ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    41.9m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • siringoS
      siringo @scottalanmiller
      last edited by

      @scottalanmiller said in What Are You Doing Right Now:

      @dbeato said in What Are You Doing Right Now:

      @scottalanmiller said in What Are You Doing Right Now:

      Another fun day of ransomware remediation.

      Another one?

      Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

      Internally, it was AD to spread. So they've removed AD to secure the environment.

      which ransomeware is it?

      1 Reply Last reply Reply Quote 0
      • nadnerBN
        nadnerB @scottalanmiller
        last edited by

        @scottalanmiller said in What Are You Doing Right Now:

        @dbeato said in What Are You Doing Right Now:

        @scottalanmiller said in What Are You Doing Right Now:

        Another fun day of ransomware remediation.

        Another one?

        Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

        Internally, it was AD to spread. So they've removed AD to secure the environment.

        If you mark admin accounts as sensetive in AD, you CAN slow it down/ stop it in its tracks as it can't impersonate admins and spread further/as fast

        1 Reply Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller
          last edited by

          Just hung up the phone. My part is done, at least for now.

          1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato @scottalanmiller
            last edited by

            @scottalanmiller said in What Are You Doing Right Now:

            @dbeato said in What Are You Doing Right Now:

            @scottalanmiller said in What Are You Doing Right Now:

            Another fun day of ransomware remediation.

            Another one?

            Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

            Internally, it was AD to spread. So they've removed AD to secure the environment.

            AD like a VPN or RDS?

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @dbeato
              last edited by

              @dbeato said in What Are You Doing Right Now:

              @scottalanmiller said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              @scottalanmiller said in What Are You Doing Right Now:

              Another fun day of ransomware remediation.

              Another one?

              Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

              Internally, it was AD to spread. So they've removed AD to secure the environment.

              AD like a VPN or RDS?

              Nope, Just AD.

              dbeatoD DashrenderD 2 Replies Last reply Reply Quote 0
              • dbeatoD
                dbeato @scottalanmiller
                last edited by

                @scottalanmiller said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                @scottalanmiller said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                @scottalanmiller said in What Are You Doing Right Now:

                Another fun day of ransomware remediation.

                Another one?

                Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

                Internally, it was AD to spread. So they've removed AD to secure the environment.

                AD like a VPN or RDS?

                Nope, Just AD.

                a non-IT vendor I get it but it is so vague lol

                1 Reply Last reply Reply Quote 0
                • WrCombsW
                  WrCombs
                  last edited by

                  Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                  dafyreD 1 Reply Last reply Reply Quote 0
                  • dafyreD
                    dafyre @WrCombs
                    last edited by

                    @WrCombs said in What Are You Doing Right Now:

                    Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                    Hope you are feeling better!

                    WrCombsW 1 Reply Last reply Reply Quote 0
                    • WrCombsW
                      WrCombs @dafyre
                      last edited by

                      @dafyre said in What Are You Doing Right Now:

                      @WrCombs said in What Are You Doing Right Now:

                      Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                      Hope you are feeling better!

                      lots better, I started feeling better Friday , after i was up half the night Thursday. Crazy stomach bug.

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @scottalanmiller
                        last edited by

                        @scottalanmiller said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        @scottalanmiller said in What Are You Doing Right Now:

                        @dbeato said in What Are You Doing Right Now:

                        @scottalanmiller said in What Are You Doing Right Now:

                        Another fun day of ransomware remediation.

                        Another one?

                        Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

                        Internally, it was AD to spread. So they've removed AD to secure the environment.

                        AD like a VPN or RDS?

                        Nope, Just AD.

                        How was this and AD issue?

                        1 Reply Last reply Reply Quote 0
                        • hobbit666H
                          hobbit666
                          last edited by

                          Wondering if this would make an OK(ish) Lab server.
                          2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @hobbit666
                            last edited by

                            @hobbit666 said in What Are You Doing Right Now:

                            Wondering if this would make an OK(ish) Lab server.
                            2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                            Sure - but why have your own box? why not just spin up some Vultr instances?

                            hobbit666H travisdh1T 2 Replies Last reply Reply Quote 0
                            • hobbit666H
                              hobbit666 @Dashrender
                              last edited by

                              @Dashrender Main reason is i want to test, Apps, Servers OS, Logging, Security, Pen Testing, stuff easily between all the VM in a isolated "Lab"

                              Have just found a HP Server for £150 (2x Xeon Hex Core, 128GB RAM )

                              DashrenderD 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @hobbit666
                                last edited by

                                @hobbit666 said in What Are You Doing Right Now:

                                @Dashrender Main reason is i want to test, Apps, Servers OS, Logging, Security, Pen Testing, stuff easily between all the VM in a isolated "Lab"

                                Have just found a HP Server for £150 (2x Xeon Hex Core, 128GB RAM )

                                The problem with any server class machine will be the noise of the fans.

                                hobbit666H 1 Reply Last reply Reply Quote 0
                                • hobbit666H
                                  hobbit666 @Dashrender
                                  last edited by

                                  @Dashrender I've got a server room to hide it in 🙂

                                  1 Reply Last reply Reply Quote 0
                                  • travisdh1T
                                    travisdh1 @Dashrender
                                    last edited by

                                    @Dashrender said in What Are You Doing Right Now:

                                    @hobbit666 said in What Are You Doing Right Now:

                                    Wondering if this would make an OK(ish) Lab server.
                                    2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                                    Sure - but why have your own box? why not just spin up some Vultr instances?

                                    Because he's like me, and wants to run about 50 different things, which adds up quicker than you'd think.

                                    @hobbit666 That looks like an ok home lab box. I recently picked up a used server for a home lab myself. Mine is an R620, 2x E5-2660, 96GB RAM (24x4GB) PERC H710. I picked up 4 500GB SSD to put in it. It's frankly overkill for what I'm doing and have planned for it, but that just means I can experiment with more things. I say go for it.

                                    hobbit666H 1 Reply Last reply Reply Quote 1
                                    • hobbit666H
                                      hobbit666 @travisdh1
                                      last edited by

                                      @travisdh1 Spot on 🙂
                                      I've been looking into Elsatic Stack, Cyber Security, Pen Testing etc etc. Doing this on a laptop/desktop soon bombs out.
                                      Don't want to do this on works network incase 🙂

                                      So i thought buy a "Lab" Server and do what i want

                                      1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Morning conference call.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Dealing with Merchants & Professional Collection Bereau who is committing financial and medical fraud.

                                          dafyreD WrCombsW 2 Replies Last reply Reply Quote 0
                                          • dafyreD
                                            dafyre @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in What Are You Doing Right Now:

                                            Dealing with Merchants & Professional Collection Bereau who is committing financial and medical fraud.

                                            Oh fun.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3468
                                            • 3469
                                            • 3470
                                            • 3471
                                            • 3472
                                            • 4443
                                            • 4444
                                            • 3470 / 4444
                                            • First post
                                              Last post