Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(issues): 2024-120-2 bis #52

Merged
merged 3 commits into from
Dec 2, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added assets/img/azure/solution/rg.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/hub/rg/create/basics.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/hub/rg/create/tags.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
percebus marked this conversation as resolved.
Show resolved Hide resolved
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/network/01.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/spoke/snapshots/01.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/spoke/vnet/create/review.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/spoke/vnet/create/security.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified assets/img/azure/solution/vnets/spoke/vnet/peering/add.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
6 changes: 5 additions & 1 deletion docs/tutorial/01/hub.md
Original file line number Diff line number Diff line change
Expand Up @@ -293,14 +293,18 @@ These are standard, to ensure connectivity with a minimum level of security on r

Your resources should look like this.-

![snapshot](../../../assets/img/azure/solution/vnets/hub/snapshots/02.png)
![snapshot](../../../assets/img/azure/solution/vnets/hub/snapshots/01.png)
percebus marked this conversation as resolved.
Show resolved Hide resolved

### Resource visualizer

You can see the relationship between the Firewall `fw` and the Public IP `fw-ip` in the resource visualizer.

![Resource visualizer](../../../assets/img/azure/solution/vnets/hub/fw/resources/01.png)

### Network Diagram

![Network Diagram](../../../assets/img/azure/solution/vnets/hub/network/01.png)

## Costs

Both **Azure Bastion** & **Azure Firewall** are expensive resources, which are charged by the hour.
Expand Down
8 changes: 7 additions & 1 deletion docs/tutorial/01/spoke.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,11 +43,13 @@ Make sure **Bastion** & **Firewall** remained **Toggled OFF**.

###### IP addresses

Virtual Network: `10.2.x.x/16`

| Subnet | IP family | CIDR Block | Size | Notes |
| --------- | --------- | ------------- | ------- | ----- |
| `default` | `0-3.x` | `10.2.0.0/22` | `1,024` | |

![Security](../../../assets/img/azure/solution/vnets/spoke/vnet/create/ip/after.png)
![Security](../../../assets/img/azure/solution/vnets/spoke/vnet/create/ip_addresses/after.png)

##### Review + Create

Expand Down Expand Up @@ -105,6 +107,10 @@ Review your settings and create the VNet.

[JSON Template](../../../azure/templates/modules/01/spoke)

### Network Diagram

![Network Diagram](../../../assets/img/azure/solution/vnets/spoke/network/01.png)

## Next Steps

[Create VNets peering](./peering.md)
21 changes: 21 additions & 0 deletions docs/tutorial/03/nsg.md
Original file line number Diff line number Diff line change
Expand Up @@ -166,6 +166,27 @@ Not part of this tutorial.

The following is meant to be only educational.

### Ping Flooding

First, read about [ICMP Flooding](../../vulnerabilities.md#icmp-flooding)

`ping` uses `ICMP` by default, which, because of flood attacks, is often blocked now by routers.

#### Inbound: Deny ICMP

- **Name**: `deny-icmp`
- **Priority**: `1000`ish
- Source: Any
- Destination: Any
- **Protocol**: `ICMP`

> [!IMPORTANT]
> There are things like "TCP Ping" that can be used that use `TCP` instead of `ICMP`.

[This article does a pretty good job of explaining this](https://www.baeldung.com/linux/tcp-packets-ping)

You can sometimes cheat with `ssh` on a **specific port**.
percebus marked this conversation as resolved.
Show resolved Hide resolved

### Storage account(s)

#### Outbound: Allow DNS
Expand Down
2 changes: 1 addition & 1 deletion docs/tutorial/04/spoke/webapp.md
Original file line number Diff line number Diff line change
Expand Up @@ -131,7 +131,7 @@ We'll tell the WebApp to use that subnet to create IPs (NICs?) it can use for an

![Virtual Network Integration](../../../../assets/img/azure/solution/vnets/spoke/webapp/settings/networking/virtual_network_integration/subnet/add.png)

- [x] **Outbound Internet Traffic**: Checked. Ensure it goes through our delegated `webapp` subnet and not directly to the internet. Will aalso
- [x] **Outbound Internet Traffic**: Checked. Ensure it goes through our delegated `webapp` subnet and not directly to the internet.

![Virtual Network Integration](../../../../assets/img/azure/solution/vnets/spoke/webapp/settings/networking/virtual_network_integration/subnet/connected.png)

Expand Down
18 changes: 16 additions & 2 deletions docs/vulnerabilities.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,21 @@
# Known Vulnerabilities

## DDoS

### ICMP Flooding

Also known as ["Ping of death"](https://www.fortinet.com/resources/cyberglossary/ping-of-death)

> The ping of death is a form of denial-of-service (DoS) attack
> that occurs when an attacker crashes, destabilizes, or freezes computers or services
> by targeting them with oversized data packets
percebus marked this conversation as resolved.
Show resolved Hide resolved

## DNS

### Poisoning
### Spoofing

Also known as [DNS Poisoning](https://www.okta.com/identity-101/dns-poisoning/)

[DNS Poisoning/Spoofing](https://www.okta.com/identity-101/dns-poisoning/)
> During a DNS poisoning attack, a hacker substitutes the address for a valid website for an imposter.
> Once completed, that hacker can steal valuable information, like passwords and account numbers.
> Or the hacker can simply refuse to load the spoofed site
Loading