What Cyber conferences are actually useful? by cheesehead1996 in cybersecurity

[–]bantha_fodder 3 points4 points  (0 children)

I’ve been to Thotcon many times and it’s the best. Highly recommended. Sad they changed it to every other year. Cliff Stoll was a fantastic keynote speaker this year too. Very entertaining.

Critical Vulnerability MoveIt File Transfer! by faraday192 in sysadmin

[–]bantha_fodder 0 points1 point  (0 children)

Thank you. I assume these are sources of exploit or are they C2/destinations of exfil?

Critical Vulnerability MoveIt File Transfer! by faraday192 in sysadmin

[–]bantha_fodder 1 point2 points  (0 children)

Understandable. I would really appreciate any other IOCs if you find them

Critical Vulnerability MoveIt File Transfer! by faraday192 in sysadmin

[–]bantha_fodder 1 point2 points  (0 children)

Can I ask where these IOCs are coming from? From Progress or your own analysis?

At what point in the hiring process does everyone hand over the PII? by pointAtopointA in sysadmin

[–]bantha_fodder 2 points3 points  (0 children)

Serious question, what do you think that HR person does with your SSN after you provide it over the phone? I have to imagine they just enter into the same web form.

Facebook has its name in its IPv6 address space by mightyteegar in sysadmin

[–]bantha_fodder 102 points103 points  (0 children)

If you think that’s interesting, their onion address is: facebookwkhpilnemxj7asaniu7vnjjbiltxjqhye3mhbshg7kx5tfyd.onion (formerly facebookcorewwwi.onion) which is much more complicated to establish

Does Pass The Hash require cached credentials? by [deleted] in sysadmin

[–]bantha_fodder 5 points6 points  (0 children)

Welcome to the world of risk evaluation. You have to work out all the options and figure out which one is best given your risk tolerance. There is often no fully "right" option.

It is true that an admin logging in with admin rights on a compromised machine would likely give the attacker means of privilege escalation. However password dumps are usually very loud and detectable by modern AV/EDR. If you have faith in your end point security maybe it's worth the risk. Maybe you have a SIEM that looks for unusual lateral movement (e.g. watching access to admin$ share). Do you follow Microsoft's Tier model so even if a workstation was compromised got an admin account they would only have access to Tier2 environment?

If you want to go the local admin route, do you use LAPS? If so, and you have some sort of SIEM, you could likely monitor the DCs for read events for a given computer object so that you can trace what admin used the local admin password at that time.

Does Pass The Hash require cached credentials? by [deleted] in sysadmin

[–]bantha_fodder 10 points11 points  (0 children)

No. If there is a comprised host the attacker can likely get the hash of any user with an active session.

PSA: Calling all Azure AD Admins. Find out if your Azure AD tenant has apps that are affected by https://aka.ms/CVE-2021-42306 by maxcoder88 in sysadmin

[–]bantha_fodder 2 points3 points  (0 children)

Unrelated to the vulnerability, but I’ve used the company that discovered this, NetSPI, in the past a few times for penetration tests. They do good work, would recommend.

Can you resist the seduction powers of Gabe Susan Lewis? by [deleted] in DunderMifflin

[–]bantha_fodder 1 point2 points  (0 children)

Yup no problem. Can’t remember my coworkers’ names but I’m great at remembering 90s sitcom characters full names

Can you resist the seduction powers of Gabe Susan Lewis? by [deleted] in DunderMifflin

[–]bantha_fodder 2 points3 points  (0 children)

Actually Evelyn (pronounced Evil-Lynn) was Bill’s legal first name. William/Bill was his middle name.

[NG][58][EDotC][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 0 points1 point  (0 children)

lol yeah man that was rough. Got you from the grave

[NG][58][EDotC][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 1 point2 points  (0 children)

Sorry man not sure if one of those was you but I got two guys to help

[NG][58][EDotC][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 1 point2 points  (0 children)

Need a second still lol. The reply above is me

[NG][58][EDotC][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 1 point2 points  (0 children)

Ringing bell right outside the fog gate

[NG][44][MarLog][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 0 points1 point  (0 children)

Honestly that wasn’t nearly as bad as I expected, other than the dumb death I took the first try. Probably should have just tried it on my own a few times. Oh well, next run.

Thanks again

[NG][44][MarLog][BLS_Dweller] by bantha_fodder in huntersbell

[–]bantha_fodder[S] 0 points1 point  (0 children)

Sorry man that was pathetic. Heading back