Can it be done on a locked PC or must a user be actively logged in? I presume the former, as I don't believe the mounting process requires the PC to be unlocked.
17 karma · joined June 6, 2015
[ my public key: https://keybase.io/dnlongen; my proof: https://keybase.io/dnlongen/sigs/hodwXHhsA08nityQ7OoKDGEEjrMpwzmRYlpN8k7S3UE ]
Can it be done on a locked PC or must a user be actively logged in? I presume the former, as I don't believe the mounting process requires the PC to be unlocked.
I'm not quite ready to +1 the idea though. It's intriguing, but seems to open a user up to abuse. Unsolicited messages (email, SMS, IM, DM, Facebook, etc.) are a popular way of phishing (tricking individuals into giving away private information). One tip security pros repeat over and over is not to click on unsolicited links.
While you say customers will only provide payment information to a company they trust, what is to keep a crook from impersonating a trusted vendor and tricking a customer into paying them instead of the actual company?
I'm all for convenience when done safely, and perhaps your business model accounts for this - I'm just curious what you have done to prevent SMS-based payments from turning into a source of fraud.
> If the smart switch is on the LAN side of the router, then I only see traffic from wired devices on the LAN and miss anything from wireless clients.
> If the smart switch is on the WAN side of the router, then I see any traffic destined for the Internet, but now the Pi has to account for NAT (everything coming back from DNS has a destination of my router's WAN interface).
1. The alert tells me the IP address of the offending computer or device, but not the domain name that was requested. I have Snort configured to store each packet that triggered an alert, and can use tcpdump to analyse the packets - but that's a bit of a pain. Do any readers know of a way to include payload fields from a DNS packet in the alert message?
2. I've identified 4 specific "warning page" DNS responses, but OpenDNS owns far more addresses that they may use for other conditions now or in the future. At a minimum, OpenDNS owns the ranges 67.215.64.0/19 and 204.194.232.0/21 -- all told, about 10,000 addresses. Snort supports matching IP ranges in CIDR notation for the source and destination, but my approach currently does a binary match in the payload. Do any readers have an example of a Snort rule that parses DNS packets into their component fields?