Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - grimelog

#31
Found a solution that works. I just made separate VM, and route that VM through tor.
#32
Hmm, how often do ip ranges switch for websites? I'm trying to not access this site from a country they do not provide services too. I might have my account closed.

Is there a means of running a script on my computer that switches the endpoint the router uses when I access the site? How would I setup passwordless login from a single device on the network?
#33
I'm using Wireguard, and would like to set it up so I don't have to manually change my endpoint for regional content. I have one entrypoint, and two endpoints. Through firewall rules I'm forcing all traffic to go out through my VPN. Is there any means of forcing traffic for specific websites out through a specific endpoint?
#34
I just picked up a Deeper Network Mini for creating a node in a decentralized VPN service. I don't fully trust the device to not have anything malicious on it. I think I should probably be running some intrusion detection with it being on the network.

I'm not sure which lists to turn on. I just know turning everyone on is not recommended. Which ones should I be running? Are there any other steps I can take to protect myself in case this device has malicious code on it?

Ideally, I'd completely silo it off with a second internet connection, but that's not an option with my building.
#35
Had a bit of an excursion where I had to recover a router without login shell access from any users. To fix this I've added bash as a login shell for my admin user. Should I keep this separate from the admin I use for the gui, locally? Which login shell is best for security purposes? Is there any reason to keep gui and console admins separate?
#36
Odd, just had to boot into Windows, and I was able to login.

Wonder if the VPN crashed eventually.
#37
Can't get in through the gui as a change to a VPN setting locked me out. For the serial console I either have the wrong password, or the fact I disabled root is preventing me from logging in. My main administrator account does not have access through the serial console.

Is there any means of factory resetting the device?
#38
General Discussion / Configure manual outbound NAT rule
November 01, 2021, 04:24:05 PM
I have outbound NAT working for WireGuard; but, I also have a port providing wireless that I don't want using a VPN. If I use the automatically generated rules I can connect to the internet, (believe hybrid would work too) but I cannot get my manual rule working. How do I need to modify this to connect to the internet?

#39
I'm thinking in terms of the processes requesting resources. I still need to identify how the ads go through the firewall. I'll have to run Brave from the command line. I'll give more details in a bit.
#40
I'm using the Mullvad VPN and their privacy preserving DNS. Only issue is that leads to me not receiving Brave ads.  If I switch to just using my ISPs DNS I still receive the ads. Is there any means of using a different DNS server based on the source?
#41
Seems to have been an issue with the DNS nameserver, and Qubes needing manual settings. Configured the LAN to use Unbound, and it seems to have fixed everything.
#42
Yes, I did google it. I'm not looking for a plugin for running a node. I just want the firewall to let tor through with a rule. I'm also routing the traffic from Qubes through a Whonix VM. This way if my network gets compromised my PC is less likely to be compromised.

A plugin seems heavy handed for my use case. I want to understand more about routing through the firewall. I'd rather just setup a custom rule, as it seems more secure than adding a plugin with a ton of additional code.
#43
I have a Qubes system, which routes all internet traffic through whonix and tor to maintain privacy. Only problem is it's causing issues getting out of my firewall. How do I need to setup the firewall to let tor and whonix out, while not compromising the security of my firewall in the process?
#44
I have Mullvad and wireguard working properly. I'd like to add a socks5 proxy through them. Do I add that to the wireguard settings under endpoint? Do I need a socks5 plugin, or can I just set it up with a gateway configuration?
#45
Not seeing anything of that form. Must be the CK kernel. Must have not had the right modules loaded.