security Swarm Podcast: “Lockbit’s Return, ScreenConnect Vulnerability & a US Healthcare Cyber Attack,” we discuss Hornetsecurity’s Monthly Threat Report analyzing recent security incidents and share expert insights.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tip

A handy shortcut, compliments of ensum: 

sysdm.cpl in the run diaglog/start menu will open System Properties.”

A Free Tool

Scintilla is a source code editing component with the usual text editing features as well as highly useful capabilities for editing and debugging source code. Features include support for syntax styling, error indicators, code completion and call tips; selection margin can contain markers like those used in debuggers to indicate breakpoints and the current line; and better styling choices. Appreciated by GeneMoody-Action1, who adds, “I have IDEs for 6 languages built into this completely portable.”

External Attack Surface Management Attack Surface Summary

A Tutorial

Introduction About BiDi SFP and BiDi Fiber explains specifically how BiDi SFP works and for what, what fiber it should operate with, and the differences between it and common SFP. Thanks for directing us to this one are offered to chaoticbear.

Another Free Tool

Prometheus SNMP Exporter exposes SNMP data in a format that is perfectly mapped for Prometheus. It translates the hierarchical data structure of SNMP to work with the Prometheus n-dimnensional matrix, thus eliminating the need to manually go through data. Our appreciation for this suggestion goes to bilbo-baggins125.

External Attack Surface Management Attack Surface Summary

Humor

A timely yet harmless prank in the category of ‘we didn’t suggest anything’… this one compliments of Ganthet72: 

“One April Fool’s Day, I put a sign on the copiers that they were now ‘voice-activated.’ It was fun listening to people telling the copier, ‘Make two copies’ all day.”

P.S. Bonus Free Tools

HTML Cheat Sheet is a quick guide to useful code examples and web developer tools, markup generators and more, including a nice pdf version you can print out. Kindly recommended by Extradiscipline_644.

Omni OS is an open-source enterprise server OS featuring data storage, lightweight virtualization, full hardware virtualization, software-defined networking, and in-depth tracing. AntranigV says, “I deployed OmniOS for a customer and I fell in love with it. Now I have 5+ deployments of OmniOS and I even setup a local mirror to download packages even faster. illumos Zones with ZFS, boot environments and SMF/FMA is really amazing, best enterprise Unix I’ve ever seen in my life. Can’t believe people are not using this gem.”

IT Pro Tuesday #298

IT Pro Tuesday #293

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Insider Threats in Microsoft 365,” we focus on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

JA4+ Network Fingerprinting explains how to leverage the new modular network fingerprint methods that replaced the JA3 TLS standard, which can be useful in helping protect your network from threats. aygupt1822 explains, “These are TLS Fingerprinting tools which generate TLS Fingerprints from raw network packets.”

External Attack Surface Management Attack Surface Summary

Scripts

9 Essential PowerShell Scripts for SharePoint Online Security shares a set of curated, precision scripts for monitoring SharePoint online file activities, external user activities, and online permissions/access. Kindly suggested by Shan_1130.

External Attack Surface Management Attack Surface Summary

Security News

Critical Security Flaws within ChatGPT Ecosystem delves into the attack vector introduced by generative AI that can be exploited to compromise user accounts. ElectroPanic0 explains, “While the whole GenAI trend is great and lets employees/teams incorporate external AI tools in their code or daily tasks, the security falls behind.”

A Tip

jamesaepp shares a handy browser shortcut: 

CTRL + Shift + DEL in Chrome/Edge (maybe FF?) brings you to the clear cache dialog box

A Tutorial

How to Build a Custom MacOS Dock is a guide that walks you through how to create a purpose-built onboarding dock for your users. The method has been verified from Sonoma back through Catalina. Recommended by trikster_online, who says, “I have about 7 different docks I use depending on the lab.”

P.S. Bonus Free Tools

Git Commands Cheat Sheet is a nicely organized quick-reference guide where you can easily locate all the essentials for making the best use of Git. Appreciation for the suggestion goes to Extradiscipline_644.

Mimir is an open-source multi-tenant time series database that is a blazingly fast, scalable, high-availability solution for long-term storage for Prometheus. Our thanks for the recommendation go to bilbo-baggins125.

IT Pro Tuesday #298

IT Pro Tuesday #292

Welcome back to IT Pro Tuesday!

In the latest Security Swarm Podcast: “Microsoft vs Midnight Blizzard,” we explore insider threats within M365 with special guest Philip Galea, R&D Manager at Hornetsecurity. The focus is on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them.

We’re looking for your favorite tips and tools we can share with the community… those that help you do your job better and more easily. Please share your suggestions on the IT Pro Tuesday subreddit, and we’ll be featuring them in the coming weeks.

Now on to this week’s list!

A Tutorial

Fiber Cable Maintenance walks you through the proper cleaning procedures that will keep your fiber cable connections working at peak performance. Appreciation for this one goes to -sirKris-, who offers the reminder, “Keep your equipment clean!” 

External Attack Surface Management Attack Surface Summary

A Free Tool

Intunewin Build and Extract is a tool that allows you to either build a new Intune Win32 application or extract the content from one that already exists. The author has written detailed instructions in this blog post. Our thanks for the suggestion go to dcg1k.

External Attack Surface Management Attack Surface Summary

Training Resource

Coursera is an online learning platform with courses from top universities and industry leaders. The catalog of options is designed to provide self-paced training options to suit all skill levels. esgeeks explains, “offers free and paid courses on a wide variety of topics, including technology.”

Humor

In the runup to April Fool’s Day, we thought we’d share this diabolical-yet-harmless prank, compliments of laguna314…

“[W]hen people set their desktop to family photos or pet photos etc., I make many copies of the photo, and change a minor detail … with paint or photoshop; something small but noticeable like adding a mustache. Then I’ll set the background to point to an album of all the copies of the picture. Have it change at like 3-minute intervals so that at some point throughout the day, their background will show the mustache for 3 minutes.

Takes time for them to notice; and when they do, by they time they can point it out to someone, it’s gone!”

A Tip

This nice shortcut was offered courtesy of bobmonkey07: 

Win+pause opens “system” so you’re right where you need [to be] for changing computer name/domain.

P.S. Bonus Free Tools

Bash Cheatsheet is a quick-reference guide that can help you get started with Linux bash shell scripting. Kindly suggested by Extradiscipline_644.

Looking Glass is an easy-to-deploy PHP option that allows you to get network information by executing commands on the router and then gathering the output for the user. thegreattriscuit explains, “[it’s] the project behind equinix’s LG.”