* Posts by Danny 14

4301 publicly visible posts • joined 15 Jun 2009

Stop us if you've heard this one before: Exchange Server zero-days actively exploited

Danny 14

Re: Side note on Exchange design

the core issue is that users can still invoke powershell remotely. They might not be allowed to do anything but it still starts the process, if there is an exploit in the process itself then this will instantly give you access as the process starts pre-authentication.

It is like unlocking your front door, letting the person into your house and THEN checking their ID hoping they dont know how to walk around you.

Danny 14

Re: Exploitable?

your wish is granted:

https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/

https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/

Danny 14

Re: I'm already using zero trust with Exchange

see this is a great approach till I read this:

https://learn.microsoft.com/en-us/powershell/exchange/control-remote-powershell-access-to-exchange-servers?view=exchange-ps

Especially THIS bit:

"By default, all user accounts have access to remote PowerShell. "

Wait what? It is qualified by:

"However, to actually use remote PowerShell to connect to an Exchange server, the user needs to be a member of a management role group, or be directly assigned a management role that enables the user to run Exchange cmdlets. "

Riiiight. So how about doing THIS instead:

USER->SERVER: Hi, I want to use powershell, totally not to pwn the server

SERVER->USER: credentials please.

USER->SERVER: No

SERVER->USER: .......

rather than

USER->SERVER: Hi, I want to use powershell, totally not to pwn the server

SERVER->USER: sure, here is powershell, please log in.

USER->SERVER: <sends exploit instead of powershell credentials>

And the fix? Surely you could set the default to deny and allow a select few? Nope! You cant set a default, you need to explicitly deny individual users! Insane.

We run hybrid so need an exchange server for management, however the exchange server is nicely locked away on its own subnet, external access is only granted from microsoft 365 IPs, not perfect but stops others knocking on the door.

Microsoft says it's boosted phishing protection in Windows 11 22H2

Danny 14

Re: Wait, What?

and fido keys are great until you need a mobile solution.

US school year opens with reading, writing, and ransomware

Danny 14

to be fair though, education licensing is cheap. Even with no money you can have free office 365 with petabytes of storage plus google classroom and free veeam community editiin backing up to immutable storage.

pfsense with snort and pfblocker is free.

Ive worked for schools with no money and it is possible to keep a secure environment.

Danny 14

Re: Firewalls needed, not little "security options"

and an immutable backup store. Even veeam community edition with a cheap linux storage box will do.

Ex-HP finance manager jailed after going on $5m spending spree using company plastic

Danny 14

Re: Addiction?

addicts like the rush when they go into a shop and purchase, its the feeling they get when they are treat well as a high roller.

Danny 14

Re: 46 handbags

clearly you have never met my ex wife. She would buy shies and never wear them, they were just ornaments really.

Danny 14

Re: Ambition, risk-training, vanity, lack of morals…

she didnt bribe the correct people.

Ex-T-Mobile US store owner phished staff, raked in $25m from unlocking phones

Danny 14

seems like he was doing people a favour. at least he did what people paid for. Phone locks are annoying.

Yodel becomes the latest victim of a cyber 'incident'

Danny 14

same here. they are atrocious to deal with.

DeadBolt ransomware takes another shot at QNAP storage

Danny 14

Re: Can't imagine exposing a QNAP NAS to the web

im not great at sarcasm so not aure if it was nor not. why is that not ok? Id say sensible to jave a firewall using different rules with no vlan routing. you can lock down your nas and lock down your iot.

Clonezilla 3: Copy and clone disk images to your heart's content

Danny 14

this what FOG project does. If you still use sysprep then it is a valid golden sample image deployment tool.

Danny 14

Re: I use Clonezilla...

take a look at FOG project. You can cron your backups automated if you prefer to hold images rather than backups.

Danny 14

Re: SSD

veeam backup then bare metal restore. This resets a few markers and is good for new hardware transfer too. Is free for extra measure.

China turns cyber-espionage eyes to Russia as Ukraine invasion grinds on

Danny 14

Re: Stealing thunder

the truth is probably far more simple. He thought he could win quickly. He wants to make Russia great again. Hes been told that his army is fantastic with wonderful new tanks that are much better. The airforce is excellent, navy is fantastic, troops are in excellent condition. In short Russia is poised to be a superpower comrade. Eat Ukraine and unite the motherland. Europe will cower behind the might of our gas wielding state.

The truth is that Ukrainian farmers with tractors have more backbone and that the war ia going really really badly.

Noone has dared tell Putin this yet.

Don’t expect to get your data back from the Onyx ransomware group

Danny 14

I expect to get my files back from the immutable backup store.

Twitter preps poison pill to preclude Elon Musk's purchase plan

Danny 14

this is the part ive never understood. I used facebook and twitter with a disposable account for times I have no choice - ive needed ot to pull information on companies, speedier support (!) and contacting long lost friends for their proper contact information.

What always amazed me was the amount of personal information people voluntarily put on there for the world to see, moat of it fairly "look at me and what ive done" or worst still their kids (who have had no say bit will now have their info put on the net for them).

Danny 14

i was thinking something similar, surely one of the larger shareholders is thinking to offload the pile onto musk, hell even buy back when it backfires on him and halves the value in a years time.

Star loses $500,000 NFT after crooks exploit Rarible market

Danny 14

I always see these "NFTs are in demand". Surely this is just idiots selling the first NFTs? Im not sure on the demand for NFT resales, wasnt the 2.9M first tweet NFT recwntly pulled from resale due to a top bid of a few thousand?

Certainly snake oil territory.

Bank had no firewall license, intrusion or phishing protection – guess the rest

Danny 14

Re: IT is a cost center isn't it?

pfsense, snort and pfblocker are free though, thats what makes no sense.

Danny 14

Re: At KatrinaB...

here kid. go to that atm. withdraw 400, 100is yours. Then go to that atm, withdraw 400, 100 ia yours. Talk about it and we hack your arms off.

Intel suspends all operations in Russia weeks after halting chip shipments

Danny 14

Re: RE: knew what they were getting into

so you are likening civilians poisoning russian soldiers vs those same russian soldier lining up a villiage, raping mothers in front of their daughters, hacking limbs off people and pulling tongues out of people who would not say that the russians were welcome?

There is something wrong with you.

Microsoft brings Cloud PCs and local desktops together in Windows 365

Danny 14

Re: I don't get it

2016,2019, 365 and 2021 are all the same codebase. Even the registry keys and files are the same. 2016 isnt click to run so there are minor differences.

365 gets a few tweaks such as stream integration, live subtitle translations, autosave to cloud (2021 has this too).

The funny thing is, our users get all sorts of splashscreens, 2019, 2021 and 365. They dont even log this as tickets any longer.

Danny 14

adobe CC too. Gone are the box copies.

Google: Russian credential thieves target NATO, Eastern European military

Danny 14

Re: Can't we flood them will millions of fake accounts ?

good idea. rent a cheap vps and script it to submit a few million an hour.

Ubiquiti sues Krebs on Security for defamation

Danny 14

Re: Ubiquiti's strategy...

enterprise kit. Errrr, have you seen the shitstorm after every firmware update? They even had one update that bricked your APs if you were using 4 SSIDs *and refused to replace them if you were out of warranty.

Have you tried adding your own ssl cert through the gui? Letsencrypt?

Powercycle their controllers that dont have journaling enabled, thats fun. Unless you have the new ones with a battery in them (so you have 18 hours to fix the power before they too power off without journaling)

the stuff is barely good enough for a campsite never mind enterprise.

Danny 14

Re: What's this 'Software QA' that you speak of?

unifi stuff is bargain basement. Looks good on paper and works well until you update the firmware. then you need a degree in googlefu to fix.

Simple tasks such as setting a proper ssl cert can only be done by rwcompiling a jks file via ssh Im sure a mom and pop outfit love that dont ask about letsencrypt support.

Their original controllers shipped with no journaling on their mongodb, so powwr outage killed the controllwr each time. Their second revision fixed this by adding a battery. you cant even make that stuff up. product lines are killed with little notice.

Their AP range used to be ok but i wouldnt touch them with a barge pole now.

UK Ministry of Defence takes recruitment system offline, confirms data leak

Danny 14

Re: Final straw for the Army/Capita marriage?

apparently capita signed off the software on the ejection seat. probably aafer to bail out.

Danny 14

Re: "quality" (sic) was considered enough of an issue to give the contract...to the highest bidder.

not if the 500 phone has a 450worth kardashian label on it.

Depends on the 30 whiskey, ive had some bad "local" nolabel and some really good local nolabel stuff.

beats audio is shite, you pay for the label but is consistently more expensive.

Dell XPS line has almost the same components as an asus ROG line but is twice as expensive with the same level of basic RTB support (im not talking about adding on the onsite support: apples with apples)

Ford to sell unfinished Explorers as chip shortage bites

Danny 14

Re: Thank god for small favors

what is the range of an electric car at -25C? 10 miles?

Danny 14

Re: Thank god for small favors

Up here in Norway we tend to have preheat as an option. It is a far better solution to get into a fully heated car.

Extradited Canadian accused of unleashing NetWalker ransomware

Danny 14

Re: FBI / US Justice Department

i was thinking 28M in bitcoin and not living in the maldives.

Moscow to issue HTTPS certs to Russian websites

Danny 14

isnt Yorkshire tea just regular tea bags that have been dried out and reused? That sounds like a Yorkshire thing.

allegedly. red rose forever!

Danny 14

Re: This won’t help them to spy

They can spy via MitM. So now your browser trusts that KremlinTech has signed your webserver cert and is a trusted RootAuth. If they decided to MitM at KremlinISP the client will be presented with KremlinTech cert, which is trusted by the client.

Not totally invisible but much easier.

It also makes it much easier for the rst of us to put the cert in the bin where it belongs.

Russia acknowledges sanctions could hurt its tech companies

Danny 14

Re: Voodoo economics

The problem is, what are they going to pay China with? Most likely cheap oil and gas. This will then free up global supplies for the rest of the world. China will go back to cheap manufacturing having had Russia over a barrel (literally). They will also gladly sell Russia knock off chips, parts, cars etc. Proxy state almost.

Danny 14

EU can lift quotas, you will be surprised how fast the EU could fill gaps. It is simply cheaper to let Ukraine export

Danny 14

plus he will find it harder when the government fall back to Lviv. That is getting closer to Nato borders, bad shit will happen if it spills over.

We wont need gas to keep things warmer in the winter by that time. We will need some good factor sunblock.

Danny 14

super hornets even had their transponders on yesterday flying CAP on Romanian border. Plenty UH60's going backwards and forwards too. It was decent enough to see the usual stratotanker lining up with a pair of hornets.

Seems the sky fuel trucks have an 8 hour shift too, as they cross over on the way back to Ramstein after 6.5 hours on station.

My mum is addicted to watching them, she got a nice picture of a pair of hercules circling to drop height, flying towards the border then the transponders went dark. She's an ex RAF SGT from the 50's and still has her marbles.

Cloudflare, Akamai: Why we're not pulling out of Russia

Danny 14

that isnt the worrying part. The worrying part is that some of his voters will think that is a good idea.

Danny 14

I was lucky enough to visit Moscow in the iron curtain years, it was a business trip at the time (not a necessary one, more of a "fancy a jolly" one. My only real knowledge of Russia in the late 80's was from watching films like Firefox etc.

TBH it felt fairly safe and just like many other large cities, I managed to get some nice photos and had an interesting midweek there.

There is no way I would have gone back in the past decade.

Danny 14

to be fair the argument against would be "Hey maybe Putin has a point and I can see why he is bombing the shite out of civilians, cities, humanitarian convoys."

Russia mulls making software piracy legal and patent licensing compulsory

Danny 14

Re: re: countries that haven't ventured an opinion on the invasion and shelling of civilians

NVM

Danny 14

Re: re: countries that haven't ventured an opinion on the invasion and shelling of civilians

Indeed, Putin has just set a NATO marketing campaign in motion.

"Dont want to join our club? You do have one of those neighbours that kicks your fences down and shits on your lawn each night"

Danny 14

Re: re: countries that haven't ventured an opinion on the invasion and shelling of civilians

That was what I thought initially. Vlad thinking "I will invade Ukraine, absorb it into new found Peoples Democratic Republic of Russia all because I dont want NATO on my border". Then all of a sudden realises that NATO is next door.

Danny 14

Re: re: countries that haven't ventured an opinion on the invasion and shelling of civilians

Correct me if im wrong but I havent seen any massive major levelling of Palestinian *cities* by daily artillery, air strikes, missile strikes - all after a condemnation by the international community?

I cant seem to remember the US or UK doing so either.

Danny 14

Re: Yay!

oh im sure the US are looking at the stats and Russian response times. I bet it has been an ELINT fest. Looking at flightradar et al there have been so many AWACS, drones, sniffer planes flying along the border it will have been an intelligence feast.

The problem is, this is all on the backs of the poor Ukranians who are getting the shit kicked out of them, and not just the military.

Here is hoping some of his cronies end up being poor and taking it out on Vlad.

Danny 14

as much as I hate the SaaS model, this will simply mean Russia sits on old unpatched software. Im betting this stance will be endorsed by other western (and Israeli) governments.

Internet backbone provider Lumen quits Russia

Danny 14

Re: Hire a few hundred thousand biplanes.

I can assure you that even small prop planes can be targeted by modern fighter aircraft. Quite a few smaller countries operate prop craft as fighters.

If you are talking about canvas biplanes then why waste a jet when a .50 will do?

Microsoft patches critical remote-code-exec hole in Exchange Server and others

Danny 14

Re: That's it. Enough already.

ahh good old dixons

10 print "dixons smells"

20 goto 10

The youth of yesterday.