Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CyberPingu
Sep 15, 2013


If you're not striving to improve, you'll end up going backwards.
gently caress sake.

Failed our CE+ audit because IT hasnt been keeping up to date with patching :negative:

Adbot
ADBOT LOVES YOU

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Vigil for Virgil posted:

gently caress sake.

Failed our CE+ audit because IT hasnt been keeping up to date with patching :negative:

:smug: "But if we patch we'd get hit by Sunburst, what now?"

The Fool
Oct 16, 2003


BaseballPCHiker posted:

From what I've seen this isnt true. Its more like some companies were using Azure so some Microsoft tenants got hit not Microsoft corporate or their services. Again just from what I've read so far.

I think I saw a thing about MS saying they found some of the compromised dll’s in some internal environments but no evidence of further intrusion.

siggy2021
Mar 8, 2010

The Fool posted:

I think I saw a thing about MS saying they found some of the compromised dll’s in some internal environments but no evidence of further intrusion.

Yesterday I read there was nothing. Today I read this. Who knows what tomorrow brings!

RFC2324
Jun 7, 2012

http 418

News about what MS has done about this hack, and its a ton of credit to them.

https://www.geekwire.com/2020/microsoft-unleashes-death-star-solarwinds-hackers-extraordinary-response-breach/

E: and something about them finding comprised binaries
https://www.engadget.com/microsoft-solarwinds-075020280.html

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Apparently Mozilla has a VPN now? Anyone here used it? Is it any good?

evil_bunnY
Apr 2, 2003

Cup Runneth Over posted:

Apparently Mozilla has a VPN now? Anyone here used it? Is it any good?

mullvad!

CyberPingu
Sep 15, 2013


If you're not striving to improve, you'll end up going backwards.

CommieGIR posted:

:smug: "But if we patch we'd get hit by Sunburst, what now?"

We had versions of Adobe Reader from 2017.

I wanna kill IT right now
I spent the last 6 weeks prepping for this and explicitly told them about this.

some kinda jackal
Feb 25, 2003

 
 
If it makes you feel better, I fully expect 3/4 of the posters in this thread would be chiming in with similar stories if not for NDAs :P

I, for my part, am not making any statements about any dreams I may or may not have had of violently throttling the people in charge of patching strategy and execution at various companies.

RFC2324
Jun 7, 2012

http 418

Ive had more than one job where I was explicitly asked if I knew how to do patching on linux(i was confused because I assumed that was asking if I knew how to use the patch command) and never once used that knowledge

The Fool
Oct 16, 2003


RFC2324 posted:

Ive had more than one job where I was explicitly asked if I knew how to do patching on linux(i was confused because I assumed that was asking if I knew how to use the patch command) and never once used that knowledge

I haven’t used the patch command since I stopped doing mud dev in the 90’s

RFC2324
Jun 7, 2012

http 418

The Fool posted:

I haven’t used the patch command since I stopped doing mud dev in the 90’s

That they were just asking if I knew how to type "yum update" blew my mind, since last time I even saw a reference to it was in some tarball for a game in the mid 2000s

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


For two years of my life I had recurring literal nightmares that I was the cause of something like this, and would never be able to enter the US again. In the dreams they also often took our cat away, which I think is not supported by case law.

brains
May 12, 2004

Cup Runneth Over posted:

Apparently Mozilla has a VPN now? Anyone here used it? Is it any good?

mozilla recently dumped over a quarter of their workforce, particularly from the dev team, and is desperate to turn a profit off anything, so uh, use at your discretion i guess.

gourdcaptain
Nov 16, 2012

Cup Runneth Over posted:

Apparently Mozilla has a VPN now? Anyone here used it? Is it any good?

I was pretty sure and the wikipedia page on it backed me up that Mozilla VPN's pay version is just a rebranded Mullvad VPN. Which is the VPN I use and it works pretty well and has a decent rep, so... it probably is alright, I'm just not sure what you gain over getting Mullvad directly.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

brains posted:

mozilla recently dumped over a quarter of their workforce, particularly from the dev team, and is desperate to turn a profit off anything, so uh, use at your discretion i guess.

Yeah, they basically gutted a lot of their appsec team, and is cozying up to profit centers. No thanks. Chrome/Google sucks, but at least they are transparently bad.

BonHair
Apr 28, 2007

Martytoof posted:

If it makes you feel better, I fully expect 3/4 of the posters in this thread would be chiming in with similar stories if not for NDAs :P

I, for my part, am not making any statements about any dreams I may or may not have had of violently throttling the people in charge of patching strategy and execution at various companies.

Now, now, it could be worse. You could be at a company with three distinct IT departments, whose systems are interconnected, but are at best completely ignoring each other. And, hypothetically, responsibilities would be clear as mud. Also outsourcing with lovely contracts and no follow-up.

:shepicide:

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


gourdcaptain posted:

I was pretty sure and the wikipedia page on it backed me up that Mozilla VPN's pay version is just a rebranded Mullvad VPN. Which is the VPN I use and it works pretty well and has a decent rep, so... it probably is alright, I'm just not sure what you gain over getting Mullvad directly.

Well, I can pay in dollars, and technically I get a discount

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


The Fool posted:

I haven’t used the patch command since I stopped doing mud dev in the 90’s

You should never have stopped

evil_bunnY
Apr 2, 2003

Vigil for Virgil posted:

explicitly told them about this.
Where's your trust but verify now fuckers?

Impotence
Nov 8, 2010
Lipstick Apathy

What is up with the absurd adjective use in almost every bullet point of that article? the entirety of it is written like "super legendary microsoft literally hacked ten billion hackers back with one stroke of the pen"

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!

Biowarfare posted:

What is up with the absurd adjective use in almost every bullet point of that article? the entirety of it is written like "super legendary microsoft literally hacked ten billion hackers back with one stroke of the pen"

Government-backed counter-propaganda

Otis Reddit
Nov 14, 2006
writer is a (former? current?) ms shill/employee

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
I know it sounds kind of Dale Gribbley, but the United States Government, one of its crown jewel companies, and thousands to tens of thousands of smaller orgs collectively have egg on their faces. It's no secret that there's a multitude of government-owned media companies, and this seems like exactly the kind of situation where flexing political damage control would need to happen. Anything that spins this positive in these coming days I think is worth treating as extremely suspect

Not that there aren't oodles of individuals who would write stuff like that all on their own out of civic/company pride

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
https://twitter.com/Viss/status/1341125545208123392?s=20

RFC2324
Jun 7, 2012

http 418


:thunk:

wonder how much liability solarwinds is going to eat on this

apseudonym
Feb 25, 2011

RFC2324 posted:

:thunk:

wonder how much liability solarwinds is going to eat on this

None, this is security products industry norms.

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?

RFC2324 posted:

:thunk:

wonder how much liability solarwinds is going to eat on this

A credit bureau lost all of their customer records. Nobody went to jail. I don't think anybody was even charged (except maybe for dumping stock?). So, probably somewhere between lol and zero.

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
I mean a bunch of people did dump stock right before the announcement

E: And they managed to directly piss off the US Government

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


What's "liability" precious?

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


It's one of the insurances you purchase so you don't have to face consequences for your actions.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Assuming that there would be consequences in the first place.

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib

Ynglaur posted:

A credit bureau lost all of their customer records. Nobody went to jail. I don't think anybody was even charged (except maybe for dumping stock?). So, probably somewhere between lol and zero.
Solarwinds doesn't keep the rich rich like the credit bureaus do and they directly screwed the US gov't, there's a decent chance there's actually some blowback here. Maybe even a slightly smaller golden parachute!

Proteus Jones
Feb 28, 2013



Reading that Bloomberg article, everything at Solar Winds pre- and post-disclosure has been

RFC2324
Jun 7, 2012

http 418

wyoak posted:

Solarwinds doesn't keep the rich rich like the credit bureaus do and they directly screwed the US gov't, there's a decent chance there's actually some blowback here. Maybe even a slightly smaller golden parachute!

This is what I was thinking, this and the whole dumpster fire thing being a norm we suddenly have to be aware of because it lit the back of the building on fire.

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"
If you're responsible for an Azure tenant, I'd suggest reading this:

https://us-cert.cisa.gov/ncas/alerts/aa20-352a

quote:

Note (updated December 19, 2020): CISA has evidence that there are initial access vectors other than the SolarWinds Orion platform. Specifically, we are investigating incidents in which activity indicating abuse of Security Assertion Markup Language (SAML) tokens consistent with this adversary’s behavior is present, yet where impacted SolarWinds instances have not been identified. CISA is working to confirm initial access vectors and identify any changes to the TTPs. CISA will update this Alert as new information becomes available.

quote:

Detection: Impossible Logins
The adversary is using a complex network of IP addresses to obscure their activity, which can result in a detection opportunity referred to as “impossible travel.” Impossible travel occurs when a user logs in from multiple IP addresses that are a significant geographic distance apart (i.e., a person could not realistically travel between the geographic locations of the two IP addresses during the time period between the logins). Note: implementing this detection opportunity can result in false positives if legitimate users apply virtual private network (VPN) solutions before connecting into networks.

Detection: Impossible Tokens
The following conditions may indicate adversary activity.

Most organizations have SAML tokens with 1-hour validity periods. Long SAML token validity durations, such as 24 hours, could be unusual.
The SAML token contains different timestamps, including the time it was issued and the last time it was used. A token having the same timestamp for when it was issued and when it was used is not indicative of normal user behavior as users tend to use the token within a few seconds but not at the exact same time of issuance.
A token that does not have an associated login with its user account within an hour of the token being generated also warrants investigation.

I always knew app registrations were the devil. The good thing is there are footnotes at the bottom for some yaml files you can pull into Sentinel (or just pull the search out of and put into normal Azure monitoring, you don't strictly need Sentinel since it's looking for AAD logs) but now I'm wondering what hasn't been disclosed if there might be other entry points for this.

Sentinel stuff:

https://github.com/Azure/Azure-Sentinel/blob/master/Detections/SigninLogs/AzureAADPowerShellAnomaly.yaml

quote:

| where AppId =~ "1b730954-1685-4b74-9bfd-dac224a7b894" // AppDisplayName IS Azure Active Directory PowerShell

^ lol

edit: did a little more reading. I feel better about having implemented PIM and required extra MFA any time the role is activated. Godspeed anyone with a poorly secured Azure tenant.

i am a moron fucked around with this message at 16:52 on Dec 22, 2020

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Proteus Jones posted:

Reading that Bloomberg article, everything at Solar Winds pre- and post-disclosure has been



Yeah, and honestly if Solarwinds had discovered it themselves, I don't think they would've taken it as seriously as Fireeye did.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


https://twitter.com/lolonghi/status/1341863667290140672

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?
Hey, my impression based solely on their ads was correct. They are assholes!

Adbot
ADBOT LOVES YOU

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"
Holy poo poo there are almost no words for this. Except bah humbug

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply