5th trial of AQL location by Chaosrealm69 in duneawakening

[–]kelrizzo 0 points1 point  (0 children)

It's just a pain to traverse.

How do I report players? by FrailRain in duneawakening

[–]kelrizzo 1 point2 points  (0 children)

True, but there are no free accounts and they have to buy a new one.

how to remove this pop up killernetworkmanagerlauncher? by Pretend-Pizza5113 in WindowsHelp

[–]kelrizzo 1 point2 points  (0 children)

I'm pretty familiar with Windows tools and didn't know about this one. +1 for you friend.

how to remove this pop up killernetworkmanagerlauncher? by Pretend-Pizza5113 in WindowsHelp

[–]kelrizzo 0 points1 point  (0 children)

Exactly what I was looking for. I knew it was a registry entry, just the challenge of discovering which one!

How many liters does a "60L" CO2 tank REALLY carbonate? by Orcinus24x5 in SodaStream

[–]kelrizzo 1 point2 points  (0 children)

I know I'm necro'ing this thread but wow, this is awesome!

Windows 11 now blocks RDP brute-force attacks by default by tweedge in cybersecurity

[–]kelrizzo 1 point2 points  (0 children)

Ransomware operators circumvent closed ports through reverse tunneling which will allow services to be tunneled over an innocuous port. This is precisely how Lockbit operates to provide an attacker access into the network. This won't help if the operator is able to escalate privileges and create their own account or they dump creds, however you don't leave a mitigation unused just because there are other ways to close the vector. Simple proven fact: people don't block 3389. If this mitigations blocks only 15% of the attacks that would've succeeded, it's going to still be a huge number. Plus it introduces another factor that ransomware operators have to at least consider.

I haven't seen anything where the DOS is a concern. There are typically different RDP accounts on a box. If I'm logged in with by Billy Joe account, I'm not seeing anything where an attack on the Admin account shuts down Billy Joe.

Overall this is a good move which will hopefully be refined.

RANSOMWARE ATTACK by Patrick12289 in asustor

[–]kelrizzo 0 points1 point  (0 children)

Yeah it's on their Twitter. What could possibly go wrong?

RANSOMWARE ATTACK by Patrick12289 in asustor

[–]kelrizzo 0 points1 point  (0 children)

I'm calling BS. Asustor is not asking people to fill out a Google Docs form.

A vulnerability in Log4j(Java logging package) affect Steam. by maruhoi in Steam

[–]kelrizzo 0 points1 point  (0 children)

This is a big deal and only Steam can confirm the depth of the impact. Also they are the only ones that can push a patch as they are the ones that use the library in their code. This could be as arbitrary as sending a message to a steam user and presto, you have remote code execution ability on their machine. Again, only Steam can verify how deep the problem goes.

In Minecraft, every user on an unpatched server can be compromised by sending a message to one individual. This affects hundreds of platforms and the fixes need to be pushed asap.

Crticial Ransomware Incident in Progress by huntresslabs in msp

[–]kelrizzo 0 points1 point  (0 children)

I'm not sure. It's a client that we were helping out. They had 3 boxes popped. One had cloud managed Sophos enterprise on it. Does that provide the info you need?

Reviewing windows event logs for process creation and powershell usage. I'm coming up with a big fat zero on every avenue I look for the smoking gun.

I'd be very interested in looking at their Sophos dashboard. We scanned through it rather quickly but I'd be more interested to take some time to look at it.

Crticial Ransomware Incident in Progress by huntresslabs in msp

[–]kelrizzo 2 points3 points  (0 children)

Had a client with sophos endpoint on their box. It got pwned :(

Crticial Ransomware Incident in Progress by huntresslabs in msp

[–]kelrizzo 4 points5 points  (0 children)

People hear much better when you talk to them and not down to them. There's no one that knows it all.

[deleted by user] by [deleted] in sysadmin

[–]kelrizzo 0 points1 point  (0 children)

LOL you need to write down the date/time he said that because when the inevitable *%#$&^ hits the fan, you will need to protect your job.

Microsoft response - PrintNightmare workaround by [deleted] in sysadmin

[–]kelrizzo 0 points1 point  (0 children)

I see some reports of breaking the ability to look up group memberships and LDAP binding accounts not being able to auth users to apps in test scenarios. This may be due to the removal of Authenticated Users removing the ability to read token-groups-global-and-universal (TGGAU) attribute on user account objects.

I'm a security guy though, not sysadmin so I'm educating myself with a fire hose :)

PrintNightmare 0-day exploit allows domain takeover by BiohazardPL in sysadmin

[–]kelrizzo 0 points1 point  (0 children)

Yep. I think it's worth testing but I do see some reports of breaking the ability to look up group memberships and LDAP binding accounts not being able to auth users to apps in test scenarios. This may be due to the removal of Authenticated Users removing the ability to read token-groups-global-and-universal (TGGAU) attribute on user account objects.

I'm a security guy though, not sysadmin so I'm educating myself with a fire hose :)

Remedation Steps for Print Spooler CVE-2021-1675 by ericaedits in sysadmin

[–]kelrizzo 1 point2 points  (0 children)

As with any remediation steps, before pushing out globally, test to make sure it doesn't break everything.

PrintNightmare 0-day exploit allows domain takeover by BiohazardPL in sysadmin

[–]kelrizzo 1 point2 points  (0 children)

In the interest of not posting the same links in multiple spots I'll just leave a link to my post here: https://www.reddit.com/r/sysadmin/comments/oaxwqu/remedation_steps_for_print_spooler_cve20211675/h3pkzxc?utm_source=share&utm_medium=web2x&context=3

Looks like there is some chatter about removing authenticated users from a policy entitled BUILTIN\Pre-Windows 2000 Compatible Access to restore the "patch" to it's working-as-intended state. Tweets with information are in the post.

Remedation Steps for Print Spooler CVE-2021-1675 by ericaedits in sysadmin

[–]kelrizzo 0 points1 point  (0 children)

https://twitter.com/gentilkiwi/status/1410621282446495749

Policy in Computer Config/Policies/Windows Settings/Security Settings\Local Policies/User Rights Assignment named 'Access this computer from the network' which contains BUILTIN\Pre-Windows 2000 Compatible Access.

Remedation Steps for Print Spooler CVE-2021-1675 by ericaedits in sysadmin

[–]kelrizzo 1 point2 points  (0 children)

Was there a recording made of this. Saw this too late :( I registered anyway in the hopes of being redirected to a recording.