[ / / / / / / / / / / / / / ] [ dir / agatha2 / animu / ausneets / b2 / choroy / dempart / freeb / vichan ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

File (hide): 021fc55be95afe5⋯.jpg (18.77 KB, 720x695, 144:139, aaa.jpg) (h) (u)

[–]

 No.1062943>>1062966 >>1062970 >>1062971 >>1063009 >>1063060 >>1063198 [Watch Thread][Show All Posts]

>be musclehead works on-field because that's what i'm good for

>occasionaly repair laptops (replace lcd,keyboards .etc) / pcs (upgrade parts, reinstalling OS, getting pirated games) / flashing android phones

>central office suddenly needs one more sysadmin guy

>he's mid age guy, in next 6 month he need to take a month off because his wife needs C-section, this happened few years ago that's why the top dog doesn't want the sysadmin position get empty

>once internal recruitment open, everyone recommends me because i'm their "tech jesus"

>the words eventually heard by HR and i got called, i got tasked to assist sysadmin from now on

>ohshit.jpg

>my friends in workshop keep encouraging me because i'm young and i'm suppose to advance more steps than them (they were 28-35 yo and i'm way younger)

>they keep saying it's going to be ok and make sure to visit sometimes because they might need help on something or just play CS on LAN together

>ended taking the job on early january and visit my bros every 2 week when i'm on day off

>sysadmin job starts smoothly, he's a cool guy

>every single PC which uses windows 7 are properly licensed, for granny on finance uses debian and got costumized almost looks like windows

>it just for gsuite works and basic printing, no need for installing for office suite as the works done entirely in browser

>the browser set up with umatrix and will break for sites which outside of gsuite

>some PC which locked on windows 7 and can't upgrade because we need it for specific proprietary cad/cam software

>every morning sysadmin dude always spent 2-3 hours to reads latest blogpost for CVEs, threatlist, securelist and whatever on his rss server and plays WOW/ESO afterwards

>once daily routines are done, he'll update the hosts blocklist and push it to his git repo, update on users pcs are monthly though

>almost all PC conditions are actually stored in git (like pc number, license, parts list, latest condition, who uses it, reverse autossh port for remote vnc)

>the git is actually stored on his thinkpad with slackware, all ports except charger line are filled with epoxy. peak hakerman i've ever seen for now

>fast forward to current_month while he's start taking days off

>everything are peaceful and under control

>suddenly got called from one user asking why is his pc antivirus keep blinking if a connection has been blocked

>apparently msiexec.exe is trying to access some scrambled russian domain, after quick searching it was one of ransomware domain

>ayylmao.jpeg ayylmao.zip ayylmao.tar.gz ayylmaos.7z

>quickly added the domain on host blocklist so the antivirus stop screaming

>after shits under control i tried to msg the sysadmin guy, he says it's weird because all of our instances are up to date, no crack ever used, no user ever got access to install things or running some random program off flashdrive

>only got told to be cautious to watch security news and windows update

i can't think anymore attack vector on our workstation, we paid heck for everything windows, corel, adobe. for other program we're using 7z for archives, sumatrapdf for top dog epaper if they want to view cad drawings.

phones are never in same network with worktation, most phones are yellow-black screen or symbian nokias. the latest-tech lady are using blackberry that only has EDGE broadband.

where are those virus thing are come? zerodays on company that barely have 40 pc? or is it even possible from the router? we're still using TP-link from ISP and it's really giving me paranoia seeing RCE for routers even though we're behind NAT

or is it even possible the virus comes from DNS? because my sysadmin guy just tells me that few months ago we're redirected to a site when mistyping something in HTTP. the redirection page from ISP contains js-based ransomware that poking baidu domain. after DNS changed to google'sdns, the problem go away for few week but now it's back.no matter DNS we use it's still got randomly redirected, or if the site is in HTTP it'll get injected with ads from ISP. how this dns fuckery could be stopped?

i also wish i could se what users pc is trying to access on web browser so i could notice if they "accidentaly" poking russian or israeli sites and somehow take countermeasure. what kind of knowledge do i need for this monitoring things?

sorry anon i was never that bright kid and probably repeatedly using fucked keyword on search engine but i'm willing to reads and learn for this sysadmin job

 No.1062946

T L fucking D R


 No.1062947

start simple - USB disabled on all stations?


 No.1062949>>1064316

Your memespeak story is far too difficult to read.


 No.1062952

>ports filled with epoxy

hot


 No.1062965

File (hide): 6dfa84162a6c7e9⋯.jpg (36.01 KB, 684x478, 342:239, D5K4TvJX4AEjD4C.jpg) (h) (u)

What did I just read?


 No.1062966

the absolute state of /tech/. filled with brainlets

>>1062943 (OP)

your sysadmin guy is based. also you seems looking for pfsense, or if you have extra shekel, check ntop.

just get a mid-tier pc, slap 2 x gigabit lan on it, the rest wire it as it's on firewall place. use dnscrypt for that ads injection problem. godspeed op


 No.1062969>>1062970

Maybe some idiot executed an attachment?


 No.1062970>>1063054 >>1063291

>>1062943 (OP)

USB key.

MS office macros in the documents.

Emails clients who renders HTML.

Files in emails.

0days.

>>1062969

This.


 No.1062971

>>1062943 (OP)

>or is it even possible from the router

Go on youtube and paste the brand or model number of your router and then add the word "backdoor".

https://librecmc.org


 No.1063009>>1063291

>>1062943 (OP)

>how this dns fuckery could be stopped

Look up DNS over https.


 No.1063022>>1063027

i hope that you have backups too. didnt see anything about that in your post and those ransomwares can fuck things up if the computer it is on has access to network shares


 No.1063027

>>1063022

Yeah, that sysadmin should have made sure to set up automated backups instead of playing WoW


 No.1063054>>1063291

>>1062970

This, it's probably Office macros.


 No.1063060

>>1062943 (OP)

Backups

There's also programs that keep an image of wingdings and everytime you boot it restores to that image, your sysadmin sounds baste despite playing shit games and could always be some super secret backdoor.


 No.1063135>>1063140

how do these systems not have any kind of protection against full filesystem overwrites.. would think that someone would have made that already since a normal user overwriting the whole filesystem even on the backup server sure isnt something that should happen.


 No.1063140

>>1063135

It really doesn't matter if the working system had corrupted by any means (user operating error, virus, hacker, hardware malfunction) everybody is supposed to have a formal data backup plan that's written down that anybody (any trained administrator) can follow. OP's operation is shit because his company doesn't have a plan in operation or otherwise OP can't access the backup plan


 No.1063161>>1063163 >>1063291

Can you epoxy the port that Intel ME connects to?


 No.1063163>>1063190

File (hide): ef5f2dbc47325a6⋯.png (115.25 KB, 531x640, 531:640, 2427935-oh-you-make-me-cry….png) (h) (u)

>>1063161

<epoxy the port that Intel ME connects to


 No.1063190>>1063193

>>1063163

>2427935-oh-you-make-me-cry-laughing-meme-rage-face-76677676.png


 No.1063193

>>1063190

suck it


 No.1063198>>1063268

>>1062943 (OP)

Never had one of those randsomware things. But sounds like a cool job, I guess I'll do that when I get PTSD from programming at some point


 No.1063268>>1063284

>>1063198

>randomware

Its a program that generates and runs random code.


 No.1063284

>>1063268

That's called a browser.


 No.1063291

>>1062970

>>1063054

It's also possible that it's a pdf, sumatra pdf extends a bit more the function of PDF than muPDF (even if sumatra uses muhpdf).

https://github.com/osnr/horrifying-pdf-experiments

>>1063009

This is possible too.

>>1063161

Topkek.

It's possible that some ME vulnerability could have been used.


 No.1064316>>1064317

>sumatrapdf

>last release 2016

>ghostscript sandbox bypass vuln was discovered 2018

Unsecure.

>antivirus

unreliable and slows down your PC, why would you use one? Just disable downloads in Firefox or something so that your retards can't download anything. Then they can't download viruses.

>ransomware

You should always have a backup anyway.

>redirection page from ISP contains js-based ransomware that poking baidu domain.

Sure dude.

>how this dns fuckery could be stopped?

Make sure Windows is not set automatically configure the DNS server.

Reinstall to be safe.

>>1062949

This,


 No.1064317

>>1064316

> is not set

*is set to


 No.1064346

I'm not reading that.




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
27 replies | 3 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / agatha2 / animu / ausneets / b2 / choroy / dempart / freeb / vichan ][ watchlist ]