Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Trinitrotoluene posted:

5) Explaining that adding "Domain Users" to "Local Administrators" is a bad idea.

My company just got acquired by a huge company that's very well known. I'm in the process of joining our networks and soon we'll be dumping our Windows domain and joining theirs.

I about poo poo myself when I heard them say "every user is Local Admin on their PCs". This company has ~3000 employees and offices in many, many countries. Why on earth they would allow this to go on is beyond my comprehension...

Oh well, it's not my problem to worry about. I'll be assigned to the Linux team full time soon anyway.

Adbot
ADBOT LOVES YOU

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

enotnert posted:

setting the dns to google would have worked, had it not kept resetting the lmhosts file yo.

I suppose I don't hit these viruses very often but what happens if you lock down lmhosts to be readonly? Are there any viruses floating around that dumb?

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Body:
Hey we were getting all these virus attachments in our emails and so I updated ClamWin and scanned the Exchange server. It says we have 799,000 viruses! Can you please help me!? Look at the screenshot I attached!


Screenshot showed ClamWin saying it has 799,000 known viruses with 0 detected...

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Strange situation --

-Client wants to change to us as a webhost

-Current webhost not responding to requests from anyone. it's a 1 man show -- business line goes right to his cell phone.

-Nobody from the client party is technically literate

-Current webhost also registered their domain -- reseller through Enom, etc

-Finally recovered domain name from the bastard without him knowing, but need website files before he shuts them down

-Find random guy they know who has access and downloaded all the files for me last night. wont give me access to the FTP for some reason -- not sure he even knows what FTP is (got it from dreamweaver or something... HOORAY!)

-Now the guy wants to send me the files like I asked. I started giving him FTP info, and he cut me off -- he's insisting on sending me the files over IM.

-I'm about to shoot myself. :smithicide:

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Well, phone call that I make a ticket out of, but here's how it went:

;-* We need to know if someone hacked into our email account, computer, or someone broke into the office and sent this email to everyone. It was sent at 4:36am today.

:clint: Ok, I see an email from around that time. It's from an SBC DSL connection that appears to be from in town.

;-* That's our DSL connection at the office.

:clint: Ok, great. Can you tell me more about the email?

;-* It said "Does anyone want to gently caress my little rear end tonight?"

:awesome:

--

and my first thought was :pervert: due to her highly attractive voice, and then I wanted to say "Sure, but what was that email about?"

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Coworker showed me this. Apparently this was a conversation had via email with a customer.... You need to see this in its entirety. I promise it's not fabricated. Not a single word.

customer posted:

Hey guys,

Our internet was not working for awhile this morning. We are wondering if you had a glitch with the [redacted] service or if it was [ISP]? Any ideas?

Don posted:

Customer,

We suffered a massive denial of service attack against one customer who
runs a spam fighting tool.
It's a very effective tool, hence, it's targetted by spammers.

We needed to take the server down, contact our upstream providers, have
them block access to the target's ip, then everything started settling down.

customer posted:

Thank you for the information. We were wondering what happened.

Is there a way to notify us in advance next time? That would be very
helpful...thanks!

Ok, at this point it seems normal. Nothing too unusual. And then Don gets into analogy mode.

don posted:

Unfortunately, we cannot predict when we will get attacked and have no
way to forewarn our customers in advance.

If you consider this in military terminology, :aaa: it becomes easier to
understand the significance of what happened.

Imagine being an infantryman on a patrol with 3 others. :aaaaa: You are the
driver and you are patrolling a section of a major street in Baghdad.

You are a trained and experienced soldier with a few years under your
belt and you have all the tools you need to do your job. Well, that's
debateable, but I digress. :doh:

While on patrol, you hit an improvised explosive device or IED that gets
set off as you pass it. :wtf:

Although you know the area is dangerous, you have been well trained, you
have all the tools at your disposal to deal with an armed combatant and
you are very alert; you have no idea whether that can or rock that you
pass will explode or not. :wtc:

Now, if we could have caught the combatants actually laying the mine,
then we can prevent the attack from occurring. However, that is a rare
occurrence.

In our case, there is no way to know that someone or someones were
planning to attack a particular server on the other side of the world,
especially on a road as big as the Internet.

I hope that made sense. :psypop:

:ughh:

No, the customer didn't respond.

feld fucked around with this message at 16:47 on Aug 19, 2010

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Yaos posted:

Our ticket client is the best, we just got achievements added. I brought it up as a joke, that we should get achievements for closing tickets. That guy that maintains it and adds features one day, tells me to click my username, and there's the achievements.

I'm hoping one day it will be released to the public since our ticket client is fast and not buggy. It's only for a small numbers of techs though, as it's way too easy to grab a ticket away from somebody else by accident.

This. Sounds. Awesome.

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

CitizenKain, what's the status on that server? :colbert:

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

This customer just printed two emails out... wrote on them with a pen... scanned them... converted to PDF... and emailed them back in to us.

:suicide:

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

:haw: I need ImageMagick and Ghostscript!
:zoro: Ok, here you go
:haw: It's not working! You didn't do what I asked!
:zoro: Yes, yes I did. Show me what's broken
:haw: It doesn't work in PHP I keep getting these errors...
:zoro: ... I didn't install any PHP modules... show me your code
:haw: <?php system("/usr/local/bin/convert....."
:zoro: You gotta be loving kidding me.
:zoro: Listen dumbass, it works from the shell and it works when I run # php test.php. Stop using system(), use this MagickWand PHP module
:haw: But I don't want to! I want to use system()!


:suicide:

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

This actually happened today

:cry: website load slow what is wrong with the server?
:wotwot: each of your website home pages are 3.5MB in size.


:downsrim:

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

quote:

BLANK from BLANK wants to know if there is any kind of encryption set up on their T1 leased line transport. They need to conform to HIPPA regulations and have all connections encrypted which they send communications over.

Comments from coworkers:

:black101: I hope they have encryption between their workstations and their switch
:colbert: Just tell them we use a cipher that replaces all data with 1's and 0's.
:pseudo: Can we just send them a picture of a padlock on each router?

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

Rhymenoserous posted:

I think anyone who worked in a LAMP shop at some point knows someone who did this, and that person served as an object lesson for the rest of the shop.

This led to the creation of fixperms.pl being distro'd out to all of our servers.

FreeBSD comes with mtree and mtree files. It's a tool to take snapshots of your filesystem permissions. I cron it on my server to capture non-system files (like everything we've installed in /usr/local, our home directories, etc) so when someone does this it's a simple fix.

example of format:
pre:
# $FreeBSD: stable/9/etc/mtree/BSD.usr.dist 225949 2011-10-03 20:27:51Z dim $
#
# Please see the file src/etc/mtree/README before making changes to this file.
#

/set type=dir uname=root gname=wheel mode=0755
.
    bin
    ..
    games
    ..
    include
    ..
    lib
        aout
        ..
        compat
            aout
            ..
        ..
        dtrace
        ..
        engines
        ..
        i18n
        ..
Any BSD server should be recoverable in single user mode with a few commands using the supplied backups in /etc/mtree. Won't fix non-base system files if you aren't making those mtree backups yourself, but it will at least bring the server back to a usable state.

Much :love: for this tool

Adbot
ADBOT LOVES YOU

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

ptier posted:

gently caress Quickbooks.
gently caress Quickbooks users with a 624MB Company File
gently caress Quickbooks users with a 624BM Company File w/ 43,000 Undeposited transactions trying to work from a client to the server.

And I'm being trapped into setting up a Quickbooks Enterprise server for a new customer. Please tell me this won't be a nightmare. :ohdear: