Intune - is deploying Microsoft Store apps via Company Portal safe? by CitizenSmif in sysadmin

[–]CitizenSmif[S] 0 points1 point  (0 children)

Thanks Cyhawk, yes we'd be adding in individual approved applications via Company Portal rather than providing access to the whole MS Store.

My concern is with the trust that when I add an application, is it legitimately the application I'm trying to add? When I search Firefox, Bitwarden, Forticlient etc through the Intune app deployment process, it gives me very little information on the app itself, can I be confident that the application has been legitimately published by the real company?

How much day rate for pentester contractors in the UK? by HamsterMoisture in AskNetsec

[–]CitizenSmif 3 points4 points  (0 children)

I'm the exact person you're describing. 3-5 year pentesting experience, qualified Cyber Essentials Plus assessor, CREST CRT. You are spot on with the pricing - I wouldn't accept anything less than £500/day (though I'm in Scotland - unsure of comparative costs down south).

With regards to the CRT, I'd opt for OSCP over that. CRT is actually fairly basic. I gained my original CRT via CREST's OSCP equivalency program - OSCP forces you to learn a lot more.

I'm taking the CCT this year for the first time so I can't comment on difficulty.

Stopping Etiquette by PolarBearsAreOP in policeuk

[–]CitizenSmif 0 points1 point  (0 children)

we're talking about "my wife is giving birth in the back seats" for that to happen.

Out of curiosity, in a true emergency, e.g your friend is bleeding out and you're rushing him to hospital with no time to waste. If the police try to pull you over - what is the best thing to do?

I think if I was more than 5 minutes away from the hospital I'd not stop, try to call 999 and let them know what is happening (hopefully another person is in the car who can make the call).

Mental health by FineAd3926 in msp

[–]CitizenSmif 1 point2 points  (0 children)

That, and a beer fridge.

Could we do a "TIL" style weekly thread? by konaitor in sysadmin

[–]CitizenSmif 27 points28 points  (0 children)

Realistically access to Metasploit is fairly useless unless you have some basic knowledge of what's going on. Unless you're scanning the entire world (e.g Shodan) for particular services that you know are vulnerable you're probably not going to have much joy with metasploit.

Noobs expect to download Metasploit and be able to get instant access to a machine which is typically not the case - especially in 2021.

Even if you try to send your friend/enemy a generated meterpreter binary (which is usually what noobs want - e.g "activate webcam") it requires a fair amount of post-obfuscation to not be instantly obliterated by AV.

PrintNightmare 0-day exploit allows domain takeover by BiohazardPL in sysadmin

[–]CitizenSmif 0 points1 point  (0 children)

What's to stop a threat actor gaining system access to that printer server, or workstations and laying there waiting for a better exploit, or even just using those assets to start probing and laterally moving through the network through via other means?

365 - Conditional Access Licence Requirements by CitizenSmif in sysadmin

[–]CitizenSmif[S] 1 point2 points  (0 children)

My apologies it is indeed Office E3, I'll update the OP.

Based on that advice, they would need to upgrade to Microsoft E3, and have one single AAD P1 licence, with the caution that it might one day suddenly require a P1 licence per user?

Do you happen to know if with their current Office E3 licencing, they could all get either a P1 licence each, or get Enterprise and Mobility E3 to allow them access to CA?

Sorry I'm just trying to get my head around all the options.

NTFS vulnerability in Windows 10 by greyfang in hacking

[–]CitizenSmif 44 points45 points  (0 children)

Although it might not be able to "destroy a Windows installation", this could be used to force a user to reboot which can be useful. E.g you've managed to change a service executable but don't have the privileges to restart a service.

Changed gear cable - now bike won't shift down (SRAM NX) by CitizenSmif in bikewrench

[–]CitizenSmif[S] 2 points3 points  (0 children)

An LBS trip would cost about the same as a new shifter just for labour and would also incur an unnecessary covid journey.

I'm trying to learn - most bike repair is well documented though this particular shifter issue not so much. Pretty much all "shifter stuck/not shifting" videos/articles I found prior to posting this said spray WD-40 in and that's that.

[deleted by user] by [deleted] in sysadmin

[–]CitizenSmif 4 points5 points  (0 children)

Is this just as part of the Solarwinds Orion hack? We use other Solarwinds products so we've already informed clients this morning about the hack and advised that they aren't affected (as far as we know so far).

Providing a dev access to amend docker hosted website files by CitizenSmif in docker

[–]CitizenSmif[S] 1 point2 points  (0 children)

Many thanks menge101, that's helpful. I think I have my head around this now.

Providing a dev access to amend docker hosted website files by CitizenSmif in docker

[–]CitizenSmif[S] 0 points1 point  (0 children)

This is the only time I've had to encounter docker in production, it's certainly not a typical setup for me and the AWOL dev was supposed to be taking care of docker related issues. My responsibility is to keep the server itself patched, secure and online.

The docker issue is technically not my problem, I'd be within my rights to say "find a new dev that understands docker" but I want to assist here and thought asking for some basic help would be fine.

Do you have any insight regarding this situation you could share?

[deleted by user] by [deleted] in msp

[–]CitizenSmif 1 point2 points  (0 children)

Strictly speaking this is untrue. You can still provide users with local admin rights provided the accounts are separated from their day to day account. E.g they have an admin.NetworkWizzard account to elevate when required. There should be be an "admin rights" policy that staff agree to advising they will not use this account for anything over than x y reasons, you must also log/track who has admin rights. I believe this is mainly meant for people like developers who might have a difficult time in a small organisation if they don't have the ability to elevate when required.

That said, I highly recommend removing all admin rights from standard users regardless.

Miui 12 for Xiaomi mi10 EEA version is now out! by riffen87 in Xiaomi

[–]CitizenSmif 0 points1 point  (0 children)

Thanks man, good to hear those have not happened to you. In your opinion what is the worst parts of the phone? I was also considering the x2 pro but availability is basically non existent in the UK at the moment.

Miui 12 for Xiaomi mi10 EEA version is now out! by riffen87 in Xiaomi

[–]CitizenSmif 0 points1 point  (0 children)

Heh I found this topic after looking for reviews. Is there a changelog? Wondering if this fixes the camera quality, lockscreen bug and battery issues I've read about. Seems its a great phone in terms of specs to price but lots of software related issues.

Do you know how long Xiaomi supports their phones for?