Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."
it's using wmi and psexec with shared creds to spread to local subnets in addition to exploiting ms17010

Adbot
ADBOT LOVES YOU

scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."

ate all the Oreos posted:

how about that "iOS and Windows are still vulnerable to the group key handshake" bit

from the paper: "Finally, when the group key handshake is attacked, an adversary can replay group-addressed frames, i.e., broadcast and multicast frames."

scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."

abigserve posted:

uni's you get the particularly tasty brand of secfuck where IT wants everything to be as secure as possible and standardized, "IT as a service" etc. but then you tell someone they can't do something and suddenly "x had a talk to the vice chancellor and they said we have to..."

im security for a university and yeah, gently caress this poo poo forever and ever. new director/cio are changing some of that culture but ugh its such a poo poo show. rip me.

scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."

yoloer420 posted:

Ours was terrible and denied all requests for changes we needed because "security". So every department had their own IT / hax so that they could get research done.

The new team are more permissive, work with you to find good solutions to problems and are ripping all the old poo poo down and replacing it with managed stuff that works better and is more secure. It owns.

we're in a similar position, all managed gear and we generally work with people to get they poo poo working as long as its a reasonable request. we still va the hell out of everything, it just takes a long rear end time because besides me, i've got one coworker. working on that part too but isnt easy when the salary isnt very competitive.

the silo problem is real loving lovely though. we're about halfway through a multiyear project to just get everything on the same drat domain. i hate to say it, but for workstation management and monitoring, mcafee is the only tool that weve managed to get campus wide installation of and their HIPS product isnt half bad for monitoring if you get creative with it.

scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."

Wiggly Wayne DDS posted:

not-not-not-petya badrabbit is making the rounds, and no one knows the initial infection vector at the moment, eternal blue, mimikatz, etc.

seems to be compromised sites offering fake flash updates.

  • Locked thread