<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>RyanZhang&apos;s Blog</title><description>Open Knowledge - Open Future</description><link>https://fuwari.vercel.app/</link><language>en</language><item><title>2025 Year in Review</title><link>https://fuwari.vercel.app/posts/89951d9b-894f-49aa-b8e9-7eac6665e5b9/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/89951d9b-894f-49aa-b8e9-7eac6665e5b9/</guid><description>2025 was a year of growth, exhaustion, and distant horizons. I still love being an engineer, but I&apos;ve realized it&apos;s time to start growing for myself.</description><pubDate>Sat, 14 Feb 2026 12:29:00 GMT</pubDate><content:encoded>&lt;p&gt;Ideally, this summary should have been written on January 1st, 2026.&lt;/p&gt;
&lt;p&gt;However, at that time, I was in Melbourne, Australia, enjoying a short but much-needed vacation.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/368c38d58e1d4aaea2a448fc3567a959.jpg&quot; alt=&quot;kangaroo&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The sunshine, the sprawling lawns, and the unfamiliar yet quiet rhythm of the city made it hard to settle down and reflect on the past year. During those few days, I only managed to squeeze in some updates for my inspection tool, Sunchha (https://sunchha.bytesycn.com), and shared a brief introduction on my WeChat official account. The engagement was unexpectedly high, and I am deeply grateful for everyone’s attention and recognition.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://mp.weixin.qq.com/s/pU692dc_TerNFrNQUFEfxA&quot;&gt;Wechat：把巡检交给机器——Sunchha网络设备巡检工具&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Since I missed the New Year&apos;s Day summary, I decided to save it for the Lunar New Year.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Today is the last working day of the Year of the Snake. I am still at my desk, watching colleagues and friends head off for their holidays early. I feel a hint of envy, &lt;strong&gt;but as an engineer, once you choose this path, you must accept its reality—staying at the post is often the norm, not the exception.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;From Internship to Professional Identity&lt;/h2&gt;
&lt;p&gt;Graduating in July 2024, I stepped out of campus like many others—filled with a mix of idealism and passion.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/f5f55a5a8e844375adf95932288541fa.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Perhaps because the job market for my major was relatively stable, I had internships before graduating and smoothly transitioned into a role that genuinely interested me. My mentors recognized my potential and offered me more opportunities. Naturally, I began taking on many tasks that were technically beyond my original scope of responsibility.&lt;/p&gt;
&lt;p&gt;At the time, I seemed to thrive on that feeling of being &quot;needed.&quot;&lt;/p&gt;
&lt;p&gt;I still remember a network upgrade project during my internship. For a whole week, we started working at 6 PM right after the regular shift and continued until 10 PM. We replaced every single switch across a five-story office building. The decommissioned Cisco switches were piled so high they almost matched my height.&lt;/p&gt;
&lt;p&gt;Was it hard?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;I didn&apos;t think so—because it was a field I loved. Passion offsets exhaustion.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Transitioning from Networking to Security&lt;/h2&gt;
&lt;p&gt;After officially joining the workforce, I shifted from the Datacom (Data Communications) field I touched during my internship to becoming a Security Service Engineer.&lt;/p&gt;
&lt;p&gt;From late 2024 through the first half of 2025, I was involved in a diverse range of security service projects: Penetration Testing, Code Auditing, Risk Assessment, Major Event Support, Red/Blue Teaming (Attack &amp;amp; Defense Drills), Incident Response, and Phishing Simulations.&lt;/p&gt;
&lt;p&gt;I evolved from relying on off-the-shelf tools to writing my own functional modules, building phishing systems, and streamlining information gathering workflows.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/710c2ff1d07348cd8b9d5348f5b159e8.png&quot; alt=&quot;phishing code&quot; /&gt;&lt;/p&gt;
&lt;p&gt;While my technical skills grew, the more significant lesson was learning how to communicate with different stakeholders. Some client engineers are technically solid and highly efficient, while others require more patient explanations.&lt;/p&gt;
&lt;p&gt;I began to realize that while technical skill is the foundation, communication is a mandatory discipline for an engineer. Even now, I feel there is still much room for improvement.&lt;/p&gt;
&lt;h2&gt;First Encounter with Large-Scale Private Clouds&lt;/h2&gt;
&lt;p&gt;In the latter half of 2025, I began working on security and operations for large-scale Private Clouds.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/b18dfe1f412f464d9dc77935ebd81ccc.png&quot; alt=&quot;phishing code&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I started from scratch, learning cloud operations and workflows, eventually managing projects like cloud data sanitization. It was a year of rapid growth across multiple domains.&lt;/p&gt;
&lt;p&gt;Yet, it was also the year where it felt hardest to stay motivated.&lt;/p&gt;
&lt;p&gt;Promises were made and repeatedly unfulfilled, while the workload only increased. In the current economic climate, people often throw around the cynical meme: &quot;If you won&apos;t do it, plenty of others will.&quot; Perhaps there’s a grain of truth in that, but when effort goes unrecognized for too long, you start to ask: What is the point of persisting?&lt;/p&gt;
&lt;p&gt;Eventually, I came to a realization:&lt;/p&gt;
&lt;p&gt;It’s not about stopping the effort or &quot;lying flat&quot;—it’s about redirecting that effort toward a direction that truly belongs to you.&lt;/p&gt;
&lt;p&gt;Do your job well, but also look for the sky where you truly belong.&lt;/p&gt;
&lt;h2&gt;Re-examining the Self&lt;/h2&gt;
&lt;p&gt;I remember a mentor during my internship telling me he hoped that by the time I graduated, I would have a two-page resume filled with solid project experience.&lt;/p&gt;
&lt;p&gt;But upon graduation, my resume was still very &quot;clean.&quot;&lt;/p&gt;
&lt;p&gt;I don&apos;t like listing things I only have a superficial understanding of, nor am I willing to exaggerate my abilities. Perhaps this is the most basic tenet of being an engineer: seeking truth from facts. I used to look down on resumes that were fluffed up with buzzwords despite minimal actual knowledge.&lt;/p&gt;
&lt;p&gt;By the second half of 2025, I reorganized my experience. I included the projects I truly participated in, was responsible for, and deeply understood. Today, I can finally present a resume that meets my former mentor&apos;s expectations—without a drop of &quot;water&quot; (exaggeration).&lt;/p&gt;
&lt;p&gt;During the same period, I started focusing on my website and WeChat account. If the knowledge and experience I share can help even a few people, then it’s all worth it.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/ac4d124bfdb84c4797916bd88de66a45.png&quot; alt=&quot;bytesycn&quot; /&gt;&lt;/p&gt;
&lt;p&gt;In this era of rapid AI evolution, human learning speed will likely never catch up with the pace of model iteration.&lt;/p&gt;
&lt;p&gt;But don&apos;t forget—everything AI learns originates from the real experiences, sincere sharing, and continuous creativity left by humans on the internet.&lt;/p&gt;
&lt;p&gt;So, keep writing. Even if it’s slow, as long as it’s authentic, it has value.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;A Few Days in Melbourne&lt;/h2&gt;
&lt;p&gt;At the end of 2025, a senior family member fell ill. According to traditional Chinese values, I shouldn&apos;t have traveled far. However, knowing my job was about to change and such an opportunity might not come again, I booked the flight. Three days after the surgery, I flew to Melbourne.&lt;/p&gt;
&lt;p&gt;I stayed for six days, which was perhaps the happiest time of my 2025.&lt;/p&gt;
&lt;p&gt;I visited the University of Melbourne and took a photo in front of the Old Engineering Building.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/5cefda5857604f2dbfcc449d0992ed5a.jpg&quot; alt=&quot;University of Melbourne&quot; /&gt;&lt;/p&gt;
&lt;p&gt;During those days, I kept thinking: As engineers, we should use technology to create value, not drown in repetitive labor. Instead of passively reacting to problems, we should actively create tools.&lt;/p&gt;
&lt;p&gt;It was in those Melbourne mornings and evenings that I became more determined to refine my inspection system and develop more practical tool platforms.&lt;/p&gt;
&lt;p&gt;In the past, the barrier to entry for these things was high. But now, with CodeX, Claude, various AI coding assistants, and automated frameworks, the ecosystem is maturing.&lt;/p&gt;
&lt;p&gt;The world is moving much faster than we imagine.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;The Boundaries of Work&lt;/h2&gt;
&lt;p&gt;The most important thing I learned in 2025 wasn&apos;t a specific technology, but rather:&lt;/p&gt;
&lt;p&gt;Facing my own shortcomings, acknowledging my limitations, and growing within my boundaries.&lt;/p&gt;
&lt;p&gt;One shouldn&apos;t endlessly hoard tasks; everyone needs personal space.&lt;/p&gt;
&lt;p&gt;Technology is a career, but it shouldn&apos;t be the entirety of one&apos;s life.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Looking Ahead to the Year of the Horse&lt;/h2&gt;
&lt;p&gt;2025 was a year of growth, anxiety, exhaustion, and distant horizons.&lt;/p&gt;
&lt;p&gt;If I were to summarize this year:&lt;/p&gt;
&lt;p&gt;Having experienced so much, I still love being an engineer, but I&apos;ve realized it&apos;s time to start growing for myself.&lt;/p&gt;
&lt;p&gt;Wishing everyone a Happy New Year for 2026, the Year of the Horse. May your families be happy, and may your paths be smooth and safe.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2026/02/79371fe1d7a643c484fe56eb823c4dc1.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
</content:encoded></item><item><title>How to Conduct a Phishing Simulation Exercise</title><link>https://fuwari.vercel.app/posts/a40396ba-3375-4356-b866-bffb0929e8cb/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/a40396ba-3375-4356-b866-bffb0929e8cb/</guid><description>Under the premise of legal authorization, phishing simulations are a vital means of assessing an organization&apos;s security awareness and defensive capabilities. This article systematically outlines the methodology and practical approach for a standardized, safe, and controlled phishing exercise conducted in 2025, covering information gathering, attack surface analysis, site cloning, platform selection, and data collection.</description><pubDate>Fri, 19 Dec 2025 18:30:00 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Under the premise of legal authorization, phishing simulations are a vital means of assessing an organization&apos;s security awareness and defensive capabilities. This article systematically outlines the methodology and practical approach for a standardized, safe, and controlled phishing exercise conducted in 2025, covering information gathering, attack surface analysis, site cloning, platform selection, and data collection.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Legal Disclaimer&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;The content of this article is intended solely for legal and compliant cybersecurity learning, research, and the enhancement of defensive capabilities. All operations, examples, and technical methods are strictly limited to environments where explicit authorization has been obtained, including but not limited to personal assets, owned systems, lab environments, or target systems with written consent.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It is strictly forbidden to use any techniques discussed herein for unauthorized penetration testing, malicious attacks, data theft, actual phishing, system disruption, or any other illegal activities.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The user assumes all legal liabilities, financial losses, and other consequences arising from the violation of laws or the use of these techniques beyond the scope of authorization. The author and the publishing platform assume no responsibility or association with such actions.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you cannot confirm whether the target environment is authorized, please cease all related operations immediately.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Types of Phishing&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Social Phishing&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Attackers reach out to target employees via commonly used social platforms (IM tools, social media, etc.), impersonating colleagues, partners, or trusted entities. They induce victims to click malicious links, visit fraudulent pages, or download malicious attachments.
This type of phishing relies on trust relationships, fabricated emergencies, or incentives. It is highly stealthy and deceptive, often resulting in account compromise or endpoint infection before the victim can verify the sender&apos;s identity.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Email Phishing (Spear Phishing)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Email phishing is the most prevalent form of social engineering. Attackers send emails disguised as official notifications, business correspondence, financial statements, system alerts, or HR documents.
These emails are often highly sophisticated, mimicking real business templates, writing styles, and sender addresses. They often leverage time sensitivity (e.g., &quot;Urgent Action Required&quot; or &quot;Account Suspension Imminent&quot;) to bypass the victim&apos;s vigilance.&lt;/p&gt;
&lt;h2&gt;How to Execute a Phishing Simulation&lt;/h2&gt;
&lt;p&gt;In professional security services, phishing exercises evaluate an organization’s resilience against social engineering. Since clients may not always provide a complete user list, the process must begin with Attack Surface Analysis.&lt;/p&gt;
&lt;h3&gt;I. Information Gathering (Attack Surface Analysis)&lt;/h3&gt;
&lt;p&gt;Without relying on internal client data, one can utilize &lt;strong&gt;Open Source Intelligence (OSINT)&lt;/strong&gt; to analyze the organization&apos;s public exposure:&lt;/p&gt;
&lt;h4&gt;(1) Search Engines &amp;amp; Public Records&lt;/h4&gt;
&lt;p&gt;Search for entity names, public notices, press releases, and official websites to identify:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Publicly exposed email addresses (e.g., info@, hr@).&lt;/li&gt;
&lt;li&gt;Contact numbers and duty desk lines.&lt;/li&gt;
&lt;li&gt;Combinations of employee names, titles, and contact info.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;(2) Corporate Intelligence Platforms&lt;/h4&gt;
&lt;p&gt;Using platforms like D&amp;amp;B, Crunchbase, or local corporate registries to assess:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Publicly registered contact details.&lt;/li&gt;
&lt;li&gt;Contact persons listed in bidding and tender announcements.&lt;/li&gt;
&lt;li&gt;Partner and supply chain relationships (potential lateral risk).&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;(3) Recruitment &amp;amp; Professional Networks&lt;/h4&gt;
&lt;p&gt;Job boards and professional social networks often inadvertently expose:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;HR/IT/Administrative roles.&lt;/li&gt;
&lt;li&gt;Organizational structures and department names.&lt;/li&gt;
&lt;li&gt;Employee work email naming conventions (e.g., firstname.lastname@company.com).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Site Cloning &amp;amp; Content Risk Assessment&lt;/h3&gt;
&lt;p&gt;A key question in security drills is: Can employees identify a &quot;high-fidelity&quot; fraudulent page? The focus is not on the &quot;how-to&quot; of cloning, but on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Domain Recognition: Can users spot a typo-squatted domain?&lt;/li&gt;
&lt;li&gt;Email Security Policies: Are SPF, DKIM, and DMARC enforced?&lt;/li&gt;
&lt;li&gt;Environmental Cues: Do employees notice abnormal redirects, SSL certificate warnings, or URL discrepancies?&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Developing Phishing Pages/Software&lt;/h3&gt;
&lt;p&gt;In 2025, cloning web pages is technically trivial. One of the simplest ways to mimic an application or portal is by saving the webpage directly via the browser (&lt;code&gt;Ctrl+S&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;However, this method often only saves the primary HTML. CSS, JavaScript, and images often still point to the original site or a third-party CDN. Common issues with this &quot;simple&quot; approach include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Resource loading failures due to relative paths.&lt;/li&gt;
&lt;li&gt;CORS (Cross-Origin Resource Sharing) policies on the original site blocking assets (403 Forbidden).&lt;/li&gt;
&lt;li&gt;Broken layouts and non-functional interactive features.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Therefore, a proper clone requires downloading all dependencies locally and correcting reference paths to ensure the page renders correctly in an isolated environment.&lt;/p&gt;
&lt;h3&gt;Phishing Platforms&lt;/h3&gt;
&lt;p&gt;Once the target list and cloned pages are ready, you need a data collection and management platform. Mature open-source tools like &lt;a href=&quot;https://getgophish.com&quot;&gt;Gophish&lt;/a&gt; are widely used.&lt;/p&gt;
&lt;p&gt;However, off-the-shelf platforms often have limitations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Inability to export raw malicious URLs for manual delivery.&lt;/li&gt;
&lt;li&gt;Rigid data fields or collection logic.&lt;/li&gt;
&lt;li&gt;Limited customization for complex workflows.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For highly customized or sophisticated simulations, developers often perform secondary development on existing platforms or build lightweight, proprietary collection systems. Technically, a web-based simulation is simply the recording and analysis of HTTP request behaviors and data flow.&lt;/p&gt;
&lt;h3&gt;Sample Collection Code (Go)&lt;/h3&gt;
&lt;p&gt;The following is a lightweight collector implemented in Go using the Gin framework. It handles UUID-based victim identification and logs data to a local file.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;package main

import (
	&quot;encoding/json&quot;
	&quot;fmt&quot;
	&quot;net&quot;
	&quot;net/http&quot;
	&quot;os&quot;
	&quot;strings&quot;
	&quot;time&quot;

	&quot;github.com/gin-gonic/gin&quot;
)

// LoginRequest defines the expected JSON structure
type LoginRequest struct {
	Username  string `json:&quot;username&quot; binding:&quot;required&quot;`
	Password  string `json:&quot;password&quot; binding:&quot;required&quot;`
	Timestamp int64  `json:&quot;timestamp&quot; binding:&quot;required&quot;`
	UUID      string `json:&quot;uuid&quot; binding:&quot;required&quot;`
}

const fixedAuthBase64 = &quot;mysecretkey&quot;

// isMobileUA detects mobile devices based on User-Agent
func isMobileUA(ua string) bool {
	ua = strings.ToLower(ua)
	mobileKeywords := []string{&quot;android&quot;, &quot;iphone&quot;, &quot;ipod&quot;, &quot;ipad&quot;, &quot;windows phone&quot;, &quot;mobile&quot;}
	for _, kw := range mobileKeywords {
		if strings.Contains(ua, kw) {
			return true
		}
	}
	return false
}

func main() {
	r := gin.Default()
	r.LoadHTMLGlob(&quot;templates/*&quot;)

	r.GET(&quot;/page/:uuid&quot;, func(c *gin.Context) {
		uuid := c.Param(&quot;uuid&quot;)
		userAgent := c.Request.UserAgent()
		isMobile := isMobileUA(userAgent)
		templateName := &quot;desktop.html&quot;
		if isMobile {
			templateName = &quot;mobile.html&quot;
		}
		c.HTML(http.StatusOK, templateName, gin.H{&quot;UUID&quot;: uuid})
	})

	r.POST(&quot;/api/user&quot;, loginHandler)
	r.Run(&quot;:30494&quot;)
}

func loginHandler(c *gin.Context) {
	// 1. Auth Header Validation
	if c.GetHeader(&quot;Auth&quot;) != fixedAuthBase64 {
		c.JSON(http.StatusUnauthorized, gin.H{&quot;code&quot;: 401, &quot;message&quot;: &quot;Unauthorized&quot;})
		return
	}

	// 2. Parse Request Body
	var req LoginRequest
	if err := c.ShouldBindJSON(&amp;amp;req); err != nil {
		c.JSON(http.StatusBadRequest, gin.H{&quot;code&quot;: 400, &quot;message&quot;: &quot;Invalid Body&quot;})
		return
	}

	// 3. Metadata Collection
	clientIP := getClientIP(c.Request)
	userAgent := c.Request.UserAgent()
	serverTime := time.Now().Format(time.RFC3339)

	// 4. Log Construction
	requestBody, _ := json.MarshalIndent(req, &quot;&quot;, &quot;  &quot;)
	logEntry := fmt.Sprintf(
		&quot;===== Request Log =====\nIP: %s\nUA: %s\nTime: %s\nBody:%s\n========================\n\n&quot;,
		clientIP, userAgent, serverTime, string(requestBody),
	)

	// 5. File Persistence
	_ = appendToLogFile(&quot;./api_logs.txt&quot;, logEntry)

	c.JSON(http.StatusOK, gin.H{&quot;code&quot;: 200, &quot;message&quot;: &quot;Logged successfully&quot;})
}

func getClientIP(r *http.Request) string {
	forwardedFor := r.Header.Get(&quot;X-Forwarded-For&quot;)
	if forwardedFor != &quot;&quot; {
		ips := strings.Split(forwardedFor, &quot;,&quot;)
		return strings.TrimSpace(ips[0])
	}
	ip, _, _ := net.SplitHostPort(r.RemoteAddr)
	return ip
}

func appendToLogFile(filePath, content string) error {
	file, err := os.OpenFile(filePath, os.O_APPEND|os.O_CREATE|os.O_WRONLY, 0644)
	if err != nil {
		return err
	}
	defer file.Close()
	_, err = file.WriteString(content)
	return err
}
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/12/19/9b9d8103-8f9f-41e4-b30f-f97aab238f68.png&quot; alt=&quot;Access Logs&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/12/19/c42aa949-1154-49f9-86ee-fad3d6db548b.png&quot; alt=&quot;Collect Info&quot; /&gt;&lt;/p&gt;
</content:encoded></item><item><title>(Cybersecurity Tools Vol.2) testssl — Comprehensive SSL/TLS Security Testing for Your Site</title><link>https://fuwari.vercel.app/posts/562206e0-38e7-4359-bb6d-faacf9b687de/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/562206e0-38e7-4359-bb6d-faacf9b687de/</guid><description>Using testssl.sh to perform comprehensive compliance and security audits on site SSL/TLS configurations.</description><pubDate>Mon, 15 Dec 2025 18:00:00 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;If you have visited my homepage, you likely know that I am currently a cybersecurity professional.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;During recent vulnerability scanning and security hardening tasks, I observed that a &lt;strong&gt;significant number of high-frequency vulnerabilities are concentrated in SSL/TLS configurations&lt;/strong&gt;. These issues include weak cipher suites, deprecated protocol versions, and incomplete certificate chains.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Such issues present two challenges: &lt;strong&gt;high manual verification costs&lt;/strong&gt; and low efficiency, as re-verifying a fix often requires re-running a full vulnerability scan.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;To address this, I have integrated &lt;strong&gt;testssl.sh&lt;/strong&gt; into my workflow for rapid, comprehensive, and repeatable SSL/TLS configuration audits.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;About testssl.sh&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;testssl.sh&lt;/strong&gt;is an open-source SSL/TLS security auditing tool designed to evaluate the security configuration of a server at the TLS layer. Key assessment areas include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Supported SSL/TLS protocol versions.&lt;/li&gt;
&lt;li&gt;Security and strength of Cipher Suites.&lt;/li&gt;
&lt;li&gt;Common TLS vulnerabilities (e.g., BEAST, POODLE, Heartbleed, etc.).&lt;/li&gt;
&lt;li&gt;Certificate validity and Chain of Trust integrity.&lt;/li&gt;
&lt;li&gt;Compliance with mainstream security best practices.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The tool does not require any agent deployment on the target server. It is executed locally as a script, making it ideal for security testing, routine inspections, and remediation verification.&lt;/p&gt;
&lt;h2&gt;Common Commands&lt;/h2&gt;
&lt;h3&gt;1. Outputting SSL/TLS Compliance Results to Console&lt;/h3&gt;
&lt;p&gt;Suitable for quick troubleshooting of site TLS configuration issues. Results are streamed directly to the terminal:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;./testssl.sh -p bytesycn.cn
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/12/16/9e1c25bc-5ac7-4d8b-b133-c2e4afe59139.webp&quot; alt=&quot;Compliance Check Results&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Parameter Explanation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;-p&lt;/code&gt;: Displays the protocols and port information supported by the target.&lt;/li&gt;
&lt;li&gt;The tool targets port 443 by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;2. Generating an HTML Report (Recommended)&lt;/h3&gt;
&lt;p&gt;In professional environments, generating an HTML report is highly recommended for documentation, comparing &quot;before and after&quot; remediation states, or as evidence for security audits.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;./testssl.sh --warnings=batch --html bytesycn.cn
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/12/16/d2c272d6-6ebe-4d65-a740-197a83b5d8ac.webp&quot; alt=&quot;Generating html report&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Parameter Explanation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;--warnings=batch&lt;/code&gt;: Displays warnings in batch mode to avoid interactive interruptions.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;--html&lt;/code&gt;: Generates a full security audit report in HTML format.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;📄 检测报告示例：
&lt;a href=&quot;https://oss-southeast-1.bytesycn.com/files/documents/bytesycn.cn_p443-20251216-1601.html&quot;&gt;bytesycn.cn testssl Audit Report Demo&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Usage Best Practices&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Run &lt;code&gt;testssl&lt;/code&gt; both before and after TLS configuration hardening to compare changes.&lt;/li&gt;
&lt;li&gt;Use this tool in conjunction with adjustments to Nginx/Apache SSL configurations for optimal results.&lt;/li&gt;
&lt;li&gt;Integrate it into daily security inspections or CI/CD pipelines for periodic automated testing.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;testssl.sh&lt;/code&gt; is a lightweight, professional, and highly practical SSL/TLS security auditing tool, specifically suited for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cybersecurity Practitioners&lt;/li&gt;
&lt;li&gt;Operations / SRE Engineers&lt;/li&gt;
&lt;li&gt;Personal Site Owners with high security requirements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you find yourself repeatedly dealing with TLS vulnerability remediation, adding testssl to your toolkit will save you significant time and effort.&lt;/p&gt;
&lt;p&gt;🔗 Related Links:&lt;/p&gt;
&lt;p&gt;[1] testssl Project Repository: &lt;a href=&quot;https://github.com/testssl/testssl.sh&quot;&gt;https://github.com/testssl/testssl.sh&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2] testssl Official Website: &lt;a href=&quot;https://testssl.sh&quot;&gt;https://testssl.sh&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>From Zero to Production:An Engineer&apos;s Journal on Building a Mini-IDC</title><link>https://fuwari.vercel.app/posts/e4d4352e-3398-43e0-a3b6-1e0576f28517/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/e4d4352e-3398-43e0-a3b6-1e0576f28517/</guid><description>A deep dive into a &apos;wild data center&apos; architecture—built with decommissioned servers, 10G fiber optics, enterprise-grade broadband, and custom tunnels. For the past six months, it has reliably hosted automated backups, off-site NAS synchronization, databases, and code repositories, proving that high availability is achievable on a budget.</description><pubDate>Mon, 17 Nov 2025 22:55:26 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Disclaimer: This article is for technical sharing purposes only and does not involve any illegal activities.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I’ve wanted to write this for a long time but couldn&apos;t find a window in my schedule. This year, some friends and I transformed a self-built house in a small rural town into a &quot;Pseudo-IDC.&quot; From server racks and dedicated AC units to enterprise broadband and UPS backups, we’ve got it all. It may not be a Tier 4 facility, but it looks more professional than many SME server rooms. It has been running stably for over half a year.&lt;/p&gt;
&lt;p&gt;If you are looking to build your own &quot;homelab-turned-IDC,&quot; let&apos;s exchange ideas—maybe I can help you skip a few pitfalls.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/124gwr0.jpg&quot; alt=&quot;Initial state&quot; /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Ground Rules (The &quot;Shield&quot; Section)&lt;/h2&gt;
&lt;p&gt;Do not use residential broadband for PCDN or for-profit traffic hosting.&lt;/p&gt;
&lt;p&gt;Do not use the network for any unauthorized Penetration Testing or attacks.&lt;/p&gt;
&lt;p&gt;Secure your devices to prevent them from becoming Jump Servers for attackers.&lt;/p&gt;
&lt;p&gt;The first rule is the ISP&apos;s bottom line; the latter two are to keep you on the right side of the law.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Remember: Cybersecurity is built by and for the people—there is no such thing as a small security oversight.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Requirement Analysis&lt;/h2&gt;
&lt;p&gt;&quot;Data Center&quot; is an abstract term. A Linux box in your bedroom is a data center; a row of 42U racks is also a data center. Our project is a &quot;Pseudo-IDC&quot; positioned in the middle, featuring:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Redundant Network Outbound&lt;/li&gt;
&lt;li&gt;Sufficient Compute &amp;amp; Storage Resources&lt;/li&gt;
&lt;li&gt;Remote Office Nodes&lt;/li&gt;
&lt;li&gt;7×24 Availability&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Current assets: Rack, AC, UPS, and Enterprise Broadband—a complete basic ecosystem.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/123rtvh.jpg&quot; alt=&quot;CR&quot; /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Build Process&lt;/h2&gt;
&lt;h3&gt;1. Server Infrastructure&lt;/h3&gt;
&lt;p&gt;Our fleet consists entirely of decommissioned Dell PowerEdge servers. Dell is the choice for a reason: as a global giant, their hardware is cost-effective and documentation is easily accessible. We previously tried the Huawei 2288Hv3—which was even cheaper—but Huawei’s documentation is restricted to authorized partners, making it &quot;wild-IDC-unfriendly.&quot;&lt;/p&gt;
&lt;p&gt;Example Node Configuration:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CPU: 2 × Intel Xeon E5-2680 v4 (2.4GHz, 14C/28T)&lt;/li&gt;
&lt;li&gt;RAM: 320GB DDR4 2133MHz REG ECC&lt;/li&gt;
&lt;li&gt;Storage: 6 × 4TB SAS&lt;/li&gt;
&lt;li&gt;Networking: 4 × 10Gbps SFP+&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/121zgrz.png&quot; alt=&quot;Virtualization Platform&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;2. Internal Network (Intranet)&lt;/h3&gt;
&lt;p&gt;Apart from the Out-of-Band (OOB) Management which still uses 1Gbps RJ45, all other links have been upgraded to OM3 Multi-mode Fiber. With dual-port Link Aggregation (LACP), we hit a theoretical throughput of 20Gbps.
For storage nodes, we utilized 40Gbps QSFP links. We initially planned for RoCE (RDMA over Converged Ethernet), but during debugging, we found our core switch would crash whenever Jumbo Frames were enabled. We’ve reverted to standard iSCSI for now.&lt;/p&gt;
&lt;p&gt;Core Switch: Cisco Nexus 3000 (N3K) Series&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;48 × 10Gbps SFP+&lt;/li&gt;
&lt;li&gt;4 × 40Gbps QSFP&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/12242te.png&quot; alt=&quot;Core Switch&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Nearly half the ports are occupied. We used a mix of Intel SFP+ modules sourced second-hand—definitely a &quot;budget&quot; vibe, but as long as the packets flow, we’re happy.&lt;/p&gt;
&lt;h3&gt;3. Network Outbound&lt;/h3&gt;
&lt;p&gt;Static Public IPv4 addresses are a rare commodity in residential settings.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;China Telecom: Offers dynamic IPv4 with the best quality, but expensive.&lt;/li&gt;
&lt;li&gt;China Unicom: Offers dynamic IPv4 at a reasonable price.&lt;/li&gt;
&lt;li&gt;China Mobile: Massive &quot;Carrier-Grade NAT&quot; (but cheap/free).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Luckily, my friend’s family business provided an Enterprise Line (300Mbps Up / 1000Mbps Down), with residential broadband as a backup. For remote access, we use DDNS (via the open-source ddns-go). Compared to writing custom scripts back in 2018, the ecosystem has truly evolved.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/1228ddb.png&quot; alt=&quot;Network Topology Diagram&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;4. Remote Connectivity: VPN Tunnels&lt;/h3&gt;
&lt;p&gt;Since the facility is nearly 100km away, 24/7 on-site presence is impossible. We established several encrypted tunnels for remote management.
This setup involves Network Topology, VPN Protocols, Port Forwarding, and SDN (Software-Defined Networking). I’ll write a dedicated deep-dive tutorial on this later.&lt;/p&gt;
&lt;p&gt;Currently, the IDC supports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automated daily backups for my Cloud VPS.&lt;/li&gt;
&lt;li&gt;Off-site data synchronization for my home NAS.&lt;/li&gt;
&lt;li&gt;Multiple Database instances.&lt;/li&gt;
&lt;li&gt;Local Code Repositories (Git).&lt;/li&gt;
&lt;li&gt;Remote Desktop for work.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/121i1p4.png&quot; alt=&quot;Cloud server auto backup&quot; /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Monitoring &amp;amp; Operations&lt;/h2&gt;
&lt;p&gt;The &quot;Wild IDC&quot; is now largely automated.
Environmental Monitoring: We leverage the Xiaomi/Mi Home ecosystem (Temperature, Humidity, Power, and Cameras). It’s surprisingly robust for the price.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/122r09y.png&quot; alt=&quot;Mi Home&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Server Monitoring: We migrated from Zabbix to Beszel. Zabbix was too &quot;heavy&quot; for a non-professional data center. For network uptime, I wrote a small heartbeat script that pushes alerts via Feishu (Lark) webhooks if the link drops.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/122m9kg.png&quot; alt=&quot;Lark&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Overall, we’ve pieced together a stable and maintainable monitoring system at minimal cost.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/17/123wd25.jpg&quot; alt=&quot;Server Rack&quot; /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;End&lt;/h2&gt;
&lt;p&gt;🫶 The reason for doing this is simple: Passion drives everything.
As for the future, perhaps this passion will quietly bloom into something even more practical.&lt;/p&gt;
</content:encoded></item><item><title>Weekend Getaway in Kinmen</title><link>https://fuwari.vercel.app/posts/60b41694-e125-4b05-bf54-7e7c2a35629e/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/60b41694-e125-4b05-bf54-7e7c2a35629e/</guid><description>Not to escape life, but to rediscover its warmth.</description><pubDate>Mon, 03 Nov 2025 19:56:12 GMT</pubDate><content:encoded>&lt;p&gt;I had planned to visit Kinmen for a long time. Early this year, I had my travel permits and endorsements ready, but a few demanding projects kept me tied down. I procrastinated until the endorsements eventually expired.&lt;/p&gt;
&lt;p&gt;One day in September, on a sudden whim, I drove to Wutong Ferry Terminal to renew them. After all, Kinmen is only a 20-minute ferry ride from Xiamen—so close it feels like a &quot;distant land&quot; just across a river. I managed to snag a standby ticket during the National Day holiday and finally set off. I intended to have a &quot;Zen-like&quot; relaxed trip, but the moment I stepped onto the island, my &quot;lone wolf&quot; persona reverted right back to &quot;Special Forces&quot; mode (intensive sightseeing).&lt;/p&gt;
&lt;p&gt;Since I didn’t take the earliest ferry, it was already noon by the time I dropped my luggage at the guesthouse. A colleague once warned me: &quot;In Kinmen, arrive on the earliest boat and leave on the last.&quot; I did book the last return ferry, but if I had chosen the earliest arrival, I probably would have had to wake up at 3 or 4 AM to pack.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzwws7.jpg&quot; alt=&quot;Shuitou Pier, Kinmen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Following the guesthouse owner&apos;s recommendation, my first meal was the local Kinmen beef noodles, followed by 50 Lan bubble tea and Monga fried chicken—all staples of the local food scene.&lt;/p&gt;
&lt;p&gt;In the past, I rarely sat down for proper meals while traveling. I was like a photographer on a deadline, &quot;checking off&quot; one destination after another. Whether in Wuhan, Changsha, or Japan, I was merely an executor on a &quot;scenic spot assembly line.&quot; It wasn&apos;t until last year in Dotonbori, Osaka, while waiting two hours in line for a bowl of ramen, that it finally clicked:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Travel shouldn&apos;t just be about the scenery; it should be about the flavors, the tempo, and becoming a part of the local life.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzxoiw.jpg&quot; alt=&quot;50 Lan Bubble Tea&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The first day was a textbook &quot;Special Forces&quot; itinerary: Chen Jinglan Western-style House → Ever Rich Duty Free → Livestock Research Institute → Juguang Tower → Model Street. It was non-stop.&lt;/p&gt;
&lt;p&gt;I had seen a cute little otter plushie on Xiaohongshu and wanted to buy one as a backpack charm for my sister. I scoured several shops on Model Street that evening, but they were all out of stock—the only minor regret of the trip.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzy6mo.jpg&quot; alt=&quot;Otters Around — Please Watch Out!&quot; /&gt;&lt;/p&gt;
&lt;p&gt;At night, the streets of Kinmen were nearly deserted; the sound of the wind replaced the chatter of people. Looking across the water, the CBD of Guanyinshan in Xiamen was brilliantly lit. It’s hard not to feel the weight of the contrast, but looking at this quiet little island, I thought to myself: the people in Kinmen must have their own kind of happiness.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzxd18.jpg&quot; alt=&quot;Overlooking Guanyinshan, Xiamen from Juguang Tower (Daytime)&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The wind at night was so strong it made the windows rattle incessantly. I barely slept. At 5 AM, I simply got up, hopped on an electric scooter, and rode to the nearest FamilyMart. I ordered a coffee and sat by the window. That moment reminded me of a scene from last autumn, watching fallen leaves outside a Starbucks near the Kyoto Kaikan. I realized then that &quot;unplugging&quot; feels exactly like this—the moment your heart finds stillness in the early morning of a foreign place.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzvo6n.jpg&quot; alt=&quot;6 AM by the Window at FamilyMart&quot; /&gt;&lt;/p&gt;
&lt;p&gt;On the second day, I visited National Quemoy University, Shuitou Village, and the Kinmen Bridge. I’ve noticed a habit of mine—whenever I visit a city, I always wander through the local university. Wuhan University, Hunan University, Kyoto University... perhaps we long most for what we feel we lack.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzvas2.jpg&quot; alt=&quot;National Quemoy University&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Around 10 AM, while standing by the Kinmen Bridge, I received a call from the guesthouse owner. He told me that ferry services would be suspended after 2:30 PM due to weather.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzw7j7.jpg&quot; alt=&quot;Kinmen Bridge&quot; /&gt;&lt;/p&gt;
&lt;p&gt;I had a ticket for the very last boat, so I had to rush back to the pier immediately to try my luck. When I got back to the guesthouse, the staff was already packed and ready to escort me to the pier, but I was still waiting for the owner to return with two bottles of his private-label Kinmen Kaoliang liquor.&lt;/p&gt;
&lt;p&gt;When the owner finally arrived, he laughed and said, &quot;You’re really something! The staff was ready to take you away, and here you are still waiting for me to bring the booze.&quot;&lt;/p&gt;
&lt;p&gt;In the end, thanks to the help of a lady staying at the same guesthouse who was also heading back to Xiamen, I successfully secured a standby spot on an earlier ferry. If I hadn&apos;t made it, I might have been stranded in Kinmen for another three or four days.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzwtzc.jpg&quot; alt=&quot;Crowds at Shuitou Pier, Kinmen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The trip to Kinmen was actually two weeks ago. My procrastination kicked in late, but the memories remain fresh. After working for so long on various projects and reports, even a brief escape is a form of healing.&lt;/p&gt;
&lt;p&gt;Whether it’s a high-intensity &quot;Special Forces&quot; trek or a &quot;Zen-like&quot; slow life, the meaning of travel likely lies in this: allowing yourself to temporarily step out of the inertia of daily life and take a breath of fresh air.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Work is a necessity, but so is living.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/yzxbmb.jpg&quot; alt=&quot;Sunset in Kinmen&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PS: More photos of Kinmen are available in my &lt;a href=&quot;https://moments.bytesycn.com/dist&quot;&gt;Moments&lt;/a&gt; section.&lt;/strong&gt;&lt;/p&gt;
</content:encoded></item><item><title>(Cybersecurity Training Vol.1)Security in the Era of Artificial Intelligence</title><link>https://fuwari.vercel.app/posts/8eb41356-8146-4c6a-aa07-c3d7499fe53a/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/8eb41356-8146-4c6a-aa07-c3d7499fe53a/</guid><description>Training is a cornerstone of the cybersecurity industry. Over time, I have developed a wide range of training presentations, stemming from both professional projects and personal interests. Guided by the principle &apos;Originate from work, excel through sharing,&apos; I believe that knowledge should not be kept in isolation. I am launching this series to publicly share my PPTs, hoping to support your learning journey.</description><pubDate>Mon, 03 Nov 2025 12:53:38 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Training is a vital component of cybersecurity. I have accumulated numerous training presentations over the years, reflecting both my professional output and my personal technical pursuits.&amp;lt;/br&amp;gt;
I firmly believe in the philosophy: &quot;Knowledge originates from practice but reaches excellence through sharing.&quot; Information should not be hidden away; only open exchange can drive the collective progress of both individuals and the industry. Therefore, I have decided to launch this series to share my original presentation decks, with the hope of facilitating your professional development.&amp;lt;/br&amp;gt;
I also invite you to join this initiative: if you have materials (such as PDFs, PPTs, or Word documents) that you are willing to share, please reach out via the WeChat Official Account or email listed at the end of this article. It would be an honor to feature your content here as we build an open-access knowledge base together.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;I. PPT Preview&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwxsl4.png&quot; alt=&quot;page-1&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwxwy0.png&quot; alt=&quot;page-2&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwy1ft.png&quot; alt=&quot;page-3&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwy06v.png&quot; alt=&quot;page-4&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwy6hp.png&quot; alt=&quot;page-5&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwy80x.png&quot; alt=&quot;page-6&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwybf5.png&quot; alt=&quot;page-7&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwydxt.png&quot; alt=&quot;page-8&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyg0m.png&quot; alt=&quot;page-9&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyfg7.png&quot; alt=&quot;page-10&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwylly.png&quot; alt=&quot;page-11&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyrbh.png&quot; alt=&quot;page-12&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwytpk.png&quot; alt=&quot;page-13&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwytcz.png&quot; alt=&quot;page-14&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyuyy.png&quot; alt=&quot;page-15&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyyf3.png&quot; alt=&quot;page-16&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwyw9t.png&quot; alt=&quot;page-17&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwz2ku.png&quot; alt=&quot;page-18&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwz7yk.png&quot; alt=&quot;page-19&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwz4fr.png&quot; alt=&quot;page-20&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwzfeq.png&quot; alt=&quot;page-21&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/11/03/jwzd0c.png&quot; alt=&quot;page-22&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;II. Download Links&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;PDF Version:&lt;/strong&gt;
https://oss-southeast-1.bytesycn.com/files/cyber-security/documents/b15c1d41-64a5-4466-82ed-ae72f36c99eb.pdf&lt;/p&gt;
</content:encoded></item><item><title>Information Leakage — A Responsibility Software Vendors Must Shoulder</title><link>https://fuwari.vercel.app/posts/ac794dce-0ff0-48b0-a6e5-0c9fa26380a0/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/ac794dce-0ff0-48b0-a6e5-0c9fa26380a0/</guid><description>Behind the frequent occurrence of information leaks lies a continuous blurring of privacy boundaries. Developer negligence, institutional apathy, and user compromise weave a &apos;naked&apos; digital world. Security has long ceased to be a purely technical issue.</description><pubDate>Thu, 16 Oct 2025 19:15:56 GMT</pubDate><content:encoded>&lt;p&gt;In my experience conducting penetration tests, I’ve observed an awkward phenomenon.&lt;/p&gt;
&lt;p&gt;Vulnerabilities leading to information leakage have become almost commonplace. It’s as if an application doesn&apos;t feel &quot;legitimately launched&quot; these days unless it has a few data exposure issues under its belt.&lt;/p&gt;
&lt;p&gt;However, why must information leakage—a problem that should theoretically be mitigated during the development phase—always wait until a system is in production to be discovered?&lt;/p&gt;
&lt;p&gt;During university, we churned out one course project after another, transitioning from C to Java and then to Python. Eventually, I realized that the essence of all software boils down to CRUD operations (Create, Read, Update, Delete) on a database.&lt;/p&gt;
&lt;p&gt;The only real difference between a programmer and an average user is that one interacts with a dry SQL console and JSON interfaces, while the other clicks a mouse on a polished Graphical User Interface (GUI).&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/16/qglt9x.png&quot; alt=&quot;MongoDB&quot; /&gt;&lt;/p&gt;
&lt;p&gt;For many &quot;pseudo-programmers&quot; in college, seeing passwords transmitted in plaintext or ID numbers hardcoded into scripts was business as usual.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security? Hardly anyone mentioned it. The guiding principle was: &quot;As long as it runs, it’s fine.&quot;&lt;/strong&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Privacy vs. Convenience: The Famous Paradox&lt;/h2&gt;
&lt;p&gt;Years ago, a certain CEO made a controversial statement:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&quot;Chinese people are more open about privacy. If they can exchange privacy for convenience, safety, or efficiency, they are often willing to do so.&quot;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;There is some truth to this, but it is equally tragic.&lt;/p&gt;
&lt;p&gt;Two or three years ago, while I was still a student, the local police station near my university required us to register for anti-fraud information. To my shock, the link provided led to a site using &lt;strong&gt;HTTP (Plaintext Transmission)&lt;/strong&gt; without SSL encryption—yet the form required sensitive data like ID numbers.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/16/qhcbu8.png&quot; alt=&quot;SSL&quot; /&gt;&lt;/p&gt;
&lt;p&gt;In other words, had I submitted that data over the campus network, any administrator with access to network probes could have intercepted my sensitive information in cleartext.&lt;/p&gt;
&lt;p&gt;In a fit of professional indignation, I called the &lt;strong&gt;12345&lt;/strong&gt; government service hotline to complain. A few days later, the police station called me back and asked, &quot;How do you think we should fix this? You’re the expert here.&quot;&lt;/p&gt;
&lt;p&gt;I realized then that many grassroots organizations don&apos;t understand technology; they are merely &quot;completing a task,&quot; not &quot;building a system.&quot;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Consequently, the burden of information leakage ultimately falls back on the programmers.&lt;/strong&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;The Blurred Boundaries of Privacy&lt;/h2&gt;
&lt;p&gt;In today&apos;s digital landscape, registering an account is nearly impossible without a phone number and real-name authentication. Once a leak occurs, your personal identity is often exposed alongside your mobile number. &quot;Doxing&quot; or precision geolocation via a phone number is no longer news.&lt;/p&gt;
&lt;p&gt;Many opt for &quot;secondary SIMs&quot; to mitigate risk, but even with the limit of five cards per person, it’s far from enough. If a software requires an ID upload, you can&apos;t exactly ask the police for &quot;a few extra identities.&quot;&lt;/p&gt;
&lt;p&gt;Yet, it is the weight of the law that compels internet service providers to act this way.&lt;/p&gt;
&lt;p&gt;The Ministry of Industry and Information Technology (MIIT) requires all websites providing services within China to be filed (ICP Filing). The core purpose is traceability—ensuring that if a problem arises, a specific accountable person can be found. This necessitates real-name systems. From this perspective, software vendors have their hands tied. This is especially true for open forums; you can never predict when a user might post inappropriate content. If the individual cannot be found, the legal liability falls solely on the site operator.&lt;/p&gt;
&lt;p&gt;This is precisely why I do not open the comments section on my own blog. It’s not a lack of desire for dialogue, but a choice for security and compliance—reducing risk for myself.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/16/qqukvk.png&quot; alt=&quot;ICP/IP地址/域名信息备案管理系统&quot; /&gt;&lt;/p&gt;
&lt;p&gt;At this point, many ask:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&quot;Isn&apos;t an IP address the ID card of the internet? Why do you need personal info if you have the IP?&quot;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;While technically true, the total pool of &lt;strong&gt;IPv4 addresses&lt;/strong&gt; is capped at roughly &lt;strong&gt;4.2 billion&lt;/strong&gt;. They cannot be mapped one-to-one to every user. Because of NAT (Network Address Translation), a single IP often hides hundreds or thousands of devices. Finding a specific person via an IP is like looking for a needle in a haystack. Real-name authentication provides far superior precision.&lt;/p&gt;
&lt;p&gt;Furthermore—&lt;strong&gt;Data is Wealth.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;E-commerce platforms track every click; short-video apps record every second you linger. This behavioral data forms your &quot;User Persona.&quot; Algorithms push content based on these preferences to keep you consuming.&lt;/p&gt;
&lt;p&gt;The more data they harvest, the greater the profit.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The more data they harvest, the greater the profit.&lt;/strong&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Why Does Information Leakage Persist?&lt;/h2&gt;
&lt;p&gt;In my view, there are two fundamental reasons:&lt;/p&gt;
&lt;h3&gt;1. Data is an Asset: Vendors Want it, but Won&apos;t Protect it&lt;/h3&gt;
&lt;p&gt;Data is used for profiling, analysis, and risk control. Many vendors simply dump data into databases in plaintext—no de-identification, no encryption, sometimes even using default passwords. Large corporations generally care about their reputation, but smaller vendors? There are no guarantees.&lt;/p&gt;
&lt;h3&gt;2. Weak Security Awareness Among Developers&lt;/h3&gt;
&lt;p&gt;Many small enterprises prefer fresh graduates—they are inexpensive and compliant. However, many Software Engineering programs have historically lacked systematic cybersecurity curricula. Students prioritize &quot;making it work&quot; over &quot;making it secure.&quot; When this habit follows them into the workplace, vulnerabilities are inevitable. Furthermore, when veteran programmers move into management with a &quot;we’ve always done it this way&quot; mindset, they dismiss security proposals as &quot;unnecessary&quot;—until a breach actually happens.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;Let the Law be the Baseline for Security&lt;/h2&gt;
&lt;p&gt;The ultimate solution to information leakage isn&apos;t relying on penetration testing to &quot;patch the holes&quot; after the fact. It requires changing the source: &lt;strong&gt;Awareness and Accountability.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If security awareness cannot be raised voluntarily, it must be enforced by law.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If there is a violation, there must be a penalty.&lt;/strong&gt;
&lt;strong&gt;A fine once is a lesson learned forever.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As the legal scholar Luo Xiang famously said:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&quot;The law is the baseline of morality.&quot;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Similarly, &lt;strong&gt;the law should be the baseline of security.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/16/qkdwiy.png&quot; alt=&quot;Luo Xiang&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Final Thoughts&lt;/h2&gt;
&lt;p&gt;In recent years, as policies have improved, apps that excessively demand user data and permissions have been delisted. The implementation of centralized digital IDs is a sign of a maturing regulatory system. I hope that one day, enterprises will be truly constrained by law, so that &quot;low-level vulnerabilities&quot; like information leakage disappear entirely from penetration testing reports.&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;✍️ 最后也欢迎关注我的微信公众号&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/2032kd.png&quot; alt=&quot;微信公众号&quot; /&gt;&lt;/p&gt;
</content:encoded></item><item><title>(Cybersecurity Tools Vol.1) Kscan — A High-Performance Golang Security Scanner</title><link>https://fuwari.vercel.app/posts/738bfb49-cd11-4fce-8e9b-aace18dec657/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/738bfb49-cd11-4fce-8e9b-aace18dec657/</guid><description>A practical quick-start guide to Kscan: installation, essential commands, use cases, and best practices.</description><pubDate>Tue, 14 Oct 2025 01:02:38 GMT</pubDate><content:encoded>&lt;h2&gt;Preface&lt;/h2&gt;
&lt;p&gt;The [Cybersecurity Tools Series] aims to showcase powerful, user-friendly open-source security tools and provide rapid implementation guides. &lt;strong&gt;Please ensure you have explicit authorization or are operating within a sandboxed lab environment before using this tool.&lt;/strong&gt; Unauthorized security testing may violate local laws; use at your own risk.&lt;/p&gt;
&lt;h2&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Kscan is a lightweight security scanner written in Go. It supports port scanning, fingerprinting, automated brute-forcing, and network segment discovery. With output support for CSV/JSON, it is ideal for rapid asset discovery and weak credential auditing (&lt;strong&gt;authorized scenarios only&lt;/strong&gt;). This article covers quick setup, common commands, usage recommendations, and performance/security considerations.&lt;/p&gt;
&lt;h2&gt;About Kscan&lt;/h2&gt;
&lt;p&gt;Kscan is a Golang-based scanner designed for high concurrency and lightweight operations. Its primary use cases include: Asset Discovery (ports/services), HTTP Fingerprinting, Service Vitality Detection, and Automated Brute-forcing (integrated with Hydra). Results can be exported to CSV or JSON for reporting or further data processing.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/15/9yndzr.png&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Project Repository&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;GitHub: &lt;a href=&quot;https://github.com/lcvvvv/kscan&quot;&gt;https://github.com/lcvvvv/kscan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;License: GPL-3.0&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Core Features at a Glance&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Port Scanning: Single port, port ranges, or Top N ports.&lt;/li&gt;
&lt;li&gt;Fingerprinting: HTTP banner grabbing and service protocol identification.&lt;/li&gt;
&lt;li&gt;Network Segment Discovery: Active discovery of intranet segments via the &lt;code&gt;--spy&lt;/code&gt; mode.&lt;/li&gt;
&lt;li&gt;Automated Brute-forcing: Integrated Hydra engine supporting multiple protocols.&lt;/li&gt;
&lt;li&gt;Data Export: CSV and JSON formats compatible with professional delivery standards.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Use Cases&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Rapid mapping of security assets (Attack Surface Enumeration).&lt;/li&gt;
&lt;li&gt;Categorization of external service fingerprints (Web, Databases, common protocols).&lt;/li&gt;
&lt;li&gt;Authorized weak credential testing and auditing.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2&gt;Quick Installation&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Prerequisite: Go environment must be installed.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;pre&gt;&lt;code&gt;git clone https://github.com/lcvvvv/kscan.git
cd kscan
go build -o kscan ./cmd/kscan
# Alternatively, use the pre-compiled binary from the GitHub Releases page.
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Command Reference&lt;/h2&gt;
&lt;p&gt;Below are the most frequently used options with brief descriptions:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;usage: kscan [-h,--help,--fofa-syntax] (-t,--target,-f,--fofa,--spy) [options]

Core Options:
  -t, --target    Specify target: Single IP, IP range, URL, or file (file:/path)
  -f, --fofa      Fetch targets from FOFA (requires FOFA_EMAIL, FOFA_KEY)
  --spy           Network segment discovery mode (auto-detects internal segments)
  -p, --port      Specify port(s) or range; defaults to Top 400
  -o, --output    Save results to file (CSV supported)
  -oJ             Save results in JSON format
  --proxy         Use proxy (socks5|socks4|http|https)://IP:Port
  --threads       Thread count; default 100, max 2048
  --timeout       Timeout duration (in seconds)
  --hydra         Enable automated brute-forcing (requires --hydra-user/--hydra-pass)
  -Pn             Skip smart vitality detection (slower but more exhaustive)
  -sV             Enable full-probe detection for open ports (Impacts efficiency; use with caution)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;strong&gt;Hydra Integration:&lt;/strong&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;  --hydra-user    Username (supports file:username.txt)
  --hydra-pass    Password (supports file:password.txt)
  --hydra-update  Append custom dictionaries to default dictionaries
  --hydra-mod     Restrict brute-force modules (e.g., rdp, ssh, ftp)
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Usage Examples (Recommended Syntax)&lt;/h2&gt;
&lt;p&gt;Asset Mapping (Full Port Scan, CSV Output):&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;kscan -t targets.txt -p 1-65535 -o output.csv
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Credential Auditing (Using custom dictionaries appended to defaults):&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;kscan -t targets.txt -p 1-65535 --hydra --hydra-user file:user.txt --hydra-pass file:pass.txt --hydra-update -o output.csv
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Network Reachability Discovery (Auto-detecting standard A/B/C private segments):&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;kscan --spy all -o output.csv
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;High-Concurrency Rapid Scan:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;kscan -t 198.51.100.0/24 -p 80,443 --threads 500 -oJ output.json
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Best Practices &amp;amp; Performance Optimization&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Concurrency &amp;amp; Resources&lt;/strong&gt;: Increasing &lt;code&gt;--threads&lt;/code&gt; boosts speed but consumes more bandwidth and target/local resources. Monitor CPU and network stability; avoid extreme values unless necessary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Timeout Configuration&lt;/strong&gt;: For unstable networks, increase &lt;code&gt;--timeout&lt;/code&gt; to prevent false negatives in service vitality.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Minimizing False Positives&lt;/strong&gt;: Before running large-scale fingerprinting with &lt;code&gt;--check&lt;/code&gt;, test on a small subset to observe response patterns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Brute-force Strategy&lt;/strong&gt;: Only perform credential testing within authorized scopes. Limit the rate and use &lt;code&gt;--hydra-mod&lt;/code&gt; to avoid triggering lockouts or alarms.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data Post-processing&lt;/strong&gt;: JSON exports are ideal for integration with tools like ELK, Pandas, or Splunk for visualization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;常见问题（FAQ）&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Q：如何仅扫描常见端口？&lt;/strong&gt;
A：使用 &lt;code&gt;--top&lt;/code&gt; 参数，例如 &lt;code&gt;--top 100&lt;/code&gt; 扫描TOP100常见端口。&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q：如何关闭 CDN 识别？&lt;/strong&gt;
A：加参数 &lt;code&gt;-Dn&lt;/code&gt;（注意：关闭后可能会对大规模扫描效率产生影响）。&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q：如何提升 Web 指纹识别精度？&lt;/strong&gt;
A：使用 &lt;code&gt;-sV&lt;/code&gt; 做全探针探测，但这会显著减慢扫描速度，适合深度确认时使用。&lt;/p&gt;
&lt;h2&gt;FAQ&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Q: How do I scan only common ports?&lt;/strong&gt;
A: Use the &lt;code&gt;--top&lt;/code&gt; parameter, e.g., &lt;code&gt;--top 100&lt;/code&gt; for the most common 100 ports.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q: How do I disable CDN identification?&lt;/strong&gt;
A: Add the &lt;code&gt;-Dn&lt;/code&gt; flag (Note: this may impact the efficiency of large-scale scans).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q: How can I improve the accuracy of Web fingerprinting?&lt;/strong&gt;
A: Use &lt;code&gt;-sV&lt;/code&gt; for full-probe detection. Note that this significantly slows down the scan and is best suited for deep confirmation.&lt;/p&gt;
&lt;h2&gt;Risk &amp;amp; Compliance Warning (Crucial)&lt;/h2&gt;
&lt;p&gt;You must use Kscan&apos;s scanning and brute-forcing features only under explicit &lt;strong&gt;authorization&lt;/strong&gt;. Scanning or brute-forcing unauthorized targets may constitute a criminal offense. This site assumes no liability for illegal usage.&lt;/p&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Kscan is a lightweight, efficient asset discovery tool perfectly suited for rapid mapping and weak credential auditing in authorized environments. When combined with appropriate dictionaries, rate-limiting, and post-processing tools (CSV/JSON), it delivers actionable asset lists and vulnerability insights in a very short timeframe.&lt;/p&gt;
</content:encoded></item><item><title>Journal-Upgrading My NAS (Network Attached Storage)</title><link>https://fuwari.vercel.app/posts/f3f6110f-f4f2-4e92-990c-a24a04494b50/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/f3f6110f-f4f2-4e92-990c-a24a04494b50/</guid><description>My original NAS ran a bootleg Synology (Xpenology) system. For unknown reasons, simultaneous R/W operations on two drives would cause the DSM web interface to freeze. This prompted a move to TrueNAS. However, since TrueNAS utilizes the ZFS file system, ECC memory is highly recommended to ensure data integrity. After verifying that my original motherboard and CPU did not support ECC, I embarked on a hardware upgrade plan.</description><pubDate>Sun, 12 Oct 2025 00:09:11 GMT</pubDate><content:encoded>&lt;h2&gt;Preface&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;This article is a repost of my original piece on Zhihu, published on March 17, 2022.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;My original NAS ran Xpenology. I encountered an issue where the DSM web interface would completely freeze during heavy I/O operations across two hard drives. I decided to switch to TrueNAS (partly to create a new project for myself). Given that TrueNAS relies on the ZFS file system, which benefits significantly from ECC (Error Correction Code) memory to prevent &quot;silent data corruption,&quot; I realized my existing Athlon 200GE and A320 motherboard were incompatible. Thus, the upgrade began.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Specifications&lt;/h2&gt;
&lt;h3&gt;Pre-Upgrade Configuration&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Model&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Motherboard&lt;/td&gt;
&lt;td&gt;Colorful A320M-K &quot;Broken Sword&quot;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CPU&lt;/td&gt;
&lt;td&gt;AMD Athlon 200GE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory&lt;/td&gt;
&lt;td&gt;ADATA DDR4 2133 16GB (8GB * 2)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Boot Drive&lt;/td&gt;
&lt;td&gt;SanDisk Cruzer Fit 32GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PSU&lt;/td&gt;
&lt;td&gt;Segotep GP600 500W (Full Modular)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Chassis&lt;/td&gt;
&lt;td&gt;Invasion X-1 (6-Bay)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;NIC (10G)&lt;/td&gt;
&lt;td&gt;Mellanox ConnectX-3 10GSFP*2 PCIx4&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Post-Upgrade Configuration&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;Model&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Motherboard&lt;/td&gt;
&lt;td&gt;ASRock B550M-Pro4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CPU&lt;/td&gt;
&lt;td&gt;AMD Athlon 200GE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory&lt;/td&gt;
&lt;td&gt;Samsung DDR4 2133 ECC 32GB (16GB * 2)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Boot Drive&lt;/td&gt;
&lt;td&gt;Intel Optane M10 16GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PSU&lt;/td&gt;
&lt;td&gt;Supermicro 480W Platinum (Modified 1U PSU)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Chassis&lt;/td&gt;
&lt;td&gt;Tuopulong NAS-08 (8-Bay, 2022 Revised Edition)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;NIC (10G)&lt;/td&gt;
&lt;td&gt;Mellanox ConnectX-3 Dual-Port 10G SFP+ (PCIe x8)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Component Selection Logic&lt;/h2&gt;
&lt;p&gt;About TrueNAS&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/97jz7.jpg&quot; alt=&quot;TrueNAS Hardware Introduction&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Selecting the right hardware for TrueNAS is critical. ZFS uses system RAM as a high-speed cache (ARC), making ECC memory essential for mission-critical data integrity. Finding a consumer-grade motherboard that actually supports ECC proved difficult.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/9pks7.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Many manufacturers claim ECC support, but it often only means they can &quot;accept&quot; ECC modules in &quot;non-ECC mode.&quot; After extensive research, ASRock and ASUS emerged as the best options for true ECC compatibility on consumer platforms. I chose the ASRock B550M-Pro4 because it supports unbuffered ECC memory, offers 6 native SATA ports, dual M.2 slots, and two PCIe x16 slots (one being PCIe 4.0). I sourced a used unit for around 3xx RMB, as new units were significantly more expensive.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/9vfrq.jpg&quot; alt=&quot;asrock B550M-Pro4介绍&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Regarding the CPU: the standard Athlon 200GE does not support ECC. However, the PRO series (OEM units) does. I opted for the Athlon Gold Pro 3150G (4C/4T). While these are technically OEM-only parts, they are readily available as &quot;pulls&quot; on the second-hand market.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/a9tkg.jpg&quot; alt=&quot;AMD Gold Pro 3150G Introduction&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Old Hardware&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/av1nf.jpg&quot; alt=&quot;&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/atk8l.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;New Hardware&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Crucial 1TB Cache SSD, Intel Optane 16GB Boot Drive, and the AMD Athlon Gold Pro 3150G.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c4ioq.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Micron DDR4 2133MHz 16GB ECC Memory.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c504b.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Motherboard I/O Shield and ports.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c55eu.jpg&quot; alt=&quot;&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c6i15.jpg&quot; alt=&quot;&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c5efw.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Verification: AIDA64 confirming that ECC is active and functional.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c6v6x.jpg&quot; alt=&quot;&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/c77ns.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Storage Configuration&lt;/h2&gt;
&lt;p&gt;I initially configured a RAID-Z array using three 4TB drives, plus one standalone drive. A Crucial 1TB SSD serves as the L2ARC (Cache).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Array Drives: 2x Western Digital (WD40PURX) and 1x Seagate (ST4000VX000). These are all CMR (Conventional Magnetic Recording) drives.&lt;/li&gt;
&lt;li&gt;Standalone Drive: Toshiba P300 (SMR - Shingled Magnetic Recording). Due to the performance penalties of SMR in RAID environments, this drive is relegated to running PT (Private Tracker) downloads individually.
Pro-Tip: Avoid using drives from the exact same production batch in a single array. If there is a manufacturing defect, they might fail simultaneously—a true &quot;data crematorium.&quot;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/e11xh.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;TrueNAS Environment&lt;/h2&gt;
&lt;p&gt;Currently, I am running one CentOS VM and about 8-10 Docker containers. Even with 16GB of RAM, the system is nearly at capacity. I am waiting for the second 16GB module to arrive, which should provide much-needed breathing room for the ZFS ARC.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/12/e0926.jpg&quot; alt=&quot;&quot; /&gt;&lt;/p&gt;
&lt;p&gt;To be continued...&lt;/p&gt;
</content:encoded></item><item><title>Farewell to Chaos:I Developed a Cable Label Formatting Tool</title><link>https://fuwari.vercel.app/posts/61ee0d58-351b-4c96-8dcf-019113182715/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/61ee0d58-351b-4c96-8dcf-019113182715/</guid><description>Born for efficiency, established for standards — check out this Cable Label Formatting Tool.</description><pubDate>Wed, 08 Oct 2025 17:39:32 GMT</pubDate><content:encoded>&lt;p&gt;As a &quot;Jack-of-all-trades&quot; engineer, my career began in network engineering. Although my current primary focus is cybersecurity, I am still frequently dispatched by my company to data centers (DC) for implementation tasks. Consequently, I’ve seen my fair share of data centers...&lt;/p&gt;
&lt;p&gt;A brand-new DC is almost perfect upon completion — tidy cabling, standardized layouts, and a sight that brings joy to any visiting supervisor. However, as an organization grows, new equipment is inevitably added. The problem is that these incremental implementations are often handled by different contractors, leading to inconsistent craftsmanship and standards.&lt;/p&gt;
&lt;p&gt;Take the most fundamental element: cable labels. Some contractors, seeking shortcuts, skip labeling entirely—as long as the link is up and the network pings, they vanish. While that might feel &quot;efficient&quot; during implementation, it digs a massive hole for future maintenance personnel. At best, you might find a vague label that just says &lt;strong&gt;&quot;OOB Management&quot; (Out-of-Band).&lt;/strong&gt; In a DC with dozens or hundreds of devices, which specific machine is this cable managing?&lt;/p&gt;
&lt;p&gt;Therefore, I believe that unifying label formats is an absolute necessity. Any operation involving cabling must be synchronized with proper labeling. This is not just a responsibility to oneself, but a mark of respect for fellow engineers. My advice is simple: &lt;code&gt;Don&apos;t be that guy&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;However, the reality is that every cable has two ends. How can we generate standardized labels quickly and efficiently? In today’s high-pressure environment, technical prowess is vital, but boosting your efficiency is what truly sets you apart from the crowd.&lt;/p&gt;
&lt;p&gt;To solve the issues of efficiency and standardization in cable labeling, I developed a small script in my spare time. Given its size, calling it a &quot;tool&quot; might be a bit of an overstatement. Initially, it was just a command-line script. However, when a college classmate asked to use it recently, I realized that requiring a CLI environment for every run was quite cumbersome. So, I had AI help me draft a frontend interface (admittedly, frontend work is a bit of a headache for me) and deployed it as a web application. Of course, if you prefer local deployment, the full source code is available on GitHub.&lt;/p&gt;
&lt;h2&gt;Introduction: Cable-Label Tool&lt;/h2&gt;
&lt;p&gt;This is a straightforward cable label formatting tool designed to quickly generate standardized, unified labels by uploading Excel data.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/txv5fh.png&quot; alt=&quot;Cable-Label Tool&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Online Access&lt;/h2&gt;
&lt;p&gt;Link: &lt;a href=&quot;https://cable-label.bytesycn.cn&quot;&gt;Cable Label Formatting Tool - bytesycn​​&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Access Note: The online service is currently restricted to IP addresses within China (including Hong Kong, Macau, and Taiwan). For security reasons, access from international IPs will be intercepted by Tencent EdgeOne.&lt;/p&gt;
&lt;h2&gt;Output Sample&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/txv836.png&quot; alt=&quot;Excel&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Local Deployment&lt;/h2&gt;
&lt;p&gt;If you prefer to deploy and use it locally, you can access the project&apos;s GitHub repository for the source code.&lt;/p&gt;
&lt;p&gt;​GitHub：&lt;a href=&quot;https://github.com/hz157/cable-label&quot;&gt;https://github.com/hz157/cable-label&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;git clone https://github.com/hz157/cable-label.git
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/txvmn2.png&quot; alt=&quot;Github&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Instructions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Download Template: Obtain the standard Excel template file first.&lt;/li&gt;
&lt;li&gt;Fill in Data: Enter the device information for both ends of the cable and the cable&apos;s function into the template.&lt;/li&gt;
&lt;li&gt;Upload File: Upload the completed Excel file to the tool page.&lt;/li&gt;
&lt;li&gt;Select Style: Choose one of the 9 preset label styles.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I hope this tool helps more engineers suffering from &quot;cable chaos&quot; and helps make our data centers tidier and more standardized!&lt;/p&gt;
</content:encoded></item><item><title>When MinIO Web Console Vanishes, CLI is King:A Beginner&apos;s Guide to mc</title><link>https://fuwari.vercel.app/posts/926617d8-ea6f-4d0f-aee0-bc7be18d1b7a/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/926617d8-ea6f-4d0f-aee0-bc7be18d1b7a/</guid><description>MinIO, the open-source object storage giant, has undergone a heavy-handed removal of its Web Management Console core code in community releases post-20250524. With over 110,000 lines of code deleted, how can we manage MinIO without the Web Console? Let&apos;s dive into the mc command line.</description><pubDate>Wed, 08 Oct 2025 16:11:32 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;MinIO, the open-source object storage giant, has drastically removed the core code of its Web Management Console in community releases following version 20250524. With approximately 110,000 lines of code stripped away, the community is in an uproar, accusing MinIO of &quot;burning bridges&quot;—reaping the benefits of open source only to pull the plug on its most accessible features. As I’ve been developing a private project utilizing MinIO recently, I’ve had to rely on AI and documentation to master the basic commands. Since the Web UI is gone, understanding mc is now essential for permission control and general management. Consider this a guide born out of necessity.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/ukvumo.png&quot; alt=&quot;Community News&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Developer Backlash&lt;/h2&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/ukvg21.png&quot; alt=&quot;Developer comments&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/10/08/ukv6cy.png&quot; alt=&quot;Developer comments&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;What is mc?&lt;/h2&gt;
&lt;p&gt;Don’t be mistaken—this mc isn&apos;t about mining blocks in Minecraft. It stands for MinIO Client. This is the official, incredibly powerful command-line tool and the primary way to interact with a MinIO server. You can install it easily through several methods.&lt;/p&gt;
&lt;h2&gt;安装&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Direct Binary Download (Recommended)&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;# Download mc for Linux amd64
wget https://dl.min.io/client/mc/release/linux-amd64/mc
# Grant execution permissions
chmod +x mc
# Move to a system PATH directory (e.g., /usr/local/bin/) for global access
sudo mv mc /usr/local/bin/
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Docker Installation&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;# Pull the mc Docker image
docker pull minio/mc
# Run a temporary container to execute a command (e.g., listing a bucket)
docker run minio/mc ls myminio
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;Command Guide&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;For a full list of all &lt;code&gt;mc&lt;/code&gt; commands, refer to the official documentation. This section covers the most common and critical operations.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Running &lt;code&gt;mc --help&lt;/code&gt; displays all available commands. Here are the core categories:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;alias      Manage server aliases (configures connection info)
  admin      Manage MinIO servers (users, policies, config, etc.)
  ...        ...
  ls         List buckets and objects
  mb         Make bucket
  cp         Copy objects
  mv         Move/Rename objects
  rm         Remove objects
  cat        Display object content
  head       Display first part of an object
  pipe       Stream from STDIN to an object
  put        Upload local files to a bucket
  mirror     Synchronize local directories to remote buckets (Powerful sync tool)
  du         Summarize disk usage
  diff       Compare differences between two buckets
  find       Search for objects
  ...        ... (Other important commands: policy, user, config, event, ilm, etc.)
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Essential Commands Detail&lt;/h3&gt;
&lt;h4&gt;Alias Management&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;Setting a Connection (alias):&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;mc alias set ALIAS HOST ACCESSKEY SECRETKEY
# Example: Connecting to a local MinIO instance
mc alias set myminio http://localhost:9000 minioadmin minioadmin
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;List all configured aliases:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;mc alias list
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Remove an existing alias:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;mc alias remove ALIAS
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Administration (admin)&lt;/h4&gt;
&lt;ol&gt;
&lt;li&gt;Check Server Information:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;mc admin info ALIAS
# Example: Check status for myminio
mc admin info myminio
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;User Management:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;# Add a user
mc admin user add ALIAS ACCESSKEY SECRETKEY
# Example: Add user AK:test SK:123456 to myminio
mc admin user add myminio test 123456

# Disable a user
mc admin user disable ALIAS USERNAME

# Enable a user
mc admin user enable ALIAS USERNAME

# View user info
mc admin user info ALIAS USERNAME

# List all users
mc admin user ls ALIAS

# Remove a user
mc admin user rm ALIAS USERNAME
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;PBAC (Policy-Based Access Control) Management:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;# Create a policy
mc admin policy create ALIAS POLICYNAME POLICYPATH
# Example: Create &quot;listmybuckets&quot; policy using a local JSON file
mc admin policy create myminio listmybuckets /tmp/listmybuckets.json

# Attach an IAM policy to a MinIO user or group
mc admin policy attach ALIAS POLICY [POLICY...] [--user USER | --group GROUP]
# Example: Bind the &quot;listmybuckets&quot; policy to user &quot;test&quot; on myminio
mc admin policy attach myminio listmybuckets test

# List all policies
mc admin policy ls ALIAS

# View policy details
mc admin policy info ALIAS POLICYNAME

# List entities (users/groups) associated with a policy
mc admin policy entities ALIAS [--user value] [--group value] [--policy value]

# Delete a policy
mc admin policy rm ALIAS POLICYNAME
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;🔗 Related Links&lt;/p&gt;
&lt;p&gt;[1] &lt;a href=&quot;https://minio.org.cn/docs/minio/linux/&quot;&gt;MinIO Object Storage Documentation(Chinese)&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>OpenSSH Security Upgrade Guide:Detailed Online and Offline Solutions</title><link>https://fuwari.vercel.app/posts/bf5c26f0-e5a4-4794-8b2a-b0cc90961a51/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/bf5c26f0-e5a4-4794-8b2a-b0cc90961a51/</guid><description>OpenSSH is a core component for remote server management. While its open-source nature occasionally reveals security vulnerabilities, it also drives continuous optimization and iteration. Upgrading is the most effective way to address these vulnerabilities. However, many Linux servers are deployed in isolated environments without direct internet access, making manual compilation and installation a necessary skill. This article details how to securely upgrade OpenSSH via source compilation in an offline environment.</description><pubDate>Wed, 24 Sep 2025 21:11:41 GMT</pubDate><content:encoded>&lt;h2&gt;Critical Warnings&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Before performing an OpenSSH upgrade in any production environment, you MUST prepare a rollback plan. This includes, but is not limited to: VM snapshots, VM cloning, or documenting executed commands for manual reversion.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Prerequisites&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;OpenSSL (May be omitted if the current version is compatible)&lt;/li&gt;
&lt;li&gt;OpenSSH Source Package&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Upgrade Procedures&lt;/h2&gt;
&lt;p&gt;Online upgrades via package managers are generally straightforward. However, for offline compilation, ensure your current SSH session remains active. If the connection is severed during the process, you will be unable to establish a new SSH session until the upgrade is complete, necessitating the use of Telnet or VNC—methods that significantly increase the difficulty of recovery.&lt;/p&gt;
&lt;h3&gt;1. Online Environment&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Upgrading in a connected environment is relatively simple. While you can use package managers like &lt;code&gt;apt&lt;/code&gt;, &lt;code&gt;dnf&lt;/code&gt;, or &lt;code&gt;yum&lt;/code&gt;, these repositories often lag behind the latest releases. &lt;strong&gt;To install the latest version, manual compilation from source is still required&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h4&gt;Ubuntu/Debian&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;# Update package index
sudo apt update
# Check for upgradable OpenSSH versions (Optional)
apt list --upgradable openssh-*
# Upgrade OpenSSH client and server
sudo apt install --only-upgrade openssh-client openssh-server
# Restart SSH service
sudo systemctl restart sshd
# Verify service status and port listening
sudo systemctl status sshd
sudo netstat -tunlp | grep :22
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;RHEL7/CentOS7&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;# Check for available updates
sudo yum check-update
# Upgrade OpenSSH components
sudo yum update openssh openssh-server openssh-clients
# Restart and verify service
sudo systemctl restart sshd
sudo netstat -tunlp | grep :22
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;RHEL8/CentOS8+/RockyLinux9+&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;# Refresh repository metadata
sudo dnf makecache
# Upgrade SSH components
sudo dnf upgrade openssh openssh-server openssh-clients
# Reload and verify service
sudo systemctl reload sshd
sudo netstat -tunlp | grep :22
&lt;/code&gt;&lt;/pre&gt;
&lt;hr /&gt;
&lt;h3&gt;2. Isolated Environment (Offline)&lt;/h3&gt;
&lt;h4&gt;Important Recommendations&lt;/h4&gt;
&lt;p&gt;Recommended versions (as of September 2025):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;OpenSSL: 1.1.1w or 3.x (depending on OS compatibility)&lt;/li&gt;
&lt;li&gt;OpenSSH: 10.0p1 or later&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Download links are provided at the end of this article.&lt;/p&gt;
&lt;h4&gt;Pre-upgrade Preparation&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;# Create a dedicated workspace
mkdir /opt/ssh_upgrade &amp;amp;&amp;amp; cd /opt/ssh_upgrade

# Secure backup of existing configurations and binaries
cp -a /etc/ssh /etc/ssh_backup_$(date +%F)
cp -a /etc/init.d/sshd /etc/init.d/sshd_backup
cp -a /usr/bin/openssl /usr/bin/openssl_backup
cp -a /etc/pam.d/sshd /etc/pam.d/sshd_backup

# Backup critical library dependencies
ldd $(which sshd) | awk &apos;NF == 4 {print $3}&apos; | xargs -I {} cp -a {} /opt/lib_backup/
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Uninstall Legacy OpenSSH Service&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;# For Yum-based systems
yum -y remove openssh openssh-server openssh-clients openssh-askpass
# Alternative for RPM
rpm -e --nodeps openssh openssh-server openssh-clients
# For Apt-based systems
apt purge -y openssh-server openssh-client
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Install OpenSSL (Optional)&lt;/h4&gt;
&lt;p&gt;Omit this step if your current OpenSSL version meets the requirements of the new OpenSSH version.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;tar -zxvf openssl-3.2.4.tar.gz
cd openssl-3.2.4

# Optimize compilation parameters
./config --prefix=/usr/local/openssl \
         --openssldir=/usr/local/openssl \
         shared zlib -Wl,-rpath=/usr/local/openssl/lib

make &amp;amp;&amp;amp; make install

# Update symbolic links
ln -sf /usr/local/openssl/bin/openssl /usr/bin/openssl
ln -sf /usr/local/openssl/include/openssl /usr/include/openssl

# Refresh library cache
echo &quot;/usr/local/openssl/lib&quot; &amp;gt; /etc/ld.so.conf.d/openssl.conf
ldconfig -v | grep -i openssl

# Verify version
openssl version -a
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Install OpenSSH&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;tar -zxvf openssh-10.6p1.tar.gz
cd openssh-10.6p1

# Configure with necessary modules (PAM and Zlib support)
./configure --prefix=/usr \
            --sysconfdir=/etc/ssh \
            --with-ssl-dir=/usr/local/openssl \
            --with-pam \
            --with-zlib

make -j$(nproc)
make install

# Verify binary compatibility and version
ldd /usr/sbin/sshd
ssh -V
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Modify sshd Configuration&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;vi /etc/ssh/sshd_config

# Ensure the following critical configurations are set
Port 22
ListenAddress 0.0.0.0
PermitRootLogin prohibit-password
PasswordAuthentication yes
UsePAM yes
&lt;/code&gt;&lt;/pre&gt;
&lt;h4&gt;Start the Service&lt;/h4&gt;
&lt;pre&gt;&lt;code&gt;systemctl start sshd
# Verify if the service is running correctly
systemctl status sshd
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;🔗 Related Links&lt;/p&gt;
&lt;p&gt;[1] Alibaba Cloud OpenSSH Mirror:: &lt;a href=&quot;https://mirrors.aliyun.com/pub/OpenBSD/OpenSSH/portable&quot;&gt;https://mirrors.aliyun.com/pub/OpenBSD/OpenSSH/portable&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2] OpenSSL: &lt;a href=&quot;https://www.openssl.org/source&quot;&gt;https://www.openssl.org/source&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>Multiplayer Gaming Guide:Building a Virtual LAN with N2N</title><link>https://fuwari.vercel.app/posts/b1851e8a-2315-455c-a331-14a289804d91/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/b1851e8a-2315-455c-a331-14a289804d91/</guid><description>Recently, my friends and I have been immersed in the &apos;Civilization&apos; series—always promising &apos;just one more turn&apos; until the early hours of the morning. Despite being on the other side of the globe, we successfully established a Virtual LAN using P2P VPN technology to enjoy a seamless multiplayer experience. This article shares the practical implementation of this technique.</description><pubDate>Thu, 11 Sep 2025 00:11:32 GMT</pubDate><content:encoded>&lt;blockquote&gt;&lt;/blockquote&gt;
&lt;p&gt;EasyN2N (also known as &apos;Little Yellow Duck&apos;) is a virtual networking tool specifically optimized for multiplayer gaming. Theoretically, N2N supports any game that allows LAN-based multiplayer. According to data from &lt;a href=&quot;https://bugxia.com&quot;&gt;Bugxia&lt;/a&gt;, successfully tested titles include: the CS series, Red Alert 2/3, StarCraft, Warcraft III, DOTA, ARK: Survival Evolved, Civilization VI, Stellaris, Meteor Butterfly Sword, Human: Fall Flat, Worms, Left 4 Dead 1 &amp;amp; 2, Minecraft, Torchlight 2, and Age of Empires II.&lt;/p&gt;
&lt;h2&gt;Client Download&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://bugxia.com/357.html&quot;&gt;EasyN2N (N2N Launcher) v3.1.2&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Server-Side Installation Guide&lt;/h2&gt;
&lt;h3&gt;Manual Installation&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;# For Ubuntu, Debian, etc.
apt-get install libzstd -y
wget https://github.com/ntop/n2n/releases/download/3.0/n2n-3.0.0-1038.x86_64.rpm
rpm -i n2n-3.0.0-1038.x86_64.rpm
# Run supernode: Listen on port 9527, define IP range, run in foreground
supernode -p 9527 -a 192.168.255.0-192.168.255.0/24 -f

# For CentOS, OpenEuler, RockyLinux, etc.
yum install libzstd -y
wget https://github.com/ntop/n2n/releases/download/3.0/n2n-3.0.0-1038.x86_64.rpm
rpm -i n2n-3.0.0-1038.x86_64.rpm
supernode -p 9527 -a 192.168.255.0-192.168.255.0/24 -f
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;One-Click Installation Script&lt;/h3&gt;
&lt;p&gt;I have developed an automation script to simplify the deployment. Execute the following command:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;wget https://script.bytesycn.com/p2p/n2n-install.sh &amp;amp;&amp;amp; chmod +x n2n-server.sh &amp;amp;&amp;amp; ./n2n-server.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/09/11/f85g1.png&quot; alt=&quot;One-Click Installation Script&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/09/11/fhw23.png&quot; alt=&quot;Install success&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;Verification&lt;/h3&gt;
&lt;p&gt;Use the &lt;code&gt;netstat -tunlp&lt;/code&gt; command to verify if the program is actively listening on port 9527.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/09/11/fi8ou.png&quot; alt=&quot;listening on port&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;N2N Client Usage Tutorial&lt;/h2&gt;
&lt;p&gt;After launching the software, enter the IP address and port of your N2N Server. Since DHCP (Auto-IP Assignment) has been configured on the server side, you can leave the Virtual IP field blank. Alternatively, you can manually assign an IP within the same subnet (requires basic networking knowledge). Ensure the Group Name is identical for all participants; think of the Group Name as a &quot;Room Number&quot;—entering the same name puts everyone in the same virtual space.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Launch EasyN2N.&lt;/li&gt;
&lt;li&gt;nter the Supernode IP and Port (e.g., &lt;code&gt;43.163.81.102:9527&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Leave the Virtual IP blank (as DHCP is enabled) or set a static IP within the subnet.&lt;/li&gt;
&lt;li&gt;Set a unique Group Name (shared with your friends).&lt;/li&gt;
&lt;li&gt;Click the Start button.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Once the server status displays a green checkmark and the Virtual IP is successfully assigned, the connection is established.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/09/11/d82q9.png&quot; alt=&quot;N2N Client&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/09/11/d7ykd.png&quot; alt=&quot;N2N connect success&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Once connected, you can enjoy a low-latency, virtual LAN gaming experience.&lt;/p&gt;
&lt;h2&gt;Important Notes&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Firewall Settings: If using a Cloud VPS, ensure the OS firewall (&lt;code&gt;iptables&lt;/code&gt;/&lt;code&gt;firewalld&lt;/code&gt;) is disabled or configured to allow the N2N port. You must also open the port in the cloud provider&apos;s Security Group (the script uses &lt;code&gt;9527/TCP &amp;amp; UDP&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Consistency: Ensure all clients use the exact same Group Name.&lt;/li&gt;
&lt;li&gt;Latency: Choose a server location that is geographically central to all players to minimize Latency and Jitter.&lt;/li&gt;
&lt;/ol&gt;
</content:encoded></item><item><title>Security Inspection Headache? Here’s the Ultimate High-Risk Port &amp; Forbidden File Upload Checklist!</title><link>https://fuwari.vercel.app/posts/321d3617-2a6d-40f4-809d-59837206ebf3/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/321d3617-2a6d-40f4-809d-59837206ebf3/</guid><description>This article provides a comprehensive checklist of high-risk ports recommended for closure and a guide to prohibited file upload types. Covering remote access, databases, file sharing, and risky executables/scripts, it aims to streamline security audits and enhance network defense.</description><pubDate>Wed, 03 Sep 2025 21:00:15 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Does the mere mention of a major security audit or &quot;heavy protection period&quot; trigger anxiety? Unsure which ports to close or how to harden Web security? Don&apos;t panic. We’ve compiled the ultimate solution: a centralized summary of all high-risk ports and forbidden file extensions. This is the only reference guide you&apos;ll ever need.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;I. Critical High-Risk Port Checklist&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Core Principle: Attack Surface Reduction—if it’s not essential, shut it down.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;While most modern firewalls utilize a &quot;Default Deny&quot; (Reject All) baseline, many administrators add an &quot;Any-to-Any&quot; permit rule at the top just to save time.&lt;/p&gt;
&lt;p&gt;As an engineer who recently entered the field, I’ve seen this &quot;shortcut&quot; far too often.&lt;/p&gt;
&lt;p&gt;Let&apos;s be clear: open policies might feel convenient now, but they lead to forensic nightmares later. Don&apos;t wait for a breach to regret your choices. We strongly recommend checking and closing the following ports immediately for public access.&lt;/p&gt;
&lt;h3&gt;1.1 Remote Access Ports&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;SSH&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;TELNET&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3389&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;RDP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5900-5904&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;VNC&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Database Ports&lt;/h3&gt;
&lt;h4&gt;1.2.1 Relational Databases (RDBMS)&lt;/h4&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1433&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Microsoft SQL&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1521&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Oracle DB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3306&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;MySQL/MariaDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5432&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;PostgreSQL&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;50000&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;IBM DB2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5236&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Dameng (DM)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;54321&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Kingbase&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5866&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;HighGo&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;30100&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;GaussDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2881-2882/2886&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;OceanBase&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;1.2.2 NoSQL Databases&lt;/h4&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;6379&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Redis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;27017/27018&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;MongoDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9042&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Cassandra&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9200&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Elasticsearch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5984&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;CouchDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;16000&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;HBase&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8091&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Couchbase&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8086&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;InfluxDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9042&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;ScyllaDB&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;1.2.3 Graph &amp;amp; Vector Databases&lt;/h4&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;7687&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Neo4j&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8529&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;ArangoDB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;14240&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;TigerGraph&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8080&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;DGraph&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;1.2.4 Database Management Tools&lt;/h4&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;80/443&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;phpMyAdmin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;80/443&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;pgAdmin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;80/443&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Adminier&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8080&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Bytebase&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;1.3 File Sharing &amp;amp; Protocol Ports&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;21&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;FTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;139/445&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;SMB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;593&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;AFP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2049&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;NFS&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;1.4 Critical Middleware &amp;amp; Vulnerable Services&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;135/136/137/138&lt;/td&gt;
&lt;td&gt;TCP/UDP&lt;/td&gt;
&lt;td&gt;Windows RPC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;139/445&lt;/td&gt;
&lt;td&gt;TCP/UDP&lt;/td&gt;
&lt;td&gt;SMB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;161&lt;/td&gt;
&lt;td&gt;TCP/UDP&lt;/td&gt;
&lt;td&gt;SNMP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;1.5 Other Vulnerable Services&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Protocol&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;8848&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Nacos&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3888/2181&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Zookpeer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9001&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Supervisor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7077&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Spark&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9092&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;Kafka&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7001&lt;/td&gt;
&lt;td&gt;TCP&lt;/td&gt;
&lt;td&gt;WebLogic&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;II. Forbidden File Upload Extension Checklist&lt;/h2&gt;
&lt;p&gt;Weak file type validation is equivalent to handing over system execution privileges. The fundamental rule: Validate not just the extension, but also the file content (Magic Bytes) and MIME type.&lt;/p&gt;
&lt;h3&gt;2.1 System Executables &amp;amp; Scripts&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Risk: These can execute commands directly on the server or client side; they are the highest risk category.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Windows: &lt;code&gt;.exe&lt;/code&gt;, &lt;code&gt;.msi&lt;/code&gt;, &lt;code&gt;.com&lt;/code&gt;, &lt;code&gt;.scr&lt;/code&gt;, &lt;code&gt;.bat&lt;/code&gt;, &lt;code&gt;.cmd&lt;/code&gt;, &lt;code&gt;.ps1&lt;/code&gt;, &lt;code&gt;.vbs&lt;/code&gt;, &lt;code&gt;.vbe&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Linux: &lt;code&gt;.sh&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Genera: &lt;code&gt;.jar&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;2.2 Web Executable Scripts&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Risk: If uploaded to a web directory, accessing these files triggers code execution, leading to a WebShell and total server compromise.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;PHP: &lt;code&gt;.php&lt;/code&gt;, &lt;code&gt;.php3&lt;/code&gt;, &lt;code&gt;.php4&lt;/code&gt;, &lt;code&gt;.php5&lt;/code&gt;, &lt;code&gt;.php6&lt;/code&gt;, &lt;code&gt;.php7&lt;/code&gt;, &lt;code&gt;.phtml&lt;/code&gt;, &lt;code&gt;.phps&lt;/code&gt;, &lt;code&gt;.phar&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;ASP.NET: &lt;code&gt;.asp&lt;/code&gt;, &lt;code&gt;.aspx&lt;/code&gt;, &lt;code&gt;.asa&lt;/code&gt;, &lt;code&gt;.asax&lt;/code&gt;, &lt;code&gt;.ascx&lt;/code&gt;, &lt;code&gt;.ashx&lt;/code&gt;, &lt;code&gt;.asmx&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;JSP: &lt;code&gt;.jsp&lt;/code&gt;, &lt;code&gt;.jspx&lt;/code&gt;, &lt;code&gt;.jspf&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Other: &lt;code&gt;.py&lt;/code&gt;, &lt;code&gt;.pl&lt;/code&gt;, &lt;code&gt;.cgi&lt;/code&gt;, &lt;code&gt;.cfm&lt;/code&gt;, &lt;code&gt;.cfml&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;2.3 Configuration &amp;amp; Exploitation Files&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Risk: Used to overwrite configurations, leak info, or launch XSS/XXE attacks.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Apache: &lt;code&gt;.htaccess&lt;/code&gt; (Can override server rules to execute arbitrary files).&lt;/li&gt;
&lt;li&gt;Configs: &lt;code&gt;.ini&lt;/code&gt;, &lt;code&gt;.conf&lt;/code&gt;, &lt;code&gt;.config&lt;/code&gt;：(May contain sensitive credentials).&lt;/li&gt;
&lt;li&gt;Markup:
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;.xml&lt;/code&gt;: Risk of XXE (XML External Entity) injection.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;.html&lt;/code&gt;, .htm, .svg：Can embed JavaScript for XSS attacks.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</content:encoded></item><item><title>nwipe Tutorial:Secure Data Sanitization via Open-Source Tooling</title><link>https://fuwari.vercel.app/posts/8532da7b-b852-4ad5-81be-9ceddd33fabb/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/8532da7b-b852-4ad5-81be-9ceddd33fabb/</guid><description>nwipe is a lightweight yet powerful open-source data erasure tool supporting various international standard algorithms. This article details its installation, usage, and applicable scenarios to help you thoroughly and securely destroy sensitive data.</description><pubDate>Fri, 22 Aug 2025 23:33:13 GMT</pubDate><content:encoded>&lt;h2&gt;I. What is nwipe?&lt;/h2&gt;
&lt;p&gt;nwipe [1] is an open-source command-line tool specifically designed to securely and thoroughly erase data from storage devices, including Hard Disk Drives (HDDs) and Solid State Drives (SSDs). It is a fork and the modernized successor of the well-known legacy tool DBAN (Darik&apos;s Boot and Nuke).&lt;/p&gt;
&lt;p&gt;Its core objective is to ensure that original data cannot be recovered by any software or hardware forensic methods before disposing of, reselling, or recycling storage media. This is achieved by overwriting the disk with multiple passes of random or specific patterns, thereby protecting privacy and security.&lt;/p&gt;
&lt;p&gt;Project Repository: https://github.com/martijnvanbrummelen/nwipe&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12iwgnl.gif&quot; alt=&quot;nwipe&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;II. Key Features of nwipe&lt;/h2&gt;
&lt;p&gt;Fully Free and Open Source: The transparent code allows for public auditing, ensuring no backdoors exist and making it a trusted tool for security-conscious users.&lt;/p&gt;
&lt;p&gt;Support for Multiple Erasure Standards: It includes internationally recognized algorithms to meet various security compliance levels, such as:
- DoD 5220.22-M: The U.S. Department of Defense standard (3 or 7 passes).
- Gutmann: A classical method proposed by Peter Gutmann (35 passes). While effective for legacy hardware, it may be excessive for modern SSDs.
- PRNG Stream: Uses a pseudo-random number generator for multiple overwrite passes (customizable).
- Verify Only: A rapid mode that checks if sectors are readable without erasing them, useful for detecting bad sectors.&lt;/p&gt;
&lt;p&gt;OS Independent: nwipe is typically integrated into various Live Linux Distributions (e.g., Parted Magic, SystemRescue) or can be made into a bootable USB drive. This allows it to run independently of the host OS, enabling the erasure of the system drive itself while bypassing file locks and permission issues.&lt;/p&gt;
&lt;p&gt;Automation &amp;amp; Batch Processing: Supports command-line arguments, allowing for scripted automated batch erasure—ideal for data centers or environments handling large volumes of drives.&lt;/p&gt;
&lt;p&gt;Detailed Logging &amp;amp; Reporting: Recent versions of nwipe generate comprehensive logs, including serial numbers, models, erasure methods, timestamps, and verification results (PASS/FAIL), which are crucial for audits and compliance.&lt;/p&gt;
&lt;p&gt;Broad Hardware Compatibility: Supports storage devices connected via multiple interfaces, including SATA, SAS, PCIe/NVMe, and USB.&lt;/p&gt;
&lt;h2&gt;III. Installing nwipe&lt;/h2&gt;
&lt;h3&gt;Prerequisites&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;A Linux-based OS (To wipe an entire device, it is recommended to use a Live OS via external media like a USB drive).&lt;/li&gt;
&lt;li&gt;A computer or server capable of recognizing your drives (SAS, SATA, SSD, NVMe, etc.).&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Step-by-Step Installation&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Enter the OS: Any Linux distro works. For full-device erasure, I recommend SystemRescue [2], a Live OS for Linux recovery that comes pre-loaded with nwipe.&lt;/li&gt;
&lt;li&gt;Package Manager Installation:&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;Note: Package managers might not provide the latest version. For PDF reporting, nwipe version ≥ 0.35 is required.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/129bh1v.png&quot; alt=&quot;Package Manager Installation&quot; /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Package Manager Installation👇&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;&lt;code&gt;# For Ubuntu/Debian:
apt-get update -y 
apt-get install nwipe -y

# For CentOS/OpenEuler/RockyLinux:
yum update -y
yum install install nwipe -y 

# dnf 
dnf update -y
dnf install install nwipe -y 
&lt;/code&gt;&lt;/pre&gt;
&lt;ul&gt;
&lt;li&gt;Manual Compilation (For the latest version):&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;&lt;code&gt;wget https://github.com/martijnvanbrummelen/nwipe/archive/refs/tags/v0.38.tar.gz
tar -xzf v0.38.tar.gz
cd nwipe-0.38/
./autogen.sh
./configure
make
sudo make install
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Verify Installation: Run &lt;code&gt;nwipe --version&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;root@ubuntu:~# nwipe --version
nwipe version 0.38
root@ubuntu:~# 
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;IV. How to Perform Data Destruction with nwipe&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Demonstration conducted on a VMware Virtual Machine running Ubuntu Server.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;Execute sudo nwipe to enter the ncurses-based interface.&lt;/li&gt;
&lt;li&gt;Select Storage Media: &lt;strong&gt;Use Up/Down arrows to navigate and Space to select&lt;/strong&gt; (the target will be marked as &quot;wipe&quot;).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12cruqg.png&quot; alt=&quot;nwipe&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Press &lt;code&gt;M&lt;/code&gt; to select the Erase Method. Use arrows and press Enter to confirm.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12defrz.png&quot; alt=&quot;Erase Method&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Press &lt;code&gt;V&lt;/code&gt; to select the Verification Mode. By default, it verifies the last pass; you can disable this to increase speed.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12e1zox.png&quot; alt=&quot;Verify&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Press &lt;code&gt;S&lt;/code&gt; to start. As this is an irreversible operation, a security prompt will appear. You must press &lt;code&gt;Shift + S&lt;/code&gt; (capital &lt;code&gt;S&lt;/code&gt;) to initiate the wipe.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12ejxbf.png&quot; alt=&quot;Start Erase&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Once complete, press CTRL + C to exit. nwipe will generate a report in the current directory (v0.35+).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12fojdv.png&quot; alt=&quot;Complete&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12fspgb.png&quot; alt=&quot;Report&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Finally, export the PDF report for your records.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/22/12y696s.png&quot; alt=&quot;PDF Report&quot; /&gt;&lt;/p&gt;
&lt;p&gt;🔗 Related Links:&lt;/p&gt;
&lt;p&gt;[1] nwipe Project Repository: &lt;a href=&quot;https://github.com/martijnvanbrummelen/nwipe&quot;&gt;https://github.com/martijnvanbrummelen/nwipe&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2] systemrescue Official Website: &lt;a&gt;https://www.system-rescue.org/&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>Data Sanitization:An Overview of Technologies and Standards</title><link>https://fuwari.vercel.app/posts/ed7eea5a-dd95-417c-9bf2-228e7333f6ff/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/ed7eea5a-dd95-417c-9bf2-228e7333f6ff/</guid><description>An analysis of data sanitization technologies and standards, including global overwriting standards (e.g., GA/T 1143, DoD 5220.22-M). This article explores logical wiping for storage media versus physical destruction, compares mainstream standards, and introduces essential tools like AOMEI and nwipe.</description><pubDate>Tue, 19 Aug 2025 20:35:12 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Data Sanitization refers to the process of completely erasing data from storage media through physical or logical means, rendering it unrecoverable to prevent sensitive information leakage. This technology is widely utilized by government agencies and enterprises across various carriers including HDDs, magnetic tapes, optical discs, and paper documents. The choice of sanitization method must strictly adhere to the medium type, storage principles, and data sensitivity level.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;I. Storage Media: Principles and Characteristics&lt;/h2&gt;
&lt;h3&gt;1. Hard Disk Drive (HDD)&lt;/h3&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4e5e.png&quot; alt=&quot;HDD&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Principle: Data is stored on magnetic tracks of spinning platters and read/written via magnetic heads.&lt;/li&gt;
&lt;li&gt;Sanitization Challenges: Conventional deletion operations (e.g., OS file deletion) only remove file system metadata (like FAT tables or MFT records); the actual data remains on the tracks. Achieving irreversible erasure requires methods such as multiple-pass overwriting, degaussing, or physical destruction.&lt;/li&gt;
&lt;li&gt;Recommended Methods: Multiple-pass overwriting, Degaussing, Physical shredding.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;2. Solid State Drive (SSD) / NVMe Drive&lt;/h3&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz3w4b.png&quot; alt=&quot;SSD&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Principle: Data is stored in NAND flash cells and managed by a controller using FTL (Flash Translation Layer) for read/write operations and wear leveling.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Sanitization Challenges:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;FTL Interference: Traditional overwriting is inefficient on SSDs. The FTL maps overwrite operations to new empty blocks, leaving original data blocks marked as &quot;invalid&quot; but not immediately erased until Garbage Collection occurs. This leads to data remanence.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Lifetime Degradation: Flash cells have finite P/E (Program/Erase) Cycles. Excessive overwriting significantly shortens the SSD&apos;s lifespan.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Recommended Methods: Controller-based Secure Erase (SE) or Sanitize commands (e.g., ATA/NVMe standards). These reset all cells (including over-provisioned space) to factory defaults via internal discharge, ensuring data is unrecoverable with minimal wear. Physical destruction is also highly reliable.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;II. Data Overwriting Standards (Mainly for HDD)&lt;/h2&gt;
&lt;h3&gt;1. OnePass (Single Pass)&lt;/h3&gt;
&lt;p&gt;A single full-disk write of a fixed pattern (e.g., &lt;code&gt;0x00&lt;/code&gt;, &lt;code&gt;0xFF&lt;/code&gt;) or random data.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pros: Fast.&lt;/li&gt;
&lt;li&gt;Security: Low.&lt;/li&gt;
&lt;li&gt;Use Case: Non-sensitive data requiring rapid clearance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;2. GA/T 1143-2014 (China)&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Technical requirements for data destruction software products.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4mng.png&quot; alt=&quot;GA/T 1143-2014&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Single Pass: Same as OnePass.&lt;/li&gt;
&lt;li&gt;3-Pass Method: 1st pass: Fixed character (e.g., &lt;code&gt;0x00&lt;/code&gt;); 2nd pass: Complement (e.g., &lt;code&gt;0xFF&lt;/code&gt;); 3rd pass: Random characters.&lt;/li&gt;
&lt;li&gt;7-Pass Method: Alternates between fixed characters, complements, single-character patterns, and random characters across seven cycles.&lt;/li&gt;
&lt;li&gt;Use Case: High-sensitivity data where maximum unrecoverability is required.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;3. DoD 5220.22-M (USA)&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;The U.S. Department of Defense standard upon which most global standards are derived.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4cgr.jpg&quot; alt=&quot;DoD 5220.22-M&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Short (3-Pass): 0x00, 0xFF, Random.&lt;/li&gt;
&lt;li&gt;Standard (ECE/7-Pass): A more rigorous sequence including multiple passes of 0x00, 0xFF, and random data.&lt;/li&gt;
&lt;li&gt;Security: Extremely high; designed to overcome the magnetic remanence effect.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;4. IEEE Std 2883-2022&lt;/h3&gt;
&lt;p&gt;Requires at least two passes: Fixed character followed by its complement, with a verification step involving a random sampling of ≥5% of the addressable space.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Crucial Note: Multiple-pass standards (DoD, GA/T) are designed specifically for the physical characteristics of HDDs. They are not recommended for SSDs/NVMe drives due to FTL mechanisms, wear issues, and inefficiency compared to Secure Erase commands.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;III. Data Sanitization Standards (Mainly for SSD)&lt;/h2&gt;
&lt;h3&gt;NIST SP 800-88 Purge / Secure Erase (SE)&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Principle: Sends specific instructions (e.g., NVMe Format NVM with Sanitize) to the controller. The controller resets the voltage levels of all NAND cells (including over-provisioned areas), returning the drive to its factory &quot;out-of-box&quot; state.&lt;/li&gt;
&lt;li&gt;Advantages: - Thorough: Clears all physical blocks, including those hidden from the OS.
&lt;ul&gt;
&lt;li&gt;Fast: Significantly faster than multi-pass overwriting.&lt;/li&gt;
&lt;li&gt;Low Wear: Minimal impact on P/E cycles.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Requirements: Requires hardware/firmware support. BIOS/UEFI or drive passwords must be disabled before execution.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;IV. Common Data Sanitization Tools&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;AOMEI Partition Assistant
Supported Standards: OnePass, DoD 5220.22-M, Gutmann (35-pass), etc.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4v3b.png&quot; alt=&quot;傲梅助手&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pros: User-friendly GUI.&lt;/li&gt;
&lt;li&gt;Cons: Requires Windows or WinPE.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;nwipe
Supported Standards: Various patterns (DoD, Gutmann, etc.).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4kbl.png&quot; alt=&quot;nwipe&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pros: Open-source CLI tool for Linux Live environments; version 0.35+ supports generating PDF erasure - certificates for audit compliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;DiskGenius&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/08/19/xz4seo.png&quot; alt=&quot;DiskGenius&quot; style=&quot;display:block; margin:auto;&quot; /&amp;gt;
&amp;lt;br&amp;gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pros: Reliable sector-level operations with a GUI.&lt;/li&gt;
&lt;li&gt;Cons: Limited sanitization algorithms compared to specialized tools.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;RAID/HBA Hardware Erase
Utilizes the onboard processor of modern RAID or HBA cards to send erase commands directly to connected drives. It is OS-independent and efficient.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;V. Summary and Recommendations&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Medium Differentiation is Key: - HDD: Use multi-pass standards (GA/T 1143 3/7-pass, DoD 5220.22-M) or degaussing for sensitive data.&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;SSD/NVMe: Prioritize controller-based Secure Erase or Sanitize (NIST SP 800-88 Purge). Avoid multi-pass overwriting.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;Ultimate Security: Physical shredding remains the &quot;Gold Standard&quot; for end-of-life media.&lt;/li&gt;
&lt;li&gt;Verification: For high-compliance environments, use tools that support Erasure Verification (IEEE 2883) and generate Audit Certificates.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;🔗 Standard Downloads:
[1] GA/T 1143-2014 Standard: &lt;a href=&quot;https://std.samr.gov.cn/hb/search/stdHBDetailed?id=8B1827F21EEBBB19E05397BE0A0AB44A&quot;&gt;https://std.samr.gov.cn/hb/search/stdHBDetailed?id=8B1827F21EEBBB19E05397BE0A0AB44A&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>A Guide to Offline Security Appliance Updates:A Collection of Vendor Download Portals (Continuously Updated)</title><link>https://fuwari.vercel.app/posts/8e9d7cba-3411-42bd-b3ca-e663cd449efa/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/8e9d7cba-3411-42bd-b3ca-e663cd449efa/</guid><description>Security appliances operating in non-networked environments require regular manual updates for signature databases and system firmware. However, finding offline update packages across various vendor portals can be challenging. This article aggregates offline update links for major vendors to streamline the maintenance process and improve update efficiency.</description><pubDate>Sun, 20 Jul 2025 23:19:21 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;In practical O&amp;amp;M (Operations &amp;amp; Maintenance), many security appliances—such as firewalls, IDS/IPS, and Anti-DDoS systems—are deployed in intranet or air-gapped environments. These devices cannot directly connect to the internet to update signature databases or system patches; instead, offline update packages must be downloaded and imported manually. Since vendor download pages are often fragmented or difficult to locate (and frequently require authentication), I have compiled this list of &lt;strong&gt;offline update portals&lt;/strong&gt; for major security vendors to simplify centralized discovery and maintenance.
This content will be continuously updated—feel free to bookmark, share, or contribute.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;🚀 Update Center Directory&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Offline Update Portal&lt;/th&gt;
&lt;th&gt;Login Required&lt;/th&gt;
&lt;th&gt;Last Updated&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Huawei&lt;/td&gt;
&lt;td&gt;https://isecurity.huawei.com/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sangfor&lt;/td&gt;
&lt;td&gt;https://support.sangfor.com.cn/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Nsfocus&lt;/td&gt;
&lt;td&gt;https://update.nsfocus.com/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hillstone&lt;/td&gt;
&lt;td&gt;https://update1.hillstonenet.com/&amp;lt;br&amp;gt;https://update2.hillstonenet.com/&amp;lt;br&amp;gt;http://sec-cloud.hillstonenet.com/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Qianxin&lt;/td&gt;
&lt;td&gt;https://ngfwup.sg.qianxin.com/offline/download/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Venustech&lt;/td&gt;
&lt;td&gt;https://venustech.download.venuscloud.cn/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Topsec&lt;/td&gt;
&lt;td&gt;https://knowledge.topsec.com.cn/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Chaitin&lt;/td&gt;
&lt;td&gt;https://product-support.chaitin.cn/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DBAPPSecurity&lt;/td&gt;
&lt;td&gt;https://bbs.dbappsecurity.com.cn/&amp;lt;br&amp;gt;http://www.websaas.com.cn/&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;2025-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;💡 &lt;strong&gt;Note&lt;/strong&gt;: ✅ indicates that account authentication is required to access the page or download content.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;📮 Contributions &amp;amp; Feedback&lt;/h2&gt;
&lt;p&gt;If you find that any links have changed, expired, or if you have information regarding other vendors&apos; offline updates, please feel free to contribute. You can reach me via:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Email：📧 &lt;a href=&quot;mailto:admin@bytesycn.com&quot;&gt;admin@bytesycn.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;🛠️ Maintenance Plan&lt;/h2&gt;
&lt;p&gt;This page will be audited and updated periodically. If your organization or clients have specific vendor update requirements not listed here, please leave a comment, and I will do my best to include them.&lt;/p&gt;
</content:encoded></item><item><title>Is InfiniBand&apos;s &quot;Infinite Bandwidth&quot; Truly Infinite? 🤔</title><link>https://fuwari.vercel.app/posts/f235a39f-8bb0-4ca6-abd6-c615eed26ae6/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/f235a39f-8bb0-4ca6-abd6-c615eed26ae6/</guid><description>A brief discussion on InfiniBand (IB)—the powerhouse of high-speed networking—and our design process for implementing a storage network using IB technology.</description><pubDate>Sun, 06 Jul 2025 23:30:00 GMT</pubDate><content:encoded>&lt;h2&gt;Preface&lt;/h2&gt;
&lt;p&gt;Recently, my friend and I decided to upgrade the storage for our &apos;DataCenter&apos; (essentially a cluster of servers). Our goal was clear: deploy a centralized storage system featuring both All-Flash and Hybrid-Flash tiers to provide mount services for virtualization nodes, aiming for an &quot;enterprise-grade&quot; feel.&lt;/p&gt;
&lt;p&gt;While purchasing a turnkey solution like Huawei’s OceanStor Dorado would be the simplest route, this setup is primarily for personal tinkering and occasional testing. Therefore:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Open-source solutions are our destiny!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;为啥选开源？别问，问就是预算有限（qiong）！# 手动狗头&lt;/p&gt;
&lt;h3&gt;⚡️ Calculating Theoretical All-Flash Throughput&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Assuming a single SSD has a R/W speed of ~500MB/s (~5Gbps), a 6-disk RAID 5 array theoretically yields:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Write: 500MB/s * (6-1) ≈ 2.5GB/s (Parity overhead may reduce actual performance).&lt;/li&gt;
&lt;li&gt;Read: 550MB/s * 6 ≈ 3.3GB/s (Significantly exceeding 10Gbps).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While a RAID 0 array would be even faster, our &quot;retired&quot; storage server is limited by a 12Gbps SAS RAID card. To go higher, we would need to move to direct PCIe paths (NVMe), which is currently beyond our budget. Thus, we set 10Gbps as our baseline requirement for the transmission medium.&lt;/p&gt;
&lt;h3&gt;Transmission Media&lt;/h3&gt;
&lt;p&gt;10Gbps media is now ubiquitous: Fiber optics, DAC (Direct Attach Copper) cables, or even high-quality Cat6A Ethernet for short distances. We previously stockpiled some &quot;gray market&quot; gear, such as Mellanox CX341 40Gbps NICs. We initially considered a Peer-to-Peer (P2P) connection, but with three compute nodes, the NIC requirements for the storage server became impractical.&lt;/p&gt;
&lt;p&gt;To remain cost-effective, we acquired a used Cisco Nexus 3064PQ-10GX (48x10G SFP+ ports + 4x40G QSFP ports). A dedicated switch perfectly solves the multi-node connectivity issue.&lt;/p&gt;
&lt;h3&gt;Storage System&lt;/h3&gt;
&lt;p&gt;Consumer-grade NAS OSs aren&apos;t quite built for this level of performance. We settled on TrueNAS—it’s open-source, free, and provides robust support for All-Flash/Hybrid-Flash tiers backed by the powerful ZFS file system.&lt;/p&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12pwinq.png&quot; width=&quot;50%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;TrueNas&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;h3&gt;Network Architecture:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Compute Nodes: Connected via 10Gbps NICs.&lt;/li&gt;
&lt;li&gt;Storage Server: Connected via 40Gbps NICs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While this creates a high-speed storage fabric, a new problem arises: with 50-60 VMs running simultaneously, concurrent I/O could easily saturate the 10Gbps bandwidth. Furthermore, the low-power CPUs we chose for the storage server would struggle with the TCP/IP stack overhead.&lt;/p&gt;
&lt;p&gt;The Solution? RDMA.&lt;/p&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12faaun.png&quot; width=&quot;50%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;p&gt;Our Mellanox NICs are famous for RDMA (Remote Direct Memory Access). This technology bypasses the CPU, moving data directly between the NIC and memory with extreme efficiency and ultra-low latency.&lt;/p&gt;
&lt;h2&gt;Introduction to RDMA &amp;amp; InfiniBand&lt;/h2&gt;
&lt;p&gt;Before discussing RDMA, we must address its foundation: InfiniBand (IB).&lt;/p&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12eh0a7.jpg&quot; width=&quot;30%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;InfiniBand Trade Association&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;p&gt;InfiniBand is a high-performance, low-latency communication protocol widely used in Supercomputing, Data Centers, and AI training clusters. The &quot;magic&quot; of RDMA is primarily realized through this fabric.&lt;/p&gt;
&lt;p&gt;The name &quot;InfiniBand&quot; suggests &quot;Infinite Bandwidth.&quot; While technically hyperbole, it refers to its massive throughput and extreme scalability, which effectively shatters the performance ceilings of traditional Ethernet. At SC24, NVIDIA showcased the ConnectX-8, boasting single-port speeds of 800Gbps—enough to transfer a Blu-ray movie in one second.&lt;/p&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12gjlpt.png&quot; width=&quot;50%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;ConnectX-8 &amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;h3&gt;✅ Advantages of InfiniBand:&lt;/h3&gt;
&lt;h4&gt;1. Ultra-High Bandwidth&lt;/h4&gt;
&lt;p&gt;Ideal for HPC and AI model training where Terabytes of data are moved constantly.&lt;/p&gt;
&lt;h4&gt;2. Ultra-Low Latency + Zero-Copy&lt;/h4&gt;
&lt;p&gt;This is the primary differentiator from standard Ethernet:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;RDMA Support: Direct memory-to-memory transfer.&lt;/li&gt;
&lt;li&gt;Kernel Bypass: Data bypasses the CPU and OS kernel.&lt;/li&gt;
&lt;li&gt;Minimal CPU Overhead: Latency is measured in sub-microseconds, compared to the tens of microseconds found in traditional Ethernet.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12ft4xz.png&quot; width=&quot;50%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;div align=&quot;center&quot;&amp;gt; &amp;lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/06/12ft5gw.png&quot; width=&quot;50%&quot;&amp;gt; &amp;lt;p style=&quot;font-size: 14px; color: gray;&quot;&amp;gt;RDMA&amp;lt;/p&amp;gt; &amp;lt;/div&amp;gt;&lt;/p&gt;
&lt;h3&gt;🧱 Disadvantages:&lt;/h3&gt;
&lt;p&gt;RoCE (RDMA over Converged Ethernet) allows IB protocols to run on traditional Ethernet hardware, which mitigates cost, but still requires specific NIC and software support.&lt;/p&gt;
&lt;h4&gt;1. Closed Ecosystem and Cost&lt;/h4&gt;
&lt;p&gt;IB isn&apos;t just a cable; it’s a proprietary ecosystem requiring:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Dedicated IB Switches.&lt;/li&gt;
&lt;li&gt;IB HCA (Host Channel Adapters).&lt;/li&gt;
&lt;li&gt;Specific software stacks (OpenFabrics Enterprise Distribution - OFED).
🧾 造价高是一大门槛，尤其是中小规模部署时性价比并不理想，不过好嘴RoCE的推出让IB网络可以在传统以太网络上跑，利用现有的高速以太网络硬件，不过还是需要IB网卡以及IB网络所支持软件支持。&lt;/li&gt;
&lt;/ol&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;InfiniBand&lt;/th&gt;
&lt;th&gt;iWARP (TCP-based)&lt;/th&gt;
&lt;th&gt;RoCE (Ethernet-based)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Performance&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Best&lt;/td&gt;
&lt;td&gt;Lower (TCP overhead)&lt;/td&gt;
&lt;td&gt;Comparable to IB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cost&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;td&gt;Low&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Switch Type&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Dedicated IB Switch&lt;/td&gt;
&lt;td&gt;Ethernet Switch&lt;/td&gt;
&lt;td&gt;Ethernet Switch&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;上表数据来自华为支持&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt;&lt;/p&gt;
&lt;h4&gt;2. Lack of Native Interoperability&lt;/h4&gt;
&lt;p&gt;InfiniBand does not use the standard IP protocol suite. It has its own addressing and flow control. To connect an IB fabric to an Ethernet network, you need an IB-Ethernet Gateway for protocol translation.&lt;/p&gt;
&lt;h2&gt;✍️ Final Thoughts&lt;/h2&gt;
&lt;p&gt;RDMA and InfiniBand are &quot;performance-at-any-cost&quot; solutions. However, with the rise of AI and Cloud Computing, many enterprise scenarios are hitting the limits of traditional Ethernet. In applications requiring High Bandwidth + High Concurrency + Ultra-Low Latency, IB is becoming essential.&lt;/p&gt;
&lt;p&gt;From a technical perspective, IB isn&apos;t for everyone due to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;High Capital Expenditure (CAPEX): Switches and HCAs are expensive.&lt;/li&gt;
&lt;li&gt;Operational Complexity: It requires specialized knowledge to maintain.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;When should you consider InfiniBand?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deploying AI training/inference clusters with multiple GPU nodes (A100/H100).&lt;/li&gt;
&lt;li&gt;Using distributed storage (e.g., Ceph) where latency is critical.&lt;/li&gt;
&lt;li&gt;Massive data distribution systems requiring maximum throughput.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔗 link:&lt;/p&gt;
&lt;p&gt;[1] &lt;a href=&quot;https://nvdam.widen.net/s/pxsjzhgw6j/connectx-datasheet-connectx-8-supernic-3231505&quot;&gt;https://nvdam.widen.net/s/pxsjzhgw6j/connectx-datasheet-connectx-8-supernic-3231505&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2] &lt;a href=&quot;https://support.huawei.com/enterprise/zh/doc/EDOC1100203347&quot;&gt;https://support.huawei.com/enterprise/zh/doc/EDOC1100203347&lt;/a&gt;&lt;/p&gt;
</content:encoded></item><item><title>VMware ESXi VM &quot;Redo Log Corrupted&quot;? Don&apos;t Panic, Here’s How to Resurrect It! 🚑</title><link>https://fuwari.vercel.app/posts/2dfb7391-93eb-4cd0-b56b-2664d8824d11/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/2dfb7391-93eb-4cd0-b56b-2664d8824d11/</guid><description>If you encounter a virtual machine boot failure on the VMware ESXi platform with the error &apos;The redo log is corrupted,&apos; it typically indicates an issue with the VM&apos;s snapshot files. Here are the effective steps to resolve this problem.</description><pubDate>Thu, 03 Jul 2025 22:02:10 GMT</pubDate><content:encoded>&lt;p&gt;Hey there 👋, back with another post! As some of you may know (or maybe I haven&apos;t mentioned it yet), a friend and I run a small virtualization cluster in a remote rural area. It hosts most of our self-developed applications and testing environments. Everything was running smoothly until we ran into a challenge: the local power grid is somewhat unstable. Frequent, sudden power outages often cause hard shutdowns across our cluster. After a recent improper power-off, our Reverse Proxy VM—which handles all external mapping—completely went on strike. Upon booting, it kept throwing the error: &quot;The redo log is corrupted!&quot; 🤯&lt;/p&gt;
&lt;p&gt;Because this cluster strictly follows a small-enterprise network architecture—with clearly defined DMZ, Tunnel, and Trust zones—there are only one or two zones capable of external mapping. Once this reverse proxy went down, several of our external-facing services were effectively &quot;cut off.&quot; A timely fix was non-negotiable.&lt;/p&gt;
&lt;h2&gt;🙋 The Issue Looked Like This:&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The redo log of &apos;xxxxxx.vmdk&apos; is corrupted. If the problem persists, discard the redo log.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Seeing this prompt left me momentarily stunned. Only one thought crossed my mind: We’re in trouble. 🥶&lt;/p&gt;
&lt;h2&gt;Troubleshooting Approach&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;VMDK? It must be disk-related! 💾&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Since the error explicitly mentioned VMDK, it was highly probable that the VM&apos;s virtual disks were the culprit. I recalled that this VM had several existing snapshots, so I immediately attempted a disk consolidation. The result? Well... it didn&apos;t do much. 🤷 The VM remained stagnant and refused to boot.&lt;/p&gt;
&lt;p&gt;When you&apos;re faced with a mission-critical VM that won&apos;t start and you don&apos;t have a fresh backup, the rule of thumb is to try every possible method (ideally after securing whatever data you can). In my case, I decided to Delete All Snapshots!&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/03/10juga6.png&quot; alt=&quot;Virtual Machine Snapshot Management&quot; /&gt;
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/03/10jtqnx.png&quot; alt=&quot;Delete All Snapshots&quot; /&gt;&lt;/p&gt;
&lt;p&gt;After confirming the deletion and watching the progress bar reach 100%, a minor miracle happened: the &quot;striking&quot; reverse proxy VM successfully booted up! 🎉🎉🎉 Back to &quot;business&quot; as usual; the world suddenly felt right again! 🥳&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/03/10js17h.png&quot; alt=&quot;Normal Startup&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;🚨 Pro-Tip (A Must-Read for Production Environments!! Critical!!!) 🚨&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;If you are managing vSphere VMs in a production environment, I strongly recommend cloning the VM to create a full backup before performing any destructive operations! This ensures you have a rollback path to avoid further data loss.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As for our &quot;home lab&quot; setup—well, we can afford to be a bit more adventurous. 😅 At worst, I’d just have to redeploy the VM and reconfigure everything from scratch. It’s a tedious process, but certainly better than having no service at all!&lt;/p&gt;
</content:encoded></item><item><title>PicImpact Upload Failures with Cloudflare R2? Here’s the Fix.</title><link>https://fuwari.vercel.app/posts/02139ee4-d1ee-496a-94a2-e1f68c1a2982/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/02139ee4-d1ee-496a-94a2-e1f68c1a2982/</guid><description>Deploying PicImpact is straightforward, but Cloudflare R2 can be tricky. Even if you follow the documentation perfectly, uploads might consistently fail without clear error messages. After tweaking permissions and investigating CORS, I realized that R2 requires more than just a &apos;default&apos; configuration. You need to understand its upload logic and dodge a few common pitfalls to make it work.</description><pubDate>Wed, 02 Jul 2025 01:02:38 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;PicImpact is a self-hosted photography showcase platform built on Next.js and Hono.js. Its interface is elegant and functional—perfect for those who love customizing their tech stack but don&apos;t want to build a frontend from scratch. 🙋‍♂️&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;📌 Project Resources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;🌐 GitHub:
&lt;a href=&quot;https://github.com/besscroft/PicImpact&quot;&gt;https://github.com/besscroft/PicImpact&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;📖 Documentation:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://pic-docs.ziyume.com&quot;&gt;https://pic-docs.ziyume.com&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;🪪 License: MIT&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;🪄 Why Choose PicImpact?&lt;/h2&gt;
&lt;p&gt;I was searching for a sleek image hosting template for my photography site, &lt;a href=&quot;https://moments.bytesycn.cn&quot;&gt;Moments&lt;/a&gt;. PicImpact stood out for its clean UI and Docker support—a perfect &quot;one-and-done&quot; solution.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;🚫 Why not local deployment?
&amp;lt;br&amp;gt;Don&apos;t ask. I just didn&apos;t want to deal with the overhead of a local Node.js environment... 💀&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;🐳 Docker Deployment Experience&lt;/h2&gt;
&lt;p&gt;The deployment is incredibly smooth. As long as your PostgreSQL instance is ready (either local or a managed cloud DB), you just run the following command, and you&apos;re airborne:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;docker run -d --name picimpact \
  -p 3000:3000 \
  -e DATABASE_URL=&quot;postgresql://[USER]:[PASSWORD]@[HOST]:[PORT]/[DB_NAME]&quot; \
  -e BETTER_AUTH_SECRET=&quot;npx auth secret or a random string&quot; \
  besscroft/picimpact:latest
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;🧨 The Obstacle...&lt;/h2&gt;
&lt;p&gt;Initially, I used Alist as the storage backend, but I was bottlenecked by my home broadband&apos;s limited upload speed 🥲. So, I pivoted to Cloudflare&apos;s R2—the generous &quot;Saint&quot; of free object storage.&lt;/p&gt;
&lt;p&gt;However, after configuration, the upload process went haywire:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;The UI popup showed a &quot;Success&quot; checkmark ☑️, but the image status below displayed &lt;strong&gt;Upload.failed&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The Browser Console was a gallery of errors:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;ERR_NAME_NOT_RESOLVED&lt;/li&gt;
&lt;li&gt;ERR_SSL_VERSION_OR_CIPHER_MISMATCH&lt;/li&gt;
&lt;li&gt;ERR_FAILED&lt;/li&gt;
&lt;li&gt;has been blocked by CORS policy: ... No &apos;Access-Control-Allow-Origin&apos; header&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Is it successful? The R2 dashboard was empty.
Is it a failure? The frontend insisted it was &quot;Success.&quot;
I felt like I had triggered every possible error in the PicImpact library 🤦‍♂️. Eventually, I narrowed it down to a CORS configuration issue.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/ni39d.png&quot; alt=&quot;Upload Error&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;🛠️ Setting Up Cloudflare R2&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Cloudflare R2 offers 10GB of free monthly storage with no egress fees. Note that CF nodes are primarily overseas, so latency may vary. For higher performance in China, consider Tencent COS or Alibaba OSS.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Access R2 Storage
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/pxox0.png&quot; alt=&quot;R2 Object Storage&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create a Bucket.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/x3ieg.png&quot; alt=&quot;Create Bucket&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Bucket Parameters&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;You can choose any location, as latency is similar. However, ensure you select the Standard storage class to stay within the free tier.😯&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/y23vn.png&quot; alt=&quot;Bucket Config&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Custom Domain&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;You must use a domain whose Nameservers (NS) point to Cloudflare.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/z8ucu.png&quot; alt=&quot;Custom Domain&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL: Configure CORS Policy&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;This is the dealbreaker. If you miss this, you’ll end up wasting hours like I did.～&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1o55yt.png&quot; alt=&quot;CORS&quot; /&gt;&lt;/p&gt;
&lt;p&gt;CORS Policy Sample: Note that &lt;code&gt;AllowedHeaders&lt;/code&gt; is mandatory; R2’s default generator often omits it.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;[
  {
    &quot;AllowedOrigins&quot;: [
      &quot;http://localhost:3000&quot;
    ],
    &quot;AllowedMethods&quot;: [
      &quot;GET&quot;,
      &quot;HEAD&quot;,
      &quot;PUT&quot;,
      &quot;POST&quot;,
      &quot;DELETE&quot;
    ],
    &quot;AllowedHeaders&quot;: [
      &quot;*&quot;
    ]
  }
]
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Create API Tokens
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1q3445.png&quot; alt=&quot;Create API&quot; /&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As a security professional, I strongly advocate for the Principle of Least Privilege.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1qj29j.png&quot; alt=&quot;Create User token&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Avoid creating &quot;Account API Tokens&quot; if possible; a specific User API Token scoped only to the required bucket is much safer.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1ra5q8.png&quot; alt=&quot;API&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Save API Credentials&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
&lt;p&gt;These credentials (Access Key ID, Secret Access Key, and Account ID) appear only once. You will need the S3 API info for PicImpact.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1s0p7s.png&quot; alt=&quot;API Info&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;🔗 Integrating PicImpact with CF-R2&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Navigate to the PicImpact dashboard: Storage Config -&amp;gt; Cloudflare R2 -&amp;gt; Edit.
&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1u500p.png&quot; alt=&quot;Cloudfalre R2&quot; /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Fill in the Details:&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;r2_accesskey_id: Your Access Key ID.&lt;/li&gt;
&lt;li&gt;r2_accesskey_secret: Your Secret Access Key.&lt;/li&gt;
&lt;li&gt;r2_account_id: The prefix of your S3 endpoint (e.g., if the endpoint is &lt;code&gt;https://123456.r2.cloudflarestorage.com&lt;/code&gt;, use &lt;code&gt;123456&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;r2_bucket: Your bucket name.&lt;/li&gt;
&lt;li&gt;r2_storage_folder: Path prefix. If using the root, leave blank. Do not start with a slash (/).&lt;/li&gt;
&lt;li&gt;r2_public_domain: Your custom domain from step 4. Must include the protocol (e.g., &lt;code&gt;https://abc.com&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;r2_direct_download: Usually set to &lt;code&gt;false&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/03/10ix0aa.png&quot; alt=&quot;R2&quot; /&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Success: You&apos;re now ready to showcase your work!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/07/02/1yi0eq.png&quot; alt=&quot;Moments&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;✅ Final Thoughts&lt;/h2&gt;
&lt;p&gt;PicImpact is a fantastic project with an elegant UI. While the documentation doesn&apos;t provide a &quot;step-by-step&quot; for every storage provider, that&apos;s the beauty of open-source—the joy of tinkering.&lt;/p&gt;
&lt;p&gt;The &quot;False Success&quot; caused by CORS is particularly misleading. If you’re struggling with PicImpact + CF-R2, remember:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Check the Console errors first.&lt;/li&gt;
&lt;li&gt;Verify your CORS headers (especially AllowedHeaders).&lt;/li&gt;
&lt;li&gt;Confirm that files are actually landing in the bucket dashboard.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Hopefully, this guide saves you some hair-pulling! 🤯&lt;/p&gt;
</content:encoded></item><item><title>Insights into Pre-Exercise Preparations for Cyber Offensive and Defensive Drills</title><link>https://fuwari.vercel.app/posts/bc2bdcf9-39c0-40ce-b553-631bd6493d3a/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/bc2bdcf9-39c0-40ce-b553-631bd6493d3a/</guid><description>Against the backdrop of intensive regulatory implementation and a continuously evolving threat landscape, solid preparation for offensive and defensive drills is no longer an optional &apos;nice-to-have.&apos; It is a statutory responsibility for organizations and a cornerstone for ensuring business continuity. This article explores effective pre-drill preparation strategies.</description><pubDate>Sat, 28 Jun 2025 21:33:19 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;In recent years, cyber offensive and defensive drills (often referred to as &apos;Red Teaming/Blue Teaming&apos; or &apos;Real-world Combat Drills&apos;) have become increasingly normalized, institutionalized, and large-scale. This trend is driven by national-level emphasis on cybersecurity and data governance. With the implementation of the Cybersecurity Law and the Data Security Law of the People&apos;s Republic of China, combat-readiness requirements and legal compliance responsibilities have been elevated to unprecedented heights.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Consequently, thorough preparation is essential not only for legal compliance but also for securing core business stability. This article conducts a preliminary discussion on how to effectively execute these preparations.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Security Equipment Selection and Deployment Strategy&lt;/h2&gt;
&lt;p&gt;A robust network environment is the foundation of effective defense. Equipment selection should be closely aligned with an organization&apos;s business scale, risk appetite, compliance requirements, and budgetary constraints. Below are typical configuration recommendations:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Protection Level&lt;/th&gt;
&lt;th&gt;Core Equipment Configuration&lt;/th&gt;
&lt;th&gt;Budget&lt;/th&gt;
&lt;th&gt;Use Case Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Baseline&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Next-Generation Firewall (NGFW)&lt;/td&gt;
&lt;td&gt;💰&lt;/td&gt;
&lt;td&gt;Small organizations with few systems and low risk. NGFW provides basic access control, stateful inspection, and simple Web protection.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Standard&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;NGFW + Network Traffic Analysis (NTA) Probe (integrated with SOC/SIEM)&lt;/td&gt;
&lt;td&gt;💰💰&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Recommended baseline.&lt;/strong&gt; NGFW handles perimeter defense; NTA provides full network visibility and deep analysis via traffic mirroring; the platform handles centralized monitoring and threat correlation.。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Advanced&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;NGFW + NTA + Intrusion Prevention System (IPS)&lt;/td&gt;
&lt;td&gt;💰💰💰&lt;/td&gt;
&lt;td&gt;Focused protection for critical business zones. IPS provides deep packet inspection (DPI) and real-time blocking of known exploits, forming defense-in-depth with the NGFW.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Comprehensive&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;NGFW + NTA + IPS + SWG + Endpoint Detection &amp;amp; Response (EDR)&lt;/td&gt;
&lt;td&gt;💰💰💰💰💰&lt;/td&gt;
&lt;td&gt;Large institutions or high-risk industries. Integrates perimeter, internal monitoring, application-layer defense, endpoint security, and auditing for a &quot;Cloud-Network-Edge-Endpoint&quot; defense-in-depth architecture.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Focusing on Core Protections&lt;/h3&gt;
&lt;h4&gt;1. Pragmatic Choices for Small-Scale Scenarios:&lt;/h4&gt;
&lt;p&gt;For small enterprises with limited resources, &quot;stacking&quot; equipment is not necessary. A single, well-configured Next-Generation Firewall (NGFW) can meet fundamental needs. Modern NGFWs integrate several legacy standalone functions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Secure Web Gateway (SWG) capabilities: Auditing and controlling internal user web activities.&lt;/li&gt;
&lt;li&gt;Web Application Firewall (WAF) features: Defending against SQL Injection, XSS, and remote command execution.&lt;/li&gt;
&lt;li&gt;Encrypted Tunnel Identification: Detecting and controlling VPNs or hidden proxy channels.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;2. The Value of the Standard Configuration: NTA + Situational Awareness (SOC)&lt;/h4&gt;
&lt;p&gt;In standard configurations, we strongly recommend deploying Network Traffic Analysis (NTA) probes at key network junctions (usually core switching areas) linked to a centralized platform.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Global Visibility: Probes capture traffic via mirroring, providing a &quot;God’s-eye view&quot; of internal lateral movement that perimeter logs simply cannot see.&lt;/li&gt;
&lt;li&gt;Defense-in-Depth Supplement: While NGFWs have IPS features, their focus is the perimeter. Probes and dedicated IPS units in core zones provide internal lines of defense.&lt;/li&gt;
&lt;li&gt;Objective Evaluation of Endpoint Security: While free security software provides basic malware protection, it lacks centralized management and advanced threat detection. Professional EDR provides deep behavioral monitoring and threat hunting. The value of NTA is that even if endpoint protection is bypassed, it independently captures traces of lateral movement, Command and Control (C2) communication, and data exfiltration at the network layer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Normalized Security Policies: &quot;Automatic Transmission&quot; for Defense&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;In large-scale drills, the &quot;Old School&quot; tactics of the Red Team remain largely unchanged: credential stuffing/weak passwords and the exploitation of N-day vulnerabilities. However, do not underestimate automated &quot;script kiddies&quot; who use scanners to bombard targets with PoC (Proof of Concept) exploits. If security policies are misconfigured (e.g., &apos;Allow All&apos;), the defense system becomes a VIP pass for attackers.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;说实话，见过不少地方的安全设备配置，策略写得那叫一个“大气磅礴”——any to any permit（允许所有流量通行）！这哪是安全设备，简直是给攻击者开的VIP通道嘛。合规是基础，但安全供应商交付时，起码得把那些“高危必杀技”策略给配上并开启吧？特别起码是untrust to trust区域要拒绝掉，这可是基础中的基础！&lt;/p&gt;
&lt;h3&gt;🛡️ Strategy 1: Enable the &quot;IPS Engine&quot; on your NGFW&lt;/h3&gt;
&lt;p&gt;Many NGFWs have their Intrusion Prevention System (IPS) capabilities disabled or set to &quot;Detect Only&quot; due to performance concerns. During drills, you must enable &quot;Block&quot; mode for all traffic policies. This acts as the first automated barrier against known exploits and malicious scanning.&lt;/p&gt;
&lt;h3&gt;🚫 Strategy 2: Harden High-Risk Ports&lt;/h3&gt;
&lt;p&gt;Minimal exposure is the goal. Use a Whitelist (Specific Trusted Source IPs) whenever possible. If a port must be open to the world, ensure the underlying service is fully hardened.
Below is a &quot;Blacklist&quot; of ports that should generally be blocked at the perimeter unless absolutely necessary:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Port&lt;/th&gt;
&lt;th&gt;Service&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;20-21&lt;/td&gt;
&lt;td&gt;FTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;22&lt;/td&gt;
&lt;td&gt;SSH&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;td&gt;Telnet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;td&gt;SMTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;69&lt;/td&gt;
&lt;td&gt;TFTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;135-139&lt;/td&gt;
&lt;td&gt;RPC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;161-162&lt;/td&gt;
&lt;td&gt;SNMP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;445&lt;/td&gt;
&lt;td&gt;SMB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3389&lt;/td&gt;
&lt;td&gt;RDP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5900-5904&lt;/td&gt;
&lt;td&gt;VNC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6379&lt;/td&gt;
&lt;td&gt;Redis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7001&lt;/td&gt;
&lt;td&gt;WebLogic&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8848&lt;/td&gt;
&lt;td&gt;Nacos&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Note: &lt;strong&gt;These blocks should be implemented at the Perimeter Firewall to stop threats outside the internal network.&lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;🚫 Strategy 3: Thwart DNSLog Probing&lt;/h3&gt;
&lt;p&gt;Attackers use public DNSLog services to verify Out-of-Band (OOB) vulnerabilities. You can set domain filtering rules on Perimeter Gateway Devices to block queries to known DNSLog suffixes (e.g., &lt;code&gt;*.dnslog.cn&lt;/code&gt;, &lt;code&gt;*.burpcollaborator.net&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;Why the Perimeter? To prevent attackers from bypassing internal DNS servers by manually setting their DNS to &lt;code&gt;8.8.8.8&lt;/code&gt;.
This serves as an effective &quot;Noise Reduction&quot; measure, though sophisticated attackers may use custom, private DNSLog domains.&lt;/p&gt;
</content:encoded></item><item><title>Disabling Automatic DNS Log Probing in Burp Suite</title><link>https://fuwari.vercel.app/posts/57a913c1-cd81-481d-a278-f72a12fa547c/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/57a913c1-cd81-481d-a278-f72a12fa547c/</guid><description>Burp Suite is a Java-based, cross-platform web application penetration testing tool primarily used for intercepting, modifying, and replaying HTTP requests. While it is indispensable for security testing, Burp Suite initiates active DNSLOG probing upon startup. These probes may trigger alerts on security devices such as STA (Security Traffic Analysis) probes.</description><pubDate>Fri, 27 Jun 2025 22:08:38 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;Burp Suite is a Java-based, cross-platform penetration testing tool for web applications. It is widely used for intercepting, modifying, and replaying HTTP requests, supporting features like packet capture, manual request tampering, and brute-force attacks.
However, when Burp Suite starts, it actively initiates DNSLOG probing. These automated requests can be flagged as suspicious activity by security infrastructure like STA (Security Traffic Analysis) probes or IDS/IPS systems.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/06/27/zna5of.png&quot; alt=&quot;Alarm&quot; /&gt;&lt;/p&gt;
&lt;h2&gt;Configuration Steps&lt;/h2&gt;
&lt;h3&gt;1、Burp -&amp;gt; Setting&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/06/27/zn40qb.png&quot; alt=&quot;Burp Suite 1&quot; /&gt;&lt;/p&gt;
&lt;h3&gt;2、Project -&amp;gt; Collaborator&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Change the setting from &quot;Use the default Collaborator server&quot; to &quot;Don’t use Burp Collaborator&quot;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://oss-southeast-1.bytesycn.com/images/2025/06/27/zn440x.png&quot; alt=&quot;Burp Suite 2&quot; /&gt;&lt;/p&gt;
</content:encoded></item><item><title>Installing Docker &amp; Docker Compose(China)</title><link>https://fuwari.vercel.app/posts/ec661856-ac41-4faa-9c35-33405bb802b1/</link><guid isPermaLink="true">https://fuwari.vercel.app/posts/ec661856-ac41-4faa-9c35-33405bb802b1/</guid><description>A guide to installing Docker and Docker Compose via online and offline methods.</description><pubDate>Sat, 14 Jun 2025 15:59:54 GMT</pubDate><content:encoded>&lt;blockquote&gt;
&lt;p&gt;This guide covers both &lt;strong&gt;online&lt;/strong&gt; and &lt;strong&gt;air-gapped&lt;/strong&gt; (offline) installation methods for Docker and Docker Compose on Linux systems. It is intended for users who need to deploy in restricted intranet environments or environments without external internet access.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;🌐 Online Installation&lt;/h2&gt;
&lt;h3&gt;Method 1: Official Script &amp;amp; Manual Compose Download&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;curl -fsSL https://get.docker.com -o get-docker.shsh 
get-docker.sh
sudo apt-get install libffi-dev libssl-dev。
curl -L &quot;https://github.com/docker/compose/releases/download/1.29.2/docker-compose-$(uname -s)-$(uname -m)&quot; -o /usr/local/bin/docker-compose
sudo chmod +x /usr/local/bin/docker-compose
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Method 2: Using Mirror Scripts (Optimized for specific regions)&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;bash &amp;lt;(curl -sSL https://linuxmirrors.cn/docker.sh)
&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;📦 Offline Installation (Air-gapped)&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Download Binaries
Download the required packages on a machine with internet access:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;# Docker Static Binary
wget https://download.docker.com/linux/static/stable/x86_64/docker-24.0.6.tgz

# Docker Compose Binary
wget https://github.com/docker/compose/releases/download/1.29.2/docker-compose-Linux-x86_64
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Extract and Install Docker
Transfer the files to the target machine, then execute:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;tar -xvzf docker-24.0.6.tgz
sudo cp docker/* /usr/bin/
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Configure Systemd Service
Create a service unit file to manage the Docker daemon:&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;sudo tee /etc/systemd/system/docker.service &amp;gt; /dev/null &amp;lt;&amp;lt;EOF
[Unit]
Description=Docker Application Container Engine
After=network.target

[Service]
ExecStart=/usr/bin/dockerd
Restart=always

[Install]
WantedBy=multi-user.target
EOF

# Reload configuration and enable the service
sudo systemctl daemon-reload
sudo systemctl enable docker
sudo systemctl start docker
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Install Docker Compose&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;sudo mv docker-compose-Linux-x86_64 /usr/local/bin/docker-compose
sudo chmod +x /usr/local/bin/docker-compose
&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Verify Installation&lt;/li&gt;
&lt;/ol&gt;
&lt;pre&gt;&lt;code&gt;docker -v
docker-compose -v
&lt;/code&gt;&lt;/pre&gt;
</content:encoded></item></channel></rss>