Friday, August 16, 2024

Deepin Package Update in Terminal

sudo su

apt-get update && apt-get upgrade

Print Friendly and PDF
Share/Bookmark

Saturday, August 10, 2024

Java application performance issue on Tomcat

Symptoms:

Each request delay 15 seconds 

Issue:

Tomcat上的java程序会调用CheckHttpEMPSID.execute()方法,该方法会调用getLocalHost()方法尝试解析本机主机名对应的地址, 当hosts文件中没配置对应的记录时,请求会通过dns对外发起解析, 当dns请求解析超时的情况下会造成java程序阻塞住。

Solution:

Vi /etc/hosts - add Server IP and hostname

E.g. 192.168.8.8 server01

Print Friendly and PDF
Share/Bookmark

WAF block request - Attack Type "HTTP parser attack"

WAF block request - Attack Type "HTTP parser attack" Violations - "HTTP protocol compliance failedhe - check maximum header of numbers" header over 21 (Default value is 20, max value is 30)

Recommended Actions

 Log on to the BIG-IP ASM/AWAF Configuration utility (gui).
 Go to Security > Policy Building > Learning and Blocking Settings.
 Expand HTTP protocol compliance failed.
 Modify the Check maximum number of headers value to the required value for your application.
 Click Save.
 Click Apply Policy.

Reference:

Increase "Check maximum number of headers" to 30 under Learning and Blocking settings screen for a policy.

Print Friendly and PDF
Share/Bookmark

Lenovo T14s Gen 4 upgrade BIOS to 1.20 (R2EUJ39W)

Lenovo T14s Gen 4 upgrade BIOS to 1.20 (R2EUJ39W)


which is fixed the charging issue.

Print Friendly and PDF
Share/Bookmark

Wednesday, August 7, 2024

D-Link DIR-867 and WPA3 support

January 29, 2024 NOTICE - This hardware revision will no longer receive firmware updates after the End of Support date
(EoS): March 29, 2024.


If you are using DIR-867, it is good for you to upgrade to the latest version 1.30 since it was fixed several bugs and also it is support WPA3.


Firmware - Hardware A1:

Print Friendly and PDF
Share/Bookmark

CrowdStrike announced a new setting relating to the Incident on 19 July 2024 to allow customer to "control" Channel file update

CrowdStrike announced a new setting relating to the Incident on 19 July 2024, allowing customers to choose update approach on Sensor Operations and Rapid Response Content, but it's a generate setting for all hosts. There is no option for us to choose which group of Hosts effective. It is recommended by CrowdStrike to use "General Availability".

Unless they're allowing customers to define a small pilot group within their company, otherwise this features is almost useless....maybe we can say that it is better than nothing...since they using customers production environment as UAT and they allow you to choice which stage you join the test.

Print Friendly and PDF
Share/Bookmark

How to disable ESET Endpoint Security via GPO?

Use "Computer Configuration" and set the following policy:


Print Friendly and PDF
Share/Bookmark

2024年7月30日腾讯安全正式在国际的站发布RASP+方案――泰石引擎

It is recommended Tencent Cloud International CWPP customer (Pro/Ultimate) to enable those new features and also the Ransomware Defence.


Reference about this product release in mainland china at 2022:



Print Friendly and PDF
Share/Bookmark