Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
r u ready to WALK
Sep 29, 2001

BaseballPCHiker posted:

Good loving lord. Now someone doesnt want to update because a change freeze was going to go into affect next week.

I should just start live tweeting this poo poo. I cant believe this company hasnt been just totally annihilated by ransomware or something yet.

point them towards https://www.bleepingcomputer.com/news/security/kronos-ransomware-attack-may-cause-weeks-of-hr-solutions-downtime/ and say this is going to be them, soon

i don't think the https://nvd.nist.gov/vuln/detail/CVE-2019-17571 CVE is as bad since an attacker would have to netcat java objects directly into the loggers listen port which is definitely not the same as https://nvd.nist.gov/vuln/detail/CVE-2021-44228 where the logger just has to see the magic jndi string in whatever plain text string was logged by an application

Adbot
ADBOT LOVES YOU

evil_bunnY
Apr 2, 2003

BaseballPCHiker posted:

I cant believe this company hasnt been just totally annihilated by ransomware or something yet.
Be the change you want to see in the world.

Nukelear v.2
Jun 25, 2004
My optional title text

BaseballPCHiker posted:

Good loving lord. Now someone doesnt want to update because a change freeze was going to go into affect next week.

I should just start live tweeting this poo poo. I cant believe this company hasnt been just totally annihilated by ransomware or something yet.

I would say sticking with 1.x for a few weeks isn't an awful idea while you wait to see how this shakes out. As r u ready to WALK pointed out, the conditions for the 2019 CVE are pretty limited and can be confirmed easily.

Log4j 2 has shown itself to have made some pretty fundamental mistakes and was pretty hastily patched. Pushing people from 1 to 2 haphazard seems a bit risky since this is potentially only the tip of the iceberg for 2.

Nukelear v.2 fucked around with this message at 20:04 on Dec 13, 2021

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Nukelear v.2 posted:

I would say sticking with 1.x for a few weeks isn't an awful idea while you wait to see how this shakes out. As r u ready to WALK pointed out, the conditions for the 2019 CVE are pretty limited and can be confirmed easily.

Log4j 2 has shown itself to have made some pretty fundamental mistakes and was pretty hastily patched. Pushing people from 1 to 2 haphazard seems a bit risky since this is potentially only the tip of the iceberg for 2.

Yeah most of the more major CVEs were in 2.x, so some bad choices were made

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


evil_bunnY posted:

Be the change you want to see in the world.

Goddammit this made me laugh way too hard

DrDork
Dec 29, 2003
commanding officer of the Army of Dorkness
Most of the time being on salary is a Good Thing for me, since no one cares if I pop off early on a regular basis as long as my stuff is getting done.

This weekend...oof. Really would'a make a nice overtime check.

Internet Explorer
Jun 1, 2005





It's a pet peeve of mine, so sorry in advance, but there's salary exempt and salary non-exempt and only the later doesn't get overtime. And if you're salaried non-exempt, then your work schedule should be flexible and you should be able to work less than 40 hours. Obviously, that's not how it often works out in practice, but yeah.

*gets down off soap box*

KillHour
Oct 28, 2007


I think you're mixing them up. Exempt does not get overtime.

Internet Explorer
Jun 1, 2005





Yes, you're right, sorry for the mixup and thanks for the correction. Was phone posting.

RFC2324
Jun 7, 2012

http 418

Internet Explorer posted:

It's a pet peeve of mine, so sorry in advance, but there's salary exempt and salary non-exempt and only the later doesn't get overtime. And if you're salaried non-exempt, then your work schedule should be flexible and you should be able to work less than 40 hours. Obviously, that's not how it often works out in practice, but yeah.

*gets down off soap box*

I have defined shifts, yet am salary-exempt.

got a long way to go before we can get salaried back to the way it should be

DrDork
Dec 29, 2003
commanding officer of the Army of Dorkness
Yeah, while salary non-exempt technically exists, it's a very rarely used status these days (it's only required if your salary is under $35k, or under $107k in some cases). Somewhere along the lines companies figured out that the vast majority of workers will accept salary-exempt and just...deal with it if they need to put in time over 40.

Really the only places I'm aware of that commonly use salary non-exempt these days are in strong union shops and some limited government areas. Neither of which tends to include tech, let alone Security :sigh:

In any event, I generally can't complain too much about my scheduling. This...has been a bad two weeks, though.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Internet Explorer posted:

It's a pet peeve of mine, so sorry in advance, but there's salary exempt and salary non-exempt and only the later doesn't get overtime. And if you're salaried non-exempt, then your work schedule should be flexible and you should be able to work less than 40 hours. Obviously, that's not how it often works out in practice, but yeah.

*gets down off soap box*

A very relevant thing for people who touch computers as a profession and make more than minimum wage (oops we're all exempt)

KozmoNaut
Apr 23, 2008

Happiness is a warm
Turbo Plasma Rifle


We had a bit of a scare at work, because a central and extremely important system uses log4j.

Turns out we're so behind on upgrades, it's not vulnerable unless you use specific functionality, which we've never used and have no plans to use :v:

Score 1 for never loving upgrading poo poo.

Internet Explorer
Jun 1, 2005





DrDork posted:

Yeah, while salary non-exempt technically exists, it's a very rarely used status these days (it's only required if your salary is under $35k, or under $107k in some cases).

Volmarias posted:

A very relevant thing for people who touch computers as a profession and make more than minimum wage (oops we're all exempt)

I hear what you all are saying, but part of raising awareness of the issue, in my eyes, is making sure we aren't going around saying salary = no overtime.

Thanks Ants
May 21, 2004

#essereFerrari


Different countries have different cultures but my experience is it wouldn’t even need to be spelled out here (UK) that if you’re salaried and working extra hours that you get that time in lieu, with some sort of multiplier for weekend days. If you’re doing billable work then no employer would object to it being paid out as OT. The idea that you just lose those hours because you’re salaried is alien.

Internet Explorer
Jun 1, 2005





Yeah, that's kind of what I was getting at with the whole salaried exempt = no set hours thing. At the very least you should be getting comp time for extra hours worked. Same thing if you somehow get called in during PTO or other days off. Or travel during non-business hours.

I think it's important to push back on that sort of stuff, otherwise it makes for a really lovely work environment. I've had a lot of success in the past, but unfortunately facing the same ol' poo poo at my current place. Slowly approaching the topic.

Lets Get Patchy
Aug 8, 2006

Internet Explorer posted:

Yeah, that's kind of what I was getting at with the whole salaried exempt = no set hours thing. At the very least you should be getting comp time for extra hours worked. Same thing if you somehow get called in during PTO or other days off. Or travel during non-business hours.

I'm pretty new to the management thing, but this is kinda how I run my salaried exempt team at our client's site. My company has a minimum hours worked requirement, a standard 40 hour workweek, but you can bet your rear end that if you work over that you're getting comp'd. The last guy in this position was a spineless slug who folded at the slightest of pushback from the main office and retention of talent was a serious issue. That's not an issue anymore and I leverage that history everytime I get flak.

some kinda jackal
Feb 25, 2003

 
 
I haven’t had “on call” on my JD in years and years but I definitely put in my time this week to help the IR and SecOps teams. My company seems to be pretty good at paying out on-call rates even if you’re not an on-call classed role so I guess log4j is paying for my next trip to Japan or something, thanks Apache.

Diva Cupcake
Aug 15, 2005

:stare: seems bad
https://twitter.com/eastdakota/status/1470767351087964164

DrDork
Dec 29, 2003
commanding officer of the Army of Dorkness

Yeah. That's because it is bad. Like, real bad.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Its not just that its bad, its that its so easy to exploit.

Internet Explorer
Jun 1, 2005





I am very glad I've been off the past few days.

r u ready to WALK
Sep 29, 2001

I wonder if i still have a job to return to after christmas or just a giant blob of encrypted data

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
What's up, still running log4j1 infosecbros :hfive: A few of the products my company makes are more vulnerable, but the ones I specifically support seem to have ducked the worst of it so the past few days my ticket count has doubled but they all consist of sending the same copy/paste email and security bulletin attachments. Some of the techs in other departments are having a rough time tho.

Internet Explorer posted:

Yeah, that's kind of what I was getting at with the whole salaried exempt = no set hours thing. At the very least you should be getting comp time for extra hours worked. Same thing if you somehow get called in during PTO or other days off. Or travel during non-business hours.

On-call rotation is my least favorite part of my job, but it's probably also why I'm non-exempt still and can put in OT and weekend hours whenever. ProTip: work for a company that's headquartered somewhere non-USA, they'll almost always treat their employees better.

CLAM DOWN
Feb 13, 2007




https://twitter.com/Laughing_Mantis/status/1470526083271303172

lol

Mustache Ride
Sep 11, 2001



secfuck thread was talking about that:

Sarah Problem posted:

:getin:
code:
 (?i)\$\{[${}:\p{L}0-9]*?-?[jϳјⅉj𝐣𝑗𝒋𝒿𝓳𝔧𝕛𝖏𝗃𝗷𝘫𝙟𝚓]\}?[${}:\p{L}0-9]*?-?[Nnոռ𝐧𝑛𝒏𝓃𝓷𝔫𝕟𝖓𝗇𝗻𝘯𝙣𝚗\}?
lol Unicode fail https://regex101.com/r/HGaf6k/1

DrDork
Dec 29, 2003
commanding officer of the Army of Dorkness
Yes, if you were expecting your WAF to stop anything above script kiddies here, you are gonna have a very bad day.

On the other hand, the number of attempts I've seen ending in /Exploit, /a, or /TotallyLegitimateJavaClass is amusing.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


*filters requests with "exploit" in them and calls it a day*

Thanks Ants
May 21, 2004

#essereFerrari


Just don't log anything :dadjoke:

Impotence
Nov 8, 2010
Lipstick Apathy
log4j 2.16.0 is out, please update

CLAM DOWN
Feb 13, 2007




Biowarfare posted:

log4j 2.16.0 is out, please update

no

Mr. Crow
May 22, 2008

Snap City mayor for life

Biowarfare posted:

log4j 2.16.0 is out, please update


https://www.youtube.com/watch?v=k8_NmCUXyiU

vanity slug
Jul 20, 2010

vulnerability disclosures will continue until morale improves

Bonzo
Mar 11, 2004

Just like Mama used to make it!

Jeoh posted:

vulnerability disclosures will continue until morale improves

Title

RFC2324
Jun 7, 2012

http 418

Jeoh posted:

Serious Hardware/Software Crap › The Infosec Thread: vulnerability disclosures will continue until morale improves

Internet Explorer
Jun 1, 2005





one day I am going to learn2code so I can edit thread titles from my phone

some kinda jackal
Feb 25, 2003

 
 
I want to scream

It didn’t help

But I think it made me feel a little better

Proteus Jones
Feb 28, 2013



KillHour
Oct 28, 2007


Internet Explorer posted:

one day I am going to learn2code so I can edit thread titles from my phone

Make me a mod so I can test it and I'll make a PR for the awful app with the functionality.

Adbot
ADBOT LOVES YOU

Internet Explorer
Jun 1, 2005





I don't have GRANT MOD ACCESS rights. :(

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply