Skip to content

Tales from the HomeLab

A Nuts and Bolts Exploration of the Cyber Landscape for System Administrators and Security Analysts

Menu
  • About Us
  • Security Onion
  • Apache
  • WordPress
  • pfSense
Menu

Category: Security Onion

Adventures in Server-Sitting

Posted on November 12, 2024

by Fred Theilig – @fmtheilig My home server seems to occasionally enter a steady state. The syslog logs, the IDS detects, the vulnerability scanner scans, the web server serves. I stop routinely…

D-Link Router Compromise Attempt

Posted on August 15, 2024

by Fred Theilig – @[email protected] Security Onion threw up three alerts this week:WGET Command Specifying Output in HTTP HeadersPossible D-Link Router HNAP Protocol Security Bypass AttemptD-Link Devices Home Network Administration Protocol Command…

A (slightly) Deeper Dive into Weird Apache Logs

Posted on May 5, 2023

By Fred Theilig – @fmtheilig My IDS alerted me to strange behavior (obfuscated Log4j) on my web server, but rather than investigate through Security Onion, I went straight to the logs. Greping…

Banner Capture for Fun and Profit

Posted on February 12, 2023

On January 30th I saw the single suricata alert “ET SCAN Zmap User-Agent (Inbound)”. This is a low severity alert and the target was my web server. Let’s see what that’s all…

A Whole Lot of Nothings

Posted on January 27, 2023

On August 18th IP address 23.227.202.82 (Tampa, Florida) triggered the suricata alert “ET SCAN MS Terminal Server Traffic on Non-standard Port” on my web server. This is apparently an attempted information leak,…

Torrent in Sheep’s Clothing

Posted on December 31, 2022

I discovered that my son was using BitTorrent. The alert GPL P2P BitTorent Transfer showed up in Security Onion in the 100’s of thousands. He said he uses it to download Linux…

WUDO and, well, that was dumb

Posted on December 2, 2022

Allow me to introduce you to WUDO. WUDO is Windows Update Delivery Optimization, and not the Western Union Defence Organisation. This is a feature introduced in Windows 10 to cut down on…

Penetration Test, No Charge

Posted on November 5, 2022

Back in early July some strange traffic was setting off Suricata alerts. The target was my WordPress website. The website is for the benefit of a non-profit and because of ISP restrictions,…

These Are the Pros and Cons of …

Posted on October 21, 2022

… Clear Text Authentication Back in June I got a Suricata alert saying a local computer was authenticating using clear text. That computer was my son’s Nintendo Wii. Security Onion is an…

©2025 Tales from the HomeLab | Design: Newspaperly WordPress Theme