Basic Assignments
 
Options & Settings
 
Main Time Information
Color Code: Red
Assigned To: JM Developments LLC
Created By: JM Developments LLC
Created Date/Time: 1/18/2021 10:53 am
 
Action Status: Blank (new)
Show On The Web: Yes - (public)
Priority: 0
 
Time Id: 7347
Template/Type: Brandon Time
Title/Caption: Pen Testing Review
Start Date/Time: 1/19/2021 10:00 am
End Date/Time: 1/19/2021 11:15 am
Main Status: Active

Sorry, no photos available for this element of time.


Notes:

Meeting between John, Wayne, Steve, and Brandon. Going over servers and security issues and solutions. John took a bunch of good notes. Brandon and John have copies of the notes on their local computers. We talked about Fireeye and incident responses, Solar Winds, "pen tests" - penetration and vulnerability testing, server challenges, code challenges, and simple steps that we can take to keep refining the process.

Long story made short, hacking and hack attempts will not go away. We have to deal with them and make plans to prevent and handle that type of traffic. We talked about a number of other topics related to those same subjects. Here is a small list of other topics that were discussed: doing the best we can, supersizing some of the servers (assets and resources), poor passwords and upping those requirements, SQL injections, watching traffic patterns and trends, watching for abuse, tightening things up as we go, using the cf query param, firewall rules, safer code, and going to the next level.

We even got way out there and were talking about bot armies and having those bot armies pointed at certain targets and other crazy things that people do. Wild times.

Dealing with password security, length is one of the best pieces of security. We got into rainbow tables and reverse decoding of common passwords, etc. Wayne recommended that one of the safest passwords is a series of non connected words. He recommended that you go on a small drive and choose 3 to 4 words that you saw on your drive. Then use that as your password. It means something to you, you'll remember it, and it means nothing to someone trying to hack their way in. Anyways, nice meeting.

Random side note, Wayne, when asked how he is doing usually responds - something like - super fantastic. When asked about that, he said that years back he heard this talk on a positive attitude. As part of that talk, he got the idea to help control his own attitude which in turns helps others. Basically, why not just be happy and then pass it on. It's deeper than that, but I liked what he was saying. Good piece of advice. Why not just be happy!