Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
chin up everything sucks
Jan 29, 2012

Volmarias posted:

2020 is really just bringing that "is it real or machine generated" vibe to the news, rising towards a crescendo as the year goes on.

The world is a simulation and we just found the bug that causes a Dwarf Fortress style tantrum spiral. Everything is spinning out of control in hilariously bad ways that shouldn't be possible.

Adbot
ADBOT LOVES YOU

chin up everything sucks
Jan 29, 2012

I hate socializing with people I don't know, so I'm never taking one of those social sales lunches unless I'm required to by a boss. If they want to send snacks to my office/home, sure - but don't expect me to remember the company that sent them.

chin up everything sucks
Jan 29, 2012

BonHair posted:

I'm betting a lot of execs would invest in butt security rather than cloud security.

You could call it Cover Your Butt Insurance, they would immediately fund it.

chin up everything sucks
Jan 29, 2012

SlowBloke posted:

Are you seriously expecting competence, skills and effort from an ubiquiti networks dev?

I have posted before about my experience working for Ubiquiti most of a decade ago. Place was a shitshow.

chin up everything sucks
Jan 29, 2012

KillHour posted:

I always thought of Ubiquiti as having really good hardware for the money but with perpetually beta software that may or may not eventually get all the features they promise. Which is great for certain market segments and terrible for others.

The hardware was always iffy, mostly because of inconsistent manufacturing in China. Sometimes it was indestructible, other times even light weather or sunshine could break it. Then you also had knock-offs made in Russia after one factory sold the build designs to someone else after losing a contract.

chin up everything sucks
Jan 29, 2012

8am in the morning yesterday I pinged our infrastructure team about Log4J. They said that we were fine. 2 hours later they start really digging in and going "ok poo poo, we aren't fine."

11am a conference bridge starts, and I was included on it. 8pm last night the bridge finally ended.

My boss sent me a $50 doordash gift card for my hard work. Yay!

chin up everything sucks
Jan 29, 2012

BaseballPCHiker posted:

Someone on a conference call around my companies response to Log4J just said they werent ever told to patch their stuff so they never have and that as a result they arent vulnerable because they run Log4J version 1x.

This place is so loving backwards and behind the times. I need to remember to just take a deep breath, not let it get to me, and keep collecting the paychecks.

Point them to the 1.x CSV from 2 years ago that is just as bad.

chin up everything sucks
Jan 29, 2012

Fart Amplifier posted:

If an iPhone was hit by this vulnerability, would a patch then erase any exploits? I'd assume you'd need to reinstall the OS, but would that be enough?

A patch would prevent future exploits, but anything already put in place would be running with whatever permissions it gave itself.

chin up everything sucks
Jan 29, 2012

Fart Amplifier posted:

Yeah, I'm assuming even at that point even a wipe might not be able to remove it

A full factory restore would be the way to go - flash firmware and everything.

chin up everything sucks
Jan 29, 2012

Fart Amplifier posted:

Is this exploit guaranteed to not survive a firmware flash? I don't know how that works.

If I were an at-risk journalist/dissident I'd definitely want a confirmation before putting myself at risk trusting the flashing process of a compromised device.

Honestly, I have no idea - I don't think anything survives a wipe + firmware flash unless the device was compromised via a supply chain attack, but I can't say that with 100% certainty.

chin up everything sucks
Jan 29, 2012

evil_bunnY posted:

"where an attacker with permission to modify the logging configuration file"

who gives a poo poo

It's not dangerous at all except when used as part of a supply chain attack.
Hacker finds a commonly used but rarely updated software package. Hacker finds a way to compromise the package so it now includes a pre-hosed version of Log4J and something that pings a C&C on rare occasion. Now the hacker has a self-identifying list of servers open for a RCE until people figure out the root cause.

chin up everything sucks
Jan 29, 2012

Volmarias posted:

A version that, apparently, cannot just pop open a shell for itself...?

Depends on how long they want to maintain access to devices, or if they want to burn them immediately. There is a business in backdooring devices and then selling access to them to other criminals.

chin up everything sucks
Jan 29, 2012

stoopidmunkey posted:

My company is in the process of getting fedramp certified. They chose Qualys for web app scanning and after having the product since may, we just got our first successful scan (their SaaS servers kept running out of memory). Anyway, I opened the scan results and they’re loving useless. To get any value you have to download the scan report as pdf to view the actual output from the scans. How do people manage with useless tools like this apart from just buying Tenable or Rapid7 next budget cycle?

Fun fact, with Qualys if you submit a false positive report - you lose access to the information and explanation you submitted. So if that issue is going to be reoccurring every time you run a scan, you need to collect that evidence and re-write the explanation again whenever the granted exception expires, which is usually every 6 months.

chin up everything sucks
Jan 29, 2012

Had an interview for a helpdesk job that had a Security+ cert as a requirement. Also, it needs a security clearance. And... it sounds like I'm actually getting an offer. It's going to pay WAY less than I hoped, but they are talking about putting me in for the clearance which is a huge step forward in my career. Crossing my fingers.

chin up everything sucks
Jan 29, 2012

It's officially :yotj: even though I failed to get a job in InfoSec. At least this place is getting me a security clearance so my range of possible positions opens up significantly next time I'm looking.

chin up everything sucks
Jan 29, 2012

eonwe posted:

Passed my CISSP exam!

Nice! How hard did it feel?

chin up everything sucks
Jan 29, 2012

unknown posted:

rear end in the middle?

The doggy style of hacking

chin up everything sucks
Jan 29, 2012

A promotion came in - moving from government helldesk to government cybersecurity in a few weeks, just waiting for someone to start in 2 weeks to backfill me. No paperwork signed yet, hoping I can negotiate a pay bump.

chin up everything sucks
Jan 29, 2012

BaseballPCHiker posted:

Local, state or federal government? Most government orgs have pretty set pay bands in my experience. They may be able to start you up a level or two higher but then youre on a set pay raise increase with each step/year of experience.

Also congratulations! I really enjoyed my time in government work and got to get hands on experience in a lot of different areas. It really set me up well for the future when I pivoted back to the private sector. Make sure you stick around long enough to qualify for any pensions.

Contractor on an USAF base, so I don't get the nice pay bands. Instead I get the minimum they can pay to keep people in the job. Turnover is unsurprisingly high due to EVERY other cybersecurity job that exists paying 25-30% more at a minimum.

chin up everything sucks
Jan 29, 2012

Methylethylaldehyde posted:

Try to angle for a clearance, so you can giggle as the pay differential goes the other way. Local TS computer toucher jobs on base are 20-35k more than equivalent private sector gigs.

They put me in for Secret clearance just to have me on base for helpdesk. My official clearance came through the same day I was told about the promotion.

chin up everything sucks
Jan 29, 2012

Speaking as someone who has problems staying motivated in learning specific stuff on my personal time for more than a month at a time, the CISSP feels like it exists specifically to block my advancement because it requires a lot of very specific niche knowledge but very little real world knowledge. But holy crap is it hard to get past doors without it or a college degree to my name.

Adbot
ADBOT LOVES YOU

chin up everything sucks
Jan 29, 2012

Last day at my current job, 2 weeks before my new job is going to start.... Got a phonecall with an offer for the job I really wanted, better pay, benefits, better work.... Everything. loving taking it. ISSO here I go.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply