Blog Entries

19. 06. 2023 Fabrizio Dovesi Atlassian, Development, Service Management

👀 The AI is coming! The AI is coming!

A brief presentation of the brand new Atlassian Intelligence features and their potential in real use case scenarios. We don’t need Chicken Little to tell us that our lives will be increasingly influenced by the Artificial Intelligence revolution – AI is transforming how we work, enhancing teamwork, and significantly accelerating team achievements. Machine learning is…

Read More
13. 06. 2023 Mirko Ioris Blue Team, Red Team, SEC4U

The New .zip Domains do More Harm Than Good

In this article we’ll discuss the security concerns caused by Google’s introduction of .zip domains. First things first, let’s understand what a domain is and how it’s structured. What is a domain? A domain is a text string that allows a user to access the specified web site once typed into a browser. This string…

Read More
13. 06. 2023 Beatrice Dall'Omo Red Team, SEC4U

What We Know about the MOVEit Transfer 0-day

0-day vulnerabilities are predicted to grow more and more, posing new threats for the cybersecurity. It’s hard to predict them and when their exploit occurs, since developers and vendors are unaware of the flaw until they are actually exploited. Hence, there is no ready patch available for a 0-day vulnerability. MOVEit Transfer 0-day On May…

Read More
12. 06. 2023 Mattia Codato NetEye

Speeding up NetEye Updates with an RPM Mirror

When it comes to upgrading and updating NetEye, many users face a common challenge: the time required for downloading the new package versions. This process can be influenced by connection speed, the number of nodes to update, and sometimes even the number of NetEye systems to manage simultaneously. Fortunately, NetEye 4.30 introduces an effective solution:…

Read More
11. 06. 2023 Massimo Giaimo SEC4U

HackInBo – talk “pompompurin & co. – stories of seizures!”

On Friday 9 June 2023 I had the opportunity to participate as a speaker at the HackInBo Business event, one of the most important conferences on cyber security in Italy. During the talk I presented, I talked about the history of RaidForum, BreachForum and ExposedForum and the Genesis and Solomon marketplaces, recounting the seizures actions…

Read More
09. 06. 2023 Giuseppe Di Garbo ITOA, NetEye

Monitoring, Collection of Metrics and Dashboard of the NetEye Database

As you all know NetEye uses MariaDB as its database. With the nep-monitoring-core module of the NetEye Extension Packs (NEP), the following aspects of MariaDB are monitored: These checks are performed with a default time interval (check_interval) of 180s. To have real time control of many aspects of the MariaDB database operation, I suggest installing…

Read More
09. 06. 2023 Francesco Pavanello Exposure Assessment, SATAYO, SEC4U, Threat Intelligence

Exposure Assessment: The Best Way to Easily Discover a Target’s Infrastructure

Overview of discovering hostnames and IP addresses using OSINT techniques.

Read More
09. 06. 2023 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.30

We fixed a bug that caused a failed authentication of Alyvix sessions having some special characters in the password, due to an inconsistent encoding. Moreover, we fixed an issue related to the installation procedure of the feature modules packages on satellites, which under some circumstances was not marking the corresponding DNF group as installed. Furthermore,…

Read More
07. 06. 2023 Andrea Mariani NetEye

NEP NRPE

After performing several migrations to NetEye 4, I realized that not all checks present on the old NetEye 3 could be migrated immediately. Sometimes for obsolete host systems on which the new Icinga 2 Agent could not be installed, or for dedicated check types for specific services, it was necessary to continue using our good…

Read More
07. 06. 2023 Federico Corona Red Team, SEC4U

Cracking the Code: Unveiling Data Breach Secrets through OSINT-driven Scripts

Welcome, today’s blog is dedicated to data breach analyses and evaluating their reliability. In an increasingly data-centric digital landscape, it’s crucial to delve into the complexities of data breaches and develop effective methods for determining the trustworthiness of the information they contain. In this blog, we’ll explore a professional approach to data breach analysis using…

Read More
06. 06. 2023 Andrea Mariani NetEye, Service Management

SSSD for Active Directory Authentication

We all know that NetEye can grant access to its Web Interface through local users, or through the use of LDAP queries that can filter and grant GUI access to users or groups of a given Active Directory domain. What I would like to explore today is the possibility of granting SSH access and elevating…

Read More
05. 06. 2023 William Calliari Development

About Set Theory, the N-queens Problem, and SQL

The n-queens problem is a common exercise in computer science. Legend has it that a mathematician once declared that women are like the queens in chess, you can’t put eight of them in a room without them trying to kill each other. This obviously isn’t true, and since I’m a feminist, but also a nerd,…

Read More
01. 06. 2023 Massimo Giaimo Red Team

TIBER-EU: Enhancing Cybersecurity Resilience in the Financial Sector

As technology continues to advance at an unprecedented pace, the financial sector faces increasing risks and challenges in safeguarding sensitive data and ensuring the security of critical systems. In response to this evolving threat landscape, the European Central Bank (ECB) and the European Union Agency for Cybersecurity (ENISA) introduced a groundbreaking framework known as TIBER-EU…

Read More
01. 06. 2023 Mattia Codato Downloads / Release Notes, NetEye, Unified Monitoring

NetEye 4.30 Release Notes

Welcome to version 4.30 of our NetEye v4 Unified Monitoring Solution. In this release, NetEye goes to one of the most famous places in the Alps: the “Tre Cime di Lavaredo” or “Drei Zinnen”. They are considered among the best-known natural wonders in the world, as well as being one of the UNESCO World Heritage…

Read More
01. 06. 2023 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.29

General Authentication via request-header backend We fixed a bug that did not allow the role to be associated with a user who was part of an LDAP group when the user logged in via the request-header backend. Tornado Tornado Director retry loop We fixed a bug that triggered the Tornado Director in a retry loop…

Read More

Archive