ITCHRONICLE
ICT JOB DIARIES
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
List topics: List topics:

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Troubleshooting DNS Avanzato: Oltre il solito ipconfig

Il Problema: Connettività Presente, Risoluzione Assente

Advanced DNS Troubleshooting
Immagine realizzata con Gemini AI


È un incubo ricorrente: il server risponde al ping 8.8.8.8, ma provando a raggiungere un dominio interno o esterno il browser restituisce ERR_NAME_NOT_RESOLVED. Il comando ipconfig /flushdns non ha sortito alcun effetto. In questi scenari avanzati, limitarsi a riavviare la scheda di rete è inutile; serve ispezionare chirurgicamente la catena di risoluzione.

La Soluzione: Gli strumenti del Sysadmin (dig e nslookup)

Per diagnosticare dove si interrompe la catena DNS, dobbiamo bypassare la cache del sistema operativo e interrogare direttamente i name server.

1. Ispezionare la risoluzione con `dig` o `nslookup`

Su Linux (o WSL su Windows), utilizza dig per tracciare il percorso della richiesta. Specifica il server DNS aziendale per capire se sta rispondendo ai record interni (es. il gestionale su intranet.local):

# Interroga specificamente il Domain Controller aziendale (10.0.20.5)
dig @10.0.20.5 intranet.local

Se il server restituisce un errore SERVFAIL, il problema risiede nei forwarder del server DNS. Se restituisce NXDOMAIN, il record semplicemente non esiste nella zona DNS.

2. Il conflitto del DNS over HTTPS (DoH) nei Browser

Un problema sempre più comune nelle reti aziendali è causato dal DNS over HTTPS (DoH). I browser moderni (Chrome, Edge, Firefox) bypassano le impostazioni DNS della scheda di rete di Windows e criptano le richieste inviandole direttamente a Cloudflare o Google. Il risultato? L'utente naviga su internet ma non riesce ad accedere alle risorse aziendali interne, perché il DNS pubblico non conosce la vostra zona privata.

Per risolvere, disabilita il "DNS Sicuro" all'interno delle impostazioni di privacy del browser o forza il traffico tramite policy GPO (Group Policy Object).

3. Verificare i file Host e Resolv.conf

Su macchine Linux, assicurati che il processo di risoluzione stia puntando al server corretto. Ispeziona il file di configurazione:

cat /etc/resolv.conf

Se è gestito da systemd-resolved, controlla lo stato globale della risoluzione eseguendo:

resolvectl status

Advanced DNS Troubleshooting: Beyond the usual ipconfig

The Problem: Connectivity Exists, Resolution Fails

Advanced DNS Troubleshooting
Image generated with Gemini AI


It is a recurring nightmare: the server successfully replies to ping 8.8.8.8, but attempting to reach an internal or external domain returns ERR_NAME_NOT_RESOLVED in the browser. The standard ipconfig /flushdns command had zero effect. In these advanced scenarios, simply restarting the network adapter is useless; you need to surgically inspect the resolution chain.

The Solution: Sysadmin Tools (dig and nslookup)

To diagnose exactly where the DNS chain breaks, we must bypass the operating system's cache and query the name servers directly.

1. Inspecting Resolution with `dig` or `nslookup`

On Linux (or WSL on Windows), use dig to trace the request path. Specify your corporate DNS server to see if it responds correctly to internal records (e.g., your intranet at intranet.local):

# Specifically query the corporate Domain Controller (10.0.20.5)
dig @10.0.20.5 intranet.local

If the server returns a SERVFAIL error, the issue lies within the DNS server's forwarders. If it returns NXDOMAIN, the record simply does not exist in the DNS zone.

2. The DNS over HTTPS (DoH) Browser Conflict

An increasingly common issue in corporate networks is caused by DNS over HTTPS (DoH). Modern browsers (Chrome, Edge, Firefox) bypass the Windows network adapter's DNS settings and encrypt requests, sending them directly to Cloudflare or Google. The result? The user can browse the public internet but cannot access internal corporate resources because the public DNS knows nothing about your private zone.

To fix this, disable "Secure DNS" within the browser's privacy settings, or enforce the block company-wide via Group Policy Objects (GPO).

3. Verifying Hosts and Resolv.conf

On Linux machines, ensure the resolution process is actually pointing to the correct server. Inspect the configuration file:

cat /etc/resolv.conf

If the network is managed by systemd-resolved, check the global resolution status by executing:

resolvectl status

Network Segmentation: Mitigating Threats with VLANs

The Problem: The "Flat" Network and Lateral Movement

Network Segmentation
Image generated with Gemini AI


In many legacy corporate infrastructures, all devices (office computers, production servers, IP cameras, and guest Wi-Fi) reside on the exact same subnet (e.g., 192.168.1.0/24). If an employee opens a malicious attachment and triggers a ransomware payload, the malware exploits this "flat" architecture to perform lateral movement, instantly scanning and infecting critical servers and backup repositories without encountering a single network obstacle.

The Solution: Segmentation via VLANs and Firewalls

The principle of least privilege applies to networking as well. We must physically or logically isolate different corporate areas using VLANs (Virtual Local Area Networks) and route traffic through an internal firewall to inspect and block unauthorized communications.

1. Creating VLANs (Logical Isolation)

On your managed switches (Layer 2 or Layer 3), carve out distinct network segments. A standard minimal architecture includes:

  • VLAN 10 (Management): 10.0.10.0/24 - Exclusive sysadmin access to hypervisors, switches, and iLOs.
  • VLAN 20 (Servers): 10.0.20.0/24 - Application servers, databases, and Active Directory.
  • VLAN 30 (Clients): 10.0.30.0/24 - Employee workstations.
  • VLAN 40 (IoT/Printers): 10.0.40.0/24 - Vulnerable embedded devices.

2. Inter-VLAN Routing and Firewall Rules

Without a router or firewall (like pfSense or FortiGate) acting as the gateway, VLANs cannot communicate. Enforce strict firewall rules to allow only strictly necessary traffic. For example, clients (VLAN 30) must not be able to initiate RDP sessions to servers (VLAN 20); only the Management VLAN should have that capability.

# Logical Firewall Rule Example on pfSense
Action: PASS
Interface: VLAN_CLIENT
Source: VLAN_CLIENT Subnet
Destination: VLAN_SERVER Subnet
Ports: 443 (HTTPS), 3306 (MySQL)

Action: DROP
Interface: VLAN_CLIENT
Source: ANY
Destination: VLAN_SERVER Subnet
Ports: 3389 (RDP), 22 (SSH)

Conclusion

Network segmentation transforms your infrastructure from an open prairie into a series of watertight compartments. If an endpoint is compromised, the blast radius is confined strictly within its VLAN, saving critical services and backups from total destruction.

Segmentazione di Rete: Mitigare le Minacce con le VLAN

Il Problema: La Rete "Piatta" e il Movimento Laterale

Segmentazione di Rete
Immagine realizzata con Gemini AI


In molte infrastrutture aziendali legacy, tutti i dispositivi (computer degli uffici, server di produzione, telecamere IP e Wi-Fi ospiti) risiedono sulla stessa subnet (es. 192.168.1.0/24). Se un dipendente apre un allegato malevolo e innesca un ransomware, il malware sfrutta questa architettura "piatta" per eseguire un movimento laterale, scansionando e infettando istantaneamente i server critici e i repository di backup senza alcun ostacolo di rete.

La Soluzione: Segmentazione tramite VLAN e Firewall

Il principio del privilegio minimo si applica anche al networking. Dobbiamo isolare fisicamente o logicamente le diverse aree aziendali utilizzando le VLAN (Virtual Local Area Network) e instradare il traffico attraverso un firewall interno per bloccare le comunicazioni non autorizzate.

1. Creazione delle VLAN (Isolamento Logico)

Sui tuoi switch gestiti (Layer 2 o Layer 3), crea segmenti di rete distinti. Un'architettura standard minima prevede:

  • VLAN 10 (Management): 10.0.10.0/24 - Accesso esclusivo per i Sysadmin a hypervisor, switch e iLO.
  • VLAN 20 (Server): 10.0.20.0/24 - Server applicativi, database e Active Directory.
  • VLAN 30 (Client): 10.0.30.0/24 - Workstation dei dipendenti.
  • VLAN 40 (IoT/Stampanti): 10.0.40.0/24 - Dispositivi embedded vulnerabili.

2. Regole di Routing e Firewall Inter-VLAN

Senza un router o un firewall (come pfSense o FortiGate) a fare da gateway, le VLAN non possono comunicare tra loro. Applica regole rigide sul firewall per consentire solo il traffico strettamente necessario. Ad esempio, i client (VLAN 30) non devono poter avviare sessioni RDP verso i server (VLAN 20); solo la VLAN di Management può farlo.

# Esempio logico di regola Firewall su pfSense (UFW non gestisce VLAN routing)
Azione: PASS
Interfaccia: VLAN_CLIENT
Sorgente: VLAN_CLIENT Subnet
Destinazione: VLAN_SERVER Subnet
Porte: 443 (HTTPS), 3306 (MySQL)

Azione: DROP
Interfaccia: VLAN_CLIENT
Sorgente: ANY
Destinazione: VLAN_SERVER Subnet
Porte: 3389 (RDP), 22 (SSH)

Conclusione

Segmentare la rete trasforma l'infrastruttura da una prateria aperta a una serie di compartimenti stagni. Se un endpoint viene compromesso, il raggio dell'attacco (blast radius) rimane confinato all'interno della sua VLAN, salvando i servizi critici e i backup.

Enterprise Shadow AI: Risks and Data Leakage Prevention

The Problem: Invisible Data Exfiltration via LLMs

Enterprise Shadow AI
Image generated with Gemini AI


The Shadow IT phenomenon has evolved. Today, the primary threat is no longer the unauthorized cloud server, but Shadow AI. To speed up their workflow, employees are pasting source code, confidential contracts, or financial data (PII) into public AI chatbots (like the free versions of ChatGPT or Claude). Because these tools often use user prompts to train their language models, the company's sensitive data is irrevocably exposed outside the corporate security perimeter.

The Solution: Policies, DNS Filtering, and Enterprise AI

Simply blocking access to AI tools generates frustration and pushes users to find loopholes (e.g., hotspot connections). The solution requires a three-tiered approach.

1. Visibility and Network-Level Blocking

The first step is to stop the data hemorrhage to unauthorized endpoints. Configure the corporate firewall or DNS resolver (like Pi-hole or NextDNS) to monitor and block queries to the public APIs of major uncontracted AI providers.

# Example domains to add to the DNS blocklist
api.openai.com
chatgpt.com
claude.ai
gemini.google.com

2. Implementing Enterprise AI (Walled Garden)

To maintain productivity without compromising security, you must provide a safe alternative. Deploy private instances via enterprise cloud services (such as Google Cloud Vertex AI or Azure OpenAI) where contracts explicitly guarantee that data will not be used for model training. Alternatively, for highly classified data, deploy open-source LLMs (like Llama 3) locally on on-premise servers.

3. Endpoint DLP Configuration

Update Data Loss Prevention (DLP) software policies on endpoints to detect and block attempts to copy-paste sensitive strings (e.g., credit card numbers, IBANs, or proprietary code) into browser windows directed at URL categories classified as "Generative AI".

Shadow AI Aziendale: Rischi e Prevenzione del Data Leakage

Il Problema: L'esfiltrazione invisibile dei dati tramite LLM

Enterprise Shadow AI
Immagine realizzata con Gemini AI


Il fenomeno dello Shadow IT si è evoluto. Oggi la minaccia principale non è più il server cloud non autorizzato, ma la Shadow AI. I dipendenti, per velocizzare il lavoro, incollano codice sorgente, contratti riservati o dati finanziari (PII) all'interno di chatbot IA pubblici (come la versione gratuita di ChatGPT o Claude). Poiché questi strumenti utilizzano spesso i prompt degli utenti per addestrare i propri modelli linguistici, i dati sensibili dell'azienda vengono irrimediabilmente esposti all'esterno del perimetro di sicurezza aziendale.

La Soluzione: Policy, DNS Filtering ed Enterprise AI

Bloccare semplicemente l'accesso agli strumenti IA genera frustrazione e spinge gli utenti a trovare scappatoie (es. connessioni hotspot). La soluzione richiede un approccio a tre livelli.

1. Visibilità e Blocco a livello di Rete

Il primo passo è fermare l'emorragia di dati verso endpoint non autorizzati. Configura il firewall aziendale o il resolver DNS (come Pi-hole o NextDNS) per monitorare e bloccare le query verso le API pubbliche dei principali fornitori IA non contrattualizzati.

# Esempio di domini da inserire in blocklist DNS
api.openai.com
chatgpt.com
claude.ai
gemini.google.com

2. Implementazione di IA Aziendale (Walled Garden)

Per mantenere la produttività senza compromettere la sicurezza, è necessario fornire un'alternativa sicura. Implementa istanze private tramite servizi cloud enterprise (come Google Cloud Vertex AI o Azure OpenAI) dove i contratti garantiscono esplicitamente che i dati non verranno utilizzati per il training dei modelli. In alternativa, per dati ad altissima classificazione, distribuisci LLM open-source (come Llama 3) localmente sui server aziendali.

3. Configurazione Endpoint DLP

Aggiorna le policy del software di Data Loss Prevention (DLP) sugli endpoint per rilevare e bloccare i tentativi di copia-incolla di stringhe sensibili (es. numeri di carte di credito, IBAN o codice proprietario) all'interno delle finestre del browser dirette a categorie URL classificate come "Generative AI".

Generative AI for IT: Accelerating Bash and PowerShell Scripting

The Problem: Development Bottlenecks

Generative AI for IT
Image generated with Gemini AI


Writing complex regular expressions (regex), handling advanced PowerShell modules, or building nested loops in Bash requires hours of focus and endless referencing of official documentation. In the fast-paced realm of ICT consulting, time spent debugging syntax is time stolen from risk analysis and strategic infrastructure design.

The Solution: Generative AI as an Operational Copilot

Leading the enterprise adoption of Generative AI does not mean aiming to replace human capital, but rather equipping it with an advanced copilot. By leveraging Large Language Models (LLMs), it is possible to delegate the structural drafting of code to artificial intelligence, drastically cutting down the time-to-market for IT automations.

1. IT-Specific Prompt Engineering

The secret to generating functional code lies in providing rigorous technical constraints. A generic prompt yields generic, often vulnerable scripts. Here is the structure of an engineered prompt designed for a Sysadmin:

"Act as a Senior Windows Sysadmin. Write a PowerShell script compatible with Windows Server 2022 that compresses IIS log files older than 30 days. Mandatory requirements: use Try/Catch constructs for error handling, write operation outputs to a local log file (in JSON format), and do not rely on any third-party modules."

2. Code Refactoring and Translation

Beyond pure generation, AI shines in technical debt analysis. By feeding undocumented legacy scripts (perhaps inherited from previous administrators) into the prompt, you can request line-by-line explanations, the addition of standardized comments, or the direct translation of entire logical blocks from Bash to PowerShell, ensuring architectural uniformity across hybrid environments.

Generative AI per l'IT: Accelerare Scripting Bash e PowerShell

Il Problema: I Colli di Bottiglia nello Sviluppo Interno

Generative AI per l'IT
Immagine realizzata con Gemini AI


Scrivere complesse espressioni regolari (regex), gestire moduli PowerShell avanzati o costruire loop annidati in Bash richiede ore di concentrazione e continua consultazione della documentazione ufficiale. Nel contesto frenetico della consulenza ICT, il tempo speso a fare debugging sintattico è tempo sottratto all'analisi del rischio e alla progettazione strategica dell'infrastruttura.

La Soluzione: Generative AI come Copilota Operativo

Guidare l'adozione dell'IA Generativa (Generative AI) a livello aziendale non significa puntare alla sostituzione del capitale umano, ma fornire un copilota avanzato. Sfruttando modelli linguistici di grandi dimensioni (LLM), è possibile delegare all'intelligenza artificiale la stesura strutturale del codice, abbattendo drasticamente il time-to-market delle automazioni.

1. Prompt Engineering Specifico per l'IT

Il segreto per ottenere codice funzionale risiede nel fornire vincoli tecnici rigorosi. Un prompt generico produce script generici e spesso vulnerabili. Ecco la struttura di un prompt ingegnerizzato per un Sistemista:

"Agisci come un Senior Windows Sysadmin. Scrivi uno script PowerShell compatibile con Windows Server 2022 che comprima i file di log di IIS più vecchi di 30 giorni. Requisiti tassativi: utilizza costrutti Try/Catch per la gestione degli errori, scrivi l'output delle operazioni in un file di log locale (formato JSON) e non fare affidamento su moduli di terze parti."

2. Code Refactoring e Traduzione

Oltre alla generazione pura, l'IA brilla nell'analisi del debito tecnico. Fornendo in input script legacy non documentati (magari ereditati da precedenti amministratori), è possibile richiedere la spiegazione riga per riga, l'aggiunta di commenti standardizzati o la traduzione diretta di interi blocchi logici da Bash a PowerShell, garantendo uniformità architetturale in ambienti ibridi.

Secure Credential Management: Removing Cleartext Passwords from Scripts

Password Safety
Image generated with Gemini AI


The Problem: Cleartext Passwords in Source Code

Automation via scripting is the beating heart of system administration. However, hardcoding credentials (passwords, API tokens, cryptographic keys) in cleartext inside .sh or .ps1 files is a critical security violation. Anyone with read access to the file system or the Git repository compromises the entire corporate ecosystem.

The Solution: Encrypted Secrets Management

We must decouple the script's logic from the sensitive data by leveraging the operating system's native protection mechanisms.

1. In PowerShell Environments (Windows)

In Microsoft infrastructures, we can use Export-Clixml to encrypt a credential object. The encryption is tightly bound to the user account that generated it and the physical machine (thanks to the Windows Data Protection API).

# Run once to save the encrypted password
Get-Credential | Export-Clixml -Path "C:\secure\admin_creds.xml"

# In the production script, call the file:
$cred = Import-Clixml -Path "C:\secure\admin_creds.xml"

2. In Bash Environments (Linux)

On Unix systems, the most immediate, zero-cost method to protect daemons and cron scripts is to isolate variables into a separate configuration file, restricting permissions exclusively to the root user.

# Create the protected configuration file
echo "DB_PASS='SuperSecret!'" > /etc/script_secrets.conf
sudo chmod 400 /etc/script_secrets.conf

In the main script (executed with elevated privileges), simply import the variables using the source /etc/script_secrets.conf command. The code remains clean, and credentials remain invisible to unauthorized users.

Gestione Sicura delle Credenziali: Eliminare le Password dagli Script

Il Problema: Password in Chiaro nei Sorgenti

L'automazione tramite scripting è il cuore nevralgico della gestione sistemistica. Tuttavia, hardcodare credenziali (password, token API, chiavi crittografiche) in chiaro all'interno di file .sh o .ps1 è una violazione critica della sicurezza. Chiunque abbia accesso in lettura al file system o al repository Git compromette l'intero ecosistema aziendale.

Password Safety
Immagine realizzata con Gemini AI


La Soluzione: Gestione Cifrata dei Segreti

Dobbiamo disaccoppiare la logica dello script dal dato sensibile, sfruttando i meccanismi di protezione nativi del sistema operativo.

1. In Ambiente PowerShell (Windows)

In infrastrutture Microsoft, possiamo usare Export-Clixml per cifrare un oggetto credenziale. La cifratura è legata a doppio filo all'account utente che l'ha generata e alla macchina fisica (grazie alle API di Data Protection di Windows).

# Eseguire una volta per salvare la password cifrata
Get-Credential | Export-Clixml -Path "C:\secure\admin_creds.xml"

# Nello script di produzione, richiamare il file:
$cred = Import-Clixml -Path "C:\secure\admin_creds.xml"

2. In Ambiente Bash (Linux)

Nei sistemi Unix, il metodo più immediato e a costo zero per proteggere i demoni e gli script cron è isolare le variabili in un file di configurazione separato, restringendo i permessi esclusivamente all'utente root.

# Creare il file di configurazione protetto
echo "DB_PASS='SuperSegreta!'" > /etc/script_secrets.conf
sudo chmod 400 /etc/script_secrets.conf

Nello script principale (eseguito con privilegi elevati), basta importare le variabili con il comando source /etc/script_secrets.conf. Il codice rimane pulito e le credenziali risultano invisibili agli utenti non autorizzati.

Linux Server Hardening: The 5 Mandatory Post-Install Steps

Linux Hardening


The Problem: Default Exposure

A freshly installed Linux server exposed to the public cloud is a blank canvas, but also an easy target. Default SSH daemon configurations and open ports immediately attract automated scanners, botnets, and brute-force attacks.



The Solution: 5 Steps to Hardening

Before installing any enterprise application, the infrastructure must be locked down by enforcing the principle of least privilege.

  • 1. Public Key Authentication: Ditch passwords entirely. Generate a certificate using ssh-keygen, copy it to the server, and edit /etc/ssh/sshd_config by setting PasswordAuthentication no.
  • 2. Disable Root Login: In the same SSH configuration file, ensure you set PermitRootLogin no to force access only via standard users and subsequent privilege elevation via sudo.
  • 3. Firewall Segmentation (UFW): Drop all incoming traffic except what is strictly necessary.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Brute-Force Mitigation (Fail2Ban): Automatically ban malicious IPs at the network level that repeatedly fail login attempts.
    sudo apt install fail2ban -y
  • 5. Silent Updates: Keep the system protected from zero-day vulnerabilities by installing unattended-upgrades for the automatic application of critical security patches without service interruptions.

Hardening Server Linux: I 5 Passi Obbligatori Post-Installazione

Immagine generata con Gemini AI


Il Problema: L'Esposizione Predefinita

Un server Linux appena installato ed esposto su cloud pubblico è una tela bianca, ma anche un bersaglio facile. Le configurazioni predefinite del demone SSH e le porte aperte attirano immediatamente scansioni automatizzate, botnet e attacchi brute-force.

La Soluzione: 5 Passaggi di Hardening

Prima di installare qualsiasi applicativo aziendale, l'infrastruttura deve essere blindata applicando il principio del minimo privilegio.

  • 1. Autenticazione a Chiave Pubblica: Abbandona le password. Genera un certificato con ssh-keygen, copialo sul server e modifica /etc/ssh/sshd_config impostando PasswordAuthentication no.
  • 2. Disabilitare l'accesso Root: Nello stesso file di configurazione SSH, assicurati di inserire PermitRootLogin no per forzare l'accesso solo tramite utenza standard e successiva elevazione tramite sudo.
  • 3. Segmentazione con Firewall (UFW): Chiudi tutto il traffico in ingresso tranne lo stretto necessario.
    sudo ufw default deny incoming
    sudo ufw allow ssh
    sudo ufw enable
  • 4. Mitigazione Brute-Force (Fail2Ban): Banna automaticamente a livello di rete gli IP malevoli che falliscono ripetutamente i login.
    sudo apt install fail2ban -y
  • 5. Aggiornamenti Silenti: Mantieni il sistema protetto dalle vulnerabilità zero-day installando unattended-upgrades per l'applicazione automatica delle sole patch di sicurezza critiche, senza interruzioni di servizio.

IT First Aid - Ep. 30: "This app has been blocked for your protection"


You are trying to install an old (perhaps management) software that is perfectly legitimate, but a large red Windows screen yells at you: "This app has been blocked for your protection". There is no "Run anyway" button.

1. The Certificate Block

The UAC (User Account Control) intercepts software whose digital signature certificate has expired or been revoked. Right-click the downloaded .exe file, go to Properties. If you see a security warning at the bottom, check the "Unblock" box and hit Apply.

2. Forced Launch via Terminal

App Lock


If Windows continues to block it, use Admin authority. Open the Command Prompt by running it as Administrator. Navigate using the cd command to the folder where the file is located (e.g., cd C:\Downloads) and type the name of the executable (e.g., setup.exe). Being launched from an already verified environment with maximum privileges, the installation will bypass the graphical block.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 30: "App bloccata a scopo di protezione"


Stai cercando di installare un vecchio software (magari gestionale) perfettamente legittimo, ma una grossa schermata rossa di Windows ti urla in faccia: "Questa app è stata bloccata a scopo di protezione". Non c'è un tasto "Esegui comunque".

1. Il blocco del certificato

L'UAC (Controllo Account Utente) intercetta i software il cui certificato di firma digitale è scaduto o revocato. Fai clic destro sul file .exe scaricato, vai in Proprietà. Se in basso vedi un avviso sulla sicurezza, spunta la casella "Annulla blocco" e dai Applica.

2. Avvio forzato da Terminale

App Lock


Se Windows continua a fare muro, usa la prepotenza da Admin. Apri il Prompt dei comandi eseguendolo come Amministratore. Naviga tramite comando cd nella cartella dove si trova il file (es. cd C:\Download) e digita il nome dell'eseguibile (es. setup.exe). Essendo lanciato da un ambiente già verificato e con privilegi massimi, l'installazione bypasserà il blocco grafico.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 29: Forgot Windows Local Password


Warning: this maneuver is exactly why we sysadmins always insist on encrypting drives with BitLocker. If the account is local (not linked to a Microsoft email) and unencrypted, here is the classic "skeleton key" trick.

Forgot Password


1. The Utilman Trick

Boot the PC with a Windows installation USB drive. Use Shift+F10 to open the command prompt. The game involves navigating to the System32 folder and renaming the Accessibility executable (utilman.exe), replacing it with the command prompt (cmd.exe).

2. The Brutal Reset

Rebooting the PC normally, when you reach the lock screen, clicking on the Accessibility icon in the bottom right will open a command prompt with maximum privileges (SYSTEM). Just type net user username newpassword to force the change and get back into the system. No formatting required.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 29: Password di Windows locale dimenticata


Attenzione: questa manovra è il motivo per cui noi sistemisti insistiamo sempre per cifrare i dischi con BitLocker. Se l'account è locale (non collegato a una mail Microsoft) e non è cifrato, ecco il classico trucco del "passpartout".

Forgot Password


1. Il trucco di Utilman

Avvia il PC con una chiavetta di installazione di Windows. Usa Shift+F10 per aprire il prompt dei comandi. Il gioco consiste nel navigare nella cartella System32 e rinominare l'eseguibile dell'Accessibilità (utilman.exe) sostituendolo con il prompt dei comandi (cmd.exe).

2. Il reset brutale

Riavviando il PC normalmente, arrivato alla schermata di blocco, cliccando sull'icona in basso a destra dell'Accessibilità, si aprirà un prompt dei comandi con privilegi massimi (SYSTEM). Basterà digitare net user nomeutente nuovapassword per forzare il cambio e rimettere piede nel sistema. Niente formattazione.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 28: Bluetooth paired but won't connect


Your headphones or mouse show up in the "Paired" devices list, but clicking Connect does absolutely nothing. Endlessly removing and re-adding the device sometimes doesn't help if the radio stack is frozen.

Bluetooth Service


1. Restarting Radio Services

Press Win + R, type services.msc, and hit Enter. Look for the Bluetooth Support Service (or bthserv). If it's stopped, Start it; if it's already running, give it a nice Right-click > Restart. Do the same for related services you find nearby (like Bluetooth Audio Gateway Service).

2. The Troubleshooter

If restarting the daemon isn't enough, go to Settings > System > Troubleshoot > Other troubleshooters and run the one dedicated to Bluetooth. Windows will force a reset of the internal antenna's radio driver.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 28: Dispositivi Bluetooth accoppiati ma non connessi


Le tue cuffie o il tuo mouse risultano nell'elenco dei dispositivi "Accoppiati", ma cliccando su Connetti non succede assolutamente nulla. Continuare a rimuovere e riaggiungere il dispositivo a volte non serve se lo stack radio si è bloccato.

Bluetooth Service


1. Il riavvio dei Servizi Radio

Premi Win + R, digita services.msc e dai Invio. Cerca il Servizio di supporto Bluetooth (o bthserv). Se è fermo, avvialo; se è già in esecuzione, fagli un bel Clic destro > Riavvia. Fai lo stesso per i servizi correlati che trovi vicino (come Servizio Gateway audio Bluetooth).

2. Lo strumento di risoluzione dei problemi

Se riavviare il demone non basta, vai in Impostazioni > Sistema > Risoluzione dei problemi > Altri strumenti di risoluzione e lancia quello dedicato al Bluetooth. Windows forzerà un ripristino del driver radio dell'antenna interna.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT

IT First Aid - Ep. 27: Can't access Network Folders or NAS


You just set up a corporate NAS or a printer with a shared folder, but your PC categorically refuses to see it on the Network, giving you a generic error.

SMB 1.0


1. Network Discovery

First common oversight: ensure your connection profile is set to "Private" and not "Public", otherwise the Windows firewall will close sharing ports by default.

2. The SMBv1 Protocol Demon

If the NAS or network device is a bit old, it uses the SMBv1 protocol to communicate. For security reasons (ransomware prevention), Windows 10/11 disables it out of the box. Press Start, type "Turn Windows features on or off", scroll down to "SMB 1.0/CIFS File Sharing Support", expand it, and check the "SMB 1.0/CIFS Client" box. Reboot your PC.

Need technical support?

Does messing with the Windows terminal or system registries feel like a minefield? If you'd rather not risk your data or don't have time to waste, let a professional handle it.

Discover my IT services

Pronto Soccorso IT - Ep. 27: Impossibile accedere al NAS o alle cartelle condivise


Hai appena configurato un NAS aziendale o una stampante con cartella condivisa, ma il tuo PC rifiuta categoricamente di vederla in Rete, restituendoti un errore generico.

SMB 1.0


1. Individuazione Rete

Prima banalità spesso ignorata: assicurati che la tua connessione sia impostata su "Rete Privata" e non "Pubblica", altrimenti il firewall di Windows chiuderà le porte di condivisione di default.

2. Il demone del protocollo SMBv1

Se il NAS o il dispositivo di rete è un po' datato, usa il protocollo SMBv1 per comunicare. Per ragioni di sicurezza (prevenzione ransomware), Windows 10/11 lo disabilitano di fabbrica. Premi Start, scrivi "Attiva o disattiva funzionalità di Windows", scorri fino a "Supporto per condivisione file SMB 1.0/CIFS", espandi e spunta la casella "Client SMB 1.0/CIFS". Riavvia il PC.

Hai bisogno di supporto tecnico?

Mettere mano al terminale di Windows o ai registri di sistema ti sembra un campo minato? Se preferisci non rischiare i tuoi dati o non hai tempo da perdere, lascia fare a un professionista.

Scopri i miei servizi IT