Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sickening
Jul 16, 2007

Black summer was the best summer.

spankmeister posted:

That's why you should block outbound 445 at the perimeter, not on individual machines.


Business need for your dudebro marketing software rawdogging smb over the internet? Tough luck, get a vpn.

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


You say "oh block SMB at the perimeter" but Azure Files is a thing

https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-azure-active-directory-enable?tabs=azure-portal

You can argue whether people should be using it I guess, but it's a valid use case.

Wibla
Feb 16, 2011

I blocked 445 outbound from my WiFi segment just in case. Don't use outlook on my personal machines anyway.

cr0y
Mar 24, 2005



Internet Explorer posted:

How does blocking at the perimeter work when 90% of your userbase is at home? Some ISPs do, but that's obviously not something you want to rely on. InfoSec isn't my area of speciality, but to me, relying on the perimeter seems old and dated.

User laptops locked to a VPN, if properly managed with policy and certificates and whatnot it's pretty hard to break the machine out of the tunnel.

Internet Explorer
Jun 1, 2005





absolutely not [will I use laptops on VPN]

Thanks Ants
May 21, 2004

#essereFerrari


Full tunnel is great if you want the user experience to be poo poo

Sickening
Jul 16, 2007

Black summer was the best summer.
Its like I am in a time machine and its 2010 all over again.

cr0y
Mar 24, 2005



Thanks Ants posted:

Full tunnel is great if you want the user experience to be poo poo

Oh poo poo we never even considered the user experience.

spankmeister
Jun 15, 2008






Another thing, by NO means is this the first or only way of getting NTLM authentications out of a network. This just happens to be nasty due to it being a really low bar, not requiring user interaction at all, and works on any user with an email address (not 100% sure on this requirement). Other examples include dropping a malicious .lnk file on a network share where the icon points to your evil server, or putting a file:// link in a word document. Stuff like that.

Inside the network this specific outlook vulnerability is way more powerful though because you can relay it against other services (IF they have SMB signing disabled) so for example you can use this bug to get a domain admin to authenticate against you, and if you can relay that to the domain controller, and the admins are dumb enough to have signing disabled.... you can do a DCSync and dump all the NTLM hashes for all the users. And not only that but you have the kerberos keys including the KRBTGT which allows you to forge any ticket for any user for any service. Even if everyone changes their password, you can still impersonate them.

Windows Active Directory is hilariously broken in a lot of ways that can't be fixed. Most or all of these problems have mitigations but it takes one mistake and you have the keys to the kingdom.

Hed
Mar 31, 2004

Fun Shoe

Thanks Ants posted:

You say "oh block SMB at the perimeter" but Azure Files is a thing

https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-azure-active-directory-enable?tabs=azure-portal

You can argue whether people should be using it I guess, but it's a valid use case.

Cool, I'm glad this exists, our Managed IT provider told us last year this didn't really work and it looks like they're still working on it.

Thanks Ants
May 21, 2004

#essereFerrari


You need a few things in place (synced AAD, Kerberos cloud trust) and I am not using it at scale, but it does work.

CLAM DOWN
Feb 13, 2007




the perimeter is dead

BonHair
Apr 28, 2007

CLAM DOWN posted:

the perimeter is dead

Long live the cloud! (The threats are also in the cloud)

AlternateAccount
Apr 25, 2005
FYGM

Sickening posted:

Its something that is easy to say but not easy to actually do. Workstation firewall management can be a lot of loving pain in the rear end poo poo to configure and support. I would say a lot of companies end up with results of being too restrictive and creating too many support tickets, or not being restrictive enough and getting into these situations.

Yeah, I guess there's a reason it's not common.

The firewall is probably not the place to make qualitative determinations of a bit of traffic's threat via dumb attributes like port.

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?

Thanks Ants posted:

Full tunnel is great if you want the user experience to be poo poo

I'm sure this single T1 line out of our data center is fine for our 10,000 employees working from home. Wireguard? That sounds new and is therefore scary. PPTP has been around a long time and I'm sure is fine.

Thanks Ants
May 21, 2004

#essereFerrari


I'm sure there's people using Zscaler or Cloudflare Magic WAN or whatever but for every one company doing that there's probably 10 with an always-on PPTP VPN routing all their traffic through a Windows 2008 server on a cable modem and messing geolocation up for everybody.

SlowBloke
Aug 14, 2017

Thanks Ants posted:

I'm sure there's people using Zscaler or Cloudflare Magic WAN or whatever but for every one company doing that there's probably 10 with an always-on PPTP VPN routing all their traffic through a Windows 2008 server on a cable modem and messing geolocation up for everybody.

2008? Shodan has ISA servers currently active running srv 2003.

https://www.shodan.io/host/181.225.240.230

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Full tunnel is great if you want the user experience to be poo poo

Sickening posted:

Its like I am in a time machine and its 2010 all over again.

My company's terrible remote IT strategy over the last few years is being called out.

Sickening
Jul 16, 2007

Black summer was the best summer.

CLAM DOWN posted:

the perimeter is dead

Its definitely a phrase that when someone says it in a meeting I automatically thing they are a dinosaur or at the very least suspect.

evil_bunnY
Apr 2, 2003

spankmeister posted:

That's why you should block outbound 445 at the perimeter, not on individual machines.
Business need for your dudebro marketing software rawdogging smb over the internet? Tough luck, get a vpn.
I literally don't know of a current/past employer/customer where users could SMB to public IP space, and I've consulted for *janky* places.
The issue with blocking at the perimeter is that it's obviously less effective at preventing pivots.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

CLAM DOWN posted:

the perimeter is dead

LMAO no its not. Even the emphasis on Edge computing doesn't really end edge firewalls.

evil_bunnY posted:

I literally don't know of a current/past employer/customer where users could SMB to public IP space, and I've consulted for *janky* places.
The issue with blocking at the perimeter is that it's obviously less effective at preventing pivots.

Segmentation and carefully auditing of internal firewall rules is critical for stuff like that. SMB is going away in some places, but its still an effective filesharing method and NFS hasn't really replaced it outside pure linux environments.

drunk mutt
Jul 5, 2011

I just think they're neat

Internet Explorer posted:

How does blocking at the perimeter work when 90% of your userbase is at home? Some ISPs do, but that's obviously not something you want to rely on. InfoSec isn't my area of speciality, but to me, relying on the perimeter seems old and dated.

While the user base is "at home" is this number assuming that there is a close representation of people using hardware not provided by the company?

Internet Explorer
Jun 1, 2005





.... no? No.

Why?

Submarine Sandpaper
May 27, 2007


Doesn't a mounted SharePoint site use SMB? Lots of places are ran by the business and will have things like that.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Submarine Sandpaper posted:

Doesn't a mounted SharePoint site use SMB? Lots of places are ran by the business and will have things like that.

Yes but they've added One Drive compatibility.

Submarine Sandpaper
May 27, 2007


If the clients I setup a onedrive sync using .lnk files for offsite backups won't pay for real backups, they won't abide an infrastructure lead block of external SMBs and a change in process, or god forbid, an expense. I'll be curious if a law firm gets hit soon.

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
"This house is protected by Ring Security"


.......well poo poo.

cr0y
Mar 24, 2005



Takes No Damage posted:

"This house is protected by Ring Security"

.......well poo poo.

Who could have ever predicted this

Shumagorath
Jun 6, 2001
ring ring ring
ring ring ring ring
THE RANSOM PHONE

Absurd Alhazred
Mar 27, 2010

by Athanatos
Ring ring ring goes the ransom/
Ding ding ding you've been hacked/
Bling bling bling went your money/
From the moment your system was cracked

Famethrowa
Oct 5, 2012

Takes No Damage posted:

"This house is protected by Ring Security"

.......well poo poo.

lol great.

have you seen my baby
Nov 22, 2009

Shumagorath posted:

ring ring ring
ring ring ring ring
THE RANSOM PHONE

ding dong ding dong
ding dong ding
THE RANSOM HOOME

cr0y
Mar 24, 2005



Perimeters are dead
Rings are dead
When will the war on circles end

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
Somewhere in a lonely basement room
There's a guy starting to realize
That eternal fate has turned its back on him
It's two A.M

It's two A.M., the password's gone
(It's two A.M., the password's gone)
I'm sitting here waitin', the camera's warm
(I'm sitting here waitin', the camera's warm)
Maybe my connection is tired of takin' chances

Yeah, there's a storm on the loose, sirens in my head
Wrapped up in ransom, all circuits are dead
Cannot decode, my whole life spins into a frenzy

Help, I'm steppin' into the IoT Zone
Place is a madhouse, data's being cloned
My bacon's been moved under moon and star
Where am I to go now that I've gone too far?

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY
loving good, ring is gross

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Kesper North posted:

loving good, ring is gross

Get your partner to wash it and it tastes fine?

cr0y
Mar 24, 2005



To the tune of ring of fire by Johny cash



I hear the doorbell ringing, it's late at night
I check my Ring app to see what's in sight
But something's wrong, it's not what it seems
My Ring's been hacked, it's like a bad dream


It's the hack of the Ring, the hack of the Ring
My smart doorbell's been compromised, it's a terrible thing
The breach of my privacy, the danger it brings
Oh, no, it's the hack of the Ring


I thought I was safe, with my high-tech device
But hackers, they found a way to break in, so precise
My heart starts racing, my face turning white
As my Ring of fire turns into a Ring of fright


It's the hack of the Ring, the hack of the Ring
My smart doorbell's been compromised, it's a terrible thing
The breach of my privacy, the danger it brings
Oh, no, it's the hack of the Ring


In this digital age, we're surrounded by screens
But with every new gadget, there's a risk unforeseen
So be cautious and careful, protect what you hold dear
Or the hack of the Ring may bring you to tears


It's the hack of the Ring, the hack of the Ring
My smart doorbell's been compromised, it's a terrible thing
The breach of my privacy, the danger it brings
Oh, no, it's the hack of the Ring

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


I fell into a burning Ring fire
They went down, down, down, and the flames went higher
And it burns, burns, burns, Ring garbage fire, Ring garbage fire

vanity slug
Jul 20, 2010

Takes No Damage posted:

Somewhere in a lonely basement room
There's a guy starting to realize
That eternal fate has turned its back on him
It's two A.M

It's two A.M., the password's gone
(It's two A.M., the password's gone)
I'm sitting here waitin', the camera's warm
(I'm sitting here waitin', the camera's warm)
Maybe my connection is tired of takin' chances

Yeah, there's a storm on the loose, sirens in my head
Wrapped up in ransom, all circuits are dead
Cannot decode, my whole life spins into a frenzy

Help, I'm steppin' into the IoT Zone
Place is a madhouse, data's being cloned
My bacon's been moved under moon and star
Where am I to go now that I've gone too far?

hell yeah

Adbot
ADBOT LOVES YOU

adnam
Aug 28, 2006

Christmas Whale fully subsidized by ThatsMyBoye

Klyith posted:

1Password if you can afford $3 per month and want to be done with this poo poo forever.

Bitwarden if you want something free.

Keepass if you are a huge nerd and want to janitor your own software.

Apple keychain if you are fully inside the apple ecosystem and don't need compatibility.

Dumb question - but I came across this post from somewhere in business, finance etc given Lastpass's incredible idiocy these last few years. I've migrated over to 1password but I saw digital cruft mentioned here. How can I go about closing accounts that I no longer use, or is it just a whack-a-mole of emailing websites to close my account, or stop using accounts at service x, y, z and pray they eventually rot away?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply