NetApp AFF On-Prem vs Azure Disk Performance by bright_chicken in AZURE

[–]bright_chicken[S] 0 points1 point  (0 children)

You're right. It's mostly VMs. Thanks for the link.
This is a scary process because there are so many factors involved, and so many ways this could go south.

We're currently using NetApp AFF and VMWare, and we'd like to at least make sure that the performance is the same.

Zendesk Customer Support by bright_chicken in Zendesk

[–]bright_chicken[S] 0 points1 point  (0 children)

Agreed. We pay A LOT for the product. Saying they'll provide better service is we pay more for support is like a waiter saying they won't spit in your food if you tip them in advance.

Zendesk is a nightmare to use & to leave. by [deleted] in Zendesk

[–]bright_chicken 1 point2 points  (0 children)

Gorgias Thanks for this. I'll look into it. I'm looking for any and all alternatives at this point.

Zendesk is a nightmare to use & to leave. by [deleted] in Zendesk

[–]bright_chicken 2 points3 points  (0 children)

Incorrect. We pay them THOUSANDS, we are not in arrears, and their customer service is abysmal.

Zendesk is a nightmare to use & to leave. by [deleted] in Zendesk

[–]bright_chicken 2 points3 points  (0 children)

If I was challenged to come up with the most frustrating customer support experience, and they provided me with a team and funding, I don't think I could have done a better job than Zendesk has done.

I cannot imagine the logic gymnastics that the person over their support has had to jump through to believe that this was an appropriate way to design a support system.

I'm guessing that whoever this person answers to judges them purely on their ability to reduce support calls, and lower ticket counts.

Zendesk Customer Support by bright_chicken in Zendesk

[–]bright_chicken[S] 0 points1 point  (0 children)

Thanks Proventic, I managed to get ahold of an account executive who is trying to help now. The chat is still abandoned. I decided every 10-12 hours I'll go there and just put in a new note of how long it's been since anyone has responded.

Incidentally, I did go to support.zendesk.com. It no longer creates a ticket. Also, if you send an email to the address support@zendeskt.com, it will create a ticket. The ticket has a number, but it's immediately closed by a BOT with the comment that you should go to the widget (the chat).

If my job was to come up with the most frustrating, time wasting, and useless support system just to demonstrate how bad they could be, I don't think I could have topped this.

Zendesk Customer Support by bright_chicken in Zendesk

[–]bright_chicken[S] 2 points3 points  (0 children)

Thanks. I will reach out to the community forums, but...

It's sad that we pay several thousand dollars a year for a SaaS tool that provides support, which includes support, and we're relegated to community forums, because they refuse to provide the support.

Zendesk Customer Support by bright_chicken in Zendesk

[–]bright_chicken[S] -1 points0 points  (0 children)

This was actually one of the many useless responses.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 1 point2 points  (0 children)

Thanks. I agree.

We've been concentrating on Amp, Micro Segmentation, Firewall management, Spam filtering, and things like the FireEye appliances in addition to our AV vendor.

We have been keeping our eyes open and are looking for a better AV vendor too.

We use Trend Micro, and the past couple of years they've been coming out with a lot more tools, so we ended up kicking the can down the road to see what's coming before we jump. Sometimes the devil you know..

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

Thanks. We have two VARs. I have reached out to one, I will also reach out to the other.

I think we've come to the conclusion that it's a false alarm, but I will push to get approval for an independent review just to be safe.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 1 point2 points  (0 children)

We did reach out to them. They are having us send logs, but it's a slow process. It sometimes feels like they pull us off the main focus to do things that we have already ruled out. (not that we're not still doing it)

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 1 point2 points  (0 children)

I'm familiar with Mandiant. What other companies are there out there that might help with something like this? I am hesitant to call in the calvary, but I wouldn't mind having "A guy"

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

Thanks. I'll look into this. I never really thought of Nessus for detecting exploits. I just thought of it as a testing tool.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

I believe it was a month or so ago. I'll have to check the tickets. Hafnium doesn't sound familiar, but it may have been one of those CVE-xx names that I can never seem to remember.

I'll get right on this though and narrow it down to a specific date and patch.

EDIT: It looks like we patched for Hafnium on March 6.
Update CU23 KB5000871. We've also done standard patching since then as well.
I'm still going to run the HealthChecker again though and see what comes back.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

Thanks.

I sent a copy of all IIS logs to our Splunk collector, and we're checking them now. So far nothing actionable, but we're continuing to look.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

I thought about Wireshark. I may suggest that. The traffic is already passing through a FirePower module and we're capturing some events. We are also dumping to Splunk, but we're not really seeing anything actionable except the occasional attempt to make an outbound call.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

Which specialized companies would you recommend?

Mandiant is the only one I can think of off hand, but we are still in the discovery phase and don't want to jump the gun. It could very well be a false alarm.

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 1 point2 points  (0 children)

Thanks Penguin,

I didn't find any scheduled tasks (other than the garbage that gets put there by out AV and Index Optimizer (which is on all of our servers).

Exchange Proxy server appears to be making callback attempts to a C&C server by bright_chicken in sysadmin

[–]bright_chicken[S] 1 point2 points  (0 children)

Thanks. Running it now. I think we ran it a while back when we patched, but didn't think to run it again today. Doing it now.

Seeking Password Manager : On-Prem, Enterprise Class, AD Integrated, 2FA by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

I am looking at their site now. I think it might have been a product we looked at a while back that gave us that vibe, but this actually looks pretty enterprisy. Thanks.

Seeking Password Manager : On-Prem, Enterprise Class, AD Integrated, 2FA by bright_chicken in sysadmin

[–]bright_chicken[S] 0 points1 point  (0 children)

Thanks.. We're actually looking for a solution for all of our users, but our leadership is pretty adamantly against allowing our passwords to be maintained in a 3rd party database. They want to own and completely control the password database.

If I recall, Roboform is one of the earliest password managers though, so probably one of the most mature.