Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
83c939fc20 | ||
|
|
92d8f4eb6b |
@@ -18,9 +18,9 @@ Your Git structure has solid bones but significant hygiene gaps. For a private,
|
|||||||
|
|
||||||
The `scripts` repo (11 commits, 75KB) contains Windows provisioning PowerShell scripts with **plaintext passwords committed to history:**
|
The `scripts` repo (11 commits, 75KB) contains Windows provisioning PowerShell scripts with **plaintext passwords committed to history:**
|
||||||
|
|
||||||
- `LoveMyBoys73!` -- ippadmin MSP backdoor account
|
- `[REDACTED]` -- ippadmin MSP backdoor account
|
||||||
- `Liberty4All!` -- liberty-admin customer admin
|
- `[REDACTED]` -- liberty-admin customer admin
|
||||||
- `tire` -- tire power user
|
- `[REDACTED]` -- tire power user
|
||||||
|
|
||||||
These appear in `dell-reimage-kit/` unattend XML and PowerShell. Even if this repo stays private forever, credentials in git history is a ticking time bomb. One accidental `git clone` to the wrong place and those passwords are exposed.
|
These appear in `dell-reimage-kit/` unattend XML and PowerShell. Even if this repo stays private forever, credentials in git history is a ticking time bomb. One accidental `git clone` to the wrong place and those passwords are exposed.
|
||||||
|
|
||||||
|
|||||||
@@ -144,9 +144,9 @@ This gives every file a clear home without over-nesting.
|
|||||||
#### `scripts` — 10 potential secrets
|
#### `scripts` — 10 potential secrets
|
||||||
Real, hardcoded credentials found in Windows provisioning scripts:
|
Real, hardcoded credentials found in Windows provisioning scripts:
|
||||||
```
|
```
|
||||||
+Password="LoveMyBoys73!"
|
+Password="[REDACTED]"
|
||||||
+Password="Liberty4All!"
|
+Password="[REDACTED]"
|
||||||
+Password="tire"
|
+Password="[REDACTED]"
|
||||||
+Username="ippadmin"
|
+Username="ippadmin"
|
||||||
+Username="liberty-admin"
|
+Username="liberty-admin"
|
||||||
```
|
```
|
||||||
@@ -156,10 +156,10 @@ These are active Windows admin credentials embedded in PowerShell unattend scrip
|
|||||||
#### `hermes-recovery` — 8 potential secrets
|
#### `hermes-recovery` — 8 potential secrets
|
||||||
Includes the Gitea API token used for this audit:
|
Includes the Gitea API token used for this audit:
|
||||||
```
|
```
|
||||||
+TOKEN="1761daa2c537fb72b365e54619208329d8e3ad33"
|
+TOKEN="[REDACTED]"
|
||||||
+TELEGRAM_BOT_TOKEN="8359374835:***"
|
+TELEGRAM_BOT_TOKEN="[REDACTED]"
|
||||||
+password="K3E1ZZWvHDu0q8ZmoBCAhzKUZawEapdGBlbaPME1sOTKgGk9FCuYS"
|
+password="***"
|
||||||
+token = "Ta9f9d1b462271a2f4-8d63a3f025eb89451edb16f2308c2e40"
|
+token = "[REDACTED]"
|
||||||
```
|
```
|
||||||
|
|
||||||
The Gitea token itself is committed. This means `hermes-recovery` as a public repo exposes admin credentials.
|
The Gitea token itself is committed. This means `hermes-recovery` as a public repo exposes admin credentials.
|
||||||
|
|||||||
@@ -8,3 +8,4 @@ Master index of all internal and client projects.
|
|||||||
- **[OSINT People Search](./osint-tool/README.md)**: An Open Source Intelligence tool for performing background checks, compiling data broker reports, and removing personal information. (IN DEVELOPMENT)
|
- **[OSINT People Search](./osint-tool/README.md)**: An Open Source Intelligence tool for performing background checks, compiling data broker reports, and removing personal information. (IN DEVELOPMENT)
|
||||||
- **[Apex Track Experience](./apex-track/README.md)**: Website and operations platform for track day experiences, vehicle registrations, and event logistics. (PLANNED)
|
- **[Apex Track Experience](./apex-track/README.md)**: Website and operations platform for track day experiences, vehicle registrations, and event logistics. (PLANNED)
|
||||||
- **[BoxPilot Logistics](./boxpilot/README.md)**: Logistics and shipping management platform. (PLANNED)
|
- **[BoxPilot Logistics](./boxpilot/README.md)**: Logistics and shipping management platform. (PLANNED)
|
||||||
|
- **[Open-Source SaaS Alternatives](../projects/oss-saas-alternatives.md)**: 10 self-hostable replacements for paid SaaS (AppFlowy, Immich, Documenso, Excalidraw, Penpot, Cal.DIY, ListMonk, Dub, RustDesk, FluidVoice). Future productize/host candidates. (FUTURE PROJECTS)
|
||||||
|
|||||||
@@ -0,0 +1,50 @@
|
|||||||
|
# Open-Source SaaS Alternatives — Future Project Candidates
|
||||||
|
|
||||||
|
**Status:** Future Projects — Research & Planning
|
||||||
|
**Saved:** 2026-08-12
|
||||||
|
**Category:** Productize / Self-Host / MSP Offering
|
||||||
|
**Owner:** IT Pro Partner (Sho'Nuff)
|
||||||
|
**Source:** "10 GitHub Repos That Will Kill Your Monthly Subscriptions" — Andrew Warner, The Next New Thing (Aug 11 2026) — https://youtu.be/jMAe1h39rHo
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Thesis
|
||||||
|
|
||||||
|
Ten open-source, self-hostable replacements for paid SaaS tools. Warner's closing pitch is the operative idea: *"take the source code, throw it at Codex or Claude, and build your own version around your needs."* For IT Pro Partner the higher-value angle is the inverse of "self-host it yourself" — **wrap each in a managed/hosted offering and sell it at premium pricing** (obstacles-as-products pattern, same as Ops Portal / Super Search / backup-restore).
|
||||||
|
|
||||||
|
## The Ten Candidates
|
||||||
|
|
||||||
|
| # | OSS Tool | Replaces | Repo | ITPP Angle |
|
||||||
|
|---|---|---|---|---|
|
||||||
|
| 1 | AppFlowy | Notion | github.com/AppFlowy-IO/AppFlowy | Flutter+Rust, block editor, kanban, AI. Hosted-plan vendor exists — white-label opportunity |
|
||||||
|
| 2 | Immich | Google Photos | github.com/immich-app/immich | 110k stars, on-device face rec. Managed photo vault for clients (respect 3-2-1 backup) |
|
||||||
|
| 3 | **Documenso** | DocuSign | github.com/documenso/documenso | **Self-hosted e-sign + audit trail.** Fits proposal/contract pipeline (VerdictTank/RFP Tank sign-off) |
|
||||||
|
| 4 | Excalidraw | Miro | github.com/excalidraw/excalidraw | MIT, instant no-signup whiteboard. Already used internally — resell not obvious |
|
||||||
|
| 5 | Penpot | Figma | github.com/penpot/penpot | Web-standards design tool. Niche, dev-facing |
|
||||||
|
| 6 | Cal.DIY | Calendly | github.com/calcom/cal.diy | Self-hosted scheduling. MSP client booking, white-label |
|
||||||
|
| 7 | ListMonk | Mailchimp | github.com/knadh/listmonk | No per-subscriber pricing. Email/outreach stack (Savannah, TIMA PTA, prospect funnels) |
|
||||||
|
| 8 | Dub | Bitly | github.com/dubinc/dub | Link mgmt + conversion tracking + affiliate. Marketing funnel tooling |
|
||||||
|
| 9 | **RustDesk** | TeamViewer | github.com/rustdesk/rustdesk | **Self-hosted remote desktop.** MSP core tool — managed relay on netcup kills per-seat TeamViewer/Splashtop fees |
|
||||||
|
| 10 | FluidVoice | Whisper Flow | github.com/altic-dev/FluidVoice | Local STT, audio never leaves the box. Windows build landing. Voice-agent adjacent |
|
||||||
|
|
||||||
|
## Priority Candidates (build/test first)
|
||||||
|
|
||||||
|
1. **RustDesk** — the highest-leverage MSP play. A self-hosted relay + managed client rollout replaces a per-seat cost line on every support contract. Test: relay on netcup, tunnel via WireGuard/Tailscale, verify NAT traversal.
|
||||||
|
2. **Documenso** — self-hosted e-signature with audit trail on our infra. Direct fit for proposal and contract sign-off in the VerdictTank/RFP Tank pipeline. DocuSign's $132/yr-for-5-envelopes pricing is the pain point to sell against.
|
||||||
|
3. **ListMonk + Dub** — cheap wins for the marketing/outreach funnel. Self-hosted newsletter + link tracking kills two subscriptions and feeds lead attribution.
|
||||||
|
|
||||||
|
## Productize Angle
|
||||||
|
|
||||||
|
Each of these is a candidate to package as "Hosted X for MSPs/clients" — managed deployment, backups (already in the Core 6 + Wasabi pipeline), updates, and support, at premium recurring pricing. The moat is not the software (it's free), it's the operation: the same infra + backup + reliability discipline we already run. Do not leave clients to self-host.
|
||||||
|
|
||||||
|
## Open Questions
|
||||||
|
|
||||||
|
1. RustDesk relay: netcup vs. app2 (Hetzner) placement, and whether a public relay or Tailscale-only mesh is the right default.
|
||||||
|
2. Documenso: does it meet legal e-signature requirements for client contracts (audit trail integrity, signer identity)?
|
||||||
|
3. ListMonk deliverability: self-hosted IP reputation vs. routing through an SMTP relay (MXroute).
|
||||||
|
|
||||||
|
## Source
|
||||||
|
|
||||||
|
- Video: https://youtu.be/jMAe1h39rHo (Andrew Warner, The Next New Thing)
|
||||||
|
- Resource links: https://thenextnewthing.ai/l/github-repos-aug14
|
||||||
|
- Retrieved: 2026-08-12
|
||||||
Reference in New Issue
Block a user