Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Super Slash
Feb 20, 2006

You rang ?
Big rear end ticket list: Get the following people fully kitted out for remote working as we're switching off the old system soon

- Organisation floundering
- Time passes
- Bulk order for very high spec laptops happens and is delivered
- Get to work putting together an imaging process, shenanigans ensue
- Process is way too hands on for this mountain of laptops, so I take a copy of an SCCM task sequence and modify things so it's basically a one-touch deployment
- "Do you want the good news or bad news?"
- "Go on then..."
- "I've been told we need to stop imaging these laptops with Windows 10 Enterprise because it's using up too many activations, and we need to use the included Pro instead"
- :whoptc:

Adbot
ADBOT LOVES YOU

Ghostlight
Sep 25, 2009

maybe for one second you can pause; try to step into another person's perspective, and understand that a watermelon is cursing me



When do you get the bad news?

Squatch Ambassador
Nov 12, 2008

What? Never seen a shaved Squatch before?
A ticket came in from an instructor asking for software that I'm pretty sure is already installed on his student laptops. So I open OneNote to look at the software list from the last time I updated that image and...



moving my cursor around causes it to corrupt further


:discourse:

iospace
Jan 19, 2038


Hungry Computer posted:

A ticket came in from an instructor asking for software that I'm pretty sure is already installed on his student laptops. So I open OneNote to look at the software list from the last time I updated that image and...



moving my cursor around causes it to corrupt further


:discourse:

I have questions.

notwithoutmyanus
Mar 17, 2009
VTP shittery continues: instead of VTP transparent and having solarwinds manage our switches, they want to do VTP Server/client. Supposedly "we have way too many switches to do it any other way". We have no more than maybe 20 at a site. :ohdear:

Squatch Ambassador
Nov 12, 2008

What? Never seen a shaved Squatch before?
Ỳ̨̛̕e̛͠s̡҉̡̢̨?̡͜

questions posted:

I have iospace.  Y̘̫̙͞e̗̭̱͓s͓̟̭?҉̰̟̱̳ͅ

Y̮͎̲e̖̙s̯̥͔͖̦̗?̯̙̺̹͠
    Y̲ͅe̷̵̙͍̘̰̺͕̼̦s͚̜̤͎͔̝̀?̛̟̪͇̠̝̬̥́

skooma512
Feb 8, 2012

You couldn't grok my race car, but you dug the roadside blur.

Oyster posted:

I just started studying for the CCENT and knew I covered VTP but couldn't remember it offhand. Looking it up brought me to this gem:


I'll now forever be on the lookout for that. Thanks, thread.

I wonder if anyone's attacked a network by just sending out VTP packets with bullshit in them and hoping the engineer forgot to turn it off.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

skooma512 posted:

I wonder if anyone's attacked a network by just sending out VTP packets with bullshit in them and hoping the engineer forgot to turn it off.

That would be possibly the single best throw away no-effort dickish java applet you could write. Connect to server, send magic packet broadcast, if it drops within 5 seconds, add another tick mark to the schadenfreude tally.

The Claptain
May 11, 2014

Grimey Drawer

Hungry Computer posted:

A ticket came in from an instructor asking for software that I'm pretty sure is already installed on his student laptops. So I open OneNote to look at the software list from the last time I updated that image and...



moving my cursor around causes it to corrupt further


:discourse:

I had this problem with Excel some time ago, the proposed solution is turning off hardware graphics acceleration, which of course, didn't work for me, because why it should. I eventually solved it by installing 64-bit version of Office.

BallerBallerDillz
Jun 11, 2009

Cock, Rules, Everything, Around, Me
Scratchmo

skooma512 posted:

I wonder if anyone's attacked a network by just sending out VTP packets with bullshit in them and hoping the engineer forgot to turn it off.

It's not exactly the same thing but I believe that abusing VTP is the primary way attackers do vlan hopping. It goes the opposite direction though, broadcast low VTP and accept VLAN configuration for a virtual (or I guess hardware if they have physical access to the target network) switch and hope things are configured poorly enough that they can use any vlan VTP pushes to them.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

The Nards Pan posted:

It's not exactly the same thing but I believe that abusing VTP is the primary way attackers do vlan hopping. It goes the opposite direction though, broadcast low VTP and accept VLAN configuration for a virtual (or I guess hardware if they have physical access to the target network) switch and hope things are configured poorly enough that they can use any vlan VTP pushes to them.

This tends to be one of the more common uses of that behavior, yes.

Jaded Burnout
Jul 10, 2004


It's been a lot time since I've worked any kind of helpdesk, but I've got one for you where I was the stupid user.

On the phone to Brother support trying to figure out why my laser printer is printing large diamonds down the center of everything I print, even test pages.

He asks me to open it up a few layers where I see a square post-it note which had somehow fallen into the output slot and was going round and round on the roller. When I explained this I got a silence which sounded like the last dregs of his soul floating away.

mewse
May 2, 2006

Jaded Burnout posted:

He asks me to open it up a few layers where I see a square post-it note which had somehow fallen into the output slot and was going round and round on the roller. When I explained this I got a silence which sounded like the last dregs of his soul floating away.

Hail printers, champions and physical manifestations of Despair

iospace
Jan 19, 2038


Hungry Computer posted:

Ỳ̨̛̕e̛͠s̡҉̡̢̨?̡͜


Y̮͎̲e̖̙s̯̥͔͖̦̗?̯̙̺̹͠
    Y̲ͅe̷̵̙͍̘̰̺͕̼̦s͚̜̤͎͔̝̀?̛̟̪͇̠̝̬̥́

Well played :golfclap:

Ghostlight
Sep 25, 2009

maybe for one second you can pause; try to step into another person's perspective, and understand that a watermelon is cursing me



The Claptain posted:

I had this problem with Excel some time ago, the proposed solution is turning off hardware graphics acceleration, which of course, didn't work for me, because why it should. I eventually solved it by installing 64-bit version of Office.
That's Microsoft for you - it's solved over a dozen instances of that in my office. I just wish I knew why office programs would need hardware acceleration in the first place that it's on by default, and how Microsoft have managed to screw it up so badly.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
Considering 64 bit Office blocks a lot of old janky plugins an environment might have had installed but which you don't need anymore, it could be that the real problem was said ancient Office plugins.

:shrug:

Ghostlight posted:

I just wish I knew why office programs would need hardware acceleration in the first place that it's on by default

Why wouldn't they? Your entire operating system has had hardware acceleration of graphics with minimal exceptions since the late 90s for sure, and a lot of people had it even earlier. Back on Windows 3.x there were already graphics cards available designed to interact with how Windows drew things on screen such that they could speed up drawing and moving the 2D graphics elements used in things like... Microsoft Office.

Ghostlight
Sep 25, 2009

maybe for one second you can pause; try to step into another person's perspective, and understand that a watermelon is cursing me



I was being facetious, but thank you for your input.

Weatherman
Jul 30, 2003

WARBLEKLONK

fishmech posted:

Considering 64 bit Office blocks a lot of old janky plugins an environment might have had installed but which you don't need anymore, it could be that the real problem was said ancient Office plugins.

:shrug:


Why wouldn't they? Your entire operating system has had hardware acceleration of graphics with minimal exceptions since the late 90s for sure, and a lot of people had it even earlier. Back on Windows 3.x there were already graphics cards available designed to interact with how Windows drew things on screen such that they could speed up drawing and moving the 2D graphics elements used in things like... Microsoft Office.

Fishmech, why do you have an average of almost 60 posts per day on these forums

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Weatherman posted:

Fishmech, why do you have an average of almost 60 posts per day on these forums

That's a lot of shitposting instead of working.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Weatherman posted:

Fishmech, why do you have an average of almost 60 posts per day on these forums

An admin did some monkey business with postcounts a while back and it's not like I post in forums where your postcount goes down.

iospace
Jan 19, 2038


Re, Macs:
https://twitter.com/lemiorhan/status/935581020774117381
:thunk:

iospace fucked around with this message at 00:02 on Nov 29, 2017

Proteus Jones
Feb 28, 2013




My post from the Infosec Grey Forum:

Proteus Jones posted:

Yeah, if you have screen sharing on, it will work.

A few more details I've found:

If you already enabled a root account and it has a password you're fine.

You have to do the initial exploit in System Prefs>Users It actually creates the password-less root account. So everyone rushing to test this has already self-owned.

System Prefs is the only place macOS will actually create the account if it's missing. However user level of the account trying this doesn't matter.

It will work on the logon screen if you have it set to force entering a User ID. If you just use the account picker 'root' won't be an option.

Setting a password will fix the issue.

To clarify, if the root account it created in Users, it will let you use the password-less account on the logon screen and VNC/Screen Sharing. Once the account is created, if you delete it, on reboot it re-creates it.

Use this to see if you already have 'root' enabled:
code:
dscl . list /Users | grep -v '^_'


Nope. I was being stupid. Root still shows up if it's in disabled, don't know why I thought it would't. Just set the drat password and disable if it isn't already.

Use the KB article: https://support.apple.com/en-us/HT204012

EDIT:

To set the password, use this in terminal
code:
sudo passwd -u root

Proteus Jones fucked around with this message at 02:17 on Nov 29, 2017

LethalGeek
Nov 4, 2009

Weatherman posted:

Fishmech, why do you have an average of almost 60 posts per day on these forums
Because someone has to absolutely be technically right at all times!*

*not actually right at all times

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)


Anything less than a full and immediate ban of all Apple products from your corporate networks is negligence.

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

carry on then posted:

Anything less than a full and immediate ban of all Apple products from your corporate networks is negligence.

FINALLY, we can settle this loving debate for good

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

carry on then posted:

Anything less than a full and immediate ban of all Apple products from your corporate networks is negligence.

Or you could set passwords on root.

Proteus Jones
Feb 28, 2013



Avenging_Mikon posted:

Or you could set passwords on root.

Yeah, I use a MacBook Pro for work, and I'm flabbergasted that Apple used best practice of having root disabled out of the box, but then had a NULL password for it. It's crazy. They really hosed up here.

Use the KB article, enable root and set a password, and then disable root. (last part is wrong. DO NOT DISABLE. Disabling root "resets" the password back to NULL. Because APPLE ARE loving MORONS)

Proteus Jones fucked around with this message at 03:24 on Nov 29, 2017

iospace
Jan 19, 2038


Proteus Jones posted:

Yeah, I use a MacBook Pro for work, and I'm flabbergasted that Apple used best practice of having root disabled out of the box, but then had a NULL password for it. It's crazy. They really hosed up here.

Use the KB article, enable root and set a password, and then disable root.

Well, here's the ticket that came in for it:

https://twitter.com/fristle/status/935670476214378496

Proteus Jones
Feb 28, 2013



iospace posted:

Well, here's the ticket that came in for it:

https://twitter.com/fristle/status/935670476214378496

Even better.

I just re-enabled it going through the Directory Utility and it prompts me to set a password when I enable. That tells me when you disable root, it clears the password back to NULL.

WHAT THE loving poo poo, APPLE.

iospace
Jan 19, 2038


Proteus Jones posted:

Even better.

I just re-enabled it going through the Directory Utility and it prompts me to set a password when I enable. That tells me when you disable root, it clears the password back to NULL.

WHAT THE loving poo poo, APPLE.

:jebstare:

Wibla
Feb 16, 2011

Newsflash: apple is poo poo.

The Fool
Oct 16, 2003


Wibla posted:

Newsflash: all hardware and software companies are poo poo.

FTFY

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)


I don't seem to recall Microsoft every pushing a product as broken as this.

Zil
Jun 4, 2011

Satanically Summoned Citrus


carry on then posted:

I don't seem to recall Microsoft every pushing a product as broken as this.

Let me tell you of a little OS named Windows ME...

The Fool
Oct 16, 2003


Because net /user:administrator /enable doesn’t work on a depressing number of computers

Kurieg
Jul 19, 2012

RIP Lutri: 5/19/20-4/2/20
:blizz::gamefreak:

Zil posted:

Let me tell you of a little OS named Windows ME...

HISSSSSS

TITTIEKISSER69
Mar 19, 2005

SAVE THE BEES
PLANT MORE TREES
CLEAN THE SEAS
KISS TITTIESS






(not mine)

Proteus Jones
Feb 28, 2013



carry on then posted:

I don't seem to recall Microsoft every pushing a product as broken as this.

MS08-067 wants a word with you.

As well as MS06-040

Proteus Jones fucked around with this message at 07:17 on Nov 29, 2017

iospace
Jan 19, 2038


Zil posted:

Let me tell you of a little OS named Windows ME...

BEGONE HEATHEN

Adbot
ADBOT LOVES YOU

LethalGeek
Nov 4, 2009

Zil posted:

Let me tell you of a little OS named Windows ME...

Omg the college flash backs to 2000. We didn't know we didn't know!!

  • Locked thread