• 0 posts
  • 3 comments
Joined 3 years ago
Cake day: June 20th, 2023
  • We had this, and I created the same rule, but they have since switched to AI generated phishing emails that use information about you (your manager etc) to make a fairly convincing email. If someone gets a lot of email from outside sources, I can totally see them clicking on a link if they’re in a hurry.

    The main things that raise my suspicion are:

    • telling me it’s urgent
    • telling me there will be dire consequences if I fail to comply
    • asking me to log in (with a direct link)
    • it’s from an external source
    • it’s not related to my job (eg, asking me to sign off on a PO)
    • telling me to download a file
    • including an attachment

    I usually just err on the side of reporting it. I’ve only had one false positive so far.

  • Fail2ban is just another tool in your toolbox. Defense in depth, as others mentioned.

    Fail2ban is primarily a tool to prevent brute force attacks, especially useful for services that don’t do their own throttling. For example I usually put ssh in fail2ban, but if Authelia’s built-in protection is good enough, then use that.

    Outside ssh, anything that could be used to brute force credentials should be in fail2ban if they’re exposed: web sites with simple auth, mail, etc.