Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I laughed much harder than I should have at this. Friday morning owns.

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

The Fool posted:

They had a contact, the responding deputies verified their identities and were about to let them go when the sheriff showed up and decided to be a cock mongrel about “his building”

The entire kerfuffle was because of a political dispute between the state and local governments.

Yeah it was this.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Yeah I feel like it goes a bit like that.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Amazing.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
The local University here also uses public IP space for each of the departments. Within the department is a private network and within the campus datacenter there is a private network, but all space between them is 100% public. Also each department has their entirely own network complete with different IT staff and what I will hazard to call "architecture".

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

duz posted:

Whatever the one built into Windows is called.

e: Wow what a lovely page snipe.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I'm only JUST winning the battle of disabling SMBv1 on my infrastructure, so alright I guess.

We also have 1803 on our desktops, so alright x2 I guess.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I'm not even going to start on the struggle I'm having getting people to buy in to PAW, but know it is not a fun one.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Yep. Enterprise. Apparently our desktop team is fighting to upgrade, but I don't know to what (hopefully not 1809) and I don't know how that's going.

Other question: Is there any reason an API would not use OAuth over the internet other than "because it's hard"?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

Where do you work? I want to get some of that free money.

There are even worse things inside my network right now; if you can believe that.

Does anyone have experience with Airlock Digital? My company is putting them up against Carbon Black for application whitelisting and I only know what their sales team has told me (which, I'm sure you can understand, I take with a massive grain of salt).

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

every motherfucker who complained about getting blindsided by this has an X painted on their back

Honestly I'm paying big attention to where I hear these coming from.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

nothing is free

Except the airline losing your bag. That one's on the house.

I will also be reporting in at B-Sides and DefCon next week.

DkHelmet posted:

Essential stuff: skytalks and villages.

Nailed it.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

that guy sounds like a massive piece of poo poo

not empty quoting

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

lol. lmao.

This perfectly sums up my reaction. Burn it to the ground.

The fallout will likely be impressive.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Yeah powershell actively yells at you about using plain text and you need to specifically change your code to work with a regular cred string as opposed to a credential object. It's incredible they went so far to do it wrong.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Full tunnel is great if you want the user experience to be poo poo

Sickening posted:

Its like I am in a time machine and its 2010 all over again.

My company's terrible remote IT strategy over the last few years is being called out.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
As of last night and seeing which screen grabs on discord could be expanded, I can see it does not appear to have been retroactively applied at this time. Maybe that's changing, but it doesn't seem to be right now.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Sickening posted:

I am got out of a meeting this morning because some vp was upset that they were prevented from uploading their personal tax filing to their browser on their work computer. They weren't in trouble for doing it, they were just prevented through DLP and were ANGRY.

Being told "a document with sensitive information was correctly detected and prevented from an action" wasn't enough. We are going to brawl over feelings now. HR doesn't take this poo poo off my hands enough.

My life is this, but with every employee wanting to use gdrive because "it's how I want to do things". I work at a bank and it is explicitly stated in our policy that uploading to cloud storage that isn't our OneDrive or ShareFile is not allowed.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Nearly all my coding is interacting with APIs these days as I write automations into our SOAR. Would I say I'm good at coding? Hell no. I'm good enough to make the drat thing work and comment it for the next guy though.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

I want one of these but they're like $400 CAD which is hard to justify.

Yeah they're pretty rough in price up here. I managed to turn mine into a pineapple though (among other things), so hey 2-for-1 toys aren't a bad deal.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

No you see to be compliant with what this third party says we have to give up our passwordless identity platform and return to enforced password complexity with 30 day expiration.

This hits close to home and is, in fact, the topic of a meeting I currently am suffering through.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Defenestrategy posted:

Can yall give me some insight into how yall triage/remediate your pentest/scan tickets.

Currently we're a small department responsible for both infrastructure and product security. When we run scans we're taking note of the who, what, when, where, why and how to fix whatever problem and kicking them over the wall to either side of the house. The product side is fine with this because they have a ton of devs so they generally fix stuff fairly quick, the IT side is very slow with this because theyre an equally small department with other priorities. Our manager wants to somehow lower their mean time to remediation, but I dont see how beyond either doing as much of the infra tickets as we can before kicking over stuff that we absolutely cant do with our permission set or getting the company to increase IT headcount.

This is the issue with Vulnerability Management in general. When I was in charge of vuln management in my shop, the only way to really grab this traction was change from above. Leadership needed to change some expectations to make it very known that the remediation of these issues is both tracked and scrutinized in relation to the gauge of performance for any given team. Once that trickles down to team managers this will actually start to move forward. There's a good chance you'll need to help build a process with those teams to deal with your requests specifically, but once that's all done you should see a pretty significant turn around in efficacy.

tl;dr - it's a long road mostly governed by people than by tech.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
https://twitter.com/vxunderground/status/1701758864390050145

You really love to see it :lolplant:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Defenestrategy posted:

Bluesnarfing, Bluebugging, bluejacking.

At least buy me a couple drinks first.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Cannon_Fodder posted:

I'm inheriting a massive vulnerability debt and taking on a vulnerability management position with very little experience.


Piss and poo poo. Here we go.

Welcome to vuln management. It doesn't get better. I ran our vuln management for about 4 years before building it out to something proper that can be reasonably handled by another team (in the security office). I like to think I've seen everything, but please do prove me wrong with any novel nightmares you come across.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Sickening posted:

My CISO is looking to expand the scope of security even more. They have a vision of SecOps to architect, create, deploy, and maintain OS vuln, app vuln, config vuln, network vuln, and CI/CD vuln for every aspect of the company. The very notion of "we can't rely on the rest of the company to do what we demand, so we are going to do it ourselves" and its never going to loving work. Our teams are going to crush themselves under boundless scope and responsibility. We are just going to fail.

That scope is purely infinite and is not achievable under any circumstance :staredog:

Obviously you know this, I'm just doubling down on it seems you have a CISO who has taken to heart the idea of "if you want something done, do it yourself". Here's you hoping you can talk them out of it and into a more reasonable path of process creation to hand out specific remediation work. Let it be known I also hate this solution in smaller corps, but I will take it over either the extremes of 'we do it all' and 'pray other teams do it themselves'.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I have been tasked with standing up an OpenCTI instance for us; sure sounds great. Anyone ever build this before or am I essentially being given another pet project for me to turn into the greybeard over?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

FungiCap posted:

Soooo is everyone else seeing a massive increase in QR code phishing for o365 logins?

Yep there are a few distinct campaigns constantly hitting us. Good times.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

I just assumed they weren't because of the amount that are getting through

Edit: You're right, they claim to scan QR codes https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-links-about?view=o365-worldwide

Most of what we see are QR codes stuck in images which probably breaks the parsing.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

MustardFacial posted:

TIL: Defender for Endpoint will send an informational alert to the dashboard if you plug in a Flipper Zero.

Sometimes more than just Defender will alert on it depending what your environment is configured to look for! First hand experience with that one. Not all of the interactions I ran were picked up (expected), some were blocked via USB policies, and others I think I didn't write properly. I am the SOC guy that was testing detections.

some kinda jackal posted:

-- I spent enough time in an operational security role to know better than to throw a grenade to those poor souls :haw:

Appreciated lol

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

evil_bunnY posted:

Also since everyone else can't be in, all your meetings on your office days will be remote or hybrid. Yes our offices are open plan why do you ask?

This is my exact problem when I have to go into the office. I tend to go in on Friday because nobody else is there and I will not have to deal with listening to everyone on my floor have a Teams meeting where they scream at their laptops. However this means I am usually one of two people in the office that day; how is this helping the "culture" again?

Moron execs push RTO.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I have absolutely no idea how you fell into their game of numbers if you don't even have an account at the bank. Perhaps an assumption that most people have an account at the major institution? An odd place to 'never attribute malice when incompetence will do', but it's hard to imagine anything other than they don't know who they're targeting.

From the FI side of that encounter, there has been a pretty large upswing in persistent ATOs (or at least attempts) as of recent. Once again though, I have no idea why they would come after you if there was nothing to gain access to.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
It's impressive how good meeting room tech has got when everyone wants nothing more than to never set foot in an office again lol.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Man they're really having a hell of a time over there aren't they?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Implies they’re rotating them by having a person click a button and someone didn’t do it

This is exactly how I read that.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

MustardFacial posted:

Vibe check this statement for me:

True and accurate. Might want to soften the blow depending on the audience, but I have had many conversations with managers that sound like this.

Your second shot at it right above this is a good edit to ensure nobody decides to throw a tantrum over you being curt, while still sending the same message.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

... we're still working under the presumption that iMessage is compromised in the Chinese market right?

Absolutely.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Subjunctive posted:

we got Amir!

:yeah: We're all cheering for the man.

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I'm sure the real answer is they do absolutely loving nothing.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply