cover of episode 2.5 Admins 232: S:

2.5 Admins 232: S:

2025/1/30
logo of podcast 2.5 Admins

2.5 Admins

AI Deep Dive AI Chapters Transcript
People
A
Alan
E
Eric
通过四年的激进储蓄和投资,实现50岁早退并达到“胖FI”状态。
H
Harold
J
Jim
专注于 IT 自动化和网络安全的技术专家
M
Mikael
Topics
@Alan 的观点,万事达卡的DNS错误暴露了其监控系统的不足。大型组织的Active Directory DNS配置常常存在问题,导致性能下降和用户体验不佳。 我经常遇到这种情况,一些组织的Active Directory中列出了多个DNS服务器,但其中一些服务器是不可访问的,因为不同站点之间缺乏VPN连接或权限。这导致DNS查找失败并重试,增加了延迟,影响了用户体验。 为了避免这种情况,我们应该定期检查所有列出的DNS服务器是否都能正常访问,并确保所有服务器都能被所有用户访问。 我补充一点,即使万事达卡的监控系统能够检测到DNS错误,也可能无法评估其安全风险。攻击者可以利用TTL设置来长期劫持域名,这需要更高级的监控手段来发现。 此外,内部监控系统可能无法检测到外部网络问题。使用外部探针可以更准确地监控网络健康状况。在复杂的网络环境中,需要在每个VLAN中部署探针进行监控,以确保每个网络段都能正常工作。 总之,我们需要一个全面的监控系统,能够从多个角度监控网络健康状况,并及时发现和解决潜在的安全风险。

Deep Dive

Shownotes Transcript

An embarrassing typo suggests that MasterCard’s monitoring isn’t as good as it should be, tricky offsite backups, why two-factor authentication over SMS is a bad idea, and keeping two Mac laptops in sync.

Plugs

Support us on patreon and get an ad-free RSS feed with early episodes sometimes

Klara Webinar, Feb 13th: RAID is NOT a Backup and Other Hard Truths About Disaster Recovery

News

MasterCard DNS Error Went Unnoticed for Years

Free Consulting

We were asked about tricky offsite backups, why Two-factor authentication over SMS is a bad idea, and keeping two Mac laptops in sync.

ServerMania

Get 15% Off dedicated servers – recurring for Life at servermania.com/25a with code 25ADMINS

Automox

Check out the brand new Autonomous IT podcast. Listen in as a variety of experts in the IT Operations space discuss the latest Patch Tuesday releases, mitigation tips, and custom automations to help with CVE remediations. Listen now on Spotify, Apple, or wherever you get your podcasts.

See our contact page for ways to get in touch.