Posts

LinkedIn Recommendations for Jegan Sri Mohan Ram | Cybersecurity Expert

Image
Welcome to my LinkedIn recommendations page. Here you'll find professional recommendations from colleagues, managers, clients, directors, executive directors, CTOs, CSOs, and other senior technology leaders that reflect my experience in cybersecurity, web application security, WAF engineering, SIEM, DevSecOps, AI-assisted security, and technical leadership. If you're interested in collaborating on cybersecurity projects, consulting, or training, feel free to contact me at +91-9790239061 Jegan LinkedIn Recommendations

Advanced OpenResty Reverse Proxy Configuration with GeoIP, ModSecurity, and Lua Load Balancing

Copy Code Example OpenResty Reverse Proxy Features This is an OpenResty (Nginx with Lua scripting capabilities) configuration for a reverse proxy that performs several advanced functions, including: HTTP to HTTPS redirection. SSL/TLS termination. Web Application Firewall (WAF) using ModSecurity. GeoIP-based routing: Directing users to different backend server pools based on their country. Custom Lua-based load balancing: Health checks for backend servers. Least connections algorithm (weighted) to select a backend. Custom logging including GeoIP data and selected backend. Let's break down each file and its components: nginx.conf (Main OpenResty Configuration) This file sets up the global Nginx/OpenResty environment. Copy Code worker_processes 1; worker_processes 1;: Configures Nginx to use a single worker process. For production, this is usually set to auto or the...

JWT Structure

  JWT Structure The token is composed of three parts, separated by dots: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VybmFtZSI6Im9wZW5zb3VyY2VqZWdhbkBnbWFpbC5jb20iLCJyb2xlcyI6WyJ1c2VyIl0sImV4cCI6MTczMzU3MzA2MX0.nxBknSlySJ0JQIFg5BpmnZhZV6VZ0Mshu7opFFgPLSc 1. First Part (Header): eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9 When decoded (base64), it reveals: { "typ" : "JWT" , "alg" : "HS256" } JSON Copy typ : Type of token (JSON Web Token) alg : Algorithm used (HMAC SHA256) 2. Second Part (Payload): eyJ1c2VybmFtZSI6Im9wZW5zb3VyY2VqZWdhbkBnbWFpbC5jb20iLCJyb2xlcyI6WyJ1c2VyIl0sImV4cCI6MTczMzU3MzA2MX0 When decoded, it reveals: { "username" : "opensourcejegan@gmail.com" , "roles" : [ "user" ] , "exp" : 1733573061 } JSON Copy username : User's email roles : User's roles (in this case, "user") exp : Expiration timestamp (Unix timestamp) 3. Third Part (Signature): nxBknSlySJ...

Jegan's SSO Auth System Code Explanation

  https://docs.google.com/document/d/1tVIsBVRwF9cESAvhBLbqwJftuJtXcx8t-fO4KmB1QaQ/edit?usp=sharing API Routes /api/signup : Handles user signup. Validates email and password, checks if the email is allowed, hashes the password, stores user data in the database, and sends a welcome email. /api/enroll : Handles TOTP enrollment. Generates a TOTP secret, stores it, and returns a QR code for 2FA setup. /api/login : Handles user login. Validates credentials, checks account lock status, generates tokens, and sets them as cookies. /api/validate : Validates the access token and returns user information if valid. /api/token/refresh : Refreshes the access token using a valid refresh token. /api/update_role : Updates the role of a user. /api/logout : Logs out the user by revoking tokens and clearing cookies. /api/request_reset : Initiates a password reset by generating a reset token and sending it via email. /api/reset_password/ : Resets the user's password using a valid reset token.

Mermaid diagram syntax for Token-based authentication system

 sequenceDiagram     participant User     participant Browser     participant AuthServer     participant Database     % Login Flow     User->>Browser: Enter Credentials     Browser->>AuthServer: POST /api/login     AuthServer->>Database: Validate Credentials     alt Credentials Valid         Database-->>AuthServer: User Found         AuthServer->>AuthServer: Generate Access Token         AuthServer->>AuthServer: Generate Refresh Token         AuthServer->>Database: Store Refresh Token         AuthServer-->>Browser: Return Tokens         Browser->>Browser: Store Tokens in HTTP-only Cookies         Browser-->>User: Login Successful     else Credentials Invalid         D...

Enhancing Flask SSO with Role-Based Access Control (RBAC)

Enhancing Flask SSO with Role-Based Access Control (RBAC) Enhancing Flask SSO with Role-Based Access Control (RBAC) To enhance your Single Sign-On (SSO) application with Role-Based Access Control (RBAC), you need to implement a mechanism to assign roles to users and control access to different routes or resources based on those roles. Here's how you can do it step by step: 1. Extend the Database Schema You'll need to add a role column to the users table so that each user can be assigned a role, such as "admin," "user," or any other custom role. def init_db(): try: with sqlite3.connect('sso_service.db') as conn: c = conn.cursor() c.execute('''CREATE TABLE IF NOT EXISTS tokens (token TEXT PRIMARY KEY, username TEXT, token_type TEXT, expiration DATETIME)''') c.execute('''CREATE TABLE IF NOT EXISTS totp_secrets (username TEXT ...

Concept of WSL (Windows Subsystem for Linux) in Windows 2022 Server

Image
 

Poll-monitor/SSH remote access to WSL (Windows Subsystem for Linux) Windows 2022 server and enable wsl.exe automatically during Windows 2022 server restart/reboot from remote Ubuntu 22.04 LTS

Poll-monitor/SSH remote access to WSL (Windows Subsystem for Linux) Windows 2022 server and enable wsl.exe automatically during Windows 2022 server restart/reboot from remote Ubuntu 22.04 LTS Shell Script Copy Code #!/bin/bash # Log file location LOG_FILE="/var/log/ping_monitor.log" SERVICE_NAME="ping_monitor.service" # Function to log messages with timestamps log_message() { echo "$(date +"%Y-%m-%d %H:%M:%S") - $1" >> $LOG_FILE } # IP address to ping IP_ADDRESS="A.B.C.D" # Number of timeouts and replies to check TIMEOUT_COUNT=2 # Adjust this as needed REPLY_COUNT=4 # Initialize counters timeout_counter=0 reply_counter=0 # Infinite loop to monitor the ping status while true; do # Ping the IP address once ping -c 1 $IP_ADDRESS > /dev/null 2>&1 # Check the exit status of the ping command if [ $? -ne 0 ]; then # Increment the timeout counter if the pi...

Automatic trigger enabling of Openresty during WSL (Windows Subsystem of Linux) startup in Windows 2022 Server

Automatic trigger enabling of Openresty during WSL (Windows Subsystem of Linux) startup in Windows 2022 Server Step 1: Login as Sudo user in WSL and Install the below package first Copy Code sudo apt install expect Step 2: Create the shell script as below Copy Code nano start_openresty_expect.sh #!/usr/bin/expect -f set timeout 10 spawn sudo service openresty start expect "password for jegan:" send "jegan@123\r" expect eof Step 3: Provide executable permission to the shell script start_openresty_expect.sh Copy Code chmod +x start_openresty_expect.sh Step 4: Go to bashrc file Copy Code nano ~/.bashrc Step 5: Add the below at the end of the bashrc file, then save and exit Copy Code ~/start_openresty_expect.sh Step 6: Update bashrc Copy Code source ~/.bashrc Whenever the WSL restarts/reboots/starts Openresty will be automat...

Enabling NAT to expose public services of WSL (Windows Subsystem for Linux) in Windows 2022 Server using Powershell as Administrator

Enabling NAT to expose public services of WSL (Windows Subsystem for Linux) in Windows 2022 Server using Powershell as Administrator Step 1 : Check the existing NAT Table Copy Code netsh interface portproxy show all Step 2 : Expose port 80 public services of WSL Copy Code netsh interface portproxy add v4tov4 listenaddress=LOCAL_SERVER_PUBLIC_IP_ADDRESS listenport=80 connectaddress=LOCAL_SERVER_PRIVATE_IP_ADDRESS_WSL connectport=80 Step 3 : Expose port 443 public services of WSL Copy Code netsh interface portproxy add v4tov4 listenaddress=LOCAL_SERVER_PUBLIC_IP_ADDRESS listenport=443 connectaddress=LOCAL_SERVER_PRIVATE_IP_ADDRESS_WSL connectport=443 Step 4 : Check the NAT Table again to confirm that the changes are applied Copy Code netsh interface portproxy show all Enabling NAT to expose public services of WSL (Windows Subsystem for Linux) in Windows 2022 Server using Powershell as Ad...

Enable OpenSSH Server Using PowerShell in Windows 2022 Server

Enable OpenSSH Server Using PowerShell in Windows 2022 Server Run Powershell as Administrator Execute the commands mentioned in the below steps Step 1 Copy Code Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0 Step 2 Copy Code Start-Service sshd Step 3 Copy Code Set-Service -Name sshd -StartupType 'Automatic' Step 4 Copy Code New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22 Step 5 Copy Code Get-Service -Name sshd Enabling OpenSSH Server Using PowerShell in Windows 2022 Server is complete !!!

Install and Enable Certbot letsencrypt SSL/TLS Certificate in NGINX Ubuntu 22.04 LTS without using snapd

Install and Enable Certbot letsencrypt SSL/TLS Certificate in NGINX Ubuntu 22.04 LTS Step 1: Update the Package List Copy Code sudo apt update Step 2: Install Certbot Copy Code sudo add-apt-repository universe Then, install Certbot using apt: Copy Code sudo apt install certbot Step 3: Install the Plugin for NGINX Copy Code sudo apt install python3-certbot-nginx Step 4: Get the certificate for the preferred domain Copy Code sudo certbot certonly --standalone -d your_domain

Install and Enable WSL (Windows Sub System For Linux) on Windows 2022 Server

Install and Enable WSL on Windows 2022 Server 1) Execute All the below commands in PowerShell as Administrator Copy Code dism.exe /online /enable-feature /featurename:Microsoft-Hyper-V /all /norestart dism.exe /online /enable-feature /featurename:Microsoft-Hyper-V-Management-Clients /all /norestart dism.exe /online /enable-feature /featurename:Microsoft-Hyper-V-Management-PowerShell /all /norestart dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart 2) Reboot the Server Copy Code shutdown /r /t 0 3) Once the server reboot is complete, execute the below command Copy Code wsl --install -d Ubuntu Note: It will ask to reboot the server Copy Code shutdown /r /t 0 4) After reboot, It will throw error, then execute the below command Copy Code wsl --update wsl --set-default-version 1 5) Again execute the below command Copy Code ...

Prevent Vulnerability Scanners from Detecting WordPress

How to Prevent Vulnerability Scanners from Detecting WordPress How to Prevent Vulnerability Scanners from Detecting WordPress Preventing vulnerability scanners from detecting that you're using WordPress for your website is an essential aspect of security through obscurity. While this won’t replace other important security practices such as patching and hardening, hiding the fact that your site uses WordPress can make it more difficult for attackers to target known vulnerabilities. Here are several strategies to help you obfuscate WordPress from vulnerability scanners. 1. Change Default URLs and Paths WordPress has many default URLs and file paths that scanners can easily detect. Changing these can help conceal that you're using WordPress. Hide wp-admin and wp-login.php Use plugins like WPS Hide Login to change the login URL from /wp-admin...

This setup allows you to continuously run the backend service, and every time you make a curl request, it performs the search and returns only the summary information

MongoDB Search Using Flask API Creating a MongoDB Search API Using Flask This post will guide you through setting up a Flask API to search through MongoDB collections based on a search string and return a summary of the results. Step 1: Setting Up the Flask API Create a Python script that sets up the Flask API and connects to MongoDB: Copy code from flask import Flask, request, jsonify from pymongo import MongoClient import re # MongoDB connection settings MONGO_URI = "mongodb://localhost:27017/" DB_NAME = "security_logs" # List of collections to search collections = [ "AlienVaultBlockedIPs", "AlienVaultIDSBlockedIPs", "CSFDenyLogs", "DDoSBlockedIPs", "IDSBlockedIPs", "maliciousDNSBlockedIPs", "OpenRestyAccessLogs", "OpenRestyErrorLogs", "SuricataFullFastLog", ...

YouTube Videos for Building Secure Web Gateway using OpenResty

 Refer my YouTube Channel link, https://www.youtube.com/channel/UCGBFp1bwadxjrA-MgwD2rTA having titles  Secure Web Gateway Part 1 to X in Tamil Keep Learning!!!

Refer Google Drive Links for YouTube Secure Web Gateway Part 1 to X in Tamil Learners

 Secure Web Gateway Part 8 in Tamil https://drive.google.com/file/d/1wKeGNnmGhzA7x_RUpdVUnAvhARMFjEV6/view?usp=sharing  Secure Web Gateway Part 9 in Tamil https://drive.google.com/file/d/1MYoPJij5qhOQIJpaMGniyhMGd2R0ZuCj/view?usp=sharing  Secure Web Gateway Part 10 in Tamil https://drive.google.com/file/d/1tkWrZjfmnzVycCL4S0zrkMIsxULahvxX/view?usp=sharing Secure Web Gateway Part 11 in Tamil https://drive.google.com/file/d/1_zrbY42YbcO-0zWgR7pSasKaC_x9icFU/view?usp=sharing Secure Web Gateway Part 12 in Tamil https://drive.google.com/file/d/1AG3d4pN9lCTVW1__s8Dy73UFVHdKUjzF/view?usp=sharing Secure Web Gateway Part 14 in Tamil https://drive.google.com/file/d/1_B3zqNoJn_bqCjBDQ_4mXM_F9LDsoQR9/view?usp=sharing Secure Web Gateway Part 15 in Tamil https://drive.google.com/file/d/1ewMvQkAd9MgkcaZMOgVeY-ceM_SGNmyD/view?usp=sharing Secure Web Gateway Part 16 in Tamil https://drive.google.com/file/d/1bbWTHwIgiuUj5QkGHUVzSWeyLh3IRbi0/view?usp=sharing Secure Web Gateway Part 17 in Tam...

Combination of https://ipapi.co/ , https://www.blacklistmaster.com/ and https://scamalytics.com/ for Web Application Security

Image
  https://ipapi.co/ , https://www.blacklistmaster.com/ and https://scamalytics.com/ Use case, For scripts/codes, refer, https://drive.google.com/file/d/1zxPAKQfNN9-Dga_oBbgDkmrzRpnF3Jez/view?usp=sharing For Support, support@ cybersecuritysolutions. raiseaticket.com

blacklistmaster.com Detection and Blocking for Web Application Security (Ubuntu 22.04 LTS)

  https://drive.google.com/file/d/1MEI-o2qRHXRSyfuXOZA9hhMBsYO2BvRN/view?usp=sharing For Support, support@ cybersecuritysolutions. raiseaticket.com

MongoDB Installation Ubuntu 22.04 LTS

https://drive.google.com/file/d/1OLBfJ6GpizGveXkhojzsAFV9aH-e-zNx/view?usp=sharing sudo apt-get install -y mongodb-mongosh For Support, support@ cybersecuritysolutions. raiseaticket.com Before Installation you have to do the below, wget  http://archive.ubuntu.com/ubuntu/pool/main/o/openssl/libssl1.1_1.1.1f-1ubuntu2_amd64.deb sudo dpkg -i  libssl1.1_1.1.1f-1ubuntu2_amd64.deb sudo apt-get install -f dpkg -l | grep libssl1.1 Then, wget -qO - https://www.mongodb.org/static/pgp/server-6.0.asc | sudo apt-key add - echo "deb [ arch=amd64,arm64 ] https://repo.mongodb.org/apt/ubuntu focal/mongodb-org/6.0 multiverse" | sudo tee /etc/apt/sources.list.d/mongodb-org-6.0.list sudo apt update sudo apt install -y mongodb-org sudo systemctl start mongod sudo systemctl status mongod sudo systemctl enable mongod