Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

MF_James posted:

Someone's head (more likely multiple people's heads) are going to roll because of a crypto incident involving multiple clients, lack of 2FA and an unreported breach. Just glad the parent company is at fault and not our company; we're just being brought in to help mitigate and assess.

Assessment: poo poo is hosed, backups were wiped out prior to everything getting encrypted, and all of the backups were local so lol

I can see it now:

“Yes, we backup everything every night!”

code:
robocopy c:\ d:\ /MIR
And D: is a usb drive

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


Server Drives dot JPEG

Antioch
Apr 18, 2003
Homeslice just clicked a phishing link 4 times over 10 minutes, then sent it to a couple of his friends who clicked it at least once each, then sent it to us to complain that the "Stupid broken microsoft system" won't let him in to his email

Mass password resets for everyone!

This is after mandatory email security training, where I found that fully 70% of our staff will readily and happily click a link in a plaintext email from support@helpdesk.ru that claims to contain information about our new Pokemon Go policy.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
What is your new Pokemon Go policy though? :ohdear:

cage-free egghead
Mar 8, 2004

Antioch posted:

Homeslice just clicked a phishing link 4 times over 10 minutes, then sent it to a couple of his friends who clicked it at least once each, then sent it to us to complain that the "Stupid broken microsoft system" won't let him in to his email

Mass password resets for everyone!

This is after mandatory email security training, where I found that fully 70% of our staff will readily and happily click a link in a plaintext email from support@helpdesk.ru that claims to contain information about our new Pokemon Go policy.

At my last job I worked in desktop support and it was right after PokeGo came out so everyone in my department was playing it. Had a friend send me a neat location spoofer app that tied into PokeGo's API or something. Got a call an hour later from NOC saying there was a virus on a user's PC. My boss had a laugh at that one.

Antioch
Apr 18, 2003

Arquinsiel posted:

What is your new Pokemon Go policy though? :ohdear:

The email, as built by Wombat/Proofpoint:

Obvious Fake Email posted:

To all employees,


Despite the appearance of Pokeymon Go characters in our office environment it is not acceptable to play Pokeymon Go at the office.


Please click here to read and agree to our Policy on Pokeymon Go .

Failure to abide by this policy could result in immediate human resources action.


If you have any questions about this please contact IT Support.

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.
Now that Team Rocket are a thing in Pokemon Go, they're probably being paid off by Giovanni. :tinfoil:

Methanar
Sep 26, 2013

by the sex ghost
The biggest flaw is people agreeing to be bound by a no Pokémon go policy rather than feigning ignorance as they continue to play.

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


I'm just sad the Team Rocket pokestops seem to not be spawning as often. I never got a Shadow Snorlax :(

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Antioch posted:

The email, as built by Wombat/Proofpoint:
That is an amazing level one softball to fail at. The gist of the policy is right there in the mail body! :stonklol:

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.
They really need to fix the healing item drop rates. Like, I get they want it to Team Rocket to be a challenge, but it's ridiculous spinning a few dozen stops and not even getting a single potion.

Exit Strategy
Dec 10, 2010

by sebmojo

TinTower posted:

They really need to fix the healing item drop rates. Like, I get they want it to Team Rocket to be a challenge, but it's ridiculous spinning a few dozen stops and not even getting a single potion.

That's why microtransactions exist, man.

Nemo2342
Nov 26, 2007

Have A Day




Nap Ghost

Thanatosian posted:

I work for a financial institution, and while I can definitely see this happening on some level, the phishermen have definitely been stepping up their game over the last few years, and I really can't get too angry at people for falling for some of these. Also, I'd much rather people report when this happens to them than not.

Lately my company has made things much worse by randomly signing us up for things without warning. One week it was an Amazon Prime Business account, yesterday it was some kind of ecard/employee recognition system.

The legitimate phishing attempts coming through (mostly semi-official emails from coworkers asking to click a link to retrieve a secure document/set up a meeting) are bad enough, without them muddying the waters like this.

ConfusedUs
Feb 24, 2004

Bees?
You want fucking bees?
Here you go!
ROLL INITIATIVE!!





MF_James posted:

Someone's head (more likely multiple people's heads) are going to roll because of a crypto incident involving multiple clients, lack of 2FA and an unreported breach. Just glad the parent company is at fault and not our company; we're just being brought in to help mitigate and assess.

Assessment: poo poo is hosed, backups were wiped out prior to everything getting encrypted, and all of the backups were local so lol

There’s at least one crypto variant that enables some kind of remote access, and I’m pretty sure it phones home to put the system in a queue, so that people on the other end can go in and delete/mess up peoples backups.

Ham Equity
Apr 16, 2013

i hosted a great goon meet and all i got was this lousy avatar
Grimey Drawer

Nemo2342 posted:

Lately my company has made things much worse by randomly signing us up for things without warning. One week it was an Amazon Prime Business account, yesterday it was some kind of ecard/employee recognition system.

The legitimate phishing attempts coming through (mostly semi-official emails from coworkers asking to click a link to retrieve a secure document/set up a meeting) are bad enough, without them muddying the waters like this.
My company just did this, we got like a dozen tickets from a training program they signed people up for without saying anything.

Antioch
Apr 18, 2003

Arquinsiel posted:

That is an amazing level one softball to fail at. The gist of the policy is right there in the mail body! :stonklol:

Yeah it's the easiest of the four I sent out. The others were classic 'Open this shared file' and 'Your password needs to be reset'. But our users are just not that bright. We've had to reimburse $4000 in Apple Gift Cards in the last 6 months, three separate people have fallen for the CEO impersonation scams.

Luckily we managed to convince the moneygrubbing miser in Finance that we need to buy an email filtering system that works, so we ended up with Proofpoint which at least is better than the ancient Barracuda system we were using previously.


Last week I got to field a call from the RCMP about Fraud Management. Someone at an unrelated company fell for a scam invoice that had our company name on it. Bless their little hearts the RCMP try really hard but I don't think I'm going to "run a forensic scan on my whole domain" because some unrelated third party used ourcompanynamespelledwrong.tw or whatever to defraud someone.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

ConfusedUs posted:

There’s at least one crypto variant that enables some kind of remote access, and I’m pretty sure it phones home to put the system in a queue, so that people on the other end can go in and delete/mess up peoples backups.

One of the many reasons why tape is great, can't gently caress up backups when they're sitting in a tool box in your break room closet!

Thanks Ants
May 21, 2004

#essereFerrari


Unless you aren't verifying the backups :eng101:

Geemer
Nov 4, 2010



Methylethylaldehyde posted:

One of the many reasons why tape is great, can't gently caress up backups when they're sitting in a tool box in your break room closet!

Are there any backup systems that offer a built-in write-access delay of (configurable up to) some hours just to prevent crypto attacks from quickly wiping them, while still letting overnight tasks be able to run?
Might make a nice selling point if there's a big crypto scare again after some giant institution gets hit.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

ConfusedUs posted:

There’s at least one crypto variant that enables some kind of remote access, and I’m pretty sure it phones home to put the system in a queue, so that people on the other end can go in and delete/mess up peoples backups.

mmm from what I've heard (I'm not part of the team dealing with this, I'm in the middle of bank audit time for a client) it was because the remote control tool they use didn't have 2FA enabled and someone's password was compromised.

Digital_Jesus
Feb 10, 2011

D. Ebdrup posted:

Well, you can try. There's a good chance that a ICMP Pong or TCP SYN-ACK will be de-prioritized or even dropped under any kind of load from any and every router on the internet - so you can't actually use it for what people use it for, which is to run traceroutes to determine if "something is broken on the internet".
InternetPulse doesn't even work anymore, so unless you've got access to RIPE ATLAS probes or a smokeping setup, you're SOL.

If your router is smokeping I would suggest putting it out!

minusX
Jun 16, 2007

Say something hideous and horrible jumps out at you. Something so disgusting that it simply must die.
Ah! Oh!..So tacky! I can't...look...directly at it!

An email request from a director with a second director (and a lot of external contractors) copied in. minusX please join this conference to setup VPN for these external contractors.

There's a few issues with this. This was bypassing the normal ticketing system, e-mailing me directly. That's an issue and we had a critical issue where the company was down the night before so the service desk needed to be all hands and we were short two people. Also I'm just a tier 1 tech not a specialist so I shouldn't be getting any tickets directly to me, we should all be able to do this. I was the last person to assist the CCed director with a similar thing and it seems like I might've been pinned as his go to for things. I told them I need to know more information and get approval from my supervisor before I can be on an hour long conference call. He said no and told me to ask them to reschedule, I did.

Other e-mails came in, after my scheduled hours (I'm hourly) setting up a call for today...as soon as my shift started without any feedback from me. After I got settled in at work (about 9:20 as other stuff was happening) and noticing an e-mail from Director who thinks I'm his go to saying hey make sure you join this call I'll be in a meeting I e-mailed saying I could not move forward without confirmation about the install being approved. The contractor e-mailed a third director and said they waited 30 minutes on the phone and couldn't get anything done. Which lead to an e-mail chain saying "minusX is working on it" which...isn't true outside of me saying I can't.

Supervisor did some political discussions, said go ahead and do it even though it was ignoring our established protocol, so I started replying saying I could move forward and...no one was replying anymore. Took a few hours but someone finally replied and a new meeting is set tomorrow in a time that works for me being there :toot:

Also having a connection to my home PC worked for a website outage for external users and I've had people ask me to stay in this area of IT instead of the new job. It's good to be wanted :unsmith:

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

Methylethylaldehyde posted:

One of the many reasons why tape is great, can't gently caress up backups when they're sitting in a tool box in your break room closet!

LOL if your boss isn't making you store a second set of monthly tapes, "off site," by which we mean, "in DRJ's garage that she shares with 3 other tenants in her apartment complex."

Renegret
May 26, 2007

THANK YOU FOR CALLING HELP DOG, INC.

YOUR POSITION IN THE QUEUE IS *pbbbbbbbbbbbbbbbbt*


Cat Army Sworn Enemy

D. Ebdrup posted:

Well, you can try. There's a good chance that a ICMP Pong or TCP SYN-ACK will be de-prioritized or even dropped under any kind of load from any and every router on the internet - so you can't actually use it for what people use it for, which is to run traceroutes to determine if "something is broken on the internet".
InternetPulse doesn't even work anymore, so unless you've got access to RIPE ATLAS probes or a smokeping setup, you're SOL.

it was one of ours. It was previously down due to a power outage.

I was hitting the management interface

but otherwise, yes I feel like half my job sometimes is yelling at the call center saying "TRACEROUTE CAN NOT BE USED TO DIAGNOSE LATENCY"

Renegret fucked around with this message at 19:19 on Aug 1, 2019

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Geemer posted:

Are there any backup systems that offer a built-in write-access delay of (configurable up to) some hours just to prevent crypto attacks from quickly wiping them, while still letting overnight tasks be able to run?
Might make a nice selling point if there's a big crypto scare again after some giant institution gets hit.

Unless it's something you can only configure via some kind of front panel that's 100% isolated from any network interface or admin page, it would still be worthless, since by the time they're actively loving with the backup server and services, they likely have a domain admin account to play with.

I suppose you could set up something with a virtual tape library with the management interfaces on a completely isolated network, then setting all the tapes as WORM to prevent 'don't need this one anymore, overwrite with all zeros please from happening.

Johnny Aztec
Jan 30, 2005

by Hand Knit
It shows that you don’t have the thinking-mindset to really be a C level.
It doesn’t MATTER if it’s ultimately be useless. You aren’t selling it to people who fix things. You are selling it to directors and other C levels.

Success or failure doesn’t mean jack shot, as long as you actually make sales.

Geemer
Nov 4, 2010



Methylethylaldehyde posted:

Unless it's something you can only configure via some kind of front panel that's 100% isolated from any network interface or admin page, it would still be worthless, since by the time they're actively loving with the backup server and services, they likely have a domain admin account to play with.

I suppose you could set up something with a virtual tape library with the management interfaces on a completely isolated network, then setting all the tapes as WORM to prevent 'don't need this one anymore, overwrite with all zeros please from happening.

Yeah sorry, I didn't really word it very well. I meant that the delay would be some device-level configuration, preferably through some physical switch w/o servos that allow remote access to it.
Alternatively, selling it as snake oil for dumb C-levels is a good way to make a quick buck. Once it inevitably fails, just blame the admin for setting it up wrong. Then cite a $$$$$$$$$ course on correct setup and also threaten sue for defamation if they keep insisting its the system at fault.

Thanks Ants
May 21, 2004

#essereFerrari


Johnny Aztec posted:

It shows that you don't have the thinking-mindset to really be a C level.
It doesn't MATTER if it's ultimately be useless. You aren't selling it to people who fix things. You are selling it to directors and other C levels.

Success or failure doesn't mean jack shot, as long as you actually make sales.

Kurieg
Jul 19, 2012

RIP Lutri: 5/19/20-4/2/20
:blizz::gamefreak:

Uhh...

Is the logo supposed to look like a dick?

Sickening
Jul 16, 2007

Black summer was the best summer.

Kurieg posted:

Uhh...

Is the logo supposed to look like a dick?

You haven't seen some important television friendo.

Antioch
Apr 18, 2003

Sickening posted:

You haven't seen some important television friendo.

That show hits way too close to home for me to enjoy it.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Dirt Road Junglist posted:

LOL if your boss isn't making you store a second set of monthly tapes, "off site," by which we mean, "in DRJ's garage that she shares with 3 other tenants in her apartment complex."
Are you charging rent for the space?

my cat is norris
Mar 11, 2010

#onecallcat

Re: ransomware incident --

The company is thanking everyone for working so hard over the last week by bringing in the best ice cream in the city on Monday and by paying for a big party at Dave and Buster's at the end of August. :unsmith:

In other news, the outage has finally overtaken my work hours, too. We're trying to get back to business as usual, but it's slow going. I got placed in charge of ticket triage for client VPN requests. Most of this involves assigning out work to our two overloaded interface engineers -- not hard work -- but the rest is all unfucking multiple teams all trying to work with the same client so that the client doesn't get eight different points of contact. :stonk: I've learned to hate the sound of Slack alerts.

In the middle of today's chaos, the UPS at one of our offices literally blew up and took out that office's services for several hours. I was somehow roped into helping resolve this panic because I once touched a VM. Fortunately, the one dev on-site used to be THE tech support for them, so all I really had to do was push buttons when asked? Still kinda dizzying being thrown into these different roles all of a sudden.

It's been a real poo poo few days.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
You get to add "incident response" to your CV now though :unsmith:

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

Geemer posted:

Are there any backup systems that offer a built-in write-access delay of (configurable up to) some hours just to prevent crypto attacks from quickly wiping them, while still letting overnight tasks be able to run?
Might make a nice selling point if there's a big crypto scare again after some giant institution gets hit.

I have a backup server in my house that is powered off. It powers on via IPMI command at midnight. Then at 12:05 the backup job runs and the server shuts itself down.

Of course this won’t prevent crypto-d files from being backed up, but I have enough capacity for three fulls and three weeks of diffs. I like to think I’d notice a crypto attack within 2-3 weeks.

Agrikk fucked around with this message at 00:41 on Aug 2, 2019

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!

Agrikk posted:

I have a backup server in my house that is powered off. It powers on via IPMI command at midnight. Then at 12:05 the backup job runs and the server shuts itself down.

Of course this won’t prevent crypto-d files from being backed up, but I have enough capacity for three fulls and three weeks of diffs. I like to think I’d notice a crypto attack within 2-3 weeks.

I should do this but with a light timer

Edit: What software do you use for incrementally backing up at home?

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

Arquinsiel posted:

Are you charging rent for the space?

I should have. Ugh. Lost opportunity.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

klosterdev posted:

I should do this but with a light timer

Edit: What software do you use for incrementally backing up at home?

A light timer! OMG how simple! I wish I’d thought of that a while ago...

I use a ten thousand year old copy of BackupExec running on Server 2008, though both are long in the tooth. But it’s proven to be very reliable since the server spends 23 hours a day turned off.

Robocopy with the archive bit as a flag works really well (I use it for identifying files that need to be copied to S3).

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

Dirt Road Junglist posted:

I should have. Ugh. Lost opportunity.
Tell them there was a breakin but luckily only other people's stuff was taken, so now they gotta pay for a safe, some CCTV gear, a better internet connection and some extra cash to keep the building super quiet or else you just can't in good conscience let them risk their data like that.

Adbot
ADBOT LOVES YOU

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

Agrikk posted:

I use a ten thousand year old copy of BackupExec running on Server 2008, though both are long in the tooth. But it’s proven to be very reliable since the server spends 23 hours a day turned off.

Oh god, I had blocked the memory of BackupExec, and when I saw those letters in that specific order, I started yelling, "BACKUPEXEC NO NO NOT AGAIN NO."

  • 1
  • 2
  • 3
  • 4
  • 5