Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Dare I invoke the spectre of log4j?

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


it's going to be really funny if that exploit works in imagemagick and the entire internet needs patching but doesn't

The Fool
Oct 16, 2003


BlankSystemDaemon posted:

So, every browser and Electron app?

"Yay"

does it affect firefox?

Fart Amplifier
Apr 12, 2003

The Fool posted:

does it affect firefox?

Yes, but as long as you're up to date, you're good.

Annoyingly, it seems that Microsoft Defender for Endpoint vulnerability management is not accurate and flags Chrome version 116.0.5845.117 and 116.0.5845.118 are vulnerable to CVE-2023-4863, and also Firefox version 117.0.1.0 as well, even though these versions have the vulnerability patched.

BlankSystemDaemon
Mar 13, 2009



Fart Amplifier posted:

Yes, but as long as you're up to date, you're good.
Yes, electron apps - well-known for always being kept up-to-date, and certainly never using ages-old vendored version-locked libraries.

Kibner
Oct 21, 2008

Acguy Supremacy

BlankSystemDaemon posted:

Yes, electron apps - well-known for always being kept up-to-date, and certainly never using ages-old vendored version-locked libraries.

Case in point, my Teams that was updated earlier today:

some kinda jackal
Feb 25, 2003

 
 
It took me like five minutes clicking around the Teams interface to even find the “check for updates” function. What a dumpster fire.

Kazinsal
Dec 13, 2011


geonetix posted:

it's going to be really funny if that exploit works in imagemagick and the entire internet needs patching but doesn't

Quick scan of the imagemagick dependencies lists libwebp as optional but required for operations on webp files.

So chances are it's compiled in by default lmao

BlankSystemDaemon
Mar 13, 2009



Kibner posted:

Case in point, my Teams that was updated earlier today:


Yea, that's the good stuff.

Also, it's a webp. :v:

Kibner
Oct 21, 2008

Acguy Supremacy
:devil:

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Guy training me wants me to help him train 30k users on using a password manager. I'm not sure that's gonna happen.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Cannon_Fodder posted:

Guy training me wants me to help him train 30k users on using a password manager. I'm not sure that's gonna happen.

Assign training in LMS, send reminder emails weekly, call it good by end of quarter. So what if the helpdesk call volume triples? You're not on helpdesk anymore!

Raymond T. Racing
Jun 11, 2019

Cannon_Fodder posted:

Guy training me wants me to help him train 30k users on using a password manager. I'm not sure that's gonna happen.

if you're getting a 30k quote from a password manager then onboarding should be included i hope

Sickening
Jul 16, 2007

Black summer was the best summer.
I dare someone to train 30k users to do anything, much less use any technology.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


I could train them to ignore my emails

some kinda jackal
Feb 25, 2003

 
 
I just set aside a day to complete all my mandated compliance training a few weeks ago. Six hours of every department producing cobbled together information from powerpoints and PDFs, read in an unskippable monotonous voiced video that pauses when you change browser window focus. Some modules went in trying to make it "fun" and "engaging" by throwing in 1999-era-quality flash "games".

By the third assigned course I was jokingly wishing there was some kind of incident call I'd be asked to join to pull me away.

By the eighth assigned course I was not so jokingly wishing we'd just go out of business.

BonHair
Apr 28, 2007

Hearts and minds: destroyed!

That is why you need communications people if you want to do wide scale training. If you can't make people care, you're better off not wasting their time.

cr0y
Mar 24, 2005



https://twitter.com/BleepinComputer/status/1707120191212048613?t=TCBXV3r4oEH5lCUSHdSTRw&s=19

Thanks Ants
May 21, 2004

#essereFerrari


sickos dot jpeg

Potato Salad
Oct 23, 2014

nobody cares



this one weird trick dramatically improves the security posture of enterprises all across the United States simultaneously

BaseballPCHiker
Jan 16, 2006

Crowdstrikes detection for this CVE is off for my team as well so far. Lots of false positives for hosts that have already updated to the latest and greatest version of Chrome/FireFox/Edge. Got a support ticket in with them, will see what comes of it.

cr0y
Mar 24, 2005



I just had an OT engineer shocked, SHOCKED that we run CrowdStrike on our industrial control servers. He had an unrelated issue, and is now making enough noise that we should:

Disable windows firewalls
Disable all automatic updates
Remove AV
If AV can't be removed, disable ALL automatic definition updates.

On our fleet of um.... a lot of servers.

Defenestrategy
Oct 24, 2010

cr0y posted:

I just had an OT engineer shocked, SHOCKED that we run CrowdStrike on our industrial control servers. He had an unrelated issue, and is now making enough noise that we should:

Disable windows firewalls
Disable all automatic updates
Remove AV
If AV can't be removed, disable ALL automatic definition updates.

On our fleet of um.... a lot of servers.

Lol and further lmao.

evil_bunnY
Apr 2, 2003

that kinda poo poo should be a firable offense TBH

BaseballPCHiker
Jan 16, 2006

cr0y posted:

I just had an OT engineer shocked, SHOCKED that we run CrowdStrike on our industrial control servers. He had an unrelated issue, and is now making enough noise that we should:

Disable windows firewalls
Disable all automatic updates
Remove AV
If AV can't be removed, disable ALL automatic definition updates.

On our fleet of um.... a lot of servers.

We must work for the same company.

I got asked this week to place approximately 500 hosts in a bypass mode because occasionally they see sustained CPU spikes on these hosts and they think its Crowdstrike. They think this because they've ran no perfmons, or done any digging into their logs whatsoever but it has to be CrowdStrike. Nevermind they are wildly under provisioned and running an application written in the 90s for on prem networks that cant handle latency at all that theyve shucked into AWS.

God drat this week.

stoopidmunkey
May 21, 2005

yep

They just bought out the company I currently work for. Not sure if it’s time to start looking again.

BaseballPCHiker
Jan 16, 2006

Having done a lot of SCADA/HVAC work in the past I'm honestly surprised things like this dont happen more often. I've been out of that space for a few years now, but it seemed like those industries lagged behind the rest of the tech space by a decade.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Cannon_Fodder posted:

Guy training me wants me to help him train 30k users on using a password manager. I'm not sure that's gonna happen.

My wife has been part of training 15,000 people to use a healthcare patient data system (it’s the one you’re thinking of) and their approach is probably the best one: train a bunch of meta-meta-meta-trainers, then have them train other trainers, (etc) then have them train people. They only had 2 layers because the software is quite complex so it takes weeks to learn well enough to teach, but for a password manager you could probably make every manager and director volunteer someone as a “local expert” to learn the software with the aid of some videos/docs and support them with an escalation path for cases that are really weird.

If you use an open-source password manager, you could add an interactive tutorial to it!

Darchangel
Feb 12, 2009

Tell him about the blower!


some kinda jackal posted:

I just set aside a day to complete all my mandated compliance training a few weeks ago. Six hours of every department producing cobbled together information from powerpoints and PDFs, read in an unskippable monotonous voiced video that pauses when you change browser window focus. Some modules went in trying to make it "fun" and "engaging" by throwing in 1999-era-quality flash "games".

That bolded poo poo right there.
gently caress the jackholes that did that.

Jokes on you bitch - I'm the IT guy. I have like 8 machines...

Sickening
Jul 16, 2007

Black summer was the best summer.
I had a "distinguished engineer" private message me in slack about how requesting privileged access doesn't make sense for developers. When asked to elaborate on what they mean they apparently been lost to the ether.

Mustache Ride
Sep 11, 2001



What the gently caress is a distinguished engineer? An engineer that failed upward too many times?

Thanks Ants
May 21, 2004

#essereFerrari


stoopidmunkey posted:

They just bought out the company I currently work for. Not sure if it’s time to start looking again.

You might get a few weeks paid to do nothing while everything is offline, so don't leave yet

Diva Cupcake
Aug 15, 2005

Mustache Ride posted:

What the gently caress is a distinguished engineer? An engineer that failed upward too many times?
Pretty much. Someone the business can't trust with actual direct reports but they still needed another title for like director level individual contributors.

The Fool
Oct 16, 2003


Diva Cupcake posted:

Pretty much. Someone the business can't trust with actual direct reports but they still needed another title for like director level individual contributors.

also known as a career goal

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Mustache Ride posted:

What the gently caress is a distinguished engineer? An engineer that failed upward too many times?

It’s basically the IC track equivalent of VP. Usually the same signing limit, in the same strategy meetings, repping the engineering rather than organizational aspects.

I’m a distinguished engineer because I was a VP they wanted to hire but didn’t have an org for me to run. I stayed pretty technical through my career, so it’s working out pretty well.

Diva Cupcake
Aug 15, 2005

The Fool posted:

also known as a career goal

Absolutely. It's a dope gig. Almost all of the money with like 20% of the stress and responsibility.

Remulak
Jun 8, 2001
I can't count to four.
Yams Fan
My daughter was phished over text for iTunes money at 4:30 on her first day, allegedly by her boss who was in a meeting and unavailable at they time. They knew his name too.

She called me to double-check that it was fraud before finding some other company authority.

Sickening
Jul 16, 2007

Black summer was the best summer.

Remulak posted:

My daughter was phished over text for iTunes money at 4:30 on her first day, allegedly by her boss who was in a meeting and unavailable at they time. They knew his name too.

She called me to double-check that it was fraud before finding some other company authority.

Check if their company subscribes to zoom info.

some kinda jackal
Feb 25, 2003

 
 

cr0y posted:

I just had an OT engineer shocked, SHOCKED that we run CrowdStrike on our industrial control servers. He had an unrelated issue, and is now making enough noise that we should:

Disable windows firewalls
Disable all automatic updates
Remove AV
If AV can't be removed, disable ALL automatic definition updates.

On our fleet of um.... a lot of servers.

If this is part of an active incident with operational impact then help triage and trouibleshoot and disable with proper incident management approval. If he's just making noise then feed him a security policy exception form to get signed off by the CIO or whoever. Let them explain why they don't need to follow policy.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Diva Cupcake posted:

Pretty much. Someone the business can't trust with actual direct reports but they still needed another title for like director level individual contributors.

Usually principal=director, distinguished=VP, I think.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply