• 0 Posts
  • 39 Comments
Joined 2 years ago
cake
Cake day: November 17th, 2022

help-circle


  • I think that mitigation requires two things for it to work.

    1. You need to use a a Type 2 hypervisor (like Virtualbox, VMware Workstation/Fusion).
    2. That VM needs to be configured in NAT mode.

    The two primary ways you can configure a network for a local virtual machine are NAT and Bridged.

    Bridged mode places your VM effectively on the same network as your host OS, meaning that any DHCP server that exists on your network (rogue or otherwise) will give your virtual machine and IP.

    In NAT mode, the virtualization platform itself includes a DHCP server to dole out IPs, and handle the routing between your virtual machine and your host OS’s network.

    The thought process is that if you trust your laptop, the DHCP address handed out for NAT mode will not have the VPN breaking DHCP option and your VPN inside the VM will not have it’s route table screwed with.









  • pezhore@lemmy.mltoScience Memes@mander.xyzTrap happy
    link
    fedilink
    English
    arrow-up
    58
    ·
    edit-2
    4 months ago

    Where an animal is camera trap shy or camera trap happy, detection probability is compromised and the assumptions of the method cannot be met. Even the study of animal behavior can be compromised if an animal exhibits atypical behavior (Gibeau and McTavish 2009). Attraction of certain species and individuals to our camera traps would confound assumptions of some other population estimators (Table S2) because the device effectively becomes a lure (Foster and Harmsen 2012).

    https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4829047/

    I gotchu fam.

    Granted I don’t know if it’s the same kind of trap happy, but at least it’s a phrase in one research paper.


  • As I get older and the abuse I put my ears through starts showing up, I completely agree. After upgrading my music library to FLAC from VBR mp3s, I stopped having the, “Oh! There’s a subtle instrument going on in this part of the song!” moments.

    It doesn’t stop me from trying to listen to the highest quality music formats that I can get my hands on, but I 100% know if I think there’s a difference to my mid-40s ears, it’s probably a placebo.







  • So first, let me be clear - I don’t know if an alternative to that software you first brought up. But some of our earlier CTFs had a similar issue with isolation.

    We ended up spinning up new VLANs per contestant, each having a single Kali Linux VM with xrdp, along with each contestants target systems. Our router/fw blocked all access in/out of those VLANs, save for RDP/SSH traffic from our Apache Guacamole server on the DMZ.

    So contestants would hit our portal (Guacamole), then from there connect into their own dedicated Kali instance and environment.

    Later, we had to make additional fw exemptions for our scoreboard/docs, etc.