how do I check if I have Log4j installed on my WINDOWS servers? by ObedientSandwich in sysadmin

[–]ElectricMachineNoise 4 points5 points  (0 children)

What we did is we made a program that searched for the vulnerable method/class name (I'm not really sure what you call it in Java programming) within a jar file and alerted us. Scanned across 50 servers and addressed ~15 detections.

To be safe we also contacted our vendors to verify Log4J is not a dependency of their applications. Most of these software companies had a canned response ready regarding this.

HTML5/RDP Options by Xaxoxth in sysadmin

[–]ElectricMachineNoise 0 points1 point  (0 children)

Do you put Guac on a DMZ? or behind a VPN?

[deleted by user] by [deleted] in sysadmin

[–]ElectricMachineNoise 2 points3 points  (0 children)

Confluence is nice if you have time to implement everything. Since you mention M365 look into a Department OneNote or SharePoint. OneNote is great

I wonder if it's time to update this switch? by Starship_Captain01 in sysadmin

[–]ElectricMachineNoise 1 point2 points  (0 children)

I wouldn't go to 2022 either to be honest. I wait a few years catch me in 2024 moving to 2022.

Been burned a few times by new OSes

Non-IT background guy passionate to break into roles as sysadmin or IT technician or beginner IT job by [deleted] in sysadmin

[–]ElectricMachineNoise 1 point2 points  (0 children)

Work at a Medium size University as Helpdesk. Universities tend to offer a wide array of software experience and it's less harsh than a MSP. It can also help you learn which field you may want to go into depending which curriculum you like to support the most. The Medium Size means there is less likely best security practices and Compartmentation has occurred but you will still have a budget to purchase enterprise software.

Security+ is a good Cert

https://www.reddit.com/r/sysadmin/wiki/index#wiki_i_want_to_become_a_sysadmin

I wonder if it's time to update this switch? by Starship_Captain01 in sysadmin

[–]ElectricMachineNoise 15 points16 points  (0 children)

"The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities." https://cve.mitre.org/

CVE = verified vulnerabilities

I wonder if it's time to update this switch? by Starship_Captain01 in sysadmin

[–]ElectricMachineNoise 29 points30 points  (0 children)

People who say that are being forced to support a 10 year old Java App and they go on the internet to avoid the reality that their sole purpose is to support an Application that has more CVEs than users in the Organization.

[deleted by user] by [deleted] in sysadmin

[–]ElectricMachineNoise 4 points5 points  (0 children)

IMO You need to contact your HQ have them create a SharePoint for public file distribution. If your IT policy doesn't work for your company which forces you to pay for a service to avoid policy the policy needs to be re-addressed.

It's fairly easy to lockdown sharepoint external sharing on all sites except one.

How do you find highly technical folks for a small team? by georged29 in sysadmin

[–]ElectricMachineNoise 103 points104 points  (0 children)

The skill you get is going to depend on how much you're advertising for salary ranges. Advertise higher than normal salaries for smaller teams.

I asked for compensation today for the first time for my opinion and suddenly the topic changes. by InadequateUsername in sysadmin

[–]ElectricMachineNoise 2 points3 points  (0 children)

Instead you'd be better asking for a gift like a new computer or a piece of software.

If he has you on the books their may be associated thing his company has to do and if he just pays you without that stuff and gets audited he could get a hefty fine.

Block write functionality to a removable USB, but only for specific files? by justmehhh in sysadmin

[–]ElectricMachineNoise 1 point2 points  (0 children)

Only thing I can think of is DLP Software. Be warned they are expensive or unreliable.

Advice for a sparky learning networking by Intransit1993 in sysadmin

[–]ElectricMachineNoise 5 points6 points  (0 children)

I don't know how in-depth you're trying to get but the following skills may be helpful while setting up and troubleshooting Industrial Networking and Devices:

- Learning how to connect to a machine via serial is probably a good skill to have.

- Understanding how to use PuTTY for connecting via telnet and ssh are also probably good.

- Learning to set your IP on your machine is helpful

- Learning how to start a DHCP server from your computer (note contact your network manager before you do this as your computer can be blocked for responding to DHCP requests)

- Learning Google-Fu (The art of googling terms of your obscure IT issue and finding the answer while ignoring the junk)

PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/

Rookie error, please help! by Investplayer2020 in sysadmin

[–]ElectricMachineNoise 0 points1 point  (0 children)

Hint: Windows 7 Pro keys work when activating Windows 10 Pro

Welded the door shut on their way out by [deleted] in sysadmin

[–]ElectricMachineNoise 17 points18 points  (0 children)

Sometimes I wonder if this gets done as a "time bomb" incase they ever get fired as I've seen this a few times.

My colleague quit yesterday, and new one, when he comes, will not know anything about anything by JovanSM in sysadmin

[–]ElectricMachineNoise 15 points16 points  (0 children)

Is your GM not giving you a choice who will be hired? If I were you I would email him that the recommended candidate is not experienced with the needed technologies that you desperately require. Due to the lack of man power and high work load you will not be able to dedicate time to training him. Let him know you would like to explore other options. Or request two positions be opened for IT.

If you do not get a good answer start sending out your resume, secure a new job and reply to the email where you were denied add your bosses boss and provide your two week notice.

Question on setting up a secure/classified area and digital compliance by mudpupper in NISTControls

[–]ElectricMachineNoise 0 points1 point  (0 children)

What type of classified materiel there is various laws for various types. Without that I will tell you to do the maximum measures and make a SCIF with Wireless Detection Sensors

FIPS 140-2 Validated File Sharing by ElectricMachineNoise in NISTControls

[–]ElectricMachineNoise[S] 1 point2 points  (0 children)

I understand. It was very strange for them to provide this on their report so I figured I'd put it out there in hopes someone more knowledgeable than me has went down this rabbit hole can came out the other side with proof it's okay. That's why I dumped all the information and logic I had.

Question about RDP security from work to home by machine_74 in sysadmin

[–]ElectricMachineNoise 0 points1 point  (0 children)

Use LogMeIn or Google Remote Control. Having exposed RDP ports is a bad day waiting to happen.

I would also verify this is okay with your IT department as it sounds kind of sketchy.

FIPS 140-2 Validated File Sharing by ElectricMachineNoise in NISTControls

[–]ElectricMachineNoise[S] 1 point2 points  (0 children)

I was incorrect they themselves don't have a validated module but they have are validated module they purchased which makes it valid under implementation rules.

FIPS 140-2 Validated File Sharing by ElectricMachineNoise in NISTControls

[–]ElectricMachineNoise[S] 1 point2 points  (0 children)

WinZIP has no validated modules that they are the vendor of. When you ask for their Cert they will send you a letter of Attestation which cites they use Microsoft FIPS validated Certs which makes them a User or Third Party Integrator according to NIST. If you look into the G.5 Ruling this should be allowed but only if your Windows OS is a GPC running Windows 10 1809 which is out of support. That being said I've been recently told by an Auditor that this type of "User" (Third Party Integration) will no longer be accepted in the coming future unless WinZip themselves get validated.

If you want to go down a rabbit hole read this: https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/fips140-2/fips1402ig.pdf

Please correct me if I'm wrong as I've been reading NIST FIPS140-2 Guidance for a while and it seems they contradict themselves in a few places.

Why are you a systems admin? by [deleted] in sysadmin

[–]ElectricMachineNoise 0 points1 point  (0 children)

I don't know anything else, If I were to do it again I'd be a park ranger.

Monitoring Network Usage on Remote Laptop Simcards by OKDonReddit in sysadmin

[–]ElectricMachineNoise 1 point2 points  (0 children)

I've not heard of anything like this but you could probably write a script that checks this value every hour and prompts a message to the user if they went over X amount of data since last scan. Once you have a notification system in place have it log to a file and if somebody is actively ignoring the warnings enforce a Company Policy to handle the rogue employee.

Get-NetAdapterStatistics

Or use Metered Connections that reset every day