<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on randomsecurity.dev</title><link>/posts/</link><description>Recent content in Posts on randomsecurity.dev</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 18 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>SRECon 2025 EMEA</title><link>/posts/srecon2025/</link><pubDate>Tue, 18 Nov 2025 00:00:00 +0000</pubDate><guid>/posts/srecon2025/</guid><description>&lt;p&gt;AI attacks is something that has been talked about in the media, but defending against them hasn&amp;rsquo;t been part of the discussion. I was able to talk about practical defenses against these attacks at &lt;a href="https://www.usenix.org/conference/srecon25emea/presentation/chamorro" class="external-link" target="_blank" rel="noopener"&gt;SRECon 2025&lt;/a&gt; in Dublin, Ireland:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/XWGjGlP2sAo?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>RSA 2023 Conference</title><link>/posts/rsac2023/</link><pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><guid>/posts/rsac2023/</guid><description>&lt;p&gt;I was honored to present at this year&amp;rsquo;s RSA Conference on Key Distribution, a topic that everyone will be looking into in the near future. The talk video can be found here:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/HMmC-0Ueod4?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>Armed to Boot: an enhancement to Arm's Secure Boot chain</title><link>/posts/armed-to-boot-cf/</link><pubDate>Thu, 26 Jan 2023 10:08:30 -0500</pubDate><guid>/posts/armed-to-boot-cf/</guid><description>&lt;p&gt;We began the process of cryptographically signing our UEFI firmware as a way to mitigate rogue firmware. While our existing solution is platform specific for our x86 AMD server fleet, we did not have a similar one for UEFI firmware signing for Arm.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s what we did: &lt;a href="https://cfl.re/3XPWxW6" class="external-link" target="_blank" rel="noopener"&gt;Armed to Boot: an enhancement to Arm&amp;rsquo;s Secure Boot chain&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Hardwear.io 2022 - Armed to Boot</title><link>/posts/armed-to-boot/</link><pubDate>Fri, 08 Jul 2022 08:08:30 -0500</pubDate><guid>/posts/armed-to-boot/</guid><description>&lt;p&gt;We’ve learned a lot about UEFI vulnerabilities over the last few years. Methods to circumvent protections via exploitation or maintain persistence have become more common. While the industry has been able to &lt;a href="https://blog.cloudflare.com/anchoring-trust-a-hardware-secure-boot-story/" class="external-link" target="_blank" rel="noopener"&gt;address this&lt;/a&gt; in a few ways, they have been primarily x86-based. So&amp;hellip;what about Arm?&lt;/p&gt;
&lt;p&gt;Below is our presentation from the &lt;a href="https://hardwear.io/" class="external-link" target="_blank" rel="noopener"&gt;Hardwear.io&lt;/a&gt; hardware security conference on a novel approach to signing UEFI firmware within the Arm ecosystem:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/i2IG6Au34xM?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>GSA 2022 Silicon Leadership Summit</title><link>/posts/gsa-2022/</link><pubDate>Fri, 27 May 2022 08:01:30 -0500</pubDate><guid>/posts/gsa-2022/</guid><description>&lt;p&gt;I was again honored to be on a panel of distinguished leaders in the silicon security field at the &lt;a href="https://community.gsaglobal.org/s/lt-event?id=a1U1K000006M21iUAC#/Overview" class="external-link" target="_blank" rel="noopener"&gt;GSA 2022 Silicon Leadership Summit&lt;/a&gt;. We discussed the benefits of the changing security industry from closed proprietary models to open collaborative innovation, how AI/ML models collaborate across end-to-end systems, and open source integration and continuous security testing practices across the industry.&lt;/p&gt;
&lt;p&gt;&lt;img src="/images/group2.png" alt=""&gt;&lt;/p&gt;</description></item><item><title>CAPEC User Summit - Hardware Security</title><link>/posts/capec-user-summit-hardware/</link><pubDate>Fri, 04 Mar 2022 08:17:30 -0500</pubDate><guid>/posts/capec-user-summit-hardware/</guid><description>&lt;p&gt;I was honored to be on a panel of hardware security experts, presenting at the &lt;a href="https://capec.mitre.org/news/index.html#march022022_Thank_You_CAPEC_Program_User_Summit_Attendees_and_Presenters" class="external-link" target="_blank" rel="noopener"&gt;CAPEC User Summit&lt;/a&gt;. Topics discussed were mapping new attack patterns to hardware and different migitation methods.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve posted the video below:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/_dUMy2mQBhI?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>Redefining Firmware Security</title><link>/posts/redefining-firmware-security/</link><pubDate>Thu, 16 Sep 2021 18:17:30 -0500</pubDate><guid>/posts/redefining-firmware-security/</guid><description>&lt;p&gt;I was fortunate to be asked by the CEO of &lt;a href="https://axiado.com/" class="external-link" target="_blank" rel="noopener"&gt;Axiado&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/gopisirineni/" class="external-link" target="_blank" rel="noopener"&gt;Gopi Sirineni&lt;/a&gt; to co-author a paper called &lt;a href="https://www.embedded.com/redefining-firmware-security/" class="external-link" target="_blank" rel="noopener"&gt;Redefining Firmware Security&lt;/a&gt;. The paper details existing ways companies leverage CPU vendors for forming a hardware root of trust (HRoT) and the improvement made by using Axiado silicon to authenticate board components.&lt;/p&gt;
&lt;p&gt;Enjoy!&lt;/p&gt;</description></item><item><title>Secure Memory Encryption Testing</title><link>/posts/secure-memory-encryption/</link><pubDate>Mon, 14 Dec 2020 13:45:18 -0600</pubDate><guid>/posts/secure-memory-encryption/</guid><description>&lt;p&gt;Earlier this year, I presented at the &lt;a href="https://www.youtube.com/watch?v=ubTDZ7w4l_8" class="external-link" target="_blank" rel="noopener"&gt;Linux Security Summit&lt;/a&gt; on how we&amp;rsquo;ve implemented secure memory encryption within our AMD EPYC edge machines. Enabling this feature is something that is fairly easy to do, but testing that it works was something that I briefly discussed during the presentation, but also something that I want to elaborate on further here. Before I get into the actual test, I&amp;rsquo;ll give a brief overview of what memory encryption is doing in the background.&lt;/p&gt;</description></item><item><title>Anchoring Trust</title><link>/posts/anchoring-trust/</link><pubDate>Tue, 17 Nov 2020 08:17:30 -0500</pubDate><guid>/posts/anchoring-trust/</guid><description>&lt;p&gt;New blog post on some of the hardware security features my team has been working on regarding moving trust anchors to silicon.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://blog.cloudflare.com/anchoring-trust-a-hardware-secure-boot-story/" class="external-link" target="_blank" rel="noopener"&gt;Anchoring Trust: A Hardware Secure Boot Story&lt;/a&gt;&lt;/p&gt;</description></item><item><title>LatinX and Cyber Security</title><link>/posts/latinx-and-cybersecurity/</link><pubDate>Wed, 11 Nov 2020 10:37:30 -0500</pubDate><guid>/posts/latinx-and-cybersecurity/</guid><description>&lt;p&gt;I recently had the privilege of interviewing &lt;a href="https://www.linkedin.com/in/ray-espinoza-b399821/" class="external-link" target="_blank" rel="noopener"&gt;Ray Espinoza&lt;/a&gt; of &lt;a href="https://cobalt.io" class="external-link" target="_blank" rel="noopener"&gt;cobalt.io&lt;/a&gt; for Latin History and National Cyber Security Awareness Month. Ray is a stalwart in the security community with a resume that most people would drool over.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s the &lt;a href="https://cloudflare.tv/event/GrolWLpXcwENZbvNMRGBW" class="external-link" target="_blank" rel="noopener"&gt;video&lt;/a&gt;. Enjoy!&lt;/p&gt;</description></item><item><title>Creating a Serverless Blog with Cloudflare and Hugo</title><link>/posts/serverless-blog/</link><pubDate>Wed, 15 Jul 2020 19:23:52 -0500</pubDate><guid>/posts/serverless-blog/</guid><description>&lt;p&gt;I hate having to rebuild stuff. I&amp;rsquo;ve rebuilt this blog a total of 4 times, with 3 of those time related to bad application/server updates. This blog was previous hosted on a &lt;a href="https://www.digitalocean.com/products/droplets/" class="external-link" target="_blank" rel="noopener"&gt;Digital Ocean virtual machine&lt;/a&gt;(VM) running a popular headless Node.js CMS called &lt;a href="https://ghost.org/" class="external-link" target="_blank" rel="noopener"&gt;Ghost&lt;/a&gt;. A failed droplet migration killed this blog once, which was recovered with a backup and some DNS changes. The last time was a Ghost CLI update (to upgrade Ghost) that wiped my config, to which I had to recover again on 06/28/20. At that point, I was fed up and decided to modernize the blog once and for all.&lt;/p&gt;</description></item><item><title>Linux Security Summit 2020</title><link>/posts/linux-security-summit-2020/</link><pubDate>Mon, 06 Jul 2020 21:34:17 -0500</pubDate><guid>/posts/linux-security-summit-2020/</guid><description>&lt;p&gt;I presented last week with my co-worker Brian at the Linux Security Summit on Securing Memory at Scale. It was an extension of our company &lt;a href="https://blog.cloudflare.com/securing-memory-at-epyc-scale/" class="external-link" target="_blank" rel="noopener"&gt;blog post&lt;/a&gt; on enabling memory encryption with our AMD EPYC 7xxx series chips. The presentation was pre-recording due to COVID, so I uploaded it here for y&amp;rsquo;all:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/ubTDZ7w4l_8?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>Google Next '19'</title><link>/posts/google-next/</link><pubDate>Fri, 12 Apr 2019 10:37:30 -0500</pubDate><guid>/posts/google-next/</guid><description>&lt;p&gt;My co-presentation from Google Next &amp;lsquo;19 on Migrating DDOS Controls to Google Cloud:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/0XbQG2QX6mY?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>Kubernetes on an Intel NUC</title><link>/posts/kubernetes-intel-nuc/</link><pubDate>Mon, 18 Apr 2016 18:29:09 +0000</pubDate><guid>/posts/kubernetes-intel-nuc/</guid><description>&lt;p&gt;With the recent rise of microservices, there has been a lot of documentation on &lt;a href="kubernetes.io/" &gt;Kubernetes&lt;/a&gt; and how to build it on various cloud platforms (AWS, GCE, etc). Since I run a small lab in my house I figured it would be beneficial to show you how to do a clustered Kubernetes install using small &lt;a href="https://www.intel.com/content/www/us/en/nuc/overview.html" class="external-link" target="_blank" rel="noopener"&gt;Intel NUC&lt;/a&gt; devices.&lt;/p&gt;
&lt;p&gt;Based on &lt;a href="https://github.com/coreos/coreos-kubernetes" class="external-link" target="_blank" rel="noopener"&gt;CoreOS&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="why"&gt;
 Why?
 &lt;a class="heading-link" href="#why"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;This is used for building small clusters based on spare servers, or in this case Intel NUC units, without incurring compute charges from cloud providers.&lt;/p&gt;</description></item><item><title>Docker Cheat Sheet</title><link>/posts/docker-cheat-sheet/</link><pubDate>Mon, 18 Apr 2016 18:13:19 +0000</pubDate><guid>/posts/docker-cheat-sheet/</guid><description>&lt;p&gt;First, my apologies for not updating in a while. For those who follow my &lt;a href="https://github.com/therandomsecurityguy" class="external-link" target="_blank" rel="noopener"&gt;Github&lt;/a&gt; site you&amp;rsquo;ll see that I have been updating that more frequently than my blog. With that said, I made a commit a while ago for a Docker Cheat Sheet that has helped a few of you out. For those that way to see it, go to the lnk below:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/therandomsecurityguy" class="external-link" target="_blank" rel="noopener"&gt;Docker Cheat Sheet&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Open vSwitch Cheat Sheet</title><link>/posts/openvswitch-cheat-sheet/</link><pubDate>Mon, 28 Dec 2015 06:39:29 +0000</pubDate><guid>/posts/openvswitch-cheat-sheet/</guid><description>&lt;p&gt;Before I begin, for those unfamiliar with &lt;a href="http://openvswitch.org" class="external-link" target="_blank" rel="noopener"&gt;Open vSwitch&lt;/a&gt;, please check out my friend David Mahler&amp;rsquo;s YouTube &lt;a href="https://www.youtube.com/user/mahler711" class="external-link" target="_blank" rel="noopener"&gt;page&lt;/a&gt; for comprehensive introductory videos.&lt;/p&gt;
&lt;p&gt;Over the past year I&amp;rsquo;ve spent some time compiling troubleshooting documents and procedures for all things cloud (OpenStack, SDN, Open vSwitch, etc). I wanted to make a series on &amp;lsquo;cheat sheets&amp;rsquo;, or common day to day configuration/troubleshooting commands and techniques for different cloud components.&lt;/p&gt;
&lt;p&gt;First on the list is Open vSwitch (aka OVS), which has become an integral part of OpenStack networking. It provides the ability to replicate many of the features of a traditional layer 2 switch, while providing advanced features that allow organizations to scale their cloud environments quickly.&lt;/p&gt;</description></item><item><title>VXLAN Offload</title><link>/posts/vxlan-offload/</link><pubDate>Sun, 08 Mar 2015 01:04:21 +0000</pubDate><guid>/posts/vxlan-offload/</guid><description>&lt;p&gt;It&amp;rsquo;s been a while since I last posted due to work and life in general. I&amp;rsquo;ve been working on several NFV projects and thought I&amp;rsquo;d share some recent testing that I&amp;rsquo;ve been doing&amp;hellip;so here we go :)&lt;/p&gt;
&lt;h2 id="let-me-offload-that-for-ya"&gt;
 Let me offload that for ya!
 &lt;a class="heading-link" href="#let-me-offload-that-for-ya"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In a multi-tenancy environment (OpenStack, Docker, LXC, etc), VXLAN solves the limitation of 4094 VLANs/networks, but introduces a few caveats:&lt;/p&gt;</description></item><item><title>VXLAN</title><link>/posts/vxlan/</link><pubDate>Sat, 07 Mar 2015 01:04:21 +0000</pubDate><guid>/posts/vxlan/</guid><description>&lt;h2 id="vlans-circa-1998"&gt;
 VLANS circa 1998
 &lt;a class="heading-link" href="#vlans-circa-1998"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;It&amp;rsquo;s amazing that a technology that is over 16 years old is still widely used today. Why? Because it works in most cases (small/medium datacenters, single/dual tenant design, etc). However, due to the growth of cloud computing, the need for secure, scalable virtual networks has changed. Although some solutions exist today to help facilitate some of the isolation concerns, such as &lt;a href="http://en.wikipedia.org/wiki/IEEE_802.1ad" class="external-link" target="_blank" rel="noopener"&gt;QinQ&lt;/a&gt;, they fail to address the increasing issue with scale. Virtual Extensible Local Area Network (or VXLAN) extends the VLAN concept of a layer 2 (L2) domain but allows it to sit on top of (overlay) your existing network. It uses MAC-in-UDP encapsulation to create tunnels (VXLAN Tunnel Endpoints or VTEPS) across a layer 3 (L3) transport to extend your L2 domain with great flexibility. This would allow for hosts to live in two disparate networks yet still operate as if they were attached to the same L2 domain. This also solves the VLAN limitation of 4096 VLAN ID&amp;rsquo;s as VXLAN supports over 16 million VXLAN id&amp;rsquo;s. I&amp;rsquo;ll provide a quick overview on how this technology works, some of the misconceptions surrounding it, as well as current adaption methods.&lt;/p&gt;</description></item><item><title>Openstack scripts</title><link>/posts/openstack-scripts/</link><pubDate>Mon, 17 Nov 2014 21:17:18 +0000</pubDate><guid>/posts/openstack-scripts/</guid><description>&lt;p&gt;I&amp;rsquo;ve updated my &lt;a href="https://github.com/therandomsecurityguy/openstack-setup-scripts" class="external-link" target="_blank" rel="noopener"&gt;Git repo&lt;/a&gt; with some of the deployment scripts I&amp;rsquo;ve used for my &lt;a href="http://www.gigabyte.us/products/list.aspx?s=47&amp;amp;ck=104" class="external-link" target="_blank" rel="noopener"&gt;Brix&lt;/a&gt;/&lt;a href="http://www.intel.com/content/www/us/en/nuc/overview.html" class="external-link" target="_blank" rel="noopener"&gt;NUC&lt;/a&gt; lab setup. Read and enjoy!&lt;/p&gt;</description></item><item><title>Self Healing OpenStack Control Plane with Kubernetes</title><link>/posts/self-healing-openstack-control-plane-with-kubernetes/</link><pubDate>Fri, 07 Nov 2014 01:04:21 +0000</pubDate><guid>/posts/self-healing-openstack-control-plane-with-kubernetes/</guid><description>&lt;p&gt;I presented, along with &lt;a href="https://www.linkedin.com/in/shixiong-shang-b876b233" class="external-link" target="_blank" rel="noopener"&gt;Shixiong Shang&lt;/a&gt; and &lt;a href="https://www.linkedin.com/in/randy-tuttle-11a538" class="external-link" target="_blank" rel="noopener"&gt;Randy Tuttle&lt;/a&gt; from &lt;a href="https://files.slack.com/files-pri/T0WAHEMLZ-F139W8WEL/img_20160424_155327.jpg" class="external-link" target="_blank" rel="noopener"&gt;CloudPerceptions&lt;/a&gt;, at the &lt;a href="https://www.openstack.org/summit/austin-2016/" class="external-link" target="_blank" rel="noopener"&gt;OpenStack Summit&lt;/a&gt; in Austin, TX regarding using Kubernetes as the underlay for building a &amp;lsquo;self-healing&amp;rsquo; OpenStack control plane:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
 &lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/lkhkY_52vJk?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
 &lt;/div&gt;</description></item><item><title>Openstack with IPv6</title><link>/posts/openstack-ipv6/</link><pubDate>Tue, 19 Aug 2014 14:19:00 +0000</pubDate><guid>/posts/openstack-ipv6/</guid><description>&lt;h2 id="openstacknow-with-lots-of-addresses"&gt;
 Openstack&amp;hellip;.now with lots of addresses!
 &lt;a class="heading-link" href="#openstacknow-with-lots-of-addresses"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;After being inspired to update my IPv6 experience in my &lt;a href="https://randomsecurity.dev/ipv6-sage/" class="external-link" target="_blank" rel="noopener"&gt;previous post&lt;/a&gt;, I figured it was time to start enabling IPv6 within my Openstack lab environment. It&amp;rsquo;s surprisingly easy as it&amp;rsquo;s similar to many dual-stacked environments that support IPv4/IPv6 today. The following is a basic Openstack Icehouse single node install with a Single Flat Network (I&amp;rsquo;ll explain shortly), dual-stacked topology. Sound good? Let&amp;rsquo;s get started!&lt;/p&gt;</description></item><item><title>IPv6 "Sage"</title><link>/posts/ipv6-sage/</link><pubDate>Sun, 03 Aug 2014 22:56:49 +0000</pubDate><guid>/posts/ipv6-sage/</guid><description>&lt;h2 id="free-stuff-motivates-me"&gt;
 Free Stuff Motivates Me
 &lt;a class="heading-link" href="#free-stuff-motivates-me"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;ll admit it. Anytime I see a challenge where one can win free schwag I dive into it head first. When I saw that one could win a free t-shirt by completing the &lt;a href="https://ipv6.he.net/certification/" class="external-link" target="_blank" rel="noopener"&gt;Hurricane Electric IPv6 Certification course&lt;/a&gt; , I became dead set on getting my hands on a new shirt. Little did I know it would not only be fun and re-teach me some concepts, but also give me motivation on testing IPv6 within Openstack. This isn&amp;rsquo;t going to be a primer on IPv6 so, if needed, go to the &lt;a href="http://en.wikipedia.org/wiki/IPv6" class="external-link" target="_blank" rel="noopener"&gt;Wikipedia article&lt;/a&gt; to brush up concepts beforehand. So let&amp;rsquo;s get into how to complete the certification.&lt;/p&gt;</description></item><item><title>Openstack Juno on Centos 7</title><link>/posts/openstack-juno/</link><pubDate>Wed, 25 Jun 2014 16:03:24 +0000</pubDate><guid>/posts/openstack-juno/</guid><description>&lt;p&gt;First, sorry for the delay in posting. I&amp;rsquo;ve been busy in rebuilding my lab (4 times) to accommodate parallel testing. In the meantime, I wanted to quickly share my experience with the latest Openstack release: Juno. As of this writing there is a repo available for Ubuntu but for this install I&amp;rsquo;m using &lt;a href="http://www.centos.org/download/" class="external-link" target="_blank" rel="noopener"&gt;Centos 7&lt;/a&gt; via &lt;a href="https://openstack.redhat.com/Quickstart" class="external-link" target="_blank" rel="noopener"&gt;RDO&lt;/a&gt; and the &lt;a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform/2/html/Getting_Started_Guide/part-Deploying_OS_using_PackStack.html" class="external-link" target="_blank" rel="noopener"&gt;Packstack installer&lt;/a&gt;. Why? Because it&amp;rsquo;s freaking easy&amp;hellip;.aside from a few minor changes depending on the configuration you choose (single node, multi-node, vlan, vxlan, etc). So let&amp;rsquo;s get started.&lt;/p&gt;</description></item><item><title>Openflow</title><link>/posts/openflow/</link><pubDate>Sun, 20 Apr 2014 16:10:29 +0000</pubDate><guid>/posts/openflow/</guid><description>&lt;h2 id="huh"&gt;
 Huh?
 &lt;a class="heading-link" href="#huh"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;With the recent advances in virtualization and abstracted computing, software-defined networking (SDN) has become a reality. Although decoupling the network control out of physical network devices into a central or clustered service has been the primary focus of SDN, the discussion around &lt;a href="http://archive.openflow.org/wp/learnmore/" title="Openflow" class="external-link" target="_blank" rel="noopener"&gt;Openflow&lt;/a&gt; and SDN being the same is a bit of a misnomer. Before I talk about Openflow concepts and deployments strategies, let&amp;rsquo;s break down a bit of what Openflow is, the difference between SDN and Openflow, and it&amp;rsquo;s messaging scheme.&lt;/p&gt;</description></item><item><title>Devstack single NIC configuration</title><link>/posts/devstack-single-nic-configuration/</link><pubDate>Fri, 28 Mar 2014 22:21:21 +0000</pubDate><guid>/posts/devstack-single-nic-configuration/</guid><description>&lt;p&gt;I made a &lt;a href="http://randomsecurity.dev/openstack-20-minutes/" title="Openstack in 20 minutes" class="external-link" target="_blank" rel="noopener"&gt;post&lt;/a&gt; recently on setting up Openstack for development using &lt;a href="http://devstack.org/" class="external-link" target="_blank" rel="noopener"&gt;Devstack&lt;/a&gt; but failed to mention some other tips on how to build a lab out of anything. I&amp;rsquo;m a big fan of the &lt;a href="http://www.gigabyte.us/products/product-page.aspx?pid=5038#ov" class="external-link" target="_blank" rel="noopener"&gt;Gigabyte Brix &lt;/a&gt;PC kit systems, with the caveat being that they only have a single NIC. You could connect a wireless USB adapter but there is a much easier way to have multiple networks&amp;hellip;.&lt;/p&gt;
&lt;h3 id="old-fashioned-bridgingthe-joy"&gt;
 Old fashioned bridging&amp;hellip;.the joy
 &lt;a class="heading-link" href="#old-fashioned-bridgingthe-joy"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Yes&amp;hellip;.bridging and VLANS still work&amp;hellip;and fairly well within a Linux system. First install the dependencies:&lt;/p&gt;</description></item><item><title>Openstack in 20 minutes</title><link>/posts/openstack-20-minutes/</link><pubDate>Fri, 28 Feb 2014 14:58:56 +0000</pubDate><guid>/posts/openstack-20-minutes/</guid><description>&lt;h2 id="openstackfor-the-lazy"&gt;
 Openstack for the lazy
 &lt;a class="heading-link" href="#openstackfor-the-lazy"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;If you are like me, you do a lot of testing.  I have built and rebuilt Openstack single (all in one) and multi-node installations hundreds of times. With &lt;a href="http://devstack.org/" title="Devstack" class="external-link" target="_blank" rel="noopener"&gt;Devstack&lt;/a&gt;, you have the ability of creating an Openstack single node instance within minutes. While the default settings should suffice for most, I&amp;rsquo;ll add some additional details that may help with all of the testing you wish to accomplish.&lt;/p&gt;</description></item><item><title>NTP reflection attacks</title><link>/posts/ntp-reflection-attacks/</link><pubDate>Tue, 11 Feb 2014 12:31:26 +0000</pubDate><guid>/posts/ntp-reflection-attacks/</guid><description>&lt;h2 id="the-buzz"&gt;
 The buzz
 &lt;a class="heading-link" href="#the-buzz"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;There has been a lot of traction in the news lately regarding a &amp;rsquo;new&amp;rsquo; DDOS attack vector in regards to network time protocol (&lt;a href="http://en.wikipedia.org/wiki/Network_Time_Protocol" class="external-link" target="_blank" rel="noopener"&gt;NTP&lt;/a&gt;) based attacks. NTP reflection is similar in nature to &lt;a href="http://en.wikipedia.org/wiki/Reflection_attack" title="DNS reflection" class="external-link" target="_blank" rel="noopener"&gt;DNS reflection&lt;/a&gt; in that it is a UDP-based protocol that can be persuaded to return a large reply to a small request. To give a little background on this type of attack I&amp;rsquo;ll explain how it works. A reflection attack works when an attacker can send a packet with a spoofed source IP address. The attacker sends a packet apparently &lt;em&gt;from&lt;/em&gt; the intended victim to a random server on the Internet that will reply immediately. Because the source IP address is spoofed to look like the victim IP, the remote Internet server replies and sends data to the victim. The result is two-fold: the real source of the attack is hidden and unknown and, if several servers are used, the attack can be amplified. The amplification becomes more severe when the attacker sends spoofed packet that elicits a large reply from the server(s) in question. This attack can turn a small amount of bandwidth that the attacker uses to generate the attack into a massive bandwidth attack from server(s) globally.&lt;/p&gt;</description></item><item><title>Ghost Blog</title><link>/posts/ghost-blog/</link><pubDate>Wed, 08 Jan 2014 18:30:52 +0000</pubDate><guid>/posts/ghost-blog/</guid><description>&lt;h2 id="new-look-same-scrutiny"&gt;
 New look, same scrutiny.
 &lt;a class="heading-link" href="#new-look-same-scrutiny"&gt;
 &lt;i class="fa fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;I figured it was time to move away from WordPress onto a faster platform, so I decided to give &lt;a href="https://ghost.org/" class="external-link" target="_blank" rel="noopener"&gt;Ghost&lt;/a&gt; a try. It is coded in &lt;a href="http://en.wikipedia.org/wiki/Node.js" class="external-link" target="_blank" rel="noopener"&gt;Node.js&lt;/a&gt; and uses &lt;a href="http://en.wikipedia.org/wiki/Markdown" class="external-link" target="_blank" rel="noopener"&gt;Markdown&lt;/a&gt; as it&amp;rsquo;s formatting syntax. Editing is facilitated using a split screen display, so it&amp;rsquo;s hard to fudge things up.&lt;/p&gt;
&lt;p&gt;A big shoutout to &lt;a href="http://lnoldan.com/" class="external-link" target="_blank" rel="noopener"&gt;Lars&lt;/a&gt; for hosting the previous blog for nearly a year.&lt;/p&gt;</description></item></channel></rss>