Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
evil_bunnY
Apr 2, 2003

CLAM DOWN posted:

RDP. We use Azure extensively so permit outbound RDP to Azure VMs in our region, Canada Central. So I'm golden :smug:
That's cheeky as gently caress and prob a great exfil channel

Adbot
ADBOT LOVES YOU

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
So I'm starting to play with port knocking as a back door method in case my OpenVPN instance dies, pretty neat.

BlankSystemDaemon
Mar 13, 2009



CLAM DOWN posted:

I use a cloud VM for non-work stuff during the day, using my MSDN credits. Hence I can still shitpost here.
Is the MSDN credit on an account separate from your work, so that it's just something you randomly spin up that has no connection to your work?
Otherwise, I would think that hypertracing via dtrace (ie. using dtrace and/or D tracepoints inside a guest from the hypervisor) renders that null and void?

CommieGIR posted:

So I'm starting to play with port knocking as a back door method in case my OpenVPN instance dies, pretty neat.
Port knocking is great, provided you remember to limit the amount of attempts per hour.

BlankSystemDaemon fucked around with this message at 11:51 on May 5, 2019

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

D. Ebdrup posted:

Is the MSDN credit on an account separate from your work, so that it's just something you randomly spin up that has no connection to your work?

Yes.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo
For the person interested in Ghidra or anyone else really, a presentation on how to use the tool with demos was done @Infiltrate recently

https://github.com/0xAlexei/INFILTRATE2019/raw/master/INFILTRATE%20Ghidra%20Slides.pdf

Proteus Jones
Feb 28, 2013



EVIL Gibson posted:

For the person interested in Ghidra or anyone else really, a presentation on how to use the tool with demos was done @Infiltrate recently

https://github.com/0xAlexei/INFILTRATE2019/raw/master/INFILTRATE%20Ghidra%20Slides.pdf

Thanks for that! I hadn't gotten around to playing with it yet, but this will give me the impetus.

I've heard that Ghidra doesn't have an internal step-debugger, but that's it's planned. Is this accurate?

Potato Salad
Oct 23, 2014

nobody cares


According to the slides that's accurate

Raenir Salazar
Nov 5, 2010

College Slice
Anyone use Suricata on ubuntu? I followed some tutorials but I can't get it to detect/log my pings between two VMs.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Does this thread do job postings? Let’s find out.

I’m going to need a software developer focused on security soon. Hit me if that’s you.

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. not kidding a little.
- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
- someone else handles all the certification/audit poo poo, you just deal with real problems and getting ahead of them
- our office is attached to a downtown subway station (line 1, west line best line)
- other software developers want to do a good job and will thank you for helping them not gently caress up
- when you tell a PM they shouldn’t ship because of a security issue, they listen
- strong privacy and tech ethics values, and we spend to honour them
- training? conferences? working from Tbilisi for two weeks because you’ve never been there (actual example)? tell your boss how it makes sense and sure. you’re an adult, and we have money
- more than a year of runway
- actual paying customers
- you should be able to tell me about how you fixed a security fuckup and made sure it stayed fixed
- we have fired recruiting agencies for bringing us only white dudes for leadership and tech positions
- you don’t need to know about AI, but you’ll sure learn about it
- talking to people (internal mostly) is part of the job. you can get coached to gently caress and back, but you can’t dodge it
- you’re moving to Toronto, but we’re paying relo. Or you can convince me that you can wreck poo poo by being here 1/3 weeks, but my standards are high

apseudonym
Feb 25, 2011

Subjunctive posted:

Does this thread do job postings? Let’s find out.

I’m going to need a software developer focused on security soon. Hit me if that’s you.

- I’d be your boss’ boss, and you’ll never have as supportive a management chain as this one. not kidding a little.
- you need to make good decisions about tooling vs process vs just writing the diffs and tests yourself
- someone else handles all the certification/audit poo poo, you just deal with real problems and getting ahead of them
- our office is attached to a downtown subway station (line 1, west line best line)
- other software developers want to do a good job and will thank you for helping them not gently caress up
- when you tell a PM they shouldn’t ship because of a security issue, they listen
- strong privacy and tech ethics values, and we spend to honour them
- training? conferences? working from Tbilisi for two weeks because you’ve never been there (actual example)? tell your boss how it makes sense and sure. you’re an adult, and we have money
- more than a year of runway
- actual paying customers
- you should be able to tell me about how you fixed a security fuckup and made sure it stayed fixed
- we have fired recruiting agencies for bringing us only white dudes for leadership and tech positions
- you don’t need to know about AI, but you’ll sure learn about it
- talking to people (internal mostly) is part of the job. you can get coached to gently caress and back, but you can’t dodge it
- you’re moving to Toronto, but we’re paying relo. Or you can convince me that you can wreck poo poo by being here 1/3 weeks, but my standards are high

I have no interest in moving to Toronto but that sounds like a not poo poo security job, hope you find someone good

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Raenir Salazar posted:

Anyone use Suricata on ubuntu? I followed some tutorials but I can't get it to detect/log my pings between two VMs.

I have a box running SELK, which is Suricata running with the ELK stack for reporting and analytics.

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/cryptoishard/status/1126674411753476096
https://twitter.com/cryptoishard/status/1126675625803165696

Proteus Jones
Feb 28, 2013




Yeah, I figured Symantec was one of the three when I read it this morning. Still not sure who the other two might be.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

From what I've seen of Symantec's strategic decisions, their CEO stepping down should maybe move the stock upwards.

astral
Apr 26, 2004

Subjunctive posted:

From what I've seen of Symantec's strategic decisions, their CEO stepping down should maybe move the stock upwards.

Sadly, people are more likely to judge based on appearances and that's a "but won't you please buy our antivirus?" face if I've ever seen one.



:unsmith::shobon:

evil_bunnY
Apr 2, 2003

Subjunctive posted:

From what I've seen of Symantec's strategic decisions, their CEO stepping down should maybe move the stock upwards.
This. Their poo poo is so loving aggravating.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Proteus Jones posted:

Yeah, I figured Symantec was one of the three when I read it this morning. Still not sure who the other two might be.

Im shooting for McAffee for sure. Then maybe Norton.

EVIL Gibson fucked around with this message at 17:24 on May 10, 2019

Proteus Jones
Feb 28, 2013



EVIL Gibson posted:

Im shooting for McAffee for sure. Then maybe Norton.

Norton is Symantec, isn't it?

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Proteus Jones posted:

Norton is Symantec, isn't it?

it is. i just always think they are different.

Lambert
Apr 15, 2018

by Fluffdaddy
Fallen Rib
Snake oil companies getting hacked is always great.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Proteus Jones posted:

Yeah, I figured Symantec was one of the three when I read it this morning. Still not sure who the other two might be.

this sure gives me a lot of confidence in their ability to run a cloud-only av product with SEP 15

apseudonym
Feb 25, 2011

BangersInMyKnickers posted:

this sure gives me a lot of confidence in their ability to run a cloud-only av product with SEP 15

Did you have confidence before...?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

Potato Salad
Oct 23, 2014

nobody cares


Lain Iwakura posted:

Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

Yess

Schadenboner
Aug 15, 2011

by Shine

Lain Iwakura posted:

Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

:suspense:

Proteus Jones
Feb 28, 2013



Lain Iwakura posted:

Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

You'll need to drop that in the general IT thread if you want an explosion, I think. :D

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Lain Iwakura posted:

Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

Playing the hits, Lain?

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

Lain Iwakura posted:

Who wants my opinions on how all anti-virus engines are hot garbage? :laugh:

I agree they are but tell me more :allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
These days my rants are more limited to how log collection is hot garbage that is necessary and loving awful.

Lambert
Apr 15, 2018

by Fluffdaddy
Fallen Rib
I'd be more interested in hearing the opposite opinion - yes, these scanners are getting exploited all the time and cause severe problems with regularity, but they're great!

Schadenboner
Aug 15, 2011

by Shine

Lain Iwakura posted:

These days my rants are more limited to how log collection is hot garbage that is necessary and loving awful.

I likewise wish to hear this rant as well!

:ohdear:

Thanks Ants
May 21, 2004

#essereFerrari


Lambert posted:

I'd be more interested in hearing the opposite opinion - yes, these scanners are getting exploited all the time and cause severe problems with regularity, but they're great!

Isn't that basically Gartner?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Thanks Ants posted:

Isn't that basically Gartner?



Look at all of that hot garbage.


Schadenboner posted:

I likewise wish to hear this rant as well!

:ohdear:

One day when I am not writing a tonne of documentation on said hot garbage.

Absurd Alhazred
Mar 27, 2010

by Athanatos

Lain Iwakura posted:



Look at all of that hot garbage.

I notice that there are exactly three in the "Leaders" quadrant, including Symantec. :getin:

Schadenboner
Aug 15, 2011

by Shine
I mean, Fortinet is p.trash?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Schadenboner posted:

I mean, Fortinet is p.trash?

We did rescue someone from them a year ago and she has been an absolutely great addition to our incident response team.

CLAM DOWN
Feb 13, 2007

nesaM killed Masen
What's your opinion on Azure Sentinel, Lain?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

apseudonym posted:

Did you have confidence before...?

No, but the execs do and they've been handwaving away my concerns so far

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

CLAM DOWN posted:

What's your opinion on Azure Sentinel, Lain?

We just had a demo today for this, more next week

Adbot
ADBOT LOVES YOU

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

CommieGIR posted:

We just had a demo today for this, more next week

I'm quite literally excited for your take on this.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply