Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
evil_bunnY
Apr 2, 2003

CLAM DOWN posted:

gently caress that, OANN deserves it.
:same:

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



trashy owl posted:

If you thought it was anything other than "haha look at these morons, these absolute buffoons" I really don't know what to tell you.

This is the most accurate summary of InfoSec in general I think I've ever seen.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Proteus Jones posted:

This is the most accurate summary of InfoSec in general I think I've ever seen.

P'much

Butter Activities
May 4, 2018

The Iron Rose posted:

This is the dumbest thing. OANN sucks but the level of interest I have in celebrating leaked Wordpress credentials is nonexistent. They’re not owning anyone. They’re certainly not pwning anyone.

No its cool actually

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
https://twitter.com/CommieGIR/status/1336424625471954947?s=20

Fireeye got popped.

Sickening
Jul 16, 2007

Black summer was the best summer.

In-loving-credible.

CLAM DOWN
Feb 13, 2007





:sickos:

spankmeister
Jun 15, 2008






Sickening posted:

In-loving-credible.

Just goes to show that everybody gets got at some point.

CyberPingu
Sep 15, 2013


If you're not striving to improve, you'll end up going backwards.
Wonder how they got in?

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Vigil for Virgil posted:

Wonder how they got in?

https://twitter.com/gsuberland/status/1336452690059141120?s=20

some kinda jackal
Feb 25, 2003

 
 
One of my vendors was making a massive push two years ago to get me to replace everything we own with FireEye equivalents lol

Thankfully I just took their sales guys for a ride to the tune of a dozen super expensive wine-and-dines and dumped them or this could have looked unfortunate for me :q:

Diva Cupcake
Aug 15, 2005

https://twitter.com/thegrugq/status/1336468185244045312

BaseballPCHiker
Jan 16, 2006

We use basically every single FireEye product in existence. Our rep called right away to assure that customer data was safe but my gut tells me otherwise...

droll
Jan 9, 2020

by Azathoth
Fireeye had an ISP problem a few years ago resulting in some emails to us not being delivered, intermittently. We had no idea, senders received no bounce. It took weeks for them to fix it, so we dropped them. poo poo company.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Yeah, those attacks are unheard of! :thunk:

Ensign Expendable
Nov 11, 2008

Lager beer is proof that god loves us
Pillbug

Already gone.

droll
Jan 9, 2020

by Azathoth
It was a post about some vmware workspace one vulnerabilities but no evidence linking to the fireeye hack

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
https://twitter.com/Bing_Chris/status/1338195736056524803?s=20

Maneki Neko
Oct 27, 2000

Oh drat, looks like multiple federal agencies got hit and the culprit seems to be a foreign state introducing back door into Solarwinds Orion monitoring tools between March/June this year:

https://twitter.com/razhael/status/1338267165221396480?s=20

https://www.reuters.com/article/us-usa-solarwinds-cyber-idUSKBN28N0Y7

Maneki Neko
Oct 27, 2000

Good info here:

https://www.fireeye.com/blog/threat...t-backdoor.html

some kinda jackal
Feb 25, 2003

 
 
Apropos of nothing, I wonder what it’s like to be a car mechanic or something, where you don’t need to worry about nation states or other shitheads keeping you up at night with worry on the reg.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
As an infosec guy who also does mechanic stuff: Customers still suck.

Garrand
Dec 28, 2012

Rhino, you did this to me!

Customers are always the biggest threat

Internet Explorer
Jun 1, 2005





This is the kinda poo poo I love to show people when they ask "how can we be 100% secure?"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Martytoof posted:

Apropos of nothing, I wonder what it’s like to be a car mechanic or something, where you don’t need to worry about nation states or other shitheads keeping you up at night with worry on the reg.

Good news, as cars become more connected, you get to deal with this poo poo there too! Beep beep, here comes the GSM > Head unit > CANBUS

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Internet Explorer posted:

This is the kinda poo poo I love to show people when they ask "how can we be 100% secure?"

We all get hacked eventually, infosec is how well you prepped and can deal with it.

uniball
Oct 10, 2003

i’m very happy that Solarwinds ended up being the vector this time around

CyberPingu
Sep 15, 2013


If you're not striving to improve, you'll end up going backwards.

Internet Explorer posted:

This is the kinda poo poo I love to show people when they ask "how can we be 100% secure?"

The thing is that a lot of companies can be protected from a lot of poo poo by doing the basics right and that's something that as an industry we still loving suck at

We over rely on passwords even though they have been known to be a really poor system. We don't do enough education for staff, we lead a blame culture instead of understanding, even though we all agree that infosec is loving hard.


And we still can't get patching right because "Eh, that would incur downtime which we can't afford".


Obviously that's not gonna protect you from everything.

BlankSystemDaemon
Mar 13, 2009



Martytoof posted:

Apropos of nothing, I wonder what it’s like to be a car mechanic or something, where you don’t need to worry about nation states or other shitheads keeping you up at night with worry on the reg.
With that cyberpunk avatar, you should know that it's only a matter of time before car mechanics have to deal with those issues because of trans-national mega-corporations

some kinda jackal
Feb 25, 2003

 
 
Ironically, I wonder how many sensitive orgs were spared this particular hack because they didn't patch Solarwinds on schedule. Given this was a patch from this summer I'd say that the number is definitely non-zero.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Martytoof posted:

Ironically, I wonder how many sensitive orgs were spared this particular hack because they didn't patch Solarwinds on schedule. Given this was a patch from this summer I'd say that the number is definitely non-zero.

Somewhere my old boss is telling people about this and saying, "And that's why we don't update our software"

:smugdog:

Farking Bastage
Sep 22, 2007

Who dey think gonna beat dem Bengos!

Internet Explorer posted:

This is the kinda poo poo I love to show people when they ask "how can we be 100% secure?"

Yeah. My answer is usually, shut it off encase it in concrete wrap in tinfoil and bury.

Maneki Neko
Oct 27, 2000

Martytoof posted:

Ironically, I wonder how many sensitive orgs were spared this particular hack because they didn't patch Solarwinds on schedule. Given this was a patch from this summer I'd say that the number is definitely non-zero.

I’m just going to say that I looked at 3 customer solarwinds servers yesterday and they all were running a version too old to be impacted so yeah.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Hotfix 1 is out for Solarwinds, another coming on the 15th.

Still should check to see what your local solarwinds was talking to.

ghostinmyshell
Sep 17, 2004



I am very particular about biscuits, I'll have you know.

Bob Morales posted:

Somewhere my old boss is telling people about this and saying, "And that's why we don't update our software"

:smugdog:

I might be your boss.

The little if any good news out of this is the InfoSec group hosed up by going right to "wipe our systems nooooooooooooooooooooooooooooooooow," and cc'd everyone before providing any actual evidence we were compromised. Someone was smart enough to call them out to ask for reports from the 2-3 security appliances we pay a fuckton for asking if there was any actual suspicious activity and what's up with them if we are so hosed we need to wipe our systems.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Maneki Neko posted:

I’m just going to say that I looked at 3 customer solarwinds servers yesterday and they all were running a version too old to be impacted so yeah.

I checked in with a customer I knew using it last night and they were in the same boat. Hooray for not updating! :D

RFC2324
Jun 7, 2012

http 418

ghostinmyshell posted:

I might be your boss.

The little if any good news out of this is the InfoSec group hosed up by going right to "wipe our systems nooooooooooooooooooooooooooooooooow," and cc'd everyone before providing any actual evidence we were compromised. Someone was smart enough to call them out to ask for reports from the 2-3 security appliances we pay a fuckton for asking if there was any actual suspicious activity and what's up with them if we are so hosed we need to wipe our systems.

Your infosec group sucks.

For one thing, never wipe your systems, shut them down and preserve them for investigation and spin up your backup network

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

RFC2324 posted:

your backup network

"our what?"

RFC2324
Jun 7, 2012

http 418

Subjunctive posted:

"our what?"

In the case of the small businesses I worked for that would have been spinning up whole new instances, while actively preserving the old compromised backups so they could be restored to a VM for investigation

Adbot
ADBOT LOVES YOU

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!


Did some poor security practices lead to the US Government and FireEye breach? SolarWinds exposed their FTP server credentials in a Github leak in 2019

https://savebreach.com/solarwinds-credentials-exposure-led-to-us-government-fireye-breach/

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply