ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Water Closet
    time waster
    285
    88.9k
    42.0m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • siringoS
      siringo
      last edited by

      chillin' to Hendrix.

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        Finishing up two exchange rebuilds from last night. IE Checking the migration status and making sure everything is working smoothly.

        DashrenderD 1 Reply Last reply Reply Quote 0
        • gjacobseG
          gjacobse
          last edited by

          Omg- domain to domain migration day two,.. they’ve managed to make a planet from a mole hill. This is going to take several hours to sort out,.. and the started it at 3pm yesterday.... and it’s 76deg F in the building.

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @gjacobse
            last edited by

            @gjacobse said in What Are You Doing Right Now:

            Omg- domain to domain migration day two,.. they’ve managed to make a planet from a mole hill. This is going to take several hours to sort out,.. and the started it at 3pm yesterday.... and it’s 76deg F in the building.

            Use Forensit for the user workstation migration. That'll make your life so much easier.

            gjacobseG 1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @DustinB3403
              last edited by

              @DustinB3403 said in What Are You Doing Right Now:

              Finishing up two exchange rebuilds from last night. IE Checking the migration status and making sure everything is working smoothly.

              Rebuilds?

              DustinB3403D 1 Reply Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403 @Dashrender
                last edited by

                @Dashrender was I unclear?

                DashrenderD 1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @DustinB3403
                  last edited by

                  @DustinB3403 said in What Are You Doing Right Now:

                  @Dashrender was I unclear?

                  I just wanted you to expand upon that - why where you doing Exchange rebuilds? I'm not entirely sure what an Exchangae rebuild is - an Exchange server died, so you have to rebuild it and restore from backup?

                  or was it a new Exchange server replacing an old one - so it's really more of a migration?

                  just looking for convo more than anything.

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • hobbit666H
                    hobbit666
                    last edited by

                    Can't remember.............................. so many little projects to many distractions. 😄

                    gjacobseG 1 Reply Last reply Reply Quote 0
                    • hobbit666H
                      hobbit666
                      last edited by

                      Does anyone here run internal Vulnerability scans internally? What do you use?
                      I'm playing with Nessus and Nexpose at the moment just wanted to see different options.

                      I have also setup a Wazuh server and deployed some agents.

                      DustinB3403D 1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403 @Dashrender
                        last edited by

                        @Dashrender said in What Are You Doing Right Now:

                        @DustinB3403 said in What Are You Doing Right Now:

                        @Dashrender was I unclear?

                        I just wanted you to expand upon that - why where you doing Exchange rebuilds? I'm not entirely sure what an Exchangae rebuild is - an Exchange server died, so you have to rebuild it and restore from backup?

                        or was it a new Exchange server replacing an old one - so it's really more of a migration?

                        just looking for convo more than anything.

                        Because of Microsoft's recent zero-day we found several customers who had been compromised with additional scanning utilities, since this has been an evolving ordeal.

                        We previously patched and closed the doors but the "hacker" was technically in.

                        So we built several new VMs for different clients last night, installed exchange and migrated the users over.

                        DashrenderD 1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403 @hobbit666
                          last edited by

                          @hobbit666 said in What Are You Doing Right Now:

                          Does anyone here run internal Vulnerability scans internally? What do you use?
                          I'm playing with Nessus and Nexpose at the moment just wanted to see different options.

                          I have also setup a Wazuh server and deployed some agents.

                          Greenbone Security Assistant (the open source one) is likely what you'd want to setup and use.

                          There is a Github repo that has a "1-click" installable on Ubuntu Server.

                          1 Reply Last reply Reply Quote 1
                          • DashrenderD
                            Dashrender @DustinB3403
                            last edited by

                            @DustinB3403 said in What Are You Doing Right Now:

                            @Dashrender said in What Are You Doing Right Now:

                            @DustinB3403 said in What Are You Doing Right Now:

                            @Dashrender was I unclear?

                            I just wanted you to expand upon that - why where you doing Exchange rebuilds? I'm not entirely sure what an Exchangae rebuild is - an Exchange server died, so you have to rebuild it and restore from backup?

                            or was it a new Exchange server replacing an old one - so it's really more of a migration?

                            just looking for convo more than anything.

                            Because of Microsoft's recent zero-day we found several customers who had been compromised with additional scanning utilities, since this has been an evolving ordeal.

                            We previously patched and closed the doors but the "hacker" was technically in.

                            So we built several new VMs for different clients last night, installed exchange and migrated the users over.

                            same domain or new domain? If the same, how do you know the invaders can't hop onto the new box?

                            DustinB3403D 1 Reply Last reply Reply Quote 0
                            • gjacobseG
                              gjacobse @hobbit666
                              last edited by

                              @hobbit666 said in What Are You Doing Right Now:

                              Can't remember.............................. so many little projects to many distractions. 😄

                              I have all these migration follow -... hey look, the 3D printer finished,....

                              1 Reply Last reply Reply Quote 0
                              • gjacobseG
                                gjacobse @DustinB3403
                                last edited by

                                @DustinB3403 said in What Are You Doing Right Now:

                                @gjacobse said in What Are You Doing Right Now:

                                Omg- domain to domain migration day two,.. they’ve managed to make a planet from a mole hill. This is going to take several hours to sort out,.. and the started it at 3pm yesterday.... and it’s 76deg F in the building.

                                Use Forensit for the user workstation migration. That'll make your life so much easier.

                                If only we had a choice!

                                1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403 @Dashrender
                                  last edited by

                                  @Dashrender said in What Are You Doing Right Now:

                                  @DustinB3403 said in What Are You Doing Right Now:

                                  @Dashrender said in What Are You Doing Right Now:

                                  @DustinB3403 said in What Are You Doing Right Now:

                                  @Dashrender was I unclear?

                                  I just wanted you to expand upon that - why where you doing Exchange rebuilds? I'm not entirely sure what an Exchangae rebuild is - an Exchange server died, so you have to rebuild it and restore from backup?

                                  or was it a new Exchange server replacing an old one - so it's really more of a migration?

                                  just looking for convo more than anything.

                                  Because of Microsoft's recent zero-day we found several customers who had been compromised with additional scanning utilities, since this has been an evolving ordeal.

                                  We previously patched and closed the doors but the "hacker" was technically in.

                                  So we built several new VMs for different clients last night, installed exchange and migrated the users over.

                                  same domain or new domain? If the same, how do you know the invaders can't hop onto the new box?

                                  Same, and because this exchange vulnerability is executed against the exchange system account and we've checked and no accounts have been added/changed or removed.

                                  Others that are old are being looked at with a fine tooth comb.

                                  DashrenderD 1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender
                                    last edited by

                                    thanks for posting the link to the scanner.

                                    ae51c92c-25a9-4b9c-b093-677dd8b9fd10-image.png

                                    1 Reply Last reply Reply Quote 1
                                    • DashrenderD
                                      Dashrender @DustinB3403
                                      last edited by

                                      @DustinB3403 said in What Are You Doing Right Now:

                                      @Dashrender said in What Are You Doing Right Now:

                                      @DustinB3403 said in What Are You Doing Right Now:

                                      @Dashrender said in What Are You Doing Right Now:

                                      @DustinB3403 said in What Are You Doing Right Now:

                                      @Dashrender was I unclear?

                                      I just wanted you to expand upon that - why where you doing Exchange rebuilds? I'm not entirely sure what an Exchangae rebuild is - an Exchange server died, so you have to rebuild it and restore from backup?

                                      or was it a new Exchange server replacing an old one - so it's really more of a migration?

                                      just looking for convo more than anything.

                                      Because of Microsoft's recent zero-day we found several customers who had been compromised with additional scanning utilities, since this has been an evolving ordeal.

                                      We previously patched and closed the doors but the "hacker" was technically in.

                                      So we built several new VMs for different clients last night, installed exchange and migrated the users over.

                                      same domain or new domain? If the same, how do you know the invaders can't hop onto the new box?

                                      Same, and because this exchange vulnerability is executed against the exchange system account and we've checked and no accounts have been added/changed or removed.

                                      Others that are old are being looked at with a fine tooth comb.

                                      OK good that no other accounts were added - privilege escalation is the major worry here to allow them to make new accounts on the domain.

                                      1 Reply Last reply Reply Quote 0
                                      • hobbit666H
                                        hobbit666
                                        last edited by

                                        just wondering. I'm spinning up a new Ubuntu server.
                                        Does anyone encrypt the drive(s)?
                                        2021_03_19_10_48_02_Window.png

                                        ObsolesceO 1 Reply Last reply Reply Quote 0
                                        • ObsolesceO
                                          Obsolesce @hobbit666
                                          last edited by

                                          @hobbit666 said in What Are You Doing Right Now:

                                          just wondering. I'm spinning up a new Ubuntu server.
                                          Does anyone encrypt the drive(s)?
                                          2021_03_19_10_48_02_Window.png

                                          I do. You should always have your data encrypted at rest.

                                          1 Reply Last reply Reply Quote 3
                                          • WrCombsW
                                            WrCombs
                                            last edited by

                                            patiently waiting for the "hey we know that March madness is going on right now, and we forgot to get these Drink Specials programmed for this weekend.. " calls to start rolling in with the games starting at 11:15am CST.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 4173
                                            • 4174
                                            • 4175
                                            • 4176
                                            • 4177
                                            • 4443
                                            • 4444
                                            • 4175 / 4444
                                            • First post
                                              Last post