HNHacker News
TopNewBestAskShowJobs

trimstray

248 karma · joined August 16, 2018

submissionscomments
trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
Sure. PRs welcome!
trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
https://github.com/trimstray/htrace.sh/issues/50
trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
dockerfile is also available: https://github.com/trimstray/htrace.sh/blob/master/build/Doc...
trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
I'll update this project with your suggestions from this thread.

Thank you for your support!

trimstray··on A Practical Hardening Guide to Advanced Linux Security, OpenSCAP (C2S/CIS, STIG)
Hi, this project is still work in progress.

What do you think about it? If you find something which doesn't make sense, or something doesn't seem right, please add issue or write here.

Thanks, trimstray

trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
ok, i'll add issue for this, thx.
trimstray··on Show HN: My shell script for HTTP/HTTPS troubleshooting and profiling
Thanks. All suggestions/PR are welcome.
trimstray··on The Book of Secret Knowledge – A collection of lists, blogs, hacks
Wow it's really good. I'll add this list to repo, thx
trimstray··on The Book of Secret Knowledge – A collection of lists, blogs, hacks
"I think it would be nice to have an actual "book", with community-composed chapters. They would follow the same topics listed here, but with actual cohesive explanations and background, rather than just a list of resources." - hmm... PR welcome :) Prove yourself man.
trimstray··on The Book of Secret Knowledge – A collection of lists, blogs, hacks
Because for me it was secret knowledge? And I wanted to share this knowledge with others?
trimstray··on The Book of Secret Knowledge – A collection of lists, blogs, hacks
I do it only for stars... really man? Creating and maintaining such a list is not a simple thing. It's not awesome or other shit in the name.

This is a collection of my short notes, one-liners, useful links, tools and more. I added it to gh, to share with others and get other interesting things. Not for stars! The amount of them is obviously nice but not crucial.

trimstray··on Nginx quick reference
"and most of the hardening seems questionable at best." - Don't do this, please add rationale, not bullshit.

"Some of the headers that is suggested have some implications that aren't really explained at all. Like HSTS including sub-domains." - This repo also contain "Force all connections over TLS". However, I understand your attention.

"And you don't set the `default_server` as this document suggest. `default_server` is a parameter to the `listen`-directive. The only reason the docs might work is because the first server-block defined, when no-one is defined as `default_server`, becomes the default server." - You're right, your suggestion is very well (it's also from Nginx official handbook) and rationale, thanks for this! I receive this criticism, My mistake.