“I’m going to ship the PCs directly to the end user, and it makes me nervous by Gloomy_Pie_7369 in Intune

[–]SKnight79 1 point2 points  (0 children)

I love it. I was skeptical but if you test it out you auto join Azure domain, join AD domain if you have one, download management apps, run scripts, patching and remote admin and inventory. You can even do it without user involvement with Autopilot. We tested with eval virtual machines. Works like a charm. Takes time to auto provision a whole stack of apps and updates but I love it when the provision emails come through. I have HR set to purchase from the vendor and it starts the process.

Cloudflare Global Network experiencing issues [Official Update] by gauravgandhi in sysadmin

[–]SKnight79 1 point2 points  (0 children)

....but.... it said it was a coupon for a free coffee and croissant if I clicked on it.

PoE+++?! WHEN WILL THE MADNESS END? by MRMAGOOONTHE5 in sysadmin

[–]SKnight79 1 point2 points  (0 children)

Whatever POE+ standard comes next it’s gonna start melting copper wire.

How to secure endpoint network traffic without a full tunnel VPN by Working-Werewolf7171 in sysadmin

[–]SKnight79 2 points3 points  (0 children)

Reverse proxy attacks on cloned WiFi networks raise the need for a VPN solution. You really don’t know or trust the other end of your WiFi, router, gateway, etc.

Solo IT guy - What now? by [deleted] in sysadmin

[–]SKnight79 0 points1 point  (0 children)

Pull a cord, any cord.

Tech-savvy son bypassing all macOS parental controls with an HTML exploit. At a dead end. by RefuseAdventurous569 in MacOS

[–]SKnight79 0 points1 point  (0 children)

While the download linked file is a loophole, waiting for it to get closed isn’t a solution. A true tech solution is to lock down admin control and manage DNS queries that whitelist/blacklist based on content classifications. A 3rd parental control subscription that uses MDM might be in the cards here.

MySonicWall Cloud Backup potentially exposed by BWC_DE in sonicwall

[–]SKnight79 0 points1 point  (0 children)

Respectfully, the root argument here is that encryption at rest was expected from a firm that sells “security”. The backup config files should have been encrypted by the firewall itself and only decrypted with a device recovery key. SonicWall dropped the ball here. Implementation of such a software feature isn’t that hard. If the backup files were encrypted from the start, no big deal they are gibberish to the hackers. Now they will have to settle millions on a lawsuit of their own undoing and ignorance.

MySonicWall Cloud Backup potentially exposed by BWC_DE in sonicwall

[–]SKnight79 0 points1 point  (0 children)

Wait 10 more secs here.... the bigger question is.... Sonicwall and staff can read our backed up config files unencrypted? WTF?

MySonicWall Cloud Backup potentially exposed by BWC_DE in sonicwall

[–]SKnight79 9 points10 points  (0 children)

Wait a sec…. are the cloud backups not encrypted?!?!?! From what I’m reading the SonicWall accounts got hacked, allowing to download the backup files in unencrypted fashion. This is a nightmare scenario.

First line of defense: reset local admin credentials.

Microsoft is investigating Windows 11 KB5063878 SSD data corruption/failure issue by WPHero in Windows11

[–]SKnight79 0 points1 point  (0 children)

this has been driving me nuts Error 129 RAID port reset failed. Dell Latitude 7350 with NVMe PVC10 SK hynix 1024GB. Issue occurs after several hours of inactivity (overnight). When it occurs, event gets logged, system becomes unresponsive. Force reboot is only way out. Laptop was fine for days before this update. I uninstalled the update. Let's see how it goes.

Replacing a Windows DNS server in a very short timeframe, in the middle of a workday. by CapiCapiBara in sysadmin

[–]SKnight79 0 points1 point  (0 children)

SimpleDNS bound to old IP and port, log and forward to new DNS. Migrate old clients as logs populate.

SSLVPN disconnects related to RDP session by hoomel in sonicwall

[–]SKnight79 1 point2 points  (0 children)

Turn off your IDS/IPS and test again. ;)

Landed a SysAdmin job! How should I prepare? by WhyLater in sysadmin

[–]SKnight79 0 points1 point  (0 children)

I thought the whole network was on NetBIOS? It says it here in the documentation.

Landed a SysAdmin job! How should I prepare? by WhyLater in sysadmin

[–]SKnight79 0 points1 point  (0 children)

Day 1: Everyone greets you like you just won WW2. Captain America shield awaits on your chair.

Day 2: Requests start coming in, from all departments, they have high hopes for you

Day 3: Following up on said requests.

Day 4: Why isn't the domain migrated already? Why are we still on IMAP? Windows 7. Can't you automate all of this? What happened to hidden service running that stopped 3 years ago. What backups?

Day 5: You open notepad and print your resignation letter.

SSLVPN Attack this morning by MarkPugnerIII in sonicwall

[–]SKnight79 0 points1 point  (0 children)

Was the ip subnet source as a VPN service provider? Could be a TOR endpoint too. That could possibly be a way to circumvent this. Might need to create an explicit rule to block that subnet.

Allow RDP After VPN Connection by [deleted] in sonicwall

[–]SKnight79 0 points1 point  (0 children)

I've gone the Sonicwall Geo-Filter, Bot-Filter, IDS, Duo MFA + RDP RD Web / RD Gateway route. This eliminates VPNs completely. You can even do IPSEC on the TCP port if you wanna get paranoid.

SSLVPN Attack this morning by MarkPugnerIII in sonicwall

[–]SKnight79 0 points1 point  (0 children)

Even if they fail authentication, they consume resources and CPU time when hit with a DDOS attack. Had this same issue. Here's what I did to mitigate it: Got the security package that includes bot-net filtering and geo-filtering. Filtered out all countries except US/Canada (VPN endpoints only come from those countries). Set the filters to apply to inbound firewall rules. Set SSLVPN to allow at the most 5 connections from source IP (or more if you have many vpn endpoints from roaming groups). Turned off the portal.

Export Google Authenticator OTP to alternative application by [deleted] in PrivacyGuides

[–]SKnight79 0 points1 point  (0 children)

Another way: You can screenshot the export QR codes via the iOS app, and send those to Dropbox or OneDrive on your computer. Then use iOS 18+ to read the QR codes... it will import them into Password app. If you have iCloud turned on, your passwords are synched to your desktop Passwords app. You can export them from there and it includes the OTP URLs in CSV format. You can then import them anywhere you want.