<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[White Shirt]]></title><description><![CDATA[Whiteshirt]]></description><link>https://whiteshirt.io/</link><image><url>https://whiteshirt.io/favicon.png</url><title>White Shirt</title><link>https://whiteshirt.io/</link></image><generator>Ghost 5.75</generator><lastBuildDate>Tue, 28 Jul 2026 09:18:09 GMT</lastBuildDate><atom:link href="https://whiteshirt.io/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Spam Email!!!!!!!!!]]></title><description><![CDATA[<p>I got this spam email, and I think it&#x2019;s a pretty good one!!! Wanted to let you all know why it&#x2019;s a good spam email and what indicators of spam are in the email!</p><p>&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;-</p><p>DocHub</p>]]></description><link>https://whiteshirt.io/spam-email/</link><guid isPermaLink="false">68dc568665c4800001600828</guid><dc:creator><![CDATA[J H]]></dc:creator><pubDate>Tue, 30 Sep 2025 22:26:41 GMT</pubDate><media:content url="https://images.unsplash.com/photo-1660644807804-ffacfd7a4137?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDh8fHBoaXNoaW5nfGVufDB8fHx8MTc1OTI3MTE2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=2000" medium="image"/><content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1660644807804-ffacfd7a4137?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDh8fHBoaXNoaW5nfGVufDB8fHx8MTc1OTI3MTE2MXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=2000" alt="Spam Email!!!!!!!!!"><p>I got this spam email, and I think it&#x2019;s a pretty good one!!! Wanted to let you all know why it&#x2019;s a good spam email and what indicators of spam are in the email!</p><p>&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;-</p><p>DocHub is a legit website where you can digitally sign and annotate documents. The cool thing (lol) about this spam email is that it comes from the email &#x201C;no-reply@dochub.com&#x201D; which is DocHub&#x2019;s legitimate email. The email says that you bought crypto for $400 using PayPal, and your PayPal will be charged $400 monthly going forward.</p><p>&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;&#x2014;-</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2025/09/image.png" class="kg-image" alt="Spam Email!!!!!!!!!" loading="lazy" width="1626" height="1444" srcset="https://whiteshirt.io/content/images/size/w600/2025/09/image.png 600w, https://whiteshirt.io/content/images/size/w1000/2025/09/image.png 1000w, https://whiteshirt.io/content/images/size/w1600/2025/09/image.png 1600w, https://whiteshirt.io/content/images/2025/09/image.png 1626w" sizes="(min-width: 720px) 720px"></figure><p><strong>Spam Email Explanation</strong>:</p><p>(1) Email Sender:</p><ol><ol><li>The email is sent from &#x201C;no-reply@dochub.com&#x201D;, which is DocHub&#x2019;s <strong>legitimate email </strong>and<strong> </strong>makes it seem like DocHub is letting you know about the charges (how nice of them!!).</li></ol></ol><p>(2) Email Subject: Account Notices shared a document with you to view.</p><ol><ol><li>DocHub allows users to upload documents and share them with people, which is what this scammer is doing&#x2026; but if DocHub was legitimately sending you an email regarding activity on your account, the subject line wouldn&#x2019;t be <strong>&#x201C;</strong>[Whomever] <strong>shared a document with you to view</strong>&#x201D; and it wouldn&#x2019;t be sent from a &#x201C;no-reply&#x201D; email. It would be from &#x201C;security@dochub.com&#x201D; or something like that. <strong><u>RED FLAG</u></strong></li></ol></ol><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2025/09/image-8.png" class="kg-image" alt="Spam Email!!!!!!!!!" loading="lazy" width="2000" height="561" srcset="https://whiteshirt.io/content/images/size/w600/2025/09/image-8.png 600w, https://whiteshirt.io/content/images/size/w1000/2025/09/image-8.png 1000w, https://whiteshirt.io/content/images/size/w1600/2025/09/image-8.png 1600w, https://whiteshirt.io/content/images/2025/09/image-8.png 2026w" sizes="(min-width: 720px) 720px"></figure><p>(3) Email Body:</p><ol><ol><li>You&#x2019;ve been charged $400 USD and are going to be charged that monthly going forward&#x2026; Spam emails try to create a sense of urgency and get you to act quickly without thinking. <strong><u>RED FLAG</u></strong></li></ol></ol><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2025/09/image-6.png" class="kg-image" alt="Spam Email!!!!!!!!!" loading="lazy" width="1364" height="800" srcset="https://whiteshirt.io/content/images/size/w600/2025/09/image-6.png 600w, https://whiteshirt.io/content/images/size/w1000/2025/09/image-6.png 1000w, https://whiteshirt.io/content/images/2025/09/image-6.png 1364w" sizes="(min-width: 720px) 720px"></figure><p>(4) URL from &#x201C;View Document&#x201D; in Email Body:</p><ol><ol><li>Usually in spam emails, the button that you click to &#x201C;View Document&#x201D; will take you to a different website than the one you were expecting. Example: You get an email you think is from Microsoft that will take you to &#x201C;microsoft.com&#x201D; but the url will take you to &#x201C;spamwebsite.com&#x201D;.</li><li>The URL links to dochub.com which is their actual website. The part that&#x2019;s interesting about this is that all files users upload to DocHub are actually saved on DocHub&#x2019;s website. So someone might think that since the document is actually on DocHub&#x2019;s website it could be real.</li></ol></ol><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2025/09/image-5.png" class="kg-image" alt="Spam Email!!!!!!!!!" loading="lazy" width="1460" height="1164" srcset="https://whiteshirt.io/content/images/size/w600/2025/09/image-5.png 600w, https://whiteshirt.io/content/images/size/w1000/2025/09/image-5.png 1000w, https://whiteshirt.io/content/images/2025/09/image-5.png 1460w" sizes="(min-width: 720px) 720px"></figure><p>(5) Account Notices:</p><ol><ol><li>Why would a LEGIT email from DocHub include a random Gmail address? <strong><u>MAJOR RED FLAG</u></strong></li></ol></ol><p>(6) Sent By:</p><ol><ol><li>The email was sent by &#x201C;Account Notices&#x201D; (the scammer signed up as First Name: <u>Account</u> &#x2013; Last Name: <u>Notices</u>) &#xA0;from a &#xA0;Gmail address&#x2026; indicating that the email is not from DocHub. <strong><u>MAJOR RED FLAG</u></strong></li><li>DocHub wouldn&#x2019;t be sending their IP address in official emails (I don&#x2019;t think)&#x2026; The <a href="https://www.virustotal.com/gui/url/8d2e1cabf541945f60007c392c845685ccea9445c1cddd851fc96a6286c30c78?ref=whiteshirt.io">IP Address Scan</a> shows as malicious</li></ol></ol><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2025/09/image-7.png" class="kg-image" alt="Spam Email!!!!!!!!!" loading="lazy" width="1106" height="328" srcset="https://whiteshirt.io/content/images/size/w600/2025/09/image-7.png 600w, https://whiteshirt.io/content/images/size/w1000/2025/09/image-7.png 1000w, https://whiteshirt.io/content/images/2025/09/image-7.png 1106w" sizes="(min-width: 720px) 720px"></figure><h2 id="thank-you"><strong><u>THANK YOU!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!</u></strong></h2>]]></content:encoded></item><item><title><![CDATA[Heartbleed - CVE-2014-0160]]></title><description><![CDATA[<p>Below shows how an attacker used RMI requests to identify which servers on the network used Java for networking. Whichever servers were found that <u>were not</u> using Java, they attacked with the exploit Heartbleed.</p><p>I recieved five Suricata rule alerts from Azure. One was unique, and the other four were</p>]]></description><link>https://whiteshirt.io/heartbleed/</link><guid isPermaLink="false">6633d4591950050001a69276</guid><dc:creator><![CDATA[J H]]></dc:creator><pubDate>Thu, 02 May 2024 18:31:42 GMT</pubDate><media:content url="https://images.unsplash.com/photo-1541728472741-03e45a58cf88?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDZ8fGhhY2tlcnxlbnwwfHx8fDE3MTQ2NzI3OTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" medium="image"/><content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1541728472741-03e45a58cf88?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDZ8fGhhY2tlcnxlbnwwfHx8fDE3MTQ2NzI3OTB8MA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" alt="Heartbleed - CVE-2014-0160"><p>Below shows how an attacker used RMI requests to identify which servers on the network used Java for networking. Whichever servers were found that <u>were not</u> using Java, they attacked with the exploit Heartbleed.</p><p>I recieved five Suricata rule alerts from Azure. One was unique, and the other four were the same. Analysis of both alerts below.</p><div class="kg-card kg-header-card kg-v2 kg-width-regular " style="background-color: #000000;" data-background-color="#000000">
            
            <div class="kg-header-card-content">
                
                <div class="kg-header-card-text kg-align-center">
                    <h2 id="insight-1500-discovery" class="kg-header-card-heading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">Insight 1500 - Discovery</span></h2>
                    <p id="et-policy-rmi-request-outbound" class="kg-header-card-subheading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">ET Policy RMI Request Outbound</span></p>
                    
                </div>
            </div>
        </div><p><strong>Source IP</strong> - 192.168.10.151:34656 <strong>Destination IP</strong> - 192.168.10.144: 445</p><p>Port 445 is the&#xA0;Server Message Block, which is network file sharing between computers on the network.</p><p><strong>Pattern of Behaviour</strong></p><p>Source device is sending RMI (remote method invocation) request from a random source port (34656) to destination device through port 445.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/1.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="140" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/1.png 600w, https://whiteshirt.io/content/images/2024/05/1.png 624w"></figure><p>&#x201C;Alert Rule&#x201D; references &#x201C;reference:url, github.com/rapid7/<strong>metasploit-framework</strong>/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/lib/rex/proto/rmi/model.rb;&#x201D;</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-1.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="610" height="71" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-1.png 600w, https://whiteshirt.io/content/images/2024/05/image-1.png 610w"></figure><p>Packet encoded in Base64. Python script to convert Base64 to byte sequence.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-2.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="104" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-2.png 600w, https://whiteshirt.io/content/images/2024/05/image-2.png 624w"></figure><p>Ethernet frame analyzer for packet.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-3.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="165" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-3.png 600w, https://whiteshirt.io/content/images/2024/05/image-3.png 624w"></figure><p>Source MAC Address is not registered, and destination MAC address to VMware device.&#xA0; Unsure if destination and source addresses are flipped in this scenario. Possible that attacker tried to connect to a honeypot, or the captured packet could be the response (destination) to the attacking machine which is using VMware.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-4.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="299" height="44"></figure><p>Packet capture was incomplete and has continuation data. Packet_info.linktype: 1 indicates ethernet connection. Likely scripts:</p><p><code>nmap --script rmi-dumpregistry -p 445 &lt;host&gt;</code><br>
<code>nmap --script=rmi-vuln-classloader -p 445 &lt;target&gt;</code><br>
<code>nmap -sV -sC -p &lt;target&gt;</code><br>
<code>msfconsole = auxiliary/scanner/misc/java_rmi_server</code></p>
<p><strong>Tactics:</strong></p><p>TA0007 - Discovery: The RMI request can be used to discover/interact with Java objects on a device.</p><p><strong>Techniques:</strong></p><p>T1046 &#x2013; Network Service Discovery: The RMI request can be used to discover/interact with Java services on a device.</p><p><strong>Procedures:</strong></p><p>Network Traffic Obfuscation: Port 445 is a notorious port as it is used for file sharing across a network. The attacker could be using an RMI request in an attempt to bypass the port 445 protection, and then discovering which devices are java enabled on the network.</p><p><strong>Recommendations:</strong></p><p>Java RMI is not used anymore as both client and server need to be programmed in Java, and is insecure. All Java RMI objects should be replaced with REST or raw socket programming immediately.</p><div class="kg-card kg-header-card kg-v2 kg-width-full kg-content-wide " style="background-color: #000000;" data-background-color="#000000">
            
            <div class="kg-header-card-content">
                
                <div class="kg-header-card-text kg-align-center">
                    <h2 id="insight1504150515521555-discovery" class="kg-header-card-heading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">Insight-1504/1505/1552/1555 - Discovery</span></h2>
                    <p id="et-info-tls-handshake-failure" class="kg-header-card-subheading" style="color: #FFFFFF;" data-text-color="#FFFFFF"><span style="white-space: pre-wrap;">ET Info TLS Handshake Failure</span></p>
                    
                </div>
            </div>
        </div><p><strong>Insight 1504:</strong></p><p>1.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Source IP &#x2013; 192.168.10.185:12320</p><p>2.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Destination IP &#x2013; 192.168.10.151:57060</p><p><strong>Insight 1505 source:</strong></p><p>1.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Source IP &#x2013; 192.168.10.198:47769</p><p>2.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Destination IP &#x2013; 192.168.10.151:44594</p><p><strong>Insight 1552 source:</strong></p><p>1.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Source IP &#x2013; 192.168.10.189:443</p><p>2.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Destination IP &#x2013; 192.168.10.146:42356</p><p><strong>Insight 1555 source:</strong></p><p>1.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Source IP &#x2013; 192.168.10.198:47769</p><p>2.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Destination IP &#x2013; 192.168.10.146:42164</p><p><strong>Pattern of Behaviour:</strong></p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-5.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="46" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-5.png 600w, https://whiteshirt.io/content/images/2024/05/image-5.png 624w"></figure><p>The Suricata alert sends a warning when a TLS message is received with content that matches the string &#x201C;00 02 02 28&#x201D;. The first two blocks &#x201C;00 02&#x201D; indicate the major version (TLS version) and minor version (CipherSuite) which in this case is TLS_RSA_WITH_NULL_SHA, respectively.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-6.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="623" height="265" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-6.png 600w, https://whiteshirt.io/content/images/2024/05/image-6.png 623w"></figure><p>TLS 1.0 was published in 1999, and TLS 1.1 in 2006, which were both &#x201C;officially&#x201D; deprecated 2021, even though more secure methods have been widely adopted a long time before deprecation.</p><p>Hopefully no internal server or device would be using TLS 1.0 or 1.1, therefore we are treating this as malicious. Immediately we would assume this as a TLS downgrade attack.</p><p>The other clue we have is that the packets included in the metadata was encoded using base64, as well as packet_info.linktype: 1 which is ethernet. Convert base64 packet to hex in screenshot below.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-7.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="42" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-7.png 600w, https://whiteshirt.io/content/images/2024/05/image-7.png 624w"></figure><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-8.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="364" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-8.png 600w, https://whiteshirt.io/content/images/2024/05/image-8.png 624w"></figure><p>Source devices below from insight 1504, 1505, 1552, and 1555 respectively.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-9.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="611" height="49" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-9.png 600w, https://whiteshirt.io/content/images/2024/05/image-9.png 611w"></figure><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-10.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="613" height="51" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-10.png 600w, https://whiteshirt.io/content/images/2024/05/image-10.png 613w"></figure><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-11.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="611" height="56" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-11.png 600w, https://whiteshirt.io/content/images/2024/05/image-11.png 611w"></figure><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-12.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="611" height="63" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-12.png 600w, https://whiteshirt.io/content/images/2024/05/image-12.png 611w"></figure><p>The source device of insight 1505, and 1555 have the same mac address, as well as the same IP address and source port (192.168.10.198:47769). The system supressed messages from each insight 69, 35, 29, and 11 times, respectively.</p><p>Another notable item is the payload_printable field which reads &#x201C;......(&#x201C;.</p><p>Through a bunch of digging around on the internet, this is found on an openssl website (<a href="https://mta.openssl.org/pipermail/openssl-users/2015-March.txt?ref=whiteshirt.io">https://mta.openssl.org/pipermail/openssl-users/2015-March.txt</a>), which fits the Suricata rule perfectly.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-13.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="469" height="46"></figure><p>Found through more digging that the traffic we&#x2019;ve seen is related to the Heartbleed vulnerability.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/image-14.png" class="kg-image" alt="Heartbleed - CVE-2014-0160" loading="lazy" width="624" height="64" srcset="https://whiteshirt.io/content/images/size/w600/2024/05/image-14.png 600w, https://whiteshirt.io/content/images/2024/05/image-14.png 624w"></figure><p>With the repeated and supressed requests we can be certain it&#x2019;s the Heartbleed exploit, which is easily accessible through Metasploit. Heartbeat was a feature added for keep-alive functionality.</p><p><strong>Tactics</strong></p><p>-&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Exploitation of the heartbeat extension (RFCC6520) causing memory leakage from the server to the client and the client to the server.</p><p><strong>Techniques</strong></p><p>-&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Sending specialized and repeated heartbeat requests.</p><p><strong>Procedures</strong></p><p>-&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0; Data extraction once encryption keys have been captured.</p><p><strong>Recommendation</strong></p><p>Identify if any servers are using TLS 1.2 or less, and ensure all servers use TLS 1.3.</p>]]></content:encoded></item><item><title><![CDATA[Setup a VPN for free with Oracle and WireGuard.]]></title><description><![CDATA[<p>How to get a free VPN using an Oracle virtual private server (VPS), Wireguard, and a little technical know-how. I currently pay for NordVPN, but this is an easy way to get a VPN for free, with just a little bit of technical knowledge.</p><p>First, signup for a free Oracle</p>]]></description><link>https://whiteshirt.io/setup-a-vpn-for-free-with-oracle-and-wireguard/</link><guid isPermaLink="false">6633c29a1950050001a6925a</guid><dc:creator><![CDATA[J H]]></dc:creator><pubDate>Thu, 02 May 2024 16:45:00 GMT</pubDate><media:content url="https://images.unsplash.com/photo-1451187580459-43490279c0fa?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fG5ldHdvcmt8ZW58MHx8fHwxNzE0NjY4MDgyfDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" medium="image"/><content:encoded><![CDATA[<img src="https://images.unsplash.com/photo-1451187580459-43490279c0fa?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fG5ldHdvcmt8ZW58MHx8fHwxNzE0NjY4MDgyfDA&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=2000" alt="Setup a VPN for free with Oracle and WireGuard."><p>How to get a free VPN using an Oracle virtual private server (VPS), Wireguard, and a little technical know-how. I currently pay for NordVPN, but this is an easy way to get a VPN for free, with just a little bit of technical knowledge.</p><p>First, signup for a free Oracle account using the below link, and download and install the Wireguard client.</p><p><a href="https://signup.cloud.oracle.com/?sourceType=_ref_coc-asset-opcSignIn&amp;language=en_CA&amp;ref=whiteshirt.io">Oracle Signup</a><a href="https://www.wireguard.com/install/?ref=whiteshirt.io">Wireguard Download</a></p><p>After you&apos;ve put in your account information, and validated your email you must choose your home region. This home region is going to be where your VPN is. You can not change this, so choose carefully. Use the link below to find your closest region.</p><p><a href="https://www.oracle.com/ca-en/cloud/public-cloud-regions/?ref=whiteshirt.io">Oracle Cloud Regions</a></p><p>Once you&apos;re in, hit the hamburger menu in the top left, click &quot;Compute&quot; and then &quot;Instances&quot;. </p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-083938---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Make sure your Compartment is selected in the bottom left, and then hit Create Instance.</p><p>Select the Canonical Ubuntu 22.04 Minimal aarch64 image, and you can leave the Shape as-is.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-084556---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Now save the private and public keys, and hit Create. </p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-170316---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>You will have to wait a few minutes for the VM to be created. After it is created, you can view the servers information. Note down the IP address, as we will need it later.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-170649---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Right click on the downloaded &quot;.key&quot; file, hit properties, then the Security tab, and hit advanced. Click Disable inheritance at the bottom and convert to inherited permissions into explicit permissions.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-171335---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Remove all accounts until your username is the only one left, and then hit apply. Copy that .key file, open up file explorer, and navigate to C:\Users\&lt;your username&gt;\.ssh, and paste the .key file. Right click on the key file and &quot;copy as path&quot;</p><p>Now we are going to access the newly created VPS using ssh. We will need two things.</p><ol><li>The path to your key file. ex: &quot;C:\Users\J\.ssh\ssh-key-2024-05-01.key&quot;</li><li>The IP address of your VPS. ex: 155.248.218.244</li></ol><p>Open Windows terminal and type:</p><p><code>ssh -i pathtoyourkeyfile ubuntu@155.248.218.244</code></p><p></p><p>Example:<br><br><code>ssh -i C:\Users\J\.ssh\ssh-key-2024-05-01.key ubuntu@155.248.218.244</code></p><p></p><p>Type in yes, and hit enter.</p><p>Now we need to update and upgrade the system. Copy the below code one by one. If it asks you which services you need to restart, say none, as we will reboot shortly.</p><p><code>sudo apt update<br><br>sudo apt upgrade -y<br><br>sudo iptables -I INPUT -j ACCEPT<br><br>sudo su<br><br>iptables-save &gt; /etc/iptables/rules.v4<br><br>exit<br><br>sudo reboot now</code></p><p></p><p>Wait about 30 seconds, and then press the up arrow key to bring back your ssh command, and then press enter. Run the code below to start the VPN process.</p><p><code>curl -O https://raw.githubusercontent.com/angristan/wireguard-install/master/wireguard-install.sh<br><br>chmod +x wireguard-install.sh<br><br>sudo ./wireguard-install.sh</code></p><p></p><p>Input your Oracle VPS IP address for the first question, and then you can press enter for the remaining questions.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-175403---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Input a client name, and press enter for the remaining questions.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-175852---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Paste the below code to view the Wireguard config file.</p><p><code>cat /home/ubuntu/wg0-client-vpn.conf</code></p><p></p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-180206---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Highlight from [Interface] all the way to AllowedIPs, and ctrl+c to copy.</p><p>Open WireGuard and hit ctrl+n to create a new tunnel. Paste in the information generated from the VPS.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-180707---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure><p>Hit save, and then activate, and then you&apos;re connected!</p><p>Google your IP address and it should be the same as the VPS IP address.</p><figure class="kg-card kg-image-card"><img src="https://whiteshirt.io/content/images/2024/05/Screenshot-2024-05-01-181431---Copy.png" class="kg-image" alt="Setup a VPN for free with Oracle and WireGuard." loading="lazy"></figure>]]></content:encoded></item></channel></rss>