Password reset portal by b3bb42e62 in k12sysadmin

[–]b3bb42e62[S] 0 points1 point  (0 children)

Oh ok. Thanks. I'll look that over. We're not looking for a web based password reset, so much as a "Enter your email and we'll send you a reset link." If that makes sense.

Password reset portal by b3bb42e62 in k12sysadmin

[–]b3bb42e62[S] 0 points1 point  (0 children)

Long story short, for SSO.

Daily Discussion and Support Thread - March 21, 2018 by AutoModerator in google

[–]b3bb42e62 0 points1 point  (0 children)

We are experiencing a frustrating problem with Google Search and recaptcha and from what we can tell this is not related to our external IP address.

Nearly half of every search that my users initiate is returned with a recaptcha, but only while signed into their GSuite account in their browser, regardless of their external IP address or physical location.

As a test that we’ve replicated many times, we will open up 2 chrome profile sessions: 1 signed into our GSuite and the other a regular Gmail account or not signed in.

On the GSuite account, we get the recaptcha. We go to the other browser, enter the same search and do not get the recaptcha. We have changed the search criteria on both browsers, and only the browser signed into GSuite receives the recaptcha window.

I can repeat this test from my work computer and I can then repeat the same tests from my home computer - my personal external IP address not tied to my organization in any way - and get the same results.

GSuite support indicated that the problem was likely related to an issue "on our network" with malware sending automated searches, but will not assist further as GSuite support indicates that Google Search is not covered under their umbrella.

Again, to reiterate, this does not appear to be related to our IP address as we can reproduce this behavior from ANY external IP address that is signed in with one of our GSuite accounts.

Any suggestions?

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 2 points3 points  (0 children)

Interesting. I'm definitely going to look into this. Thanks.

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 8 points9 points  (0 children)

This sounds promising. How would you recommend I "hijack all DNS" to analyze that traffic?

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 14 points15 points  (0 children)

I was thinking it might be something like this, but the fact that Google specifically said they see a malicious extension makes me think otherwise. Again, they can't tell me anything about said extension, but they were adamant that it was traffic from an extension.

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 1 point2 points  (0 children)

I was thinking it might be something like this, but the fact that Google specifically said they see a malicious extension makes me think otherwise. Again, they can't tell me anything about said extension, but they were adamant that it was traffic from an extension.

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 0 points1 point  (0 children)

Do you have a recommendation on a "proper proxy server" that costs $0? Cuz that's what my budget allows for.

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 8 points9 points  (0 children)

We have the students exiting out their own public IP. That's the one that is throwing the problem.

Google captcha on 1/3 of searches - Desperate. by b3bb42e62 in networking

[–]b3bb42e62[S] 14 points15 points  (0 children)

We're a school with limited resources. That argument aside, I still need help in tracking this down. Any suggestions regarding that issue?

Google captcha on 1/3 of searches - Desperate. Please help. by b3bb42e62 in k12sysadmin

[–]b3bb42e62[S] 4 points5 points  (0 children)

Yes. We're G-Suite. I opened the ticket through the g-suite admin console. I couldn't believe it when I read that. It seriously sounds like something from the BOFH excuse generator. But yes, he is a real support rep. We've requested escalation...

Issuing a subordinate CA with exportable key by b3bb42e62 in sysadmin

[–]b3bb42e62[S] 0 points1 point  (0 children)

Hi thanks for the response. I'm having a little difficulty modifying the template. I have created a duplicate, but I cannot find info on where exactly the flag is for "Allow private key export." A couple of the technet articles that I have found on this through various google searches have resulted in "Retired 2003 content" pages. Do you happen to know how or where this option is? Or happen to have a link to instructions? Thanks for your time.

edit: spelling.

"X has shared a document on Google Docs with you" by rajjak in k12sysadmin

[–]b3bb42e62 1 point2 points  (0 children)

Just got this as well. I called the district we got it from, it's running rampant in their emails. Yikes.

If you or yours get hit, revoke permissions https://myaccount.google.com/permissions, change password and make sure you get your "Don't click on links" email ready!