Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
outhole surfer
Mar 18, 2003

laziness and ineptitude, mostly

i spent $3k on a work thinkpad after we got funded then promptly left it in a rental car less than a week later, never to be seen again

i have a new m2 macbook that i pulled from the supply shelf a month or so ago, but still haven't gotten around to setting it up because asahi doesn't run on it yet and i don't like osx

now i have a framework 16 on preorder that i'm probably going to expense, but it doesn't ship til january

Adbot
ADBOT LOVES YOU

univbee
Jun 3, 2004




of course, my first time touching windows server in like a decade and i became the secfuck

was setting up software for collecting electronic exams submitted by students. said software if you connect to its port from a browser, gives you a page that, among other things, reveals the windows server version (including patch level) to the entire internet

that software approval got yanked right quick

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.
lol that's how we found out one of our vendors was using an OS that was 15 years out of support for an app they were providing. found from a simple bug that you could do to make it throw a DB exception.

we dropped them shortly after. tip of the iceberg.

univbee
Jun 3, 2004




FungiCap posted:

lol that's how we found out one of our vendors was using an OS that was 15 years out of support for an app they were providing. found from a simple bug that you could do to make it throw a DB exception.

we dropped them shortly after. tip of the iceberg.

wait, 15 years out of support, so like if a vendor was running windows 2000 today? :stare:

Pile Of Garbage
May 28, 2007



so VBScript is being deprecated in Windows 10 and 11. they're relegating it to an optional feature on demand and then at some point in the future they'll remove it altogether: https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features-resources#vbscript. imo it's a welcome change which won't really do much security-wise as powershell is the preffered vector these days but at least it will stop grognard sysadmins from writing and deploying new vbs scripts in TYOOL 2023 (yes these psychos exist, complete sickos).

Wiggly Wayne DDS
Sep 11, 2010



Pile Of Garbage posted:

so VBScript is being deprecated in Windows 10 and 11. they're relegating it to an optional feature on demand and then at some point in the future they'll remove it altogether: https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features-resources#vbscript. imo it's a welcome change which won't really do much security-wise as powershell is the preffered vector these days but at least it will stop grognard sysadmins from writing and deploying new vbs scripts in TYOOL 2023 (yes these psychos exist, complete sickos).
should have depreciated powershell as well while they had the chance...

Pile Of Garbage
May 28, 2007



mlmp

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
vbs powers MDT and thus SCCM. Very curious what they'll do with it.

(lol)

shackleford
Sep 4, 2006

Pile Of Garbage posted:

so VBScript is being deprecated in Windows 10 and 11. they're relegating it to an optional feature on demand and then at some point in the future they'll remove it altogether: https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features-resources#vbscript. imo it's a welcome change which won't really do much security-wise as powershell is the preffered vector these days but at least it will stop grognard sysadmins from writing and deploying new vbs scripts in TYOOL 2023 (yes these psychos exist, complete sickos).

"before being retired in future Windows releases"

so those grognards will be able to continue deploying VBS scripts on a supported windows version well into the future but it'll have to be on (checks notes) Windows 10 IoT Enterprise LTSC 2021 (lol) which has extended support until TYOOL 2032

https://learn.microsoft.com/en-us/lifecycle/products/windows-10-iot-enterprise-ltsc-2021

mystes
May 31, 2006

shackleford posted:

"before being retired in future Windows releases"

so those grognards will be able to continue deploying VBS scripts on a supported windows version well into the future but it'll have to be on (checks notes) Windows 10 IoT Enterprise LTSC 2021 (lol) which has extended support until TYOOL 2032

https://learn.microsoft.com/en-us/lifecycle/products/windows-10-iot-enterprise-ltsc-2021
Where are you getting that information about what specific versions it will be supported in?

some kinda jackal
Feb 25, 2003

 
 
We”ll all freeze in a nuclear winter way before vbs perishes

Shame Boy
Mar 2, 2010

imagine running windows on an iot device

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"

Shame Boy posted:

imagine running windows on an iot device

some kinda jackal
Feb 25, 2003

 
 

Shame Boy posted:

imagine running windows on an iot device

Lots of people run windows on idiot devices

You spelled idiot wrong btw

Shaggar
Apr 26, 2006

Shame Boy posted:

imagine running windows on an iot device

yeah it sounds pretty nice

shackleford
Sep 4, 2006

mystes posted:

Where are you getting that information about what specific versions it will be supported in?

just guessing based on

https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features posted:

VBScript is being deprecated. In future releases of Windows, VBScript will be available as a feature on demand before its removal from the operating system.

and

https://learn.microsoft.com/en-us/windows/iot/iot-enterprise/whats-new/windows-iot-enterprise-ltsc posted:

Windows IoT Enterprise LTSC is designed for specialty devices and use cases where functionality and features remain constant for the life of the device. These devices are typically found in industries including, but not limited to, banking, healthcare, hospitality, manufacturing and retail. Devices that require regulatory certification and devices that perform a critical business function can't accept feature updates for years at a time.

We designed Windows IoT Enterprise LTSC with these use cases in mind. We support each Windows IoT Enterprise LTSC release for 10 years, and that features and functionality don't change over the course of that 10-year lifecycle.

Windows IoT Enterprise LTSC releases approximately every three years, and each release contains all the new capabilities and support included in Windows feature updates that have been released since the previous LTSC release. LTSC releases are named with a specific year, such as Windows 10 IoT Enterprise LTSC 2021.

Windows IoT Enterprise LTSC releases receive 10 years of servicing and support. Upgrading from one version of Windows IoT Enterprise LTSC to the next version requires a new license.

"Windows 10 IoT Enterprise LTSC 2019" is a release of windows

"Windows 10 IoT Enterprise LTSC 2021" is a release of windows

hypothetically "Windows 10 IoT Enterprise LTSC 2025" could make VBScript optional and "Windows 10 IoT Enterprise LTSC 2029" could remove it entirely. but "Windows 10 IoT Enterprise LTSC 2021" would still be supported until 2032

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
cue the vulnerability

justcallhimdragon
Aug 23, 2023

file indexers ftw

please run around my user storage and read various structured and unstructured data, what can possibly go wrong

Wiggly Wayne DDS
Sep 11, 2010



justcallhimdragon posted:

file indexers ftw

please run around my user storage and read various structured and unstructured data, what can possibly go wrong
it's always annoyed me how you can never truly disable many of these index functions...

sb hermit
Dec 13, 2016





tracker miner always runs at the worst possible moment

it’s like having an antivirus… just random rear end slowdowns and jankiness at either random parts of the day or very soon after you login that lasts for fifteen minutes to an hour

no wonder people like the cloud so much because something else is hogging the disk bandwidth

Cybernetic Vermin
Apr 18, 2005

i mean, it was unavoidable writing this text mangling task in c, some audio cd's have like 30 tracks, got to get that performance up there to make it through that in reasonable time.

sb hermit
Dec 13, 2016





the only surefire way I’ve found to disable tracker miner is to symlink the cache directories to /dev/null

pseudorandom name
May 6, 2007

libcue is like 30 years old, of course it was written in C

justcallhimdragon
Aug 23, 2023

Wiggly Wayne DDS posted:

it's always annoyed me how you can never truly disable many of these index functions...

looking for sane secure defaults, thanks *tips hat*

justcallhimdragon
Aug 23, 2023

Even better are DLP products that shant be named relying on Windows Search to do all the heavy lifting. Fun to bypass DLP on accident by removing the user folder from Indexing Service in Control Panel, which didn't require admin.

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
Windows start menu search, where a program will only appear if you type in exactly 4 letters of its name, but not if you type 5.

I still have no idea what the gently caress the people at MS are smoking. How do you gently caress up a simple substring search that badly?

Armitag3
Mar 15, 2020

Forget it Jake, it's cybertown.


if you type more than 5 characters clearly you’re making an internet search which we will helpfully facilitate with bing.com - product goblin at m$, presumably

flakeloaf
Feb 26, 2003

Still better than android clock

unless you end that search with a dot and three letters, in which case you aren't searching for a program called dogballs.exe, but instead you want the website dogballs in the .exe tld, which I will now look up for you

flakeloaf
Feb 26, 2003

Still better than android clock

do I want the command line interpreter or do i want to hang a picture on my wall

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

flakeloaf posted:

do I want the command line interpreter or do i want to hang a picture on my wall

you want the dogballs

Armitag3
Mar 15, 2020

Forget it Jake, it's cybertown.


Captain Foo posted:

you want the dogballs

:dogtits:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

flakeloaf posted:

do I want the command line interpreter or do i want to hang a picture on my wall

Por que no los dos?

sb hermit
Dec 13, 2016





flakeloaf posted:

do I want the command line interpreter or do i want to hang a picture on my wall

por


Volmarias posted:

Por que no los dos?

:argh:

Quackles
Aug 11, 2018

Pixels of Light.


Armitag3 posted:

if you type more than 5 characters clearly you’re making an internet search which we will helpfully facilitate with bing.com - product goblin at m$, presumably

Bung Search STRIKES again!

Shame Boy
Mar 2, 2010

don't get bingled

mystes
May 31, 2006

Shame Boy posted:

don't get bingled
I think that's when the no fly list gets leaked

Clyde Radcliffe
Oct 19, 2014

univbee posted:

wait, 15 years out of support, so like if a vendor was running windows 2000 today? :stare:

One of our Fortune 500 clients has a bunch of identical pension management sites for employees of other big companies to log in to, to view their pension information. Once a year they sign up new clients' subdomain sites - newclient.companyname.com and ask us to assess them.

So for every new site we have to report that the ASP (not ASP.net) version number leaked by the site fingerprints the version of Windows 2000 Server they're running, along with the XSS, SQL injection, CSRF and a host of other sec fuckups.

I expect them to bring more online next year.

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".

Clyde Radcliffe posted:

One of our Fortune 500 clients has a bunch of identical pension management sites for employees of other big companies to log in to, to view their pension information. Once a year they sign up new clients' subdomain sites - newclient.companyname.com and ask us to assess them.

So for every new site we have to report that the ASP (not ASP.net) version number leaked by the site fingerprints the version of Windows 2000 Server they're running, along with the XSS, SQL injection, CSRF and a host of other sec fuckups.

I expect them to bring more online next year.

lol, gotta be either Mercer or Hewitt

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


justcallhimdragon posted:

file indexers ftw

please run around my user storage and read various structured and unstructured data, what can possibly go wrong

I got dinged by IT security for trying to run a powershell script to read the OCR data from pdfs that had been indexed by windows


Antigravitas posted:

Windows start menu search, where a program will only appear if you type in exactly 4 letters of its name, but not if you type 5.

I still have no idea what the gently caress the people at MS are smoking. How do you gently caress up a simple substring search that badly?

it is so bad if you search "settings" it gives you everything except the actual settings menu. Sorry, settings "app"

and the settings menu sucks as well since they renamed everything for no reason, breaking 20 years of consistency

Adbot
ADBOT LOVES YOU

Chalks
Sep 30, 2009

Powerful Two-Hander posted:

I got dinged by IT security for trying to run a powershell script to read the OCR data from pdfs that had been indexed by windows

it is so bad if you search "settings" it gives you everything except the actual settings menu. Sorry, settings "app"

and the settings menu sucks as well since they renamed everything for no reason, breaking 20 years of consistency

I feel like I spend half my life logging into servers, typing "iis" into the search bar, being told "no results", pressing space, still no results, deleting the space, oh now you've found it thanks.

Every single time.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply