Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
baka kaba
Jul 19, 2003

PLEASE ASK ME, THE SELF-PROFESSED NO #1 PAUL CATTERMOLE FAN IN THE SOMETHING AWFUL S-CLUB 7 MEGATHREAD, TO NAME A SINGLE SONG BY HIS EXCELLENT NU-METAL SIDE PROJECT, SKUA, AND IF I CAN'T PLEASE TELL ME TO
EAT SHIT

Oh so uploading to VT isn't a bad thing in itself usually, it's just that they've basically created a worse variant and made it 'public' by uploading it too soon? And the current situation means it might start a whole new fire before it can be contained?

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



baka kaba posted:

Oh so uploading to VT isn't a bad thing in itself usually, it's just that they've basically created a worse variant and made it 'public' by uploading it too soon? And the current situation means it might start a whole new fire before it can be contained?

Well, there is certainly the possibility they shortcut the lead time for someone developing and releasing a nastier variant.

At this point it in WCry's lifecycle it was irresponsible.

Cugel the Clever
Apr 5, 2009
I LOVE AMERICA AND CAPITALISM DESPITE BEING POOR AS FUCK. I WILL NEVER RETIRE BUT HERE'S ANOTHER 200$ FOR UKRAINE, SLAVA
On May 12th, Comodo had a "database system error" that has resulted in their loss of all certificates issued from May 3rd to the 12th. Given the suspect timing, what's the likelihood the largest certificate authority in the world depended on unpatched XP or Server 2003?

Internet Explorer
Jun 1, 2005





They had a database issue and lost... 9 days worth of orders? That's insane.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Cugel the Clever posted:

On May 12th, Comodo had a "database system error" that has resulted in their loss of all certificates issued from May 3rd to the 12th. Given the suspect timing, what's the likelihood the largest certificate authority in the world depended on unpatched XP or Server 2003?

Same comodo that went after let's encrypt? Nah, just straight up incompetence.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I really hope things are segmented in such a way that not everyone was affected. They seem to funnel a bunch of things through their cert-portal.com interface.

Moatman
Mar 21, 2014

Because the goof is all mine.
Note to self: don't stop massive malware attacks or the press will doxx you. https://flipboard.com/@thenextweb/-doxing-the-hero-who-stopped-wannacry-wa/f-fa540c0a7c%2Fthenextweb.com

RFC2324
Jun 7, 2012

http 418


Jesus, I thought US journos were poo poo.

CLAM DOWN
Feb 13, 2007




RFC2324 posted:

Jesus, I thought US journos were poo poo.

:laffo: British tabloids are notorious for this kind of thing, remember the whole phone hacking scandal?

Forgall
Oct 16, 2012

by Azathoth

incoherent posted:

Same comodo that went after let's encrypt? Nah, just straight up incompetence.
Went after in what way?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

What in the actual gently caress is this...

Unreal lol

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Forgall posted:

Went after in what way?

https://arstechnica.com/tech-policy/2016/06/800-pound-comodo-tries-to-trademark-upstart-rivals-lets-encrypt-name/

CEO went after the "Lets encrypt" trademark deeming it a part of their bussness, the free 90 day certificate. The difference is LE can be renewed indefinitely for free and comodo was using it to upsell certs.

Thanks Ants
May 21, 2004

#essereFerrari


CLAM DOWN posted:

:laffo: British tabloids are notorious for this kind of thing, remember the whole phone hacking scandal?

The British tabloid press (that includes the Telegraph now) are a festering sewer and the sooner everybody involved ends up on the street because someone has found out how to make people angry through Instagram or whatever the better.

hobbesmaster
Jan 28, 2008

ChubbyThePhat posted:

What in the actual gently caress is this...

Unreal lol

yeah I can't believe flipboard is still going either

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

hobbesmaster posted:

yeah I can't believe flipboard is still going either

:perfect:

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate



loving unbelievable.

XenJ
Aug 1, 2014
Scarry

Solaron
Sep 6, 2007

Whatever the reason you're on Mars, I'm glad you're there, and I wish I was with you.
Anyone here have much experience with Netscaler? Having some issues getting syslog from Netscaler to Splunk to our SIEM because of headers that Splunk is adding. We're looking at just adding the SIEM as a syslog destination to Netscaler but it would be the 3rd destination and an IT manager is afraid that it would have performance impacts to add a 3rd. I don't work with the Citrix environment so I don't know if that's realistic or not. I would not normally expect it to be an issue with other network devices...

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Solaron posted:

Anyone here have much experience with Netscaler? Having some issues getting syslog from Netscaler to Splunk to our SIEM because of headers that Splunk is adding. We're looking at just adding the SIEM as a syslog destination to Netscaler but it would be the 3rd destination and an IT manager is afraid that it would have performance impacts to add a 3rd. I don't work with the Citrix environment so I don't know if that's realistic or not. I would not normally expect it to be an issue with other network devices...

What do you mean "headers"? Do you just have generic syslog collection going on or are you doing some sort of transform in the process?

Solaron
Sep 6, 2007

Whatever the reason you're on Mars, I'm glad you're there, and I wish I was with you.

OSI bean dip posted:

What do you mean "headers"? Do you just have generic syslog collection going on or are you doing some sort of transform in the process?

Well, this process is managed overseas and they're not really open to giving us access to see the inner workings, so I only know what they're telling me. I own the SIEM and that's why I'm even having to be involved. I'm told that Splunk is just forwarding the logs they receive from Netscaler but we're seeing IPADDR TIMESTAMP IPADDR instead of the 3164 format of <PRI> TIMESTAMP IPADDR when we receive the logs from Splunk, and it's breaking the parser.

I can only assume they're massaging the data on their end somehow but all I'm being told is 'Splunk doesn't offer any options to let us modify this'.

LochNessMonster
Feb 3, 2005

I need about three fitty


Solaron posted:

Well, this process is managed overseas and they're not really open to giving us access to see the inner workings, so I only know what they're telling me. I own the SIEM and that's why I'm even having to be involved. I'm told that Splunk is just forwarding the logs they receive from Netscaler but we're seeing IPADDR TIMESTAMP IPADDR instead of the 3164 format of <PRI> TIMESTAMP IPADDR when we receive the logs from Splunk, and it's breaking the parser.

I can only assume they're massaging the data on their end somehow but all I'm being told is 'Splunk doesn't offer any options to let us modify this'.

Put logstash on your end and strip the useless crap from it.

If you're using ArcSight you can use the CEF codec to format your data.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Solaron posted:

Well, this process is managed overseas and they're not really open to giving us access to see the inner workings, so I only know what they're telling me. I own the SIEM and that's why I'm even having to be involved. I'm told that Splunk is just forwarding the logs they receive from Netscaler but we're seeing IPADDR TIMESTAMP IPADDR instead of the 3164 format of <PRI> TIMESTAMP IPADDR when we receive the logs from Splunk, and it's breaking the parser.

I can only assume they're massaging the data on their end somehow but all I'm being told is 'Splunk doesn't offer any options to let us modify this'.

Splunk natively doesn't add anything to the data being received other than putting the raw data into a field if there are no field extractions. If you're finding that the data is being modified then either it's an issue with the Netscaler, somehow there is a transform/props configuration going awry, or they're not giving you the whole truth.

https://splunkbase.splunk.com/app/2770/

This likely has the right configuration and they should be using this at the forwarder.

Solaron
Sep 6, 2007

Whatever the reason you're on Mars, I'm glad you're there, and I wish I was with you.

OSI bean dip posted:

Splunk natively doesn't add anything to the data being received other than putting the raw data into a field if there are no field extractions. If you're finding that the data is being modified then either it's an issue with the Netscaler, somehow there is a transform/props configuration going awry, or they're not giving you the whole truth.

https://splunkbase.splunk.com/app/2770/

This likely has the right configuration and they should be using this at the forwarder.

OSI and Loch - thanks for the feedback and the link, I'll check it out. What you're saying makes sense.

Levitate
Sep 30, 2005

randy newman voice

YOU'VE GOT A LAFRENIÈRE IN ME
People using KeePass for password management, do you just open up the database and copy your password every time you need to login to a site or is there an easier method?

How do people feel about other password managers like Dashlane if the information is kept local and not synced through their servers?

The Fool
Oct 16, 2003


Levitate posted:

People using KeePass for password management, do you just open up the database and copy your password every time you need to login to a site or is there an easier method?

How do people feel about other password managers like Dashlane if the information is kept local and not synced through their servers?

Ctrl-v

mewse
May 2, 2006

I went to a local infosec conference here in Winnipeg on Tuesday. I got Kevin Mitnick's business card.



Like most conferences (probably) it was jammed with vendors trying to sell stuff and I don't know how much I learned in the various sessions.

I'm basically a desktop support guy at my current IT job but from listening to the talks it sounds like I want to move to tier 1/tier 2 SOC analyst at a larger company that actually has a NOC/SOC. Would I need certs for that type of work? CCNA or an ISACA cert or something?

XenJ
Aug 1, 2014

Levitate posted:

People using KeePass for password management, do you just open up the database and copy your password every time you need to login to a site or is there an easier method?

How do people feel about other password managers like Dashlane if the information is kept local and not synced through their servers?

KeePass2 for example Android.
You can store it in gdrive or services like that or use it local for more secure.

Best is you can do a fast log in that means the first time you have to uses your complete password than you can manage that you only have to write the last 5 symbols of your password until you close the databank.
That is extrem useful if you need over a longer time diverent logins and passwords.

Best ist you can implement the sit that needs your pass/ login so keepass2 can login you automatical no copy and paste needed.
If you have to copy and paste
It brings his own keyboard so other android apps can't steal your datas with this shared cache thing....
All you have to do is press button a for loginname and b for password
You dont have to copy and past that dose the app.

https://play.google.com/store/apps/details?id=keepass2android.keepass2android

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Levitate posted:

People using KeePass for password management, do you just open up the database and copy your password every time you need to login to a site or is there an easier method?

How do people feel about other password managers like Dashlane if the information is kept local and not synced through their servers?

On the desktop, if you're using Professional edition (still free) there is an autotype option. It gets setup based on the title of the window that has focus when you hit the keyboard shorty, ctrl+alt+a by default.

CLAM DOWN
Feb 13, 2007




KeePass + Google Drive/Dropbox + Keepass2Android (or there is an iOS app too) is fantastic

XenJ
Aug 1, 2014

rafikki posted:

On the desktop, if you're using Professional edition (still free) there is an autotype option. It gets setup based on the title of the window that has focus when you hit the keyboard shorty, ctrl+alt+a by default.

Thank you that exactly was in my mind what I want to tell him but didnt find the right words. ☺

Guy Axlerod
Dec 29, 2008

rafikki posted:

On the desktop, if you're using Professional edition (still free) there is an autotype option. It gets setup based on the title of the window that has focus when you hit the keyboard shorty, ctrl+alt+a by default.

I don't get why 2.x is called "Professional" edition. It's just 2.0.

Levitate
Sep 30, 2005

randy newman voice

YOU'VE GOT A LAFRENIÈRE IN ME
Cool, thanks, I'll keep looking into it. :)

SeismicTriangle
Nov 5, 2012
anyone here come from military background? im currently about to enlist for this. People are saying it will be pretty easy to transition to a civilian career afterwards, just wondering if thats true from your perspectives and anything else you'd like to share. I dont really know anything about infosec/networks atm and school is only 6mo long so i have my doubts about those claims

am i goina be the bad guy

SeismicTriangle fucked around with this message at 05:52 on May 20, 2017

hobbesmaster
Jan 28, 2008

That's because you would have a clearance and veteran's preference for any federal jobs. So you could do help desk for SIPRnet or whatever

Furism
Feb 21, 2006

Live long and headbang

rafikki posted:

On the desktop, if you're using Professional edition (still free) there is an autotype option. It gets setup based on the title of the window that has focus when you hit the keyboard shorty, ctrl+alt+a by default.

I could never get that to works and I have no idea why :(

Levitate
Sep 30, 2005

randy newman voice

YOU'VE GOT A LAFRENIÈRE IN ME

Furism posted:

I could never get that to works and I have no idea why :(

Just playing around with this and it seems like the key to it working with a given site is that the title of your keypass entry match the display name of the website in the browser window. e: though sometimes it doesn't work but you can edit the entry and autotype settings and there's an option to select a current browser window as one that would activate the autotype

but ultimately I guess you have to open the keypass database whenever you are gonna be browsing and close it when you're done type of thing eh

e: I mean without a plugin or something that can hit the database each time requested, that makes sense.

Levitate fucked around with this message at 19:20 on May 20, 2017

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

Theres also the webautotype plugin which will match against the url of the page displayed in the browser. Can use regex against the url as well.

I'm conflicted about whether the security implications of taking on yet another devs code is worth it, but I do use it.

Cirofren
Jun 13, 2005


Pillbug
lol the British tabloids apparently doxxed the MalwareTech guy that stopped the first version of WannaCry by registering the killswitch domain.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Savagely so, yeah. Address, picture of house, etc.

Adbot
ADBOT LOVES YOU

astr0man
Feb 21, 2007

hollyeo deuroga

SeismicTriangle posted:

anyone here come from military background? im currently about to enlist for this. People are saying it will be pretty easy to transition to a civilian career afterwards, just wondering if thats true from your perspectives and anything else you'd like to share. I dont really know anything about infosec/networks atm and school is only 6mo long so i have my doubts about those claims

am i goina be the bad guy

I wasn't military but I used to work with CTNs and the other branch equivalents on the DoD civilian side. You'll gain a lot of exposure to things like pentesting that will make you employable in infosec as a civilian, but like hobbesmaster said the biggest thing is that you will end up with a TS/SCI clearance. This means that the civilian companies that will want to employ you the most will be defense contractors. Infosec is really broad so you will have other options, but having the clearance is basically a golden ticket to a large paycheck if you stick with government contractors. And no you won't be stuck just doing help desk/IT stuff in the civilian world.


Whether or not you will be the bad guy really depends on how you feel about the US military industrial complex. The NSA would be a potential duty station for a CTN, so again it depends on your personal opinions.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply