Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Soricidus posted:

it’s security-related software so almost certainly everything

Not gonna lie. I feel this in my bones

Adbot
ADBOT LOVES YOU

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Diva Cupcake posted:

The ippsec videos for HackTheBox are still up but he’s been pushing people to his patreon to download the raw files. worth the $10 imo.

Didnt even know he had one somehow. Ill have to check it out his stuff is enjoyable

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

geonetix posted:

I ran a snyk test on our companies repo once. panicked, closed the terminal, and went to find another job.

worked out great thusfar

HAHAHA HAHAHAHAHAHA HAHAHA *begins to have nam like flashback about container security*

Its all red. All red.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

abigserve posted:

1000% agree, and every time I've raised this with the relevant security stakeholders they look at you like a deer in the headlights

Ensuring all data is encrypted at rest and in transit is a wonderful thing that for some reason everyone is terrified of and or clueless about implementing.

I wonder if there are easy resources for implementing to just point people at and be like.. do that.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

cinci zoo sniper posted:

another day, another s3 bucket. this time 700k birth certificate applications, not taken down after disclosure

Goddamn people dont pay attention

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

BangersInMyKnickers posted:

I'm sick and tired of hearing about EDR and threat hunting when I don't even have the staffing to install the current poo poo on half the assets we own

Fuuuck do i feel this. I feel this in my goddamn bones.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Anyone using endgame on hosts?

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Doesnt pihole act as a local dns server or am i misremembering this

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Isnt the google 2fa now tied to the google account its "linked" to? I coulda sworn they added a migration feature.

Seconding the microsoft 2fa being alright

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Thats fuckin amazin

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I havent watched westworld :shrug: so it was lost on me

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Rufus Ping posted:

g13 government weed

Brb moving

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Fuckin solarwinds

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

DoomTrainPhD posted:

"The TTP project" of course

Recursive Acronyms should be a thing.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Shame Boy posted:

"theoretically capable of" and "actually required to" are pretty different

This applies to every single enterprise security tool and scale btw

Edit: this has nothing to do with current convo I'm just bitter at "enterprise" atm

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I keep having to explain how a cve from 1999 can show up on a recent host and how that doesn't mean that the host has been vulnerable SINCE 1999 and I want to die.

Thanks in advance to whatever kind soul puts a loving bullet in me.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

infernal machines posted:

lol. ms pushed an out-of-band patch for print nightmare. notably, the description for kb5004945 mentions printnightmare by name but doesn't include the word "resolves" anywhere

The number of "critical" patches that in no way resolve the issue this year has been high.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

haveblue posted:

the remote code execution was producing excessive log messages

So we turned off logging.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

flakeloaf posted:

gotta work hard to outdo the the mcd's hamburger builder fiasco

That was fine art and I will hear no argument.

That was legit one of the funniest things I've experienced and I still laugh thinking about it.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Now I'm wondering if I remember this or another similar one. All I remember is a desultory glob of ketchup being presented as a burger and just absolutely losing it.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Better than actual vuln releases though

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I feel like cloudflare should make that a marketing slogan its so good

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Shaggar posted:

only a unix greybeard could be dumb enough to think case sensitive userids are a good idea.

Having SAML flashbacks now

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Shame Boy posted:

i transposed those letters and was very confused why a website would want to profile whistleblowers

SAME.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

RFC2324 posted:

I started my current job jan 4, and one of the first things I got to see was people having to talk someone down who thought making an offer to parler was a good idea for a fedramp company

What the gently caress

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I dont know a lot. But one thing I do know is to treat shaggar posts like foam floating by in an otherwise pristine creek. Feel free to look at it as it goes by but never engage.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I dont mean to bring up the low hanging fruit / old news. But was that missouri thing literally as dumb as it sounds.

No way the SSNs were just in the html right?

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Thank you for both those very appropriate posts.

*ahem*


:lmao:

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
The "you wouldnt steal a car" ad except now it reads "view a webpage"

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

spankmeister posted:

Welcome to OT networks.

Everytime i interact with OT im stunned with how loving low effort every thing in that space is.

I get that a lot of it needs a light footprint but the poo poo used to manage the stuff is also straight outta 2005.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Hed posted:

I mean SSL is obviously more robust security it's at what, 3.0? Why would you trust version 1.3 software.

I laughed and then frowned because this has been said to me before without irony.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Not throwing stones at you but yikes that writing hasnt aged well.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Has anyone said log4shit yet.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
People keep giving me looks when i say assume you are vulnerable, act like you are about to be popped. Patch now.

Like im the ITsec equivalent of the end of times sandwhich board man.

But i feel like thats a reasonable stance. Check your poo poo. Patch it if you can. Get your walls up.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
They shoot horses dont they?

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Welp the first patch didnt take. HIT IT AGAIN BOYS.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

haveblue posted:

the lack of payments will continue until security improves

This is very good.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
I have a real love / hate relationship with regex at this point

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
The sheer amount of parallel 'unused' log4j 1x installed next to log4j 2x that i have seen during this really validates my views on vendor's attention to detail

Adbot
ADBOT LOVES YOU

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Oh holy poo poo please no

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply