User Tools

Site Tools


projects:secure_ocf_webhosting

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
projects:secure_ocf_webhosting [2025/10/14 21:02] kuljitprojects:secure_ocf_webhosting [2025/10/21 21:42] (current) serrindipity
Line 79: Line 79:
 ===== Action Items ===== ===== Action Items =====
  
-====== Meeting Notes - 10/07 =======+===== Meeting Notes - 10/07 ======
  
 Setting up Docker: Setting up Docker:
Line 144: Line 144:
   * {{next_step_2}}   * {{next_step_2}}
   * {{next_step_3}}   * {{next_step_3}}
 +
 +
 +===== Meeting Notes - 10/21 ======
 +
 +Userdata volumes exist now, there's an open issue to add data to them. Current plan with 3 volumes:
 +
 +  - userdata1 is default - no plugins
 +  - userdata2 is good - plugins that are legit
 +  - userdata3 is malicious - as many plugins as we can find that are bad bad bad
 +
 +==== Assignments ====
 +
 +Whitelist Blacklist - big json file pushed of vulnerabilities
 +
 +Signature Detection - YARA
 +  * Some preset YARA Rules for detecting wordpress added
 +
 +Logging Aggregation
 +  * Alloy (replace Promtail)
 +  * apparently harder to teach than Promtail
 +  * need to write documentation for the tool
 +  * GrafanaLoki + Fluent Bit are current stack, may not even need alloy / promtail
 +  * infosession 10/22 9 am for GrafanaLoki (I would go but I have class :/ - JQ)
 +
 +Wordpress Site Scanning
 +  * probably not feasible: you only get 25 requests per API key
 +  * 
 +
 +===== Agenda =====
 +  - Infra changes
 +  - Issues
 +
 +===== Action Items =====
 +  - [ ] {{person}} to {{task_description}} by {{deadline}}
 +  - [ ] {{person}} to {{task_description}} by {{deadline}}
 +
 +===== Next Steps =====
 +  * {{next_step_1}}
 +  * {{next_step_2}}
 +  * {{next_step_3}}
 +
  
projects/secure_ocf_webhosting.txt · Last modified: by serrindipity