ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Miscellaneous Tech News

    Scheduled Pinned Locked Moved News
    7.4k Posts 83 Posters 3.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      For reference, I buy box wine.

      WLS-ITGuyW 1 Reply Last reply Reply Quote 0
      • WLS-ITGuyW
        WLS-ITGuy @scottalanmiller
        last edited by

        After getting interrupted for the 3rd time when trying to ask questions, I wouldn't have cared at that point what the benefits were, I would've been DUDE! You're SO BEING A DICK RIGHT NOW!

        1 Reply Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller
          last edited by

          https://www.vice.com/en/article/akek8e/walmart-30tb-ssd-hard-drive-scam-sd-cards

          1 Reply Last reply Reply Quote 1
          • ObsolesceO
            Obsolesce
            last edited by Obsolesce

            Uber Breach 2022

            The critical vulnerability that granted the attacker such high levels of access was hardcoded credentials in a PowerShell script

            scottalanmillerS 1 Reply Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @Obsolesce
              last edited by

              @Obsolesce said in Miscellaneous Tech News:

              Uber Breach 2022

              The critical vulnerability that granted the attacker such high levels of access was hardcoded credentials in a PowerShell script

              Argh, why the heck is there Windows development on a platform like Uber? And who approved THAT GIT checkin?

              ObsolesceO DashrenderD 2 Replies Last reply Reply Quote 1
              • ObsolesceO
                Obsolesce @scottalanmiller
                last edited by

                @scottalanmiller said in Miscellaneous Tech News:

                @Obsolesce said in Miscellaneous Tech News:

                Uber Breach 2022

                The critical vulnerability that granted the attacker such high levels of access was hardcoded credentials in a PowerShell script

                Argh, why the heck is there Windows development on a platform like Uber? And who approved THAT GIT checkin?

                No idea. Android and ios only AFAIK. No need for Windows. But I have a feeling that one who bakes credentials into scripts would do it in any scripting language. You'd also think a vulnerability like that would have been found during scanning. They must not have any devsecops or code scanning tools in place.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Obsolesce
                  last edited by

                  @Obsolesce said in Miscellaneous Tech News:

                  @scottalanmiller said in Miscellaneous Tech News:

                  @Obsolesce said in Miscellaneous Tech News:

                  Uber Breach 2022

                  The critical vulnerability that granted the attacker such high levels of access was hardcoded credentials in a PowerShell script

                  Argh, why the heck is there Windows development on a platform like Uber? And who approved THAT GIT checkin?

                  No idea. Android and ios only AFAIK. No need for Windows. But I have a feeling that one who bakes credentials into scripts would do it in any scripting language. You'd also think a vulnerability like that would have been found during scanning. They must not have any devsecops or code scanning tools in place.

                  Clearly no one is scanning or checking anything. That's the problem. And that's why Windows development is an issue, it starts a "trend" of looking the other way for obvious non-best practices. Once something so fundamental as making business software or production server software on a platform that is costly, risky and less performant (presumably to allow hiring less than capable developers - that's why that ecosystem exists there) then where do you start adding best practices when clearly, it's not even on the radar? you don't, it just doesn't make sense to. So you get here.

                  1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said in Miscellaneous Tech News:

                    @Obsolesce said in Miscellaneous Tech News:

                    Uber Breach 2022

                    The critical vulnerability that granted the attacker such high levels of access was hardcoded credentials in a PowerShell script

                    Argh, why the heck is there Windows development on a platform like Uber? And who approved THAT GIT checkin?

                    I'm sure their desktop environment is Windows for their non techies. And there's probably little to no separation between the Uber app platform and their staff.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in Miscellaneous Tech News:

                      I'm sure their desktop environment is Windows for their non techies.

                      That's weird as that is a power user platform. You'd never put that in to make things harder jsut for the less capable staff if you don't for the good staff. But that's not really relevant, why would their applications be getting built on Windows regardless of that? And even if they were BUILT on Windows, why would the app deployment happen to Windows? What is used by some non-dev staff has zero to do with what is talking to their system.s

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @scottalanmiller
                        last edited by

                        @scottalanmiller said in Miscellaneous Tech News:

                        @Dashrender said in Miscellaneous Tech News:

                        I'm sure their desktop environment is Windows for their non techies.

                        That's weird as that is a power user platform. You'd never put that in to make things harder jsut for the less capable staff if you don't for the good staff. But that's not really relevant, why would their applications be getting built on Windows regardless of that? And even if they were BUILT on Windows, why would the app deployment happen to Windows? What is used by some non-dev staff has zero to do with what is talking to their system.s

                        You're asking people to do things your way - we all know that's not the typical way.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Dashrender
                          last edited by

                          @Dashrender said in Miscellaneous Tech News:

                          @scottalanmiller said in Miscellaneous Tech News:

                          @Dashrender said in Miscellaneous Tech News:

                          I'm sure their desktop environment is Windows for their non techies.

                          That's weird as that is a power user platform. You'd never put that in to make things harder jsut for the less capable staff if you don't for the good staff. But that's not really relevant, why would their applications be getting built on Windows regardless of that? And even if they were BUILT on Windows, why would the app deployment happen to Windows? What is used by some non-dev staff has zero to do with what is talking to their system.s

                          You're asking people to do things your way - we all know that's not the typical way.

                          No, I'm asking people to do their jobs and do them well. Nothing more. Basic competence.

                          1 Reply Last reply Reply Quote 0
                          • nadnerBN
                            nadnerB
                            last edited by

                            Optus (second largest telco in Australia) has been compromised and customer data loss has been confirmed

                            https://www.itnews.com.au/news/optus-attack-exposes-customer-information-585567

                            1 Reply Last reply Reply Quote 1
                            • DanpD
                              Danp
                              last edited by

                              How Citrix dropped the ball on Xen ... according to Citrix

                              https://www.theregister.com/2022/09/30/citrix_xen/

                              scottalanmillerS 1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @Danp
                                last edited by

                                @Danp said in Miscellaneous Tech News:

                                How Citrix dropped the ball on Xen ... according to Citrix

                                https://www.theregister.com/2022/09/30/citrix_xen/

                                Jaja, yay I got sort of referenced (as the one who proposed XCP-NG. They also screwed themselves royally by mixing the names all over the place. They left that out, the utter market confusion that they created by calling everything Xen.

                                They did more than crush trust in Xen. They caused many people to simply distrust Citrix.

                                ObsolesceO 1 Reply Last reply Reply Quote 1
                                • ObsolesceO
                                  Obsolesce @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Miscellaneous Tech News:

                                  Jaja, yay I got sort of referenced

                                  The "weird systems users": hobbyists who offer virtualization to non-profit and charity users, using old, out-of-maintenance hardware that had been inherited or passed on to them. Enthusiast users, with no funds to buy licenses?

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @Obsolesce
                                    last edited by

                                    @Obsolesce said in Miscellaneous Tech News:

                                    @scottalanmiller said in Miscellaneous Tech News:

                                    Jaja, yay I got sort of referenced

                                    The "weird systems users": hobbyists who offer virtualization to non-profit and charity users, using old, out-of-maintenance hardware that had been inherited or passed on to them. Enthusiast users, with no funds to buy licenses?

                                    That too.

                                    1 Reply Last reply Reply Quote 0
                                    • stacksofplatesS
                                      stacksofplates
                                      last edited by

                                      For almost two years, Microsoft officials botched a key Windows defense, an unexplained lapse that left customers open to a malware infection technique that has been especially effective in recent months.

                                      Microsoft officials have steadfastly asserted that Windows Update will automatically add new software drivers to a blocklist designed to thwart a well-known trick in the malware infection playbook. The malware technique—known as BYOVD, short for "bring your own vulnerable driver"—makes it easy for an attacker with administrative control to bypass Windows kernel protections. Rather than writing an exploit from scratch, the attacker simply installs any one of dozens of third-party drivers with known vulnerabilities. Then the attacker exploits those vulnerabilities to gain instant access to some of the most fortified regions of Windows.

                                      It turns out, however, that Windows was not properly downloading and applying updates to the driver blocklist, leaving users vulnerable to new BYOVD attacks.

                                      https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/

                                      scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @stacksofplates
                                        last edited by

                                        @stacksofplates damn, that's significant.

                                        1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender @stacksofplates
                                          last edited by

                                          @stacksofplates said in Miscellaneous Tech News:

                                          For almost two years, Microsoft officials botched a key Windows defense, an unexplained lapse that left customers open to a malware infection technique that has been especially effective in recent months.

                                          Microsoft officials have steadfastly asserted that Windows Update will automatically add new software drivers to a blocklist designed to thwart a well-known trick in the malware infection playbook. The malware technique—known as BYOVD, short for "bring your own vulnerable driver"—makes it easy for an attacker with administrative control to bypass Windows kernel protections. Rather than writing an exploit from scratch, the attacker simply installs any one of dozens of third-party drivers with known vulnerabilities. Then the attacker exploits those vulnerabilities to gain instant access to some of the most fortified regions of Windows.

                                          It turns out, however, that Windows was not properly downloading and applying updates to the driver blocklist, leaving users vulnerable to new BYOVD attacks.

                                          https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/

                                          OK that's definitely bad that they don't block it - but since you're an admin - why do you even care? the article says that the attacker is starting as a local admin.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @Dashrender
                                            last edited by

                                            @Dashrender said in Miscellaneous Tech News:

                                            @stacksofplates said in Miscellaneous Tech News:

                                            For almost two years, Microsoft officials botched a key Windows defense, an unexplained lapse that left customers open to a malware infection technique that has been especially effective in recent months.

                                            Microsoft officials have steadfastly asserted that Windows Update will automatically add new software drivers to a blocklist designed to thwart a well-known trick in the malware infection playbook. The malware technique—known as BYOVD, short for "bring your own vulnerable driver"—makes it easy for an attacker with administrative control to bypass Windows kernel protections. Rather than writing an exploit from scratch, the attacker simply installs any one of dozens of third-party drivers with known vulnerabilities. Then the attacker exploits those vulnerabilities to gain instant access to some of the most fortified regions of Windows.

                                            It turns out, however, that Windows was not properly downloading and applying updates to the driver blocklist, leaving users vulnerable to new BYOVD attacks.

                                            https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/

                                            OK that's definitely bad that they don't block it - but since you're an admin - why do you even care? the article says that the attacker is starting as a local admin.

                                            Installers are typically local admins.

                                            DashrenderD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 372
                                            • 373
                                            • 6 / 373
                                            • First post
                                              Last post