Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
RFC2324
Jun 7, 2012

http 418

GnarlyCharlie4u posted:

We had an HP printer completely shutdown a whole leg of our network.
Apparently with the firmware it was running, this particular model "responds as if it were a router in some Cisco environments".
If I can find the case notes I'll post em up.

what? how? why?

:psyboom:

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

That's amazing.

devmd01
Mar 7, 2006

Elektronik
Supersonik
I've had an aerohive AP take down a branch network, it went haywire and started spamming garbage that shut down the entire network.

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


I had lovely cameras that gives up networks. 3 of the same model, when I left the office security company still insisted it was us and had refused to replace even, even though we could swap the cameras and have them work. Just 3 of the 2 dozen broke spectacularly.

Someone else on my team was handling that one, poorly, was a known issue for over a year.

RFC2324
Jun 7, 2012

http 418

Why don't you have the cameras on an isolated network anyway?

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


Probably the same or similar reasons that Target's externally accessible HVAC system was just plugged into the whole Target network with no isolation.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
My camera was on an isolated network and I plugged it into a port that was supposed to be assigned to that vlan, which is why I was so loving baffled it crushed another isolated network for the wireless bridges. I figured the port was misconfigured as a mirror or had a high priority route assigned to it or something off the wall.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.
Wooo!

I've never been a thread title before. :)

Pacra
Aug 5, 2004

Agrikk posted:

Wooo!

I've never been a thread title before. :)

I salute you, full time work at home-r. Living the dream. In your MeUndies.

Ghostlight
Sep 25, 2009

maybe for one second you can pause; try to step into another person's perspective, and understand that a watermelon is cursing me



Finally the Internet of Things arrives on the PC.

https://www.modzero.ch/advisories/MZ-17-01-Conexant-Keylogger.txt posted:

Conexant's MicTray64.exe is installed with the Conexant audio driver package and registered as a Microsoft Scheduled Task to run after each user login. The program monitors all keystrokes made by the user to capture and react to functions such as microphone mute/unmute keys/hotkeys.

In addition to the handling of hotkey/function key strokes, all key-scancode information [2] is written into a logfile in a world-readable path (C:\Users\Public\MicTray.log). If the logfile does not exist or
the setting is not yet available in Windows registry, all keystrokes are passed to the OutputDebugString API, which enables any process in the current user-context to capture keystrokes without exposing malicious behavior.

:psyduck:

uPen
Jan 25, 2010

Zu Rodina!

GnarlyCharlie4u posted:

We had an HP printer completely shutdown a whole leg of our network.
Apparently with the firmware it was running, this particular model "responds as if it were a router in some Cisco environments".
If I can find the case notes I'll post em up.

We had a VoIP fax machine that happily assigned bogus IPs to iPhones and nothing else.

Chickenwalker
Apr 21, 2011

by FactsAreUseless
Looking at Jira+Confluence vs Salesforce Service Cloud. I really like the Service Cloud knowledgebase suggestion feature for agents when responding to tickets but drat if the pricing isn't steep.

I like Jira but it doesn't lend itself towards internal documentation and assisting junior techs as much as trying to make the KB a self service resource, which we don't want. Our KB is pretty much 100% for internal reference.

Anyone know of anything comparable in any other products? What's the consensus on best ticketing platform/KB around here?

RFC2324
Jun 7, 2012

http 418

Chickenwalker posted:

Looking at Jira+Confluence vs Salesforce Service Cloud. I really like the Service Cloud knowledgebase suggestion feature for agents when responding to tickets but drat if the pricing isn't steep.

I like Jira but it doesn't lend itself towards internal documentation and assisting junior techs as much as trying to make the KB a self service resource, which we don't want. Our KB is pretty much 100% for internal reference.

Anyone know of anything comparable in any other products? What's the consensus on best ticketing platform/KB around here?

Freshdesk integrates pretty well with jira and confluence to form a petty nice trifecta imo.

Freshdesk for incident management, jira for issues and change management, and confluence for a tied in kb.

CheeseSpawn
Sep 15, 2004
Doctor Rope
There was some fiber breakage with our market in canada in early morning yesterday, I come back tonight to learn a wolf got stuck in some pipe and was just chewing the fiber. They sent us a nice pic of wolf stuck, wish I could share it.

Almost as good as the country folk shooting the aerial fiber out west.

guppy
Sep 21, 2004

sting like a byob

devmd01 posted:

I've had an aerohive AP take down a branch network, it went haywire and started spamming garbage that shut down the entire network.

I've had a small desktop switch start doing exactly the same thing. Took us forever to figure out, it was behind a desk.

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



CheeseSpawn posted:

There was some fiber breakage with our market in canada in early morning yesterday, I come back tonight to learn a wolf got stuck in some pipe and was just chewing the fiber. They sent us a nice pic of wolf stuck, wish I could share it.

Almost as good as the country folk shooting the aerial fiber out west.

Canadian wolves, the fiber squirrels of the great white north.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

pixaal posted:

I had lovely cameras that gives up networks. 3 of the same model, when I left the office security company still insisted it was us and had refused to replace even, even though we could swap the cameras and have them work. Just 3 of the 2 dozen broke spectacularly.

Someone else on my team was handling that one, poorly, was a known issue for over a year.

OH! we had super-Chinese cameras that did the same thing. For some reason, a few of them would randomly freeze up and somehow gently caress up the ARP tables on our HP Procurve switches. Looking at the traffic, all traffic ceased except ARP requests from the switch to whichever camera was hosed. Even though they were on their own VLAN the entire switch would still poo poo the bed and everything on that switch would stop.

uPen posted:

We had a VoIP fax machine that happily assigned bogus IPs to iPhones and nothing else.

lol what the gently caress?

GnarlyCharlie4u fucked around with this message at 15:33 on May 12, 2017

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

That keylogger HP laptop audio issue, supposedly HP pushed out a fix via Windows Update yesterday for 2016 models and 2015 models today?

http://www.zdnet.com/article/keylogger-found-on-several-hp-laptops/

divabot
Jun 17, 2015

A polite little mouse!
Raise your glass for the NHS IT people, who may have foolishly thought they were about to have a weekend.

ConfusedUs
Feb 24, 2004

Bees?
You want fucking bees?
Here you go!
ROLL INITIATIVE!!





That poo poo is going code red all hands on deck serious all over.

It uses a known (patched in march) SMB exploit to spread across networks. Unpatched systems anywhere on the network are vulnerable.

And of course xp/2003 systems do not have the patch.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

ConfusedUs posted:

That poo poo is going code red all hands on deck serious all over.

It uses a known (patched in march) SMB exploit to spread across networks. Unpatched systems anywhere on the network are vulnerable.

And of course xp/2003 systems do not have the patch.

Has there been an absolute point before where XP / 2003 was specifically vulnerable to a major threat due to lack of patching? Is this finally the point where we can print a piece of paper, put it in somebody's hands, and say with absolute authority that XP / 2003 isn't good enough and they're simply not allowed to have it on any network?

chin up everything sucks
Jan 29, 2012

devmd01 posted:

I've had an aerohive AP take down a branch network, it went haywire and started spamming garbage that shut down the entire network.

Ubiquiti's outdoor wireless stuff used to occasionally cause packet storms on networks after nearby lightning strikes. I don't know if they ever figured out why, but SOMETHING connected to the ethernet port would cause garbage to start spamming over the network.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Judge Schnoopy posted:

Has there been an absolute point before where XP / 2003 was specifically vulnerable to a major threat due to lack of patching? Is this finally the point where we can print a piece of paper, put it in somebody's hands, and say with absolute authority that XP / 2003 isn't good enough and they're simply not allowed to have it on any network?
You're looking at this all wrong. Instead, have them look at the cost of upgrading from XP/2003, and then contrast that with the cost they'll pay for downtime, ransom payments, forensic investigations, "don't click on emails" training, and everything else consultants are going to bill them for over the next few months.

Proteus Jones
Feb 28, 2013



anthonypants posted:

You're looking at this all wrong. Instead, have them look at the cost of upgrading from XP/2003, and then contrast that with the cost they'll pay for downtime, ransom payments, forensic investigations, "don't click on emails" training, and everything else consultants are going to bill them for over the next few months.

Absolutely, always put the dollars in front of them.

Also stress that in either scenario it's not an "if it happens" cost, it's a "when it happens" cost. They are guaranteed to be paying for one of those scenarios, why not chose the cheaper option while they still can.

PierreTheMime
Dec 9, 2004

Hero of hormagaunts everywhere!
Buglord
Count my corp as one hit. Email comes in: "non-essential systems must shut down asap". Was playing MtG with a coworker in full view of management before I went on a run on company time.

I will pour one out for SA/Ops when I get home. :rip:

The Fool
Oct 16, 2003


I checked wsus when I came in this morning after seeing all of the reports and I have 98% coverage with that update.

I will continue making plans for the weekend.

ConfusedUs
Feb 24, 2004

Bees?
You want fucking bees?
Here you go!
ROLL INITIATIVE!!





Judge Schnoopy posted:

Has there been an absolute point before where XP / 2003 was specifically vulnerable to a major threat due to lack of patching? Is this finally the point where we can print a piece of paper, put it in somebody's hands, and say with absolute authority that XP / 2003 isn't good enough and they're simply not allowed to have it on any network?

I'm building the blocks for this at my work. Roughly 10% of the users of my product(s) are using XP/2003 systems today. There is rapidly coming a point where the price of their subscription won't cover the price of supporting their compromised systems.

But as others say, it comes down to $$$.

If I can prove that:

We make $x in profit off each sale
Each XP/2003 user costs $y in support
And $y > $x

Then I'll have a case for us stop selling to these users.

Collateral Damage
Jun 13, 2009

Ticket rejected: Not a business application.

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...

bitterandtwisted posted:

Last job had a dresscode of smart shoes, trousers and shirt. Fair enough, sometimes clients visited the office.
Then they got branded clothing - bright polyester polos and ill-fitting combat trousers that chaffed if you walked more than a mile in them. They still insisted on formal shoes.

They also had a branded car with the livery of Elmer the Elephant.
Clients started calling a mate of mine "Mr Tumble" when he drove it.

I have to say this may be the most British post I've ever read.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

bitterandtwisted posted:

Last job had a dresscode of smart shoes, trousers and shirt. Fair enough, sometimes clients visited the office.
Then they got branded clothing - bright polyester polos and ill-fitting combat trousers that chaffed if you walked more than a mile in them. They still insisted on formal shoes.

They also had a branded car with the livery of Elmer the Elephant.
Clients started calling a mate of mine "Mr Tumble" when he drove it.

The absolute madman.

Yawgmoth
Sep 10, 2003

This post is cursed!

Virigoth posted:

Canadian wolves, the fiber squirrels of the great white north.
Our cable line got chewed down to the copper by a squirrel back when we had cable. The comcast guy let me keep the big piece of cable that got replaced. :3:

"I think I found your problem! :haw:" *holds up a couple feet of chewed-through cabling*

A Frosty Witch
Apr 21, 2005

I was just looking at it and I suddenly got this urge to get inside. No, not just an urge - more than that. It was my destiny to be here; in the box.
loving everything came in.

Everything.

Budget cuts, the termination of my assistant position, and approvals for a shitload of grants I applied for and was told I wasn't going to get.

So not only am I going to be a one-man shop by the end of summer, but over the summer break I am going to be replacing every single computer, server, switch, Wi-Fi AP, projector, and SMART Board, but I am also installing an entirely new security camera and card reader system for the whole campus.

And it's going to cost us, like, $10k total.

I don't know how I managed this but I've got a feather a thousand stories high in my cap right now and all I feel is unrelenting guilt that I have to fire someone I just hired.

Also, hearing all the money for projects we just became eligible for, the director immediately wants detailed lists of everything we are purchasing for the explicit purpose of trying to skim as much as possible for other departments and I can't decide whether to share the wealth or fight for what's mine.

ConfusedUs
Feb 24, 2004

Bees?
You want fucking bees?
Here you go!
ROLL INITIATIVE!!





larchesdanrew posted:

loving everything came in.

Everything.

Budget cuts, the termination of my assistant position, and approvals for a shitload of grants I applied for and was told I wasn't going to get.

So not only am I going to be a one-man shop by the end of summer, but over the summer break I am going to be replacing every single computer, server, switch, Wi-Fi AP, projector, and SMART Board, but I am also installing an entirely new security camera and card reader system for the whole campus.

And it's going to cost us, like, $10k total.

I don't know how I managed this but I've got a feather a thousand stories high in my cap right now and all I feel is unrelenting guilt that I have to fire someone I just hired.

Also, hearing all the money for projects we just became eligible for, the director immediately wants detailed lists of everything we are purchasing for the explicit purpose of trying to skim as much as possible for other departments and I can't decide whether to share the wealth or fight for what's mine.

Line item #1: a new loving chair for you

Thanks Ants
May 21, 2004

#essereFerrari


Lol absolutely gently caress sharing the wealth

Kurieg
Jul 19, 2012

RIP Lutri: 5/19/20-4/2/20
:blizz::gamefreak:
I'm not sure if he should be having sex at the office, though.

RFC2324
Jun 7, 2012

http 418

Kurieg posted:

I'm not sure if he should be having sex at the office, though.

Especially at a school.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

larchesdanrew posted:

loving everything came in.

Everything.

Budget cuts, the termination of my assistant position, and approvals for a shitload of grants I applied for and was told I wasn't going to get.

So not only am I going to be a one-man shop by the end of summer, but over the summer break I am going to be replacing every single computer, server, switch, Wi-Fi AP, projector, and SMART Board, but I am also installing an entirely new security camera and card reader system for the whole campus.

And it's going to cost us, like, $10k total.

I don't know how I managed this but I've got a feather a thousand stories high in my cap right now and all I feel is unrelenting guilt that I have to fire someone I just hired.

Also, hearing all the money for projects we just became eligible for, the director immediately wants detailed lists of everything we are purchasing for the explicit purpose of trying to skim as much as possible for other departments and I can't decide whether to share the wealth or fight for what's mine.

Fire him. Then hire him on as an outside contractor and pay him one time, big time, from the grant money.
That plus the severance he'll probably get is gonna be a nice goodbye present.

Proteus Jones
Feb 28, 2013



larchesdanrew posted:

Also, hearing all the money for projects we just became eligible for, the director immediately wants detailed lists of everything we are purchasing for the explicit purpose of trying to skim as much as possible for other departments and I can't decide whether to share the wealth or fight for what's mine.

If he does, report him if you can do so anonymously and in a way that doesn't point back at you.

Alternatively, use every loving penny you are allocated.

larchesdanrew posted:

all I feel is unrelenting guilt that I have to fire someone I just hired.

That sucks.

LethalGeek
Nov 4, 2009

GnarlyCharlie4u posted:

Fire him. Then hire him on as an outside contractor and pay him one time, big time, from the grant money.
That plus the severance he'll probably get is gonna be a nice goodbye present.

Took the words out of my mouth. Do this.

Adbot
ADBOT LOVES YOU

Kurieg
Jul 19, 2012

RIP Lutri: 5/19/20-4/2/20
:blizz::gamefreak:
Use his contractors fee as an excuse to get his help putting in new equipment over the summer.

  • Locked thread