Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
The Fool
Oct 16, 2003




quote:

This can be combined with an NTLM relay attack to escalate from any user with a mailbox to Domain Admin

quote:

If we perform a SMB to HTTP (or HTTP to HTTP) relay attack (using LLMNR/NBNS/mitm6 spoofing) we can relay the authentication of a user in the same network segment to Exchange EWS and use their credentials to trigger the callback


From nothing to domain admin as long as you're on the same network as an athenticated user?

:vancouverhousefire:

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
That's some crazy poo poo. Good find.

hobbesmaster
Jan 28, 2008

Truga posted:

exclusive locking in general is a big old clusterfuck on windows. "no, you can't play/open/close/delete/write/copy this resource or file. someone, somewhere has it open"

And you need to use sysinternals to get something like "fuser"

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

hobbesmaster posted:

And you need to use sysinternals to get something like "fuser"

I’ve always assumed there was some MFC-era app hidden in a system folder that would do this, and that I’d just never found it.

geonetix
Mar 6, 2011


ChubbyThePhat posted:

That's some crazy poo poo. Good find.

The best part is Microsoft saying “please wait on our patch”. Ok, Microsoft.

SnatchRabbit
Feb 23, 2006

by sebmojo
Has anyone worked with an F5 WAF device? We have a client that wants us to configure theirs and I've never done it before. I was hoping to find a VM image or something before I start screwing around with their box. Anyone know where I could find one or some documentation?

edit: I checked the F5 website and it seems all they have is a changelog for the WAF devices and no manuals unless I'm missing something.

SnatchRabbit fucked around with this message at 21:13 on Feb 6, 2019

Docjowles
Apr 9, 2009

Does your client have an F5 support account you can use? It's dumb and annoying, but it's extremely common for vendors to put all their documentation and virtual appliances and whatnot behind a login.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
F5 devices by far have some of the worst logging in the world.

geonetix
Mar 6, 2011


Maybe true about logging but I really like the idea of waf detection at the tls termination rather than having it fully routed through their “cloud”

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

SnatchRabbit posted:

Has anyone worked with an F5 WAF device? We have a client that wants us to configure theirs and I've never done it before. I was hoping to find a VM image or something before I start screwing around with their box. Anyone know where I could find one or some documentation?

edit: I checked the F5 website and it seems all they have is a changelog for the WAF devices and no manuals unless I'm missing something.

I've worked with wafs enough to know it takes longer than a week to train it.

Guy Axlerod
Dec 29, 2008
Anyone using linux on Azure?

I've turned on the System Assigned Managed Identity for some VMs on launch. It's like giving the VM a IAM instance role in AWS, as far as I understand. On boot, cloud-init runs, and adds the SSH Public Key I specified and adds it to authorized_keys for the user I specified. However, it also converts the Managed Identity keypair to ssh format, and also adds that to authorized_keys.

This doesn't make any sense to me, the key pair is just for the software on the VM to authenticate to Azure APIs, not for stuff to gain shell access to the VM, right? I feel like I'm losing my mind because both Azure support and the cloud-init project don't seem to recognize that this is a problem.

Saukkis
May 16, 2003

Unless I'm on the inside curve pointing straight at oncoming traffic the high beams stay on and I laugh at your puny protest flashes.
I am Most Important Man. Most Important Man in the World.

D. Ebdrup posted:

Does Windows still do the thing where, if you enable Hyper-V, it doesn't let any other hypervisor access VT-x/AMD-V?

I don't think that exclusive to Windows. When I have VirtualBox virtual machines running on my Ubuntu 16 computer I am unable to start any KVM virtual machines. I haven't tested if it were possible to start them the other way around.

wolrah
May 8, 2006
what?

Saukkis posted:

I don't think that exclusive to Windows. When I have VirtualBox virtual machines running on my Ubuntu 16 computer I am unable to start any KVM virtual machines. I haven't tested if it were possible to start them the other way around.

The difference is that, because of the way Hyper-V operates, it's always running regardless of if you're actually using it.

If you stop those Virtualbox VMs, you can start your KVM VMs, and vice versa. If Hyper-V is even installed on a Windows machine you can't use Virtualbox or anything else without entirely disabling it. You can't just stop your Hyper-V session and start up something else.

Thanks Ants
May 21, 2004

#essereFerrari


The iOS release with FaceTime fixed is available now

Zaepho
Oct 31, 2013

wolrah posted:

The difference is that, because of the way Hyper-V operates, it's always running regardless of if you're actually using it.

Once the Hyper-V Role is installed, the OS you are presented with at the console is actually running inside Hyper-V hence if it's installed, you're always using it.

BlankSystemDaemon
Mar 13, 2009



Saukkis posted:

I don't think that exclusive to Windows. When I have VirtualBox virtual machines running on my Ubuntu 16 computer I am unable to start any KVM virtual machines. I haven't tested if it were possible to start them the other way around.
From comparing and contrasting FreeBSD bhyves and NetBSDs new in-kernel hardware-assisted virtualization engine, I got the impression that there are two registers (of sort?) with which you can do it, and that if implemented properly you can have any number of virtualization software access those? I'm not a programmer though, just a network- and sometimes systems-administrator.

Wiggly Wayne DDS
Sep 11, 2010



the real answer for win10 blocking it is credentialguard

evil_bunnY
Apr 2, 2003

Subjunctive posted:

I’ve always assumed there was some MFC-era app hidden in a system folder that would do this, and that I’d just never found it.
Hahahahaha no.

BlankSystemDaemon
Mar 13, 2009



If you have half an hour to an hour (plus however much memory is needed for the tab explosion), may I suggest you read about CheriABI: Enforcing Valid Pointer Provenance and Minimizing Pointer Privilege in the POSIX C Run-time Environment and how they're using FreeBSD (built mostly on C, C++ and some assembly) plus a modified RISC-chip to do a bunch of neat things including fine-grained capability-based security (yes, capabilities from the 70s!), mitigating out-of-bounds speculative reads (not just the ones Intel, ARM and AMD have patched in their microcode, either), and explicit minimizing of privileges on the whole base system plus PostgreSQL.
All of it combines to make a what they call a "complete memory-safe UNIX system that is practical for general use".

FunOne
Aug 20, 2000
I am a slimey vat of concentrated stupidity

Fun Shoe
My preferred password manager is now alerting for a Trojan. I'm guessing the guy running it had his dev pipeline compromised at some point. Whats the recommended password manager for multiple desktops and mobile.

I'd prefer something fully encrypted with my own key, but am willing to be reasonable for quality of life improvements.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
If you want full encryption, keep another one in a safe with otp codes.

E: There's a small chance that they've cooked up some scheme to obscure memory, and that's what's getting flagged. Perhaps its been modified by something else, too. Are you comfortable sharing the name of it?

Only registered members can see post attachments!

dougdrums fucked around with this message at 22:44 on Feb 12, 2019

Guy Axlerod
Dec 29, 2008

FunOne posted:

My preferred password manager is now alerting for a Trojan. I'm guessing the guy running it had his dev pipeline compromised at some point. Whats the recommended password manager for multiple desktops and mobile.

I'd prefer something fully encrypted with my own key, but am willing to be reasonable for quality of life improvements.

Which one is that?

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/VFEmail/status/1095038701665746945

:stonklol:

wolrah
May 8, 2006
what?
A perfect example of why at least one of the copies making up your backup scheme needs to be offline.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
RBAC your poo poo y'all. It shouldn't be that easy for somebody to delete your entire company.

FunOne
Aug 20, 2000
I am a slimey vat of concentrated stupidity

Fun Shoe

Guy Axlerod posted:

Which one is that?

Safe-In-Cloud, its a lesser known desktop/mobile app pair. I like it because it isn't total loving poo poo, I don't HAVE to use a Chrome extension, and my password database is in my cloud provider, not theirs.

Tried LastPass, holy hell, how is that the recommended service for most people?

Andohz
Aug 15, 2004

World's Strongest Smelly Hobo

FunOne posted:

Tried LastPass, holy hell, how is that the recommended service for most people?

It's not. KeePass and 1Password are the ones I've seen recommended here recently.

CLAM DOWN
Feb 13, 2007




FunOne posted:

Safe-In-Cloud, its a lesser known desktop/mobile app pair. I like it because it isn't total loving poo poo, I don't HAVE to use a Chrome extension, and my password database is in my cloud provider, not theirs.

Tried LastPass, holy hell, how is that the recommended service for most people?

It never was?

Wiggly Wayne DDS
Sep 11, 2010



where do you all find these services?!

Lambert
Apr 15, 2018

by Fluffdaddy
Fallen Rib

Andohz posted:

It's not. KeePass and 1Password are the ones I've seen recommended here recently.

People also seem to like Bitwarden, although I haven't tried that one.

The Fool
Oct 16, 2003


I don't understand the question.


Google?

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

wolrah posted:

A perfect example of why at least one of the copies making up your backup scheme needs to be offline.

It's really hard to rm -rf your tapes when they're stored in a file cabinet across town.

Like, it should be a standard backup/disaster recovery scenario to ask "If an attacker found my keepass keyring and had root access to everything, and did an rm -rf, how would I recover from that?"

evobatman
Jul 30, 2006

it means nothing, but says everything!
Pillbug
I'm considering using Passwordstate for the IT dept at work, to get away from USB sticks, safes and outdated printouts. Anyone got good/bad experiences, or alternatives?

Potato Salad
Oct 23, 2014

nobody cares


evobatman posted:

I'm considering using Passwordstate for the IT dept at work, to get away from USB sticks, safes and outdated printouts. Anyone got good/bad experiences, or alternatives?

Centrify, Azure HSM and KMS, 1Password

Gallatin
Sep 20, 2004

FunOne posted:

Safe-In-Cloud, its a lesser known desktop/mobile app pair. I like it because it isn't total loving poo poo, I don't HAVE to use a Chrome extension, and my password database is in my cloud provider, not theirs.

Tried LastPass, holy hell, how is that the recommended service for most people?

I've been using SafeInCloud and it works great across browsers (safari/chrome/firefox) and all of my devices (ios/android) and computers (win/mac) and the db is stored on my cloud. I tried several programs a LONG time ago so I cannot compare it but I haven't yet found a reason to try anything else. I'm open to alternatives if there is a reason I should stop using it. One negative is no Edge integration but I use it as rarely as possible. I use the standalone app when necessary.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)

Methylethylaldehyde posted:

It's really hard to rm -rf your tapes when they're stored in a file cabinet across town.

Like, it should be a standard backup/disaster recovery scenario to ask "If an attacker found my keepass keyring and had root access to everything, and did an rm -rf, how would I recover from that?"

I would thank jesus that they didn't do the needful instead:
https://twitter.com/VFEmail/status/1095021927972909056?s=20

Proteus Jones
Feb 28, 2013



dougdrums posted:

I would thank jesus that they didn't do the needful instead:
https://twitter.com/VFEmail/status/1095021927972909056?s=20

Looks like they used some undisclosed exploit to shovel out the tunnel from the backup server.

My first question is why the backup server was reachable from the Internet, let alone allowing it access to the Internet.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
Yeah I had way to much time yesterday to read about it, and it seems the motive was to destroy some info after it was retrieved, without giving away what the target was. He said something to the effect of, "I don't know how they had the password to every vm." Of course they probably did not have the password/keys to every vm so whatever it was had to really be worth it.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Proteus Jones posted:

My first question is why the backup server was reachable from the Internet, let alone allowing it access to the Internet.

How do we know that I t was directly reachable from the internet? They could have pivoted from something else they compromised, no?

Adbot
ADBOT LOVES YOU

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
That still qualifies as reachable from the internet though. I keep the backups for my business in a deposit box. I remeber one place where they just had a zip file on the dc and were like, "yeah of course we keep backups!"

I think some places have some confusion between backups in case you gently caress up some configuration and backups in case your poo poo gets wiped by an attacker/fire/mother nature.

dougdrums fucked around with this message at 12:42 on Feb 14, 2019

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply