pouet.chapril.org est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Chapril https://www.chapril.org est un projet de l'April https://www.april.org

Administré par :

Statistiques du serveur :

1,1K
comptes actifs

#logs

5 messages4 participants0 message aujourd’hui

A few reasons why we say that #VictoriaLogs is a great solution for log management:

⚙️ Easy to configure and manage.
💾 Production setup doesn’t need #S3-compatible storage.
🆙 Doesn’t break already existing configs in new releases, so the upgrade path is very simple.
📝 Supports high-cardinality #log fields such as user_id, trace_id and ip, out of the box.
📚 Provides fast full-text search over plaintext #logs.

Guide to Interpreting Security Incident #Announcements:

"extremely sophisticated attack" : The attackers put more time into the attack than we spent designing our defences.

"no evidence customer #data was accessed" : We lack audit records and the logs have been rotated out.

"due to a misconfiguration issue" : We deployed with default #insecure settings.

"possible for only a short window" : We didn't dig too deep to determine how far back the bug existed.

"crafted invalid request data" : We forgot to add input #validation.

"supplementary fix" : We didn't understand the problem as well as we thought, so our previous fix was insufficient.

"may have been exploited" : We're positive they got away with data, but they deleted our #logs.

"multiple threat actors" : Everyone was in our systems before we noticed.

"most customers are unaffected" : There are corner cases that aren't as #vulnerable.

"error in a third-party component" : We forgot to update our dependencies.

"could lead to remote code execution" : You're #p0wned.

"malicious activity has been observed" : The issue has already appeared in the press.

"review equipment inventory to verify if devices require other mitigations" : You need to buy new stuff.

"remotely exploited to allow authentication bypass" : We forgot to require #login for this function.

"not aware of any exploits in the wild" : The attackers aren't bragging on darkweb fora yet.

Je viens de voir mes #logs d'accès #web. Le bot de #chatGPT se prend bien des erreurs 403 suite à ma conf Apache. Mais il ne s'estime pas vaincu pour autant: "tiens je me suis pris une erreur 403 sur cette URL ? Bon bin je vais la retenter toutes les minutes pendant 15 minutes, on sait jamais, sur un malentendu..."