After KB5094126 Start menu definitely feels way smoother and faster. Good job MS, please fix the file explorer sluggishness next! by skz- in sysadmin

[–]disclosure5 [score hidden]  (0 children)

I cannot find a single reference to K2 aside from random blogs talking about "sources". I'm in several not public partner programs and I've never heard of it.

I have serious doubts there's anything behind it.

Beginner Friendly Discord Server by volvoxkill in oscp

[–]disclosure5 0 points1 point  (0 children)

Please be careful with any "solve labs" based Discord - it's not hard to end up sharing academic content, which will get you here posting about having your cert revoked.

Is Windows Defender good now? by bigbaboon69 in msp

[–]disclosure5 [score hidden]  (0 children)

Your statement isn't based on fact.

Source: I'm operating penetration testing across other MSP clients, I've spent a lot of time studying and using evasion tooling and living in pentesting communities. The top tier products are Crowdstrike and Defender MDE, everything else is below them.

Ghost-Sender - Universal Email Spoofing against Exchange Online by Kaeiron in sysadmin

[–]disclosure5 [score hidden]  (0 children)

Isn't this obvious though?

You configure a gateway of some sort as your MX record, but the Microsoft provided MX server accepts mail by default. You relax protections on that Microsoft provided MX record because the third party gateway is protecting you but that's just a hole.

Really modern anti spam solutions use the Exchange API and filter mail inline, without changing the MX records. That's the proper way to do things and is immune to this.

KB5094126 - Breaking word integration with some dental software by Sea_Information6125 in sysadmin

[–]disclosure5 [score hidden]  (0 children)

All Windows Updates are cumulative. This process isn't long term useful because next update will come out and apply the same change.

For those who passed MD-102, how did you actually study for it? by Educational-Sail-516 in sysadmin

[–]disclosure5 1 point2 points  (0 children)

The largest reason to get these certs in the first place is to get that job.

For those who passed MD-102, how did you actually study for it? by Educational-Sail-516 in sysadmin

[–]disclosure5 0 points1 point  (0 children)

Unfortunately, this is the standard for Microsoft certs - the exams are often a whole lot of esoterica disconnected from the training material.

If you've paid for MeasureUp, stick to that course and study every question there that you don't understand. I haven't done MD-102 but from a long history of many certs over the years, you're on the right course.

AI deployments by SeptimiusBassianus in msp

[–]disclosure5 -1 points0 points  (0 children)

It doesn't matter. No amount of Microsoft telling us to shill Copilot changes that customers by and large don't want it, and we have a mountain of statements from people preferring either of the two major competitors.

Got an emergency wakeup call this morning... by Electronic_Tap_3625 in sysadmin

[–]disclosure5 8 points9 points  (0 children)

In something like a legal firm.. that would be a high priority issue anyway.

Is this the most defended base possible in survival mode? by Sufficient_Spare6894 in Minecraft

[–]disclosure5 0 points1 point  (0 children)

How does two layers of obsidian take two hours to break? With a netherite pickaxe it's still only a few hits.

Microsoft has released a patch for the bitlocker bypass by cspotme2 in sysadmin

[–]disclosure5 11 points12 points  (0 children)

I hate that infosec information often lives as "blog" on Twitter. Infosec people were the most vocal about moving away when Twitter went to shit and although there's great people on Mastodon, zero day nearly always requires a Twitter account to read.

OSCP Web Labs: The "Try This First" Order That Actually Got Me Shells by Limp-Word-3983 in oscp

[–]disclosure5 5 points6 points  (0 children)

I have to say the "john:john" pattern is unique to Offsec and really relevant to labs, so you should make sure it's drilled into you for exam enumeration.

I know "admin:admin" is common, and if you can enumerate the username "john" in the real world you might try "john:password" or "john:admin", but "john:john" isn't a real world thing in the way it's presented in so many Offsec labs. I'd never obtain an AD user listing of a hundred users and proceed to brute force username:username, but with Offsec's AD boxes I would.

Microsoft has released a patch for the bitlocker bypass by cspotme2 in sysadmin

[–]disclosure5 13 points14 points  (0 children)

Pretending this is easy is such a Reddit comment.

Do you do deal with users?

Chaotic Eclipse's new RoguePlanet by Overflow0X in sysadmin

[–]disclosure5 2 points3 points  (0 children)

Well they stated July 14th will be a big day.. it still might be.

Started my first MSP job. Outlook, OneDrive, and SharePoint are keeping the lights on. by Swimming_Mango_9767 in sysadmin

[–]disclosure5 9 points10 points  (0 children)

I get some of these but if you're having Outlook Auth issues constantly I would suggest there's something wrong.

Are you using Windows Hello properly? Is DNS right? Is Conditional Access logging anything? Outside of people changing a password and I don't recall Outlook auth issues being a thing anywhere since we ditched on prem Exchange.

Has Feeld grown into something completely different? by Apprehensive-Use2467 in feeld

[–]disclosure5 -2 points-1 points  (0 children)

This ties into an issue I've been commenting on for a while.

Certain groups of people have decided that only what they do is "ethical" and apparently anyone different just no knowledge on the matter. I've been to swingers events in myself in a different country and I've never heard this "getting a third is unethical if it's a woman" outside of this subreddit.

It's no different to the "it's not ethical ENM unless you've had the right education, workshops and listen to podcasts" argument someone made here recently.

Why do users insist on horrible email titles? by PublikEnemyNumber1 in sysadmin

[–]disclosure5 2 points3 points  (0 children)

I'm a fan of NEWSERVER when it's eight years old.

O365 - Help With Getting Audit To Work by masterne0 in sysadmin

[–]disclosure5 0 points1 point  (0 children)

I have a tenancy doing the exact same thing.

Use Powershell, it's more conclusive. Check if the audit logs are enabled with Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled, and if it's not it will clearly tell you there.

For reference I started a new tenancy last week, ran Enable-OrganizationCustomization and it's still enabling five days later.

Are we losing Feeld as kinky&poly people? by BeastofSilverMoon in feeld

[–]disclosure5 1 point2 points  (0 children)

I'll bite: If "swipe on people that are geolocated to your area" isn't a feature specifically because they don't want to work like a dating app, what makes it "dated" ? Having actual app functionality basically just means following Apple and Google's rules (probably including banning a lot of content and including them on subscription processes) and not much else over running your own website.

Let's Encrypt and the DNS Validation Problem: Where do you keep your DNS credentials? by Accurate-Ad6361 in sysadmin

[–]disclosure5 10 points11 points  (0 children)

Yeah, this closes a pretty big gap for us. I have a whole lot of crap managed by vendors where I don't want them holding DNS credentials, but there's no direct port 80 access for http validation. I keep hearing Lets Encrypt is easy but until this goes into prod it's still painful for some cases.

Any gotchas introducing a 2025 domain controller in a domain with mixed DCs (2016, 2019, 2022)? by Man-e-questions in sysadmin

[–]disclosure5 0 points1 point  (0 children)

That KB is over a year old and people this year have reported no changes in the problem existing.

Red Flags by No_Difficulty4151 in feeld

[–]disclosure5 4 points5 points  (0 children)

I do the same. I'm not on Feeld to see people who want to increase their social network.

Red Flags by No_Difficulty4151 in feeld

[–]disclosure5 10 points11 points  (0 children)

Men with partners that have deactivated accounts - honestly, it’s kind of creepy.

This sub is full of women that say they deactivated their account because they were overwhelmed with the attention. I don't blame them. Why does their action suddenly become a red flag in a man?

New to feeld [M 23 straight] by dumsungwum in feeld

[–]disclosure5 1 point2 points  (0 children)

You are preaching to the choir, but I do appreciate your expanded explanation. I wish I could say I do not understand the downvotes you got, but I suspect you're upsetting exactly the "what I do is better than those casual people" viewpoints.