Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sickening
Jul 16, 2007

Black summer was the best summer.
I want a something like that except in the form of a hammer, that I would throw at anyone talking about "the perimeter" as if it has really any meaning anymore.

Adbot
ADBOT LOVES YOU

The Fool
Oct 16, 2003


when I worked uni lab support/helpdesk in the early 2000's, in peak slashdot cringe, we had a short handled sledgehammer labeled LART

Luser Attitude Readjustment Tool for those that are not old enough

Achmed Jones
Oct 16, 2004




oh poo poo it's 1999 on alt.2600 and valuhack is all the rage

some kinda jackal
Feb 25, 2003

 
 
You could put a gun to my head and the only thing I'd tell you about CISSP is that I think there was something about how high a fence is supposed to be oh my god don't shoot me I'm beggin' ya

I thought it was fairly worthless from a practical perspective, but I didn't have to shell out for it AND it was a career payday so you won't hear me complaining.

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.

some kinda jackal posted:

You could put a gun to my head and the only thing I'd tell you about CISSP is that I think there was something about how high a fence is supposed to be oh my god don't shoot me I'm beggin' ya

Same except fire extinguishers instead of fences.

MustardFacial
Jun 20, 2011
George Russel's
Official Something Awful Account
Lifelong Tory Voter

Nuclearmonkee posted:

Extremely this. Just like in any part of IT or any job really, there are a lot of people going through the motions and the minority of them will be those individuals you are comparing yourself to in your head.


some kinda jackal posted:

Every day I'm amazed I've managed to trick people into believing I have a marketable skill, going on a decade plus now. Welcome to the gang.


Internet Explorer posted:

Congrats! And also, you'll be fine. Deep breaths. After a few weeks you'll be wondering why everyone you work with is so bad at their job. :-D

Thanks for trying to put me at ease and also for the welcomes. Ultimately, while I realize that I just have to take it slowly, one challenge at a time it's still going to be a big mountain to climb. I'll probably be posting in this thread a hell of a lot more to ask for advice lol.


Sickening posted:

The CISSP is an anomaly among certifications. It isn't technically challenging at all but holds more water than it should because its price and adoption. Sans stuff pricing is also extreme but seems less embarrassing from a difficulty perspective.

From what I've heard, the CISSP is more of a management cert than it is for any real technical skills. I was going to try to get it a couple years ago, but the requirement for industry experience plus you need to know another CISSP to sign off on your work stopped that.

CLAM DOWN posted:

I'm extraordinarily proud of my SANS challenge coin, not just because I got 1st place in the CTF but because it's blade runner themed which rules



:swoon: That is so loving cool.

Thanks Ants
May 21, 2004

#essereFerrari


Sickening posted:

I want a something like that except in the form of a hammer, that I would throw at anyone talking about "the perimeter" as if it has really any meaning anymore.

Do you mean you don't want to buy a Next-Generation Firewall with Intrusion Prevention? Let me see if I can interest you in these Gartner reports!

Sickening
Jul 16, 2007

Black summer was the best summer.

Thanks Ants posted:

Do you mean you don't want to buy a Next-Generation Firewall with Intrusion Prevention? Let me see if I can interest you in these Gartner reports!

I sat in a long meeting with sre’s today where we talked about basic network segregation. I might as well have been talking about nuances of the elvish language. I am done with human beings for then rest of the week.

Sickening fucked around with this message at 01:40 on Aug 16, 2023

Diva Cupcake
Aug 15, 2005

MustardFacial posted:

From what I've heard, the CISSP is more of a management cert than it is for any real technical skills. I was going to try to get it a couple years ago, but the requirement for industry experience plus you need to know another CISSP to sign off on your work stopped that.
It doesn’t really teach you manage either. Unless you mean it’s mostly a high level overview of security concepts with a heavy risk management focus. Also do they even check the industry experience thing? Do any AD administration? IAM experience. Patching? Asset security. That should be easy to attest to.

CISSP is an A+ for career value though whereas just about every other cert out there, except maybe the operational cloud architecture track stuff, is probably a C or D so if you have the means I highly recommend.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Thanks Ants posted:

Do you mean you don't want to buy a Next-Generation Firewall with Intrusion Prevention? Let me see if I can interest you in these Gartner reports!

Stick it in your magic quadrant.

Guy Axlerod
Dec 29, 2008
Go best of breed yourself

Head Bee Guy
Jun 12, 2011

Retarded for Busting
Grimey Drawer
Do you guys like your jobs?

Achmed Jones
Oct 16, 2004



all jobs sucks but my job sucks way less than most

post hole digger
Mar 21, 2011

It could be worse, and indeed, has been.

Wibla
Feb 16, 2011

Head Bee Guy posted:

Do you guys like your jobs?

Most days of the week.

Not the days of the week I have to be in meetings to deal with Azure Stack HCI though.

Seems pretty hollow to implement full network micro-segmentation and spending stupid amounts of money on Palo Alto firewalls, only to have IT move our SCADA VM stack from VMware to Azure Stack HCI ... that requires all VMs to talk to the loving cloud :negative:

Famethrowa
Oct 5, 2012

Head Bee Guy posted:

Do you guys like your jobs?

not digging grc right now.

third party risk makes me want to die.

e. but, the love of the field and all that it offers so far makes it feel worth it

Famethrowa fucked around with this message at 06:19 on Aug 16, 2023

spankmeister
Jun 15, 2008






Wibla posted:

Most days of the week.

Not the days of the week I have to be in meetings to deal with Azure Stack HCI though.

Seems pretty hollow to implement full network micro-segmentation and spending stupid amounts of money on Palo Alto firewalls, only to have IT move our SCADA VM stack from VMware to Azure Stack HCI ... that requires all VMs to talk to the loving cloud :negative:

Putting your OT in Azure seems like a risky move. What if Azure goes down? Entire regions and indeed entire cloud providers have been known to go down from time to time. Does HCI keep working in such an occurrence or does it break along with everything else?

Wibla
Feb 16, 2011

They say it keeps working, but we obviously lose all the fancy functionality.

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"

spankmeister posted:

Putting your OT in Azure seems like a risky move. What if Azure goes down? Entire regions and indeed entire cloud providers have been known to go down from time to time. Does HCI keep working in such an occurrence or does it break along with everything else?

Stack has nothing to do with Azure regions being available afaik. I’ve been doing azure consulting for… I dunno a decade or something but I’ve never actually implemented it so I could be wrong. That would be counter to the entire premise of using it. It’s dumb for a billion other reasons though

evobatman
Jul 30, 2006

it means nothing, but says everything!
Pillbug

MustardFacial posted:

I applied for Cybersec Analyst position and got it (been a sysadmin for years and always security-first, but never actually done an infosec job). I was hyped for it from the beginning but then when my future manager called me to tell me that I got it and what to expect he mentioned that I'd be enrolled in a couple SANS courses, some SEIM training, I'd have to get my CISSP at some point, what my colleagues specialize in and mentioned that one of them has a SANS Challenge Coin.

Since then imposter syndrome has hit hard and now I'm wondering if I am even capable of doing this to their level. I'm 2 years younger than the manager and at least 5 years older than everyone else on my team. I haven't even started and I'm already feeling behind an unable to catch up. There is so much stuff I don't know how to do, and even more that I only have a general understanding of.

I work with hundreds if not thousands of infosec people, and none of them know poo poo about computers. If I want a 72 page Powerpoint about why having your firewall turned on is a good thing according to the latest security framework they learned about a conference they are great. If I ask them if the firewall is actually turned on, they look at me like they are a goldfish and I'm asking them to explain how an automatic transmission works.

Diva Cupcake
Aug 15, 2005

There are a lot of jobs in security, especially if you work at a large org. Not all are computer toucher roles, although they're mainly staffed by ex-computer touchers.

Governance teams create and own the security policy.
Architecture teams own the design to the policy/best practices. Create lots of data flow diagrams and PowerPoints.
Engineering teams own the implementation to the design.

Wibla
Feb 16, 2011

i am a moron posted:

Stack has nothing to do with Azure regions being available afaik. I’ve been doing azure consulting for… I dunno a decade or something but I’ve never actually implemented it so I could be wrong. That would be counter to the entire premise of using it. It’s dumb for a billion other reasons though

Stack will run up to 30 days offline, yeah.

It's still really dumb.

BonHair
Apr 28, 2007

Diva Cupcake posted:

There are a lot of jobs in security, especially if you work at a large org. Not all are computer toucher roles, although they're mainly staffed by ex-computer touchers.

Governance teams create and own the security policy.
Architecture teams own the design to the policy/best practices. Create lots of data flow diagrams and PowerPoints.
Engineering teams own the implementation to the design.

This is very true, at least on paper. In reality though, ownership doesn't really happen in a lot of places.

Also there's the compliance department staffed by legal guys who aggressively don't understand computers, balanced approaches and shades of grey. And they will still require a yes/no answer to whether the network is segmented.

Wizard of the Deep
Sep 25, 2005

Another productive workday

BonHair posted:

This is very true, at least on paper. In reality though, ownership doesn't really happen in a lot of places.

Also there's the compliance department staffed by legal guys who aggressively don't understand computers, balanced approaches and shades of grey. And they will still require a yes/no answer to whether the network is segmented.

Lawyer: "Is the network segmented?"
You: "Unequivocable Yes."
Your thoughts: "There's an inside segment and an outside segment."

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer

evobatman posted:

they look at me like they are a goldfish and I'm asking them to explain how an automatic transmission works.

My go-to phrasing of this is 'they look at me like a dog that's just been shown a card trick.'

AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf
Sorry if this is the wrong place but I'm desperate

How should I go about reinstalling windows as SAFELY as possible?

Pretty sure I have a nasty rootkit, check this out

https://imgur.com/a/b2tQTFi

I'm running Windows 11 pro with an Asus Z690-a mobo and a 13600k with the latest ME

Secure boot, DEP enabled, no VT-d, no hypervisor enabled, ASUS Armory crate disabled in bios, all the windows security is enabled

I even ran ShredOS on a M.2 before installing Windows

Legit thinking about getting an external DVD reader for installation

I had TONS of weird entries in drivers/etc

https://imgur.com/a/1e4IoUD

Any help would be amazing

Achmed Jones
Oct 16, 2004



what makes you think you have a root kit? please describe the issue(s) you're seeing in prose - do not assume it's obvious from a picture (especially one that doesn't show what command was run to produce the output)

Internet Explorer
Jun 1, 2005





Please start a new thread in Haus of Tech Support. Since you're already here and talking about it, you can link it here any if folks are interested they can go over and help. A good first step in that thread would be answering the question above.

But please don't turn this into a troubleshooting thread. These poor infosec folks have been abused enough.

Wibla
Feb 16, 2011

Internet Explorer posted:

But please don't turn this into a troubleshooting thread. These poor infosec folks have been abused enough.

Thank you :glomp:

I got a mail from a consultant on the way home from work today, they want all the things opened to the internet from one of our SCADA zones because of Azure bullshit. Of course it has to happen yesterday. I want to strangle someone.

A stiff drink feels very tempting at this point.

AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf
Sorry guys, it's probably paranoia combined with me messing around with my settings too much.

I have remote+physical backups and bitlocker so I'm just gonna see this as an opportunity to CBT train my brain.

Thanks

Saukkis
May 16, 2003

Unless I'm on the inside curve pointing straight at oncoming traffic the high beams stay on and I laugh at your puny protest flashes.
I am Most Important Man. Most Important Man in the World.

AEMINAL posted:

I had TONS of weird entries in drivers/etc

https://imgur.com/a/1e4IoUD

Any help would be amazing

That services-file you are looking at is just a listing of standard names for different port numbers. Every Unixy computer has the same listing and it doesn't do anything.

AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf

Saukkis posted:

That services-file you are looking at is just a listing of standard names for different port numbers. Every Unixy computer has the same listing and it doesn't do anything.

Haha of course that's what it is lmao

How do you guys stay sane? A friend of mine told me infosec is THE most stressful job out there

Wibla
Feb 16, 2011

I have a well stocked liquor cabinet ... that I have to refill regularly.

spankmeister
Jun 15, 2008






AEMINAL posted:

Haha of course that's what it is lmao

How do you guys stay sane? A friend of mine told me infosec is THE most stressful job out there

Lots of alcohol and/or weed.

Sickening
Jul 16, 2007

Black summer was the best summer.
Apparently HR reached out to me today because another employee cursed my name so many times in the previous days that they set off teams communication policies that sent alerts to HR. They tripped the "physical violence" filters. My sin? Created azure security policies (now called initiatives) that created guardrails like "can't create a public accessible storage account in x subscriptions". I was also shocked to find that the storage account they wanted to create as public was because networking is too hard and not because it was actually required. Sucks to suck I guess.

I also sat in an executive security leadership meeting where I was told the company needs to create a culture of security. Nobody could define what that meant, but everyone agreed we needed it. There was also mixed signals about wanting security training to be a happy thing while also punishing people who fail phishing simulations, so lets just say execs are still dumb sociopaths who don't understand human emotions.

Thanks Ants
May 21, 2004

#essereFerrari


Oh wow is that a feature that flags when someone is on the brink of going postal? I never knew that was a thing.

SlowBloke
Aug 14, 2017

Thanks Ants posted:

Oh wow is that a feature that flags when someone is on the brink of going postal? I never knew that was a thing.

https://learn.microsoft.com/en-us/purview/communication-compliance

And as all most interesting features in 365, it only works properly in English.

Zorak of Michigan
Jun 10, 2006


Sickening posted:

Apparently HR reached out to me today because another employee cursed my name so many times in the previous days that they set off teams communication policies that sent alerts to HR.

I am not sure I have ever been this jealous of a fellow IT professional.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Sickening posted:

Apparently HR reached out to me today because another employee cursed my name so many times in the previous days that they set off teams communication policies that sent alerts to HR. They tripped the "physical violence" filters. My sin? Created azure security policies (now called initiatives) that created guardrails like "can't create a public accessible storage account in x subscriptions". I was also shocked to find that the storage account they wanted to create as public was because networking is too hard and not because it was actually required. Sucks to suck I guess.

Oh my God, I cannot imagine how many curses are aligned to my name if this is true.

It took till 3 months ago for them to actually implement the basic guardrails I asked for aligned to Google and Azures own security best practices because it "Created too many gates" even after we had multiple public facing buckets get created, and them popped.

Adbot
ADBOT LOVES YOU

Sickening
Jul 16, 2007

Black summer was the best summer.

CommieGIR posted:

Oh my God, I cannot imagine how many curses are aligned to my name if this is true.

It took till 3 months ago for them to actually implement the basic guardrails I asked for aligned to Google and Azures own security best practices because it "Created too many gates" even after we had multiple public facing buckets get created, and them popped.

I like the trade of...

Can't make use infrastructure settings associates with stupid decisions -> go through exemption process

vs

Let people do whatever they want -> clean up mess afterwards


GCP's guardrails are maybe the worst designed in all of the public clouds, but that is part for anything GCP.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply