Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
Methanar
Sep 26, 2013

by the sex ghost
Install wsl and then dd his laptop over ssh for local analysis

Adbot
ADBOT LOVES YOU

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


Schadenboner posted:

I mean no single-spinners on endpoints, obvs. Big spinners on RAIDed and backed-up storage is fine unless you’re :homebrew: af and can spring for all-flash arrays in which case “you do you” (as the kids say these days).

But spinners on desktops/laptops in 20-loving-19 are malpractice per se in my book.

We just bought a bunch of all-flash v7k and yes, my dick IS feeling rather large these days. Thanks for asking.

nepetaMisekiryoiki
Jun 13, 2018

人造人間集中する碇
In this current time one can order 240 GB SSD for 30€ and 500 GB SSD for 50€ . The 5400 RPM 500 GB drive is 25€ refurbished or more like 40€ new, let alone 7200 rpm costs.

Simply no reason to leave a system with conventional hard drive anymore. Especially in laptop, where there are still price premiums for hard drive over the desktop sizes, but all SSDs already fit the size so the value is even worse for hard drive. You basic need to waste money to use conventional hard drive now.

Shut up Meg
Jan 8, 2019

You're safe here.

Zero VGS posted:

Ticket came in from the company lawyer: does anyone know of a file recovery program with a Server / Client setup so that I can silently push to a remote laptop, and run the file recovery client from here?

I need proof that someone was downloading some pirated stuff, but browsing their C$ doesn't show the incriminating files. I'm like 90% sure if I run Recova or something I'll see the evidence they tried to ditch, but I don't want to tip them off.

Edit the Hosts file to block access to Facebook.

Wait til they scream at your support desk that they have lost internet access.

Ship them a loaner, run forensics on the original machine.

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

:yayclod:

It only affects people who use the Pardot tools on their org. Which is pretty much anyone with marketing tools, so yeah, it's a big, impressive fuckup.

:yaybutt:

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Shut up Meg posted:

Edit the Hosts file to block access to Facebook.

Wait til they scream at your support desk that they have lost internet access.

Ship them a loaner, run forensics on the original machine.

This, but move it to a custom vlan with random image replacement or whatever. If you modify the machine they get to claim it was you downloading stuff.

Digital_Jesus
Feb 10, 2011

Shut up Meg posted:

Edit the Hosts file to block access to Facebook.

Wait til they scream at your support desk that they have lost internet access.

Ship them a loaner, run forensics on the original machine.

Disable the keyboard and mouse on the laptop remotely from device manager is better IMO. Instant callback.

Schadenboner
Aug 15, 2011

by Shine

[IMG:Drake turning his head and putting up a hand unhappily]


[IMG:Drake looking and pointing approvingly]

Rooted Vegetable
Jun 1, 2002
Can you tell us more why you don't want to tip this person off? Can't you and the lawyer just walk up and snatch it, toss a loaner at him and leave without saying a single word? Better still if you wear matching suits and sunglasses to look like some sort of covert government agency.

Schadenboner
Aug 15, 2011

by Shine
Schedule a meeting with him, then gank his lappy when he’s away?

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Heners_UK posted:

Can you tell us more why you don't want to tip this person off? Can't you and the lawyer just walk up and snatch it, toss a loaner at him and leave without saying a single word? Better still if you wear matching suits and sunglasses to look like some sort of covert government agency.
Presumably because of a wish to avoid pissing off an employee in case the dude isn't actually doing whatever they think he is?

Mustache Ride
Sep 11, 2001



TITTIEKISSER69 posted:

If there's a way to stealthily get an all-sectors image of his drive you could then browse it away from his computer.

How much money are you willing to spend?
F-Response
Encase Enterprise
FTK

All have the ability to do remote full disk forensic images, but get your wallet out.

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

Mustache Ride posted:

How much money are you willing to spend?
F-Response
Encase Enterprise
FTK

All have the ability to do remote full disk forensic images, but get your wallet out.

You might be able to swing it if you make a case for having the proper tools on hand for potential future cases.

nullfunction
Jan 24, 2005

Nap Ghost

Dirt Road Junglist posted:

it's a big, impressive fuckup.

Guess who built a system for our customers that uses Salesforce's OAuth2 because password management is annoying and this seemed easier since they already have portal creds?

Our SF admins are in the process of rebuilding all of the permissions for our customer portal profiles.

I'll be shocked if Monday rolls around and everything still works the way it did yesterday.

:yaybutt:

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

nullfunction posted:

Guess who built a system for our customers that uses Salesforce's OAuth2 because password management is annoying and this seemed easier since they already have portal creds?

Our SF admins are in the process of rebuilding all of the permissions for our customer portal profiles.

I'll be shocked if Monday rolls around and everything still works the way it did yesterday.

:yaybutt:

Godspeed, mon frere. I want to tell you it's gonna be okay, but my team has nothing to do with that side of poo poo. However, the girlfriend of one of my teammates is in customer support, and she's hella competent, so you might be in good hands.

Not being glib, tho, I hope it gets resolved without a lot of stress for you. That fuckin sucks.

nullfunction
Jan 24, 2005

Nap Ghost
I'm not too worried about it all things considered. Our folks are competent and I'm sure they'll get it restored, I'm just not looking forward to hearing about it until they do.

xsf421
Feb 17, 2011

AlexDeGruven posted:

Ahh, no fun there. I'll drink plenty in your stead.

Also, lol. If you had said architect it would have had more impact.

They're having so much trouble getting qualified applicants that they promoted me from windows sysadmin (noc) to devops engineer. Time to do this long enough to learn everything and then :yotj:.

divabot
Jun 17, 2015

A polite little mouse!

xsf421 posted:

They're having so much trouble getting qualified applicants that they promoted me from windows sysadmin (noc) to devops engineer. Time to do this long enough to learn everything and then :yotj:.

if you're familiar with the deep down evil bits of NT being evil, and how to beat it into submission, you'll do well at devops.

bitterandtwisted
Sep 4, 2006




Zero VGS posted:

Ticket came in from the company lawyer: does anyone know of a file recovery program with a Server / Client setup so that I can silently push to a remote laptop, and run the file recovery client from here?

I need proof that someone was downloading some pirated stuff, but browsing their C$ doesn't show the incriminating files. I'm like 90% sure if I run Recova or something I'll see the evidence they tried to ditch, but I don't want to tip them off.

I assume this is important business related stuff they’re pirating, and the lawyer isn’t wasting your time hounding someone for downloading Game of Thrones

Shut up Meg
Jan 8, 2019

You're safe here.

bitterandtwisted posted:

I assume this is important business related stuff they’re pirating, and the lawyer isn’t wasting your time hounding someone for downloading Game of Thrones

They aren't using the company internet to download it and they aren't installing it on their laptop, so I am guessing it is indeed GoT and they have a puritannical streak about using company resources for doing illegal things.

Cool Dad
Jun 15, 2007

It is always Friday night, motherfuckers

I never pirate anything on my work computer. I download it at home, then copy it to my work computer.

Rooted Vegetable
Jun 1, 2002

Shut up Meg posted:

puritannical streak about using company resources for doing illegal things.

You realise of course that copyright "enforcers" see companies as filled with virgin blood?

Inspector_666
Oct 7, 2003

benny with the good hair

Shut up Meg posted:

They aren't using the company internet to download it and they aren't installing it on their laptop, so I am guessing it is indeed GoT and they have a puritannical streak about using company resources for doing illegal things.

I don't think "Trying to limit the company's liability for costly and incredibly easily avoidable litigation" is necessarily a "puritanical streak" sort of thing.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof
A ticket came in...

a very nice user posted:

Hello,
I was recently told that all data on City computers should be backed up by a UPS. My computer doesn't have a back-up device. Would it be possible to have a UPS installed to back up all data on my computer?

Not sure if someone is just pulling his leg or if someone else is also this stupid.
Also, he doesn't even need a UPS because he has a laptop.

Super Slash
Feb 20, 2006

You rang ?

bitterandtwisted posted:

I assume this is important business related stuff they’re pirating, and the lawyer isn’t wasting your time hounding someone for downloading Game of Thrones

We pay how ever many hundreds of thousands of pounds/dollars for all sorts of professional software that is only a mere IT ticket request away from granting access, of course this doesn't stop our security processes occasionally getting hits for poo poo like "Autodesk Maya 2017 Keygen.exe" on some yahoo's desktop.

People smart

Data Graham
Dec 28, 2009

📈📊🍪😋



I back up my laptop with a Fedex

Ham Equity
Apr 16, 2013

i hosted a great goon meet and all i got was this lousy avatar
Grimey Drawer

Inspector_666 posted:

I don't think "Trying to limit the company's liability for costly and incredibly easily avoidable litigation" is necessarily a "puritanical streak" sort of thing.

Not to mention the enormous potential security risks. Like, I'm definitely not the copyright police, and mostly stopped pirating because there is more media than I will ever be able to consume on Netflix and Amazon Prime, but keep that poo poo off of my network.

poo poo like that is what gets you crypto'd.

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

GnarlyCharlie4u posted:

A ticket came in...


Not sure if someone is just pulling his leg or if someone else is also this stupid.
Also, he doesn't even need a UPS because he has a laptop.

awwww :3:

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Thanatosian posted:

Not to mention the enormous potential security risks. Like, I'm definitely not the copyright police, and mostly stopped pirating because there is more media than I will ever be able to consume on Netflix and Amazon Prime, but keep that poo poo off of my network.

poo poo like that is what gets you crypto'd.

At least bittorrent issn't quite as bad as kazaa. Nothing like giving your computer aids because someone decided Brittany_spears_leaked_nudes.jpg.exe was a great idea to download.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

I know... He's a nice fellow, so I don't mind explaining to him that this isn't correct. My concern is whomever is running around telling people that their data is backed up in batteries.

The Macaroni
Dec 20, 2002
...it does nothing.

Methylethylaldehyde posted:

At least bittorrent issn't quite as bad as kazaa. Nothing like giving your computer aids because someone decided Brittany_spears_leaked_nudes.jpg.exe was a great idea to download.
Is Kazaa still around?

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

GnarlyCharlie4u posted:

I know... He's a nice fellow, so I don't mind explaining to him that this isn't correct. My concern is whomever is running around telling people that their data is backed up in batteries.

They likely just heard it was backed up by UPS out of context, no real user stupidity here. You should be happy they WANT remote backups.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

The Macaroni posted:

Is Kazaa still around?

The client? No. But there are derivatives and successors that still connect to the Fasttrack network used by Kazaa, so you can still get Leaked_Nudes_not_a-Virus.jpg.exe just like you did in....2002? gently caress I'm old.

BlankSystemDaemon
Mar 13, 2009



Methylethylaldehyde posted:

The client? No. But there are derivatives and successors that still connect to the Fasttrack network used by Kazaa, so you can still get Leaked_Nudes_not_a-Virus.jpg.exe just like you did in....2002? gently caress I'm old.
:corsair::hf::corsair:

bitterandtwisted
Sep 4, 2006




A user created an account with a website when prompted to by a spam email. I asked if he used his company credentials when setting it up.

quote:

The password I used is one I use for other things like my Hotmail account and linkedIn, and bank, but it’s not the same password as the one that gets me into [company] portal, etc

OK cool

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
Still worth telling him to reset them all in case the difference is just an exclamation mark or something.

Schadenboner
Aug 15, 2011

by Shine

Arquinsiel posted:

in case the difference is just an exclamation mark or something.

RON HOWARD VOICE: It was.

angry armadillo
Jul 26, 2010

GnarlyCharlie4u posted:

A ticket came in...


Not sure if someone is just pulling his leg or if someone else is also this stupid.
Also, he doesn't even need a UPS because he has a laptop.

I'd be finding out who said that and if it doesn't sound like genuine stupidity have a look at their setup

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
A ticket came in:

Outlook meetings with no attachment. When the meeting is updated with an attachment, that update email goes directly to deleted items on the attendee's mailbox. Can be replicated sometimes, but other times is not automatically moved to deleted items until it is read by the recipient.

I have so many other things I would rather be doing but nope this ticket escalation is apparently life or death for somebody.

Adbot
ADBOT LOVES YOU

Rhymenoserous
May 23, 2008

Arquinsiel posted:

This, but move it to a custom vlan with random image replacement or whatever. If you modify the machine they get to claim it was you downloading stuff.

Have tier 1 gen up a new laptop and just take his and say it was infected with something. I've done this many times for similar reasons, ya'll are making poo poo hard.

  • 1
  • 2
  • 3
  • 4
  • 5