Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Mustache Ride
Sep 11, 2001



That loving TCP joke happened to me today. I noticed some timestamp issues with logs flowing into Logstash (running 4+ weeks behind) so I said "Wait why are you running TCP just use UDP" and they did. The volume went up 100x and crashed our Elastic Cluster.

Fuckers.

Adbot
ADBOT LOVES YOU

Mustache Ride
Sep 11, 2001



The only way I got salary increases was by changing jobs. If I had stayed with my first IT job I'd still be making $18-25/hour. I know this because I play DnD with a dude who started 2 years before I did, still works there 12 years later and is making that.

Mustache Ride
Sep 11, 2001



I think the easiest thing to start with as far as Ansible is concerned is setting up an Algo VPN :yaycloud: instance.

https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-that-works/
https://github.com/trailofbits/algo

Specifically by running the non-interactive Ansible Deploy: https://github.com/trailofbits/algo/blob/master/docs/deploy-from-ansible.md

It's functional, it doesn't cost you any money, and you can stop giving Lowtax awful NordVPN money.

They even have an experimental Terraform build your can try too: https://github.com/trailofbits/algo-ng

Mustache Ride fucked around with this message at 13:59 on Aug 6, 2020

Mustache Ride
Sep 11, 2001



Sickening posted:

Give me a loving break. No company is that loving important.

I've got a buddy that works for them. Basically it's a PC nightmare.

Mustache Ride
Sep 11, 2001



Yeah I guess given that I only shared the stuff said that doesn't directly identify him, it can be taken that we were making light of the problems he told me about. Fair enough.

Mustache Ride
Sep 11, 2001



Goddamn that shits expensive. I just bought one of these cheapo frames from Amazon and a piece of butcher block from Lowes and got the same thing. Spent less than 300 bucks and got something that exactly fit the space I needed.

Mustache Ride
Sep 11, 2001



Linux Academy has some pretty good courses that helped me learn a bit when I was asked to deploy Hashi Vault to work with CF.

Mustache Ride
Sep 11, 2001



uhhhhahhhhohahhh posted:

They're both NAC consultant/engineer jobs. The first/big one is specifically designing and then I guess supporting a NAC rollout for their biggest client. The second would be doing it for any of their existing and new clients then handing it off.

The question is do you want to be on long term support for a single NAC deployment that has a larger than average chance of getting cancelled halfway through because somebody's cousins uncle got hired at the client as a consultant and said this is a bad thing or do you want to be the NAC specialist who does the same thing 12-45 times a year and maybe pick up alcoholism in the process.

Both have downsides, but I prefer the job stability, so when presented with the same choice (but not for NAC) a few years ago I went with the second choice and now have a subscription whiskey delivery service.

Mustache Ride
Sep 11, 2001



Now that we've learned about defrag, everyone make sure to degauss your monitor.

Mustache Ride
Sep 11, 2001



Yes this. Does anybody actually want to spend the rest of their lives being computer janitors?

Mustache Ride
Sep 11, 2001



https://www.youtube.com/watch?v=Z4FXe3PMevo&t=45s

Mustache Ride fucked around with this message at 14:44 on Jun 25, 2021

Mustache Ride
Sep 11, 2001



Bring Pugs in to offices so they can snore on call bridges for you.

Mustache Ride
Sep 11, 2001



GreenNight posted:

Have any of you dealt or worked with Arctic Wolf? Management just signed a huge contract for them to be our SIEM, among other things.

I had to deal with it for an IR. The interface is poo poo and I don't think they do field parsing correctly. I had to dump their logs into Excel in order to get filtering to work. Wasn't impressed.

Also: https://techcrunch.com/2021/07/13/arctic-wolf-series-f/
Hope you feel $4.3B warm and fuzzies from them.

Mustache Ride fucked around with this message at 22:38 on Jul 13, 2021

Mustache Ride
Sep 11, 2001



Wait you're installing qradar?

Mustache Ride
Sep 11, 2001



Why not? Lets you know how much of a business focused mindless drone he is and what he expects of his people. If he never takes vacations, he'll probably never expect you to take vacations.

Plus its a good talking point, and gives you insight into what he likes to do in his free time. CISOs are people too, you don't have to put them on a pedestal because they have 'Chief' in their title.

Mustache Ride
Sep 11, 2001



Agrikk posted:

Has anyone managed to pull up from a downwards trajectory of burnout while remaining at the same company?

Yes. I told my boss I needed a month off before I started punching other employees in the face. Including him. He told me to get my rear end out the door. I then went on a 1 month road trip, didn't think about work once, and when I got back I learned he had disabled my o365 account so that no emails or teams messages could reach me, and in our contact list had put a huge read DO NOT CALL MUSTACHE RIDE FOR ANY REASON UNTIL <Date of Return>. They even paid me, even though it was far over my allowed PTO for the year. We then had a discussion about stress and amount of work I was comfortable doing at one time, and so far he has respected it (its been about a year).

I guess I don't have any suggestions to give you to do the same other than, if you find a great boss, stick with them. I followed this boss around (we're on our 3rd company) and even though I've gotten offers for jobs with 20-40% pay raises, I haven't followed through, simply because I'm afraid of finding a poo poo boss leading that team.

Internet Explorer posted:

I've changed jobs quite a bit in the past few years and I am just as burnt out as ever. I don't know what the answer is, but I want to get out of corporate IT completely. I have been doing this poo poo for too long. The state of the world is not helping. I don't find enjoyment in working on this poo poo, fighting with management, fighting with engineers, all while the world burns.

I've got a good buddy of mine who quit corporate IT about 6 year ago and took up building custom cabinets, which he said was his dream job. I heard last year he got burnt out of that and is back in IT. When I asked him about it, he said that he was getting the same stress but directly from lovely customers/homebuilders wanting impossible timelines and requirements without appropriate compensation, and decided that if he was going to be stressed for that he might as well get paid doing it. He told me to gently caress off when I asked for a bedside table.

Mustache Ride
Sep 11, 2001



Tell him you're taking Memorial Day tomorrow and skip work.

Mustache Ride
Sep 11, 2001



That's perfect. Make sure to take the cake home.

Mustache Ride
Sep 11, 2001



Internet Explorer posted:

Kanban. It's been the best effort:return ratio ever.

You don't even have to buy a tool for this, it's included in an o365 subscription as Microsoft Planner. You can even drop it into teams.

Mustache Ride
Sep 11, 2001



I had an IOC threat feed do the same thing automatically years ago because our Intel guy wanted us to OCR these Mandiant pdf reports and for some loving reason they put the explorer.exe hash in one. The bastards. At least it was an easy fix and we got to test our break glass process.

Mustache Ride
Sep 11, 2001



Not CISO, that position is a punching bag.

Mustache Ride
Sep 11, 2001



What's wrong with a text file in a restricted onedrive?

Mustache Ride
Sep 11, 2001



FB Outage will probably lead to >1+ deaths due to so much infrastructure requiring WhatsApp functionality

Mustache Ride
Sep 11, 2001



I'm trying to work out how to shove as many raspberry pis into a 6u server rack as possible to build cheap compute without paying :bezos:



This is not me, this is just my current plan

Mustache Ride
Sep 11, 2001



You must use pandas without looking at documentation

Mustache Ride
Sep 11, 2001



You either have to create a TXT record on the DNS or place a file on a webserver to verify the domain in Google Workspaces. Does this person have access to a webserver that hosts the company site?

Mustache Ride
Sep 11, 2001



VDIs are awesome. I get onboarded to a new client and immediately ask for a VDI solution. Why have a laptop when I can connect using my 3 screen MacBook so I don't have to look stupid doing the win key+c thing and wondering why it doesn't work?

Also why the hell do companies still issue laptops that can't drive 3 screens?

Mustache Ride
Sep 11, 2001




Ew

Mustache Ride
Sep 11, 2001



All my projects are on hold until January so I'm in hiring mode. Some people suck (not any of the goons I've tried to hire yet, mostly just the referrals we get from recruiters).

Mustache Ride fucked around with this message at 16:20 on Nov 23, 2021

Mustache Ride
Sep 11, 2001



I started my career in forensics and haven't seriously touched it in 6 years. The only times I've used it are when performing an IR and the insurance company required a certified forensicator to perform the after action analysis on a compromised host.

It's a good skill to have simply because of the knowledge it gives you around how an operating system works. I highly suggest anyone in security that wants to do more than look at siem logs and wants to work on IRs to get a giac cert around forensics and possibly purchase a copy of EnCase or get really familiar with Autopsy. Basic evidence handling and chain of custody is really good to know as well.

Mustache Ride
Sep 11, 2001



The Devo guys hate me cause I always start humming "Whip it" whenever they come around. I bought some of these for my bosses after they forced me to implement Devo once. I refuse to do any more Devo deployments, it is absolutely poo poo.

Mustache Ride
Sep 11, 2001



I'm giving a potential security engineer a lab interview right now and he's doing an excellent job, but I can tell he's stressed to the gills and feels like he's doing bad.

He's not. We're going to make him an offer. He's done better than 90% of the idiots we interview.

Mustache Ride
Sep 11, 2001



Looks like a fancy and new version of Security Onion.

Mustache Ride
Sep 11, 2001



Defender for Endpoint for Servers is also only sold in packs of 50

Mustache Ride
Sep 11, 2001



Sickening posted:

At my main gig we have just onboarded a new CISO (old one retired). The new CISO has decided in the first meeting of our entire division would be a social affair. It started out pleasant enough, but their questions are now moving to thing that are borderline inappropriate. She just ask people to post their kids pictures in chat.

My teams is lighting up my teams like a christmas tree because people are like "Help, I am not comfortable with discussing the names and ages of my children in this setting".

This has been going on since the top of the hour. Please send help goons.

Talk to the most senior person in the chat and get them to shut it down with a simple , "hey we'll do family details at a later date, let's keep this to a company setting" and if it continues get them to leave the chat and go talk to a c level about this.

Also, lol if it's you

Mustache Ride
Sep 11, 2001



KVM Switch

Mustache Ride
Sep 11, 2001



Sickening posted:

This thread is outing who sucks and who is funny. Hats off to those who have made me laugh. I had a root canal yesterday and I was in poor spirits.

FYI, I have truly found a big bad bug and everyone on the call freaked out. Doubt I get a ham out of it.

can you put in a ticket to have them send me a pa-200 before they fix your bug?

Mustache Ride
Sep 11, 2001



Sickening posted:

I guess I have a other crazy CISO. They have just asked me to greatly restrict all employees in what they are allowed to do is they don’t possess a cissp certification. Their words are “these employees are neither credible or credentialed”. Basically I have to restrict all these employees to paper pushing duties.

Happy loving holidays.

Wait is this your main gig or the new CISO on the side gig. I'm so confused!

Mustache Ride
Sep 11, 2001



Sickening posted:

I use a combination of sticky notes and azure dev ops backlog.

My DevOps backlog makes me sad

Adbot
ADBOT LOVES YOU

Mustache Ride
Sep 11, 2001



22 Eargesplitten posted:

Oof, I just got out of a job interview and I think it went well but it's the third interview and they want to do one more. Please just make a decision. This one was kind of weird because the position got put on hold for a new director to get up to speed and then got taken off hold so this is the first one since the position got put on hold.

Maybe it's a meet the team interview? Can't imagine they'd need more than 3 unless someone was out for all the other interviews.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply