Sunny Heart

Information Security Incident Response Policy and Procedures

Information Security Incident Response Policy and Procedures

Overview: This document offers a recommended, cyclic approach to managing both cybersecurity and information security related events in a systematic manner. The phased incident response approach outlined in this document aligns with the approach recommended by the US National Institute of Standards and Technology (NIST).

Information Security Incident Response Policy and Procedures Read More »

Security Awareness Deployment Plan

Security Awareness Deployment Plan

Overview : The purpose of this document is to outline a proposed approach to deploying the security awareness and training program at the ITPROSEC.  This document will outline the proposed approach, timing and materials the ITPROSEC’s Information Security team would like to deploy over the course of the upcoming fiscal year (FY2017/2018).  The intended audience

Security Awareness Deployment Plan Read More »

Securely Remote Connect to MySQL with Navicat SSH

Securely Remote Connect to MySQL with Navicat SSH

Navicat connects to the MySQL database through ssh, without opening the database port (3306 by default), and without creating another user that allows external network connections, which can greatly improve security. Of course, if your server is enabled with ssh service. The following uses Mac version of Navicat as an example to teach you how to

Securely Remote Connect to MySQL with Navicat SSH Read More »

Several Methods to Run Mimikatz

Several Methods to Run Mimikatz

Mimikatz is an artifact that can obtain memory from the Windows Authentication (LSASS) process, and obtain plaintext passwords and NTLM hashes. Mimikatz is commonly used in intranet penetration to obtain plaintext passwords or hash values ​​to roam the intranet. However, in actual application, we often encounter the interception of killing soft, so here I refer to the information on

Several Methods to Run Mimikatz Read More »

Some Useful Information Security Websites/Blogs to Visit

Some Useful Information Security Websites/Blogs to Visit

1. Brian Krebs 2. Wombat Security 3.  Errata Security 4. Kaspersky Labs 5. Security Bloggers Network 6. Sophos 7. Paul’s Security Weekly 8. Akamai 9. The Security Ledger 10. Graham Cluley 11. Akamai 12. McAfee AntiVirus securing tomorrow 13. Naked Security 14. Shodan  15. NoMoreRansom 16. National Cyber Security Centre 17. Reddit:  r/infosec  r/sysadmin  r/crypto  r/cybersecurity  r/opsec  r/privacy r/intelligence  r/asknetsec 18. Google’s Digital Attack Map 19. OSINT

Some Useful Information Security Websites/Blogs to Visit Read More »

Apache webpage and security optimization-webpage caching (connotation experiment)

Apache webpage and security optimization-webpage caching (connotation experiment)

Foreword: Apache’s mod_expries module automatically generates Express tags and Cache-Control tags in the header information of the page. The client browser determines according to the tag that the next visit is to fetch the page in the cache of the local machine, and does not need to make a request to the server again, thereby

Apache webpage and security optimization-webpage caching (connotation experiment) Read More »

My Privacy Cleaner Prov3.1 green version

My Privacy Cleaner Prov3.1 green version

Software size: 3.98MB My Privacy Cleaner Pro Green Edition is a very useful software for erasing Internet traces. It can find and delete the history of all your recent online activities, including recently visited websites and any downloaded files or photos. When surfing the Internet, sometimes we have some records that we do not want to be kept

My Privacy Cleaner Prov3.1 green version Read More »