Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Docjowles
Apr 9, 2009

GreenNight posted:

If I dump all the code in this thread will he sue SA?

I think I speak for all non mods when I say “do it and let’s find out lol”

It’ll be like that time somebody printed the DVD encryption key on a t shirt.

Adbot
ADBOT LOVES YOU

CLAM DOWN
Feb 13, 2007




Bring it on

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

v2.11

https://pastebin.com/i0vN7UkG

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




Sickening posted:

I have seen the script before and don't I remember a single thing about the script that gave me the impression that it did anything groundbreaking. Useful? Absolutely. Widely used? It did catch on anywhere people were talking about wsus. So unique that it needed to be monetized? :laffo:

Developing a script like that and getting it tested and touching production servers ? That will get into the low four figures in most corporate environments. Even if you're a Powershell expert already, that'll take some real time to research just exactly what you want it to do. And do you have a test environment with a WSUS in it ? If not, you have to spin that up, get it working, and do some useful tests. Than can easily take days from multiple people.

In the positive news department, I did our first PoC for using qemu to virtualize lab machines. We have literally hundreds of systems controlling instruments running XP and Win 7 Pro (and our Win 7 Pro image sucked). Many of these machines can't be replaced or even re-imaged because the vendor for the instrument they control no longer exists, or wants $10,000 to have someone come out to reinstall the software - and that not necessarily as soon as next week.

We're going to capture images of those machines and virtualize them. Lab downtime for software issues will be a thing of the past, just revert to the last good checkpoint and start the run over again. Qemu on Centos 7 will save us an extra Windows license vws doing it in Hyper-V. Today I demonstrated a guest OS controlling a USB device connected to the host machine. Okay, it was just a USB DVD drive, but the Win7 VM saw it and was able to eject the drive tray. That's trivial. Next week, we book some time with a lab manager and try it with a nanodot sampler. That's money. We've got a long way to go, but we have seen the future for Research, and it's virtual.

Oh, and firewall-cmd is the poo poo, the absolute greatest poo poo, for someone who had to hand-roll iptables configs back in the day.


e. The WSUS script is 5000 lines of Powershell ? High four- to low five-figures to develop in-house. Low 4-figures to grok and test it, but still much less than doing your own solution from scratch.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


I’m not reading through that mess. Someone highlight the funny parts.

DropsySufferer
Nov 9, 2008

Impractical practicality

angry armadillo posted:

I am trying to work out if one of the helpdesk guy does this because he doesn't know the answer or if he believes the things he says.

I might start taking bets because I just cant call it.

I'm going to say that he actually believes what he says. He went on a rant the other day about how the whole dev team are basically idiots and only he knows what's best. :allears:

Anyway just from what little my boss has said I can tell his opinion of the person is not great. How long he lasts is what I'm really curious about.

CLAM DOWN
Feb 13, 2007





Jesus wtf

MC Fruit Stripe
Nov 26, 2002

around and around we go
Page has been removed, what sort of drama happened here?

Schadenboner
Aug 15, 2011

by Shine

:tinfoil::hf::ohdear:

Defenestrategy
Oct 24, 2010

I didn't know this, but recruiters will snitch on you.

One of tech leads? I guess was sitting in on an interview, and our company does the schtick where the HR and management leave and the interviewee can just ask what ever of a potential higher up co-worker, while theoretically less being pressured about asking "polite" questions. So the dude pressured the tech lead in to answering the "whats a negative thing about working here", question, and honestly it is pretty cool working here, so I would be hard pressed to think of one. I do know the answer isn't in half jest, "Yea, one of the execs can be kind of a d-bag, but he doesn't come in much so it'll be fine." especially to someone who doesn't work here, but the Interviewee told his recruiting company, who told the exec in question, who then wanted the dudes head on a platter.

What I wonder is, why did the recruiter think that was a good route to take? At best nothing comes of it, except maybe one of the execs likes your candidates a bit more, and at worse you've hosed yourself, because anyone who liked the dude that got canned who has a say in recruitment is gonna dumpster any of your clients out of spite. In repentance the recruiters in question have been leaving breakfast in our kitchen for the last week.

Defenestrategy fucked around with this message at 15:30 on Feb 23, 2019

Che Delilas
Nov 23, 2009
FREE TIBET WEED

Defenestrategy posted:

What I wonder is, why did the recruiter think that was a good route to take? At best nothing comes of it, except maybe one of the execs likes your candidates a bit more, and at worse you've hosed yourself, because anyone who liked the dude that got canned who has a say in recruitment is gonna dumpster any of your clients out of spite. In repentance the recruiters in question have been leaving breakfast in our kitchen for the last week.

Yeah this makes up for deliberately trying to ruin someone's life.

chocolateTHUNDER
Jul 19, 2008

GIVE ME ALL YOUR FREE AGENTS

ALL OF THEM

Boy, that sure did disappear fast.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Narcs itt

chocolateTHUNDER
Jul 19, 2008

GIVE ME ALL YOUR FREE AGENTS

ALL OF THEM

Dudes probably trollin around on pastebin looking for it a few times a day.

Wibla
Feb 16, 2011

He probably has a script that scrapes pastebin, a lot of people do.

Sickening
Jul 16, 2007

Black summer was the best summer.

Wibla posted:

He probably has a script that scrapes pastebin, a lot of people do.

Heh, If you take all the comments out, change up the order of various tasks, and then post it on pastebun, what kind of case does he have to take it down?

This person is using similar calls to default windows commandlets, take down my intellectual property!

Sickening
Jul 16, 2007

Black summer was the best summer.
I am putting a Eula on all of my 6 line powershell script. All of you have been warned.

Don’t you dare be trying to copy my get-aduser original content. All of you putting together ipconfig batch scripts are in notice too!

CLAM DOWN
Feb 13, 2007




Sickening posted:

I am putting a Eula on all of my 6 line powershell script. All of you have been warned.

Don’t you dare be trying to copy my get-aduser original content. All of you putting together ipconfig batch scripts are in notice too!

you're going down

Methanar
Sep 26, 2013

by the sex ghost
code:
#!/bin/bash
original content do not copy

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

Methanar posted:

code:
#!/bin/bash
original content do not copy

*changes it to sbin*

Tetramin
Apr 1, 2006

I'ma buck you up.
What’s in the loving paste bin. Put it in a post here

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Sepist posted:

*changes it to sbin*

#!/bin/env python

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

code:
#!/usr/bin/env bash

Methanar
Sep 26, 2013

by the sex ghost
code:

docker run bash $(cat << EOF > /dev/stdout 
echo hello
EOF
)

:chanpop:




cat <(docker run bash $(cat << EOF > /dev/stdout
echo hello
EOF
)
) > /dev/null


Methanar fucked around with this message at 02:50 on Feb 24, 2019

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Nerds

30 TO 50 FERAL HOG
Mar 2, 2005



Tetramin posted:

What’s in the loving paste bin. Put it in a post here

its loving huge, it would take up several posts

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


It was 5k lines of crappy code in a single file.

E: I once supported Perl code that shelled out to perl. It was awesome.

jaegerx fucked around with this message at 04:33 on Feb 24, 2019

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.
I once embedded a Perl script in unreachable lines past the end of a bash script, don't @ me

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.
code:
If 1 then 1 
Fear me

Methanar
Sep 26, 2013

by the sex ghost

Vulture Culture posted:

I once embedded a Perl script in unreachable lines past the end of a bash script, don't @ me

Why



<?php
shell_exec(' cat lol.sh | grep -A999 "#!/usr/bin/perl" | perl ');
?>




I've written a series of shell scripts that pipe poo poo into a gnu expect interpreter that controls like 50KW worth of electrical circuits.

Methanar fucked around with this message at 06:03 on Feb 24, 2019

CLAM DOWN
Feb 13, 2007




Methanar posted:

I've written a series of shell scripts that pipe poo poo into a gnu expect interpreter that controls like 50KW worth of electrical circuits.

It worries me that someone let you do this.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

It worries me that someone let you do this.

I don’t even trust this guy to rake my rocks.

Potato Salad
Oct 23, 2014

nobody cares


Methanar posted:


I've written a series of shell scripts that pipe poo poo into a gnu expect interpreter that controls like 50KW worth of electrical circuits.


How do you think many businesses log in to their banks?

Wibla
Feb 16, 2011

Methanar posted:

I've written a series of shell scripts that pipe poo poo into a gnu expect interpreter that controls like 50KW worth of electrical circuits.

Fuuuuck.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


So,

All the InfoSec guys on twitter are telling me to stop focusing on 0-Days and start focusing more on IT Hygiene. Not that 0-Days aren't important but that in the terms of most medium-large businesses that aren't the military, government or otherwise a likely target of hackers being organized is much more important than we once realized.

Thoughts?

Thanks Ants
May 21, 2004

#essereFerrari


As in, as a career?

cheque_some
Dec 6, 2006
The Wizard of Menlo Park

jaegerx posted:

It was 5k lines of crappy code in a single file.

E: I once supported Perl code that shelled out to perl. It was awesome.

I remember seeing one of my co-workers having a Perl script that shelled out to the Perl interpreter. I was like "WHY?" and he was like, "What, it works :shrug:"

translation: I copied this from the Internet and have no idea what it does

cheque_some fucked around with this message at 20:53 on Feb 24, 2019

lampey
Mar 27, 2012

Tab8715 posted:

So,

All the InfoSec guys on twitter are telling me to stop focusing on 0-Days and start focusing more on IT Hygiene. Not that 0-Days aren't important but that in the terms of most medium-large businesses that aren't the military, government or otherwise a likely target of hackers being organized is much more important than we once realized.

Thoughts?

Yes it is likely that focusing on patching, best practices for network design, following least privilege principles, auditing current permissions, and monitoring for all of the above to ensure it doesn't change is a better use of your time. You are 1000x more likely to have a problem because a server has 3389 exposed to the internet and you have a weak administrator account password with the default name. Or a user downloaded malware that takes advantage of a vulnerability that should have been patched a year ago.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Tab8715 posted:

So,

All the InfoSec guys on twitter are telling me to stop focusing on 0-Days and start focusing more on IT Hygiene. Not that 0-Days aren't important but that in the terms of most medium-large businesses that aren't the military, government or otherwise a likely target of hackers being organized is much more important than we once realized.

Thoughts?

I’d agree with them

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



lampey posted:

Yes it is likely that focusing on patching, best practices for network design, following least privilege principles, auditing current permissions, and monitoring for all of the above to ensure it doesn't change is a better use of your time. You are 1000x more likely to have a problem because a server has 3389 exposed to the internet and you have a weak administrator account password with the default name. Or a user downloaded malware that takes advantage of a vulnerability that should have been patched a year ago.

skipdogg posted:

I’d agree with them

:same:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply