Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CLAM DOWN
Feb 13, 2007




Inept posted:

WebSphere lol

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos
Update your Apples.

https://twitter.com/RachelTobac/status/1437504811289563140

Tryzzub
Jan 1, 2007

Mudslide Experiment
related: what do y’all see being used for MDM for stuff like this?

Sickening
Jul 16, 2007

Black summer was the best summer.

Tryzzub posted:

related: what do y’all see being used for MDM for stuff like this?

Far too often the device being used is BYOD. You are better off with a conditional access policy that blocks out of date devices in that case in order to force compliance for devices you don't own/manage. Staple that together with a brief email to your org letting them know to update their poo poo.

Done.

some kinda jackal
Feb 25, 2003

 
 
All my updates are going at like 100kb/s with 17 hours to go

Big online panic

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

Sickening posted:

Far too often the device being used is BYOD. You are better off with a conditional access policy that blocks out of date devices in that case in order to force compliance for devices you don't own/manage. Staple that together with a brief email to your org letting them know to update their poo poo.

Done.

Also consider downloading and mirroring the updates on your local share/network, save your bandwidth and help everyone update faster. I remember too many big release days crippling our circuits with everyone updating phones.

Shuu
Aug 19, 2005

Wow!

Tryzzub posted:

related: what do y’all see being used for MDM for stuff like this?

We use Jamf for forced updates & have other software for conditional access/zero trust to prevent devices that don't meet policy (up to date, MDM installed, other required security tools installed) from connecting to important services.

This is really only viable though if you have a large enough OSX user base to justify it and millions of dollars to burn.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
https://twitter.com/amiluttwak/status/1437898746747097090?s=20

Zil
Jun 4, 2011

Satanically Summoned Citrus


That seems like a big deal. Like a really big deal right?

CLAM DOWN
Feb 13, 2007




Just tested in our sandbox. It works lol

Tryzzub
Jan 1, 2007

Mudslide Experiment
unsubscribe

some kinda jackal
Feb 25, 2003

 
 
Can I have one week where I don’t wish for the sweet release of death?

Uh, I mean lmao

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

CLAM DOWN posted:

Just tested in our sandbox. It works lol

Tested it in our Azure test lab. Oops

Albinator
Mar 31, 2010

I am exceedingly glad I'm "between jobs" and not responsible for any linux machines in Azure right now.

Potato Salad
Oct 23, 2014

nobody cares


CLAM DOWN posted:

Just tested in our sandbox. It works lol

don't stop there,

do it in prod c0ward

Internet Explorer
Jun 1, 2005





Amazing.

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?
AWS sales reps be all like :sickos:

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD
Taking the rest of my IT budget, buying pallets of Big Chief tablets and leaving my keys on the desk

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:eyepop:

This is laughably, aggressively bad. Impressively bad.

some kinda jackal
Feb 25, 2003

 
 
Anyone know if this affects Azure on-prem stacks or only the cloud platform?

e: I should probably just read the CVE. It’s too early in the morning and not nearly enough caffeine for me to be thinking clearly.

Mustache Ride
Sep 11, 2001



loving hell, I was putting this loving agent on onprem systems for a Sentinel POC

BaseballPCHiker
Jan 16, 2006

Lol at microsoft trying to say OMI is open source and not paying the bounty to Wiz when they were the ones who first developed it and seem to be the only contributors to it on GitHub.

SlowBloke
Aug 14, 2017

Martytoof posted:

Anyone know if this affects Azure on-prem stacks or only the cloud platform?

e: I should probably just read the CVE. It’s too early in the morning and not nearly enough caffeine for me to be thinking clearly.

If you push logs to sentinel or log analytics you have another agent, i think even HCL uses a different stack. It might be used if you have powershell DSC enabled on linux machines on premises.

Impotence
Nov 8, 2010
Lipstick Apathy
lovely, walmart has joined the trend in retailers port scanning your device and local network and abusing webrtc

Only registered members can see post attachments!

RFC2324
Jun 7, 2012

http 418

Biowarfare posted:

lovely, walmart has joined the trend in retailers port scanning your device and local network and abusing webrtc



this is why you should never go to any website

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Episode 100 of Darknet Diaries is out https://darknetdiaries.com/episode/100/

BlankSystemDaemon
Mar 13, 2009



Biowarfare posted:

lovely, walmart has joined the trend in retailers port scanning your device and local network and abusing webrtc


This is kinda funny for anyone old enough to remember a time when authorities, I think in the US, were trying to argue that portscanning was a crime - which led to tshirts and bumper stickers with the phrase "port scanning is not a crime" appearing at various hacker conferences.

Heck, nmaps website still has an entire page dedicated to the legal ramifications, so I wonder how much trouble an enterprising individual could get into, if they really wanted.

Famethrowa
Oct 5, 2012

Biowarfare posted:

lovely, walmart has joined the trend in retailers port scanning your device and local network and abusing webrtc



heh. I'm working on a pentesting assignment for class and my professor warned us very strongly to never portscan outside the test because that could be a felony!!

RFC2324
Jun 7, 2012

http 418

Lmao, considering the number of times I have gotten bored and tried to scan 0.0.0.0...

Also, if port scanning is a felony, then how shodan?

Defenestrategy
Oct 24, 2010

You think it's possible to knock over a lovely legacy network/device with a scan like nmap -sV -p- -T4 that maybe totally "reasonable" for a network built today, but not one stood up 10-20 years ago? While portscanning is legal, I think accidentally somehow knocking over someone's lovely server with a scan might be.

Defenestrategy fucked around with this message at 17:36 on Sep 19, 2021

RFC2324
Jun 7, 2012

http 418

Pretty sure I always set things up to be relatively polite, since its was out of curiosity not malice, but the checkpoint firewall I learned about firewalls on in 2002 could handle multiple portscans trivially

Like, I am pretty sure that knocking a server that can fall down because of a portscan off the internet is a public service

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Famethrowa posted:

heh. I'm working on a pentesting assignment for class and my professor warned us very strongly to never portscan outside the test because that could be a felony!!

Its laughably difficult to enforce because there is almost constant port scanning on the public internet.

evil_bunnY
Apr 2, 2003

CommieGIR posted:

Its laughably difficult to enforce because there is almost constant port scanning on the public internet.
Don't touch the poop

Axe-man
Apr 16, 2005

The product of hundreds of hours of scientific investigation and research.

The perfect meatball.
Clapping Larry
I scanned a computers ports and then i was arrested and put away for 5 years.

Famethrowa
Oct 5, 2012

RFC2324 posted:

Lmao, considering the number of times I have gotten bored and tried to scan 0.0.0.0...

Also, if port scanning is a felony, then how shodan?

pretty sure it was a cyoa for the universities benefit because we are using shodan in a lab. context for the class is contracted pentest work and he emphasizes making sure you know your target scope for the pentest.

RFC2324
Jun 7, 2012

http 418

Famethrowa posted:

pretty sure it was a cyoa for the universities benefit because we are using shodan in a lab. context for the class is contracted pentest work and he emphasizes making sure you know your target scope for the pentest.

oh yeah, anything more than a general port scan is probably asking for trouble, and I can see pentesting having more stringent ethics

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


https://twitter.com/PhleBuster/status/1439285455267188741

these social media virus warnings always seem so hysterical, poorly-sourced, technically dubious, and full of lols

like the fact that this guy claims to have been debugging malware on his developer computer outside of a VM

BrianRx
Jul 21, 2007

Biowarfare posted:

lovely, walmart has joined the trend in retailers port scanning your device and local network and abusing webrtc



Why would they do this? Fingerprinting?

Klyith
Aug 3, 2007

GBS Pledge Week

Cup Runneth Over posted:

https://twitter.com/PhleBuster/status/1439285455267188741

these social media virus warnings always seem so hysterical, poorly-sourced, technically dubious, and full of lols

like the fact that this guy claims to have been debugging malware on his developer computer outside of a VM

It looks to me like the person you linked got hit by the scam, and then sent the file on to someone else who supposedly is "a white hat" (that also hacks consoles). And that second unknown person is the one saying it can hack the gibson from inside a debugger behind 9 proxies.

IE they sent a file to some rando on their weeb discord who claimed to be a hacker, and got back that bullshit.

So don't blow them up on twitter or whatever, they're just trying to do the right thing.

Adbot
ADBOT LOVES YOU

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Klyith posted:

It looks to me like the person you linked got hit by the scam, and then sent the file on to someone else who supposedly is "a white hat" (that also hacks consoles). And that second unknown person is the one saying it can hack the gibson from inside a debugger behind 9 proxies.

IE they sent a file to some rando on their weeb discord who claimed to be a hacker, and got back that bullshit.

So don't blow them up on twitter or whatever, they're just trying to do the right thing.

oh for sure, it's just that EVERY twitter post warning about the latest hack or scam or whatever is exactly like this and it's very amusing

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply