Saturday, August 6, 2016

How to Fix VMware ESXi 6.0 Root Account Lockout and Brute-Force Restrictions

Starting with version 6.0, VMware ESXi introduced an automated security lockout feature that locks the root account after consecutive failed login attempts. On hypervisors exposed to public networks, malicious automated SSH bots frequently trigger this threshold, inadvertently locking legitimate administrators out of the vSphere Client and Web UI.

Security Best Practices: Enforce SSH key-based authentication • Restrict ESXi management firewall to designated administrative IPs.

1. Unlocking the Root Account via Local Console (DCUI)

Log in via the physical or out-of-band Direct Console User Interface (DCUI), navigate to Troubleshooting Options, enable the ESXi Shell, and reset the lockout counter:

# Check failed login attempt count
pam_tally2 --user root

# Reset failed attempt counter and unlock account
pam_tally2 --user root --reset

2. Permanent Hardening: Restrict Management Access

To eliminate unauthorized brute-force attempts permanently:

  1. Disable SSH password logins in /etc/ssh/sshd_config:
    PasswordAuthentication no
  2. Restrict the ESXi management firewall rule for the vSphere Client (port 443 / 902) to your office or VPN gateway IPs:
    esxcli network firewall ruleset set --ruleset-id vSphereClient --allowed-all false
    esxcli network firewall ruleset allowedip add --ruleset-id vSphereClient --ip-address 203.0.113.10

Thursday, August 4, 2016

Essential Techniques to Block Browser Fingerprinting, Canvas Tracking, and Audio APIs

Standard "Private Browsing" or "Incognito" modes prevent local history from saving to disk, but they do little to protect your identity from sophisticated web trackers. Modern tracking networks rely on device fingerprinting—measuring system fonts, GPU rendering quirks via HTML5 Canvas, WebGL parameters, audio latency, and installed plugins to create a persistent hardware signature across sessions.

Auditing Tools: Test your browser uniqueness at EFF Panopticlick (Cover Your Tracks) and BrowserLeaks.

Key Tracking Vectors and Countermeasures

  • HTML5 Canvas Fingerprinting: Trackers draw invisible shapes and text behind the scenes; minute GPU driver rendering variations produce a unique hash.

    Defense: Install privacy tools like Canvas Defender or Firefox's native privacy.resistFingerprinting = true in about:config.

  • AudioContext API Tracking: Variations in audio buffer processing across system sound cards provide another identifiable vector.

    Defense: Block non-consensual Web Audio processing through extension policies.

  • System Font Enumeration: Tracking scripts measure font rendering metrics across hundreds of installed fonts.

    Defense: Restrict font queries to standard platform fonts (layout.css.font-visibility.standard = 1 in modern Firefox).

  • WebRTC IP Leakage: WebRTC STUN requests can expose real public and private LAN IPs even when connected behind a VPN proxy.

    Defense: Set media.peerconnection.enabled = false.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...