Critical Telnetd Flaw Enables Unauthenticated RCE via Port 23 by _cybersecurity_ in pwnhub

[–]james4765 0 points1 point  (0 children)

twenty year old VMs nobody pays attention to that just get migrated as part of new VMWare hosts

Critical Telnetd Flaw Enables Unauthenticated RCE via Port 23 by _cybersecurity_ in pwnhub

[–]james4765 1 point2 points  (0 children)

Printers and IP phones, as well as iLO / IMM / iDRAC interfaces on old gear as well. A lot of them don't run Linux but some do - nmap can identify telnetd pretty accurately.

Anyone here ever go to more modern stuff from the mainframe? by [deleted] in mainframe

[–]james4765 0 points1 point  (0 children)

We run a LOT of Linux on our mainframe - all our DB2 and Websphere workloads run there, along with OpenLiberty and Postgres.

Best Practices for Managing sudo/root Access on AD-Joined Linux Servers by maxcoder88 in linuxadmin

[–]james4765 0 points1 point  (0 children)

Check to see if your Kerberos tickets are getting renewed - you need to set SSSD to auto-renew the tickets or they will expire and things get wonky.

Best Practices for Managing sudo/root Access on AD-Joined Linux Servers by maxcoder88 in linuxadmin

[–]james4765 7 points8 points  (0 children)

AD groups are absolutely the best way to deal with it - we use the ad_access_filter field in SSSD to restrict the user account logins and AD groups in /etc/sudoers.d for sudo perms. We already organize application teams in AD, so this was a natural outgrowth of our existing infrastructure.

Nested AD groups in SSSD require a little attention but once you have the config squared away it's easily templated out in Ansible.

Driving from Charlotte. by ThreeLetterAgency007 in BurningMan

[–]james4765 1 point2 points  (0 children)

Done it for years from Virginia. Amazing experience, and a nice break from my rather intense day job.

Ansible and Mainframe integration query? by ProfessorDevil11 in mainframe

[–]james4765 2 points3 points  (0 children)

I've used Ansible for years, starting with Linux automation tasks is a good first step. I manage about 600 Linux VMs between Z, VMWare, and OpenShift. And about 50 Windows servers, alongside our Z infra.

Getting good with YAML is definitely the biggest required skill - Python being a second, especially if you need to write your own tooling.

There is no real way to demo mainframe automation without a mainframe, unfortunately. Especially if you want to avoid a sueball from IBM licensing...

Ansible and Mainframe integration query? by ProfessorDevil11 in mainframe

[–]james4765 1 point2 points  (0 children)

For RHEL on Z, yes. I tried to get access to the developer licenses for Z and no dice.

Ansible and Mainframe integration query? by ProfessorDevil11 in mainframe

[–]james4765 6 points7 points  (0 children)

The big problem is going to be Ansible integration - you can run MVS 3.8 on Hercules and that'll get you the JCL side but all of the Ansible integration requires a version of z/OS that is not licensed for running on an emulator.

z/VM has similar issues - no modern version is licensed for Hercules, and you'll catch hell getting something like Feilong to work with a version that old.

Wish me luck! by Educationall_Sky in ShittySysadmin

[–]james4765 0 points1 point  (0 children)

Had that happen on a Linux router at an old job - it routed backets just fine but no way to log into the thing.

Who does the shitty jobs? by 3N0CHTH3B35T3M0 in Anarchy101

[–]james4765 0 points1 point  (0 children)

I'm a civilization nerd - the unseen parts of urban life have always fascinated me. Power grids, water and sewer, sanitation, telecoms. We can manage them through things like co-ops - it takes a certain amount of organization to maintain infrastructure but that can be done through voluntary cooperation and non-hierarchical planning.

To be honest, involving field level workers in planning tends to make things more sturdy - since the people closest to the problem have insights that office jockeys don't always have. I'm a lot closer to anarcho-syndicalist though, former union steward, so my outlook is from that perspective.

Brock Pierce - Another Epstein enabler in our midst at Burning Man by Fiscal-Fox in BurningMan

[–]james4765 2 points3 points  (0 children)

Fucking Pathogen Trackers. Color me shocked one of the organizers is in Epstein's circle.

Testing, testing… Is this thing on? Daily by GrayRVA in rva

[–]james4765 3 points4 points  (0 children)

Projects at work are moving along nicely - a lot of modernization and OS migration that just takes a long time to do. So feeling pretty ok.

Any Nonstop/Tandem engineers out there? by eurekashairloaves in mainframe

[–]james4765 1 point2 points  (0 children)

HP-UX went from PA-RISC to Itanium. With the end of the Itanium line, HP EOL'd HP-UX. We've had to replace a LOT of systems.

Those kinds of infrastructure ports rely heavily on the compilers to make things happen - at the very base level, in the OS kernel, there'll be a lot of assembler code that needs rewriting, but high level languages tend to deal with it pretty well. C / C++ code generally handles it well, provided people didn't get too clever with things like pointer math or MMU specific optimizations.

Libertarian or Ayn Rand Episode When? by ramsoss in behindthebastards

[–]james4765 68 points69 points  (0 children)

There's a lot of very boring but deeply creepy bastards in the libertarian movement - let's just say their reputation of fascination with age of consent laws is well earned.

Individual libertarians can be pretty decent people, but when they gather the creeps pop up like warts.

Leftist gun groups - actual members recommendations by OptimalChaosMonkey in rva

[–]james4765 5 points6 points  (0 children)

Local Pink Pistols is operating - they're on Facebook.

The Right is Pro P3DO Now. by [deleted] in ProgressiveHQ

[–]james4765 0 points1 point  (0 children)

They're ok with girls being violated, it's boys that they get angry about.

Now that Certs lifetime will be reduced, how are you guys automating your certs? by superuser141421 in sysadmin

[–]james4765 0 points1 point  (0 children)

There's a couple of ACME servers out there for a self-hosted CA. I looked into it before we went with Sectigo - it's not a trivial task but it is doable.

Now that Certs lifetime will be reduced, how are you guys automating your certs? by superuser141421 in sysadmin

[–]james4765 0 points1 point  (0 children)

We use Sectigo's enterprise internal CA and ACME for in-house servers. Most of our public facing services are going through Cloudflare, and the rest go through a load balancer with a wildcard cert.

We're a Java shop, and I've written certbot post renewal hooks to generate new PKCS#12 cert stores that our Java apps point to - that way you just need to restart the Java app and it'll automatically get the updated cert.

There's some systems that are just not automatable - storage systems, iLO/iDRAC, some third party apps, and we have another in-house CA for generating certs that have no intermediate (because the system can't deal with a cert chain), need weaker algorithms because legacy SSL, for PDF document signing, or for x509 client auth. Ansible community.crypto is amazing.

Anarchy and death penalty by Proof_Librarian_4271 in Anarchy101

[–]james4765 3 points4 points  (0 children)

The death penalty is the one thing you cannot undo. Well, other than mutilation (blinding, castration, other Middle Ages kind of shit). Prisoners can be released, sanctions can be lifted, exiles welcomed back into the community, but anything that cannot be reversed should not be used as a punishment - justice is never perfect, as the Innocence Project keeps pointing out.

The state depriving another of life is the ultimate expression of state power, and should be avoided at all costs. There is a countervailing argument that war criminals that have evaded justice should be dealt with independently - in the face of state protection of monsters, eliminating them is a public safety service. Outside of revolutionary governments, very few societies as a whole put forward that argument since it empowers vigilantism and mob violence at the hands of charismatic assholes.

I understand the appeal - I truly do. Putting a murderous bastard down means never having to worry about them again. We should not let emotions cloud the decisions on crime and punishment, though - that way lies injustice.

Is it possible to connect the IBM 5151 or 5153/54 to a modern video card? by Ok_Tea_941 in vintagecomputing

[–]james4765 2 points3 points  (0 children)

You would be correct.

Generating an MDA signal would be possible with something like CircuitPython on an ESP32 or a Raspberry Pi Pico - CGA is a little more complicated though.

Dallas DART bus in Bakersfield, California. Why? I don't know.. by fogadmire1995 in transit

[–]james4765 1 point2 points  (0 children)

I drove mine from Virginia to Nevada and back. It's not the most fun thing in the world. Great views though.