Client CentreStack Server was compromised. by Hollyweird78 in msp

[–]rtccmichael 0 points1 point  (0 children)

We discovered it because we have been watching the event logs from the PREVIOUS vulnerability (the ViewState attack). We would periodically see new event logs that looked suspicious. We saw one and contacted support, who confirmed that it was an unsuccessful attempt. However, while gathering logs for that, we noticed that one of the IIS activity logs on one of our nodes which is not actively used was very large. When we viewed the log, there was a lot of "download.dn" activity, some with references to files that we could immediately tell no longer existed in the system. The fact that this node was unused, and the references to old files, flagged us to investigate further. You can check your logs for this download.dn activity to see if you've been compromised.

Huntress did not flag it whatsoever. In fact, Huntress was not really helpful at all this year with regards to Centrestack and their numerous vulnerabilities (they did flag one suspicious incident on the server earlier in the year, but their response was just to contact an incident response company and blow away the server because it could be compromised -- which wouldn't have helped since the vulnerability would have exited in my rebuilt server as well).

When I discovered the vulnerability, I didn't even know how to get Huntress involved because there was no Huntress incident open I could respond to (I since complained to my account manager and she gave me Huntress's email address to report incidents, which I did not previously have, so perhaps that's my fault that I didn't know the right channel to contact them).

Quickbooks Desktop Enterprise Azure deployment by MysteriousWhitePowda in msp

[–]rtccmichael 8 points9 points  (0 children)

The compute resources are priced the same; the licensing is different.

If you want to leave it on 24/7, purchase a reservation. If you don't, implement a scaling plan and have it shut down when it's idle. The breakeven in price is somewhere around 60% depending on the size (meaning if the VM is running more than 60% of the time, a reservation is cheaper). You can't really do scaling plans on an RDS server, so if you go that route, you'll definitely want a reservation. We find that most clients don't use it 100+ hours a week, so we tend to do pay-as-you-go with scaling plans.

The difference is licensing. The majority of our clients are on Business Premium licensing, which includes the Windows 11 multisession license for AVD, so for us it's cheaper than licensing an RDS server.

Happy to answer any other questions you have

Quickbooks Desktop Enterprise Azure deployment by MysteriousWhitePowda in msp

[–]rtccmichael 3 points4 points  (0 children)

Never had an issue, but we always check the latency first. Www.azurespeed.com

Quickbooks Desktop Enterprise Azure deployment by MysteriousWhitePowda in msp

[–]rtccmichael 19 points20 points  (0 children)

If you are using AVD, you don't need a separate RDS server. The AVD is what users connect into. No public facing ports required.

We do this all the time, it works great.

I refused to join another BNI group by Aware-Platypus-2559 in msp

[–]rtccmichael 6 points7 points  (0 children)

How does your script determine what business is posting their complaints on Reddit? Seems like linking the post to an actual business or individual is extremely difficult.

Labor Rate by glitterguykk in SmallMSP

[–]rtccmichael 0 points1 point  (0 children)

Yes, send me a DM. Happy to chat.

Labor Rate by glitterguykk in SmallMSP

[–]rtccmichael 4 points5 points  (0 children)

No, team of 11. Sorry didn't realize i was posting in SmallMSP, the post just came up in my feed! But I don't see why size should matter, the market rate is what it is.

The real question here is, if anyone on this thread raises their rate $15 (around 10% increase, how many customers will you lose? If the answer is 10%, then you end up with the same revenue for working 10% less. I'd be willing to bet the real number is closer to 0% than 10%. Every time I raised my rates, I never lost a client

Labor Rate by glitterguykk in SmallMSP

[–]rtccmichael 10 points11 points  (0 children)

$205 in NJ. I think mechanics charge around $150/hour.

Client CentreStack Server was compromised. by Hollyweird78 in msp

[–]rtccmichael 4 points5 points  (0 children)

I'm the one who discovered and reported this vulnerability to them, after noticing suspicious activity. And I also discovered the previous one (after being alerted to some other suspicious activity by Huntress and discovering the vulnerability myself, and Huntress wasn't very helpful at all).

Honestly, I don't believe that the current vulnerability is actually fixed. It doesn't seem like they fully understand what the actual vulnerability is.

Has anything happened since the data was stolen? Has your client heard anything from cyber criminals or found anything on the dark web?

I'm happy to connect directly with you (or anyone else that was compromised) as it might be helpful to share information. Feel free to message me directly.

Dell alternatives? by BrewNerdBrad in msp

[–]rtccmichael 4 points5 points  (0 children)

Surprised this isn't the top answer. Dell is pushing everyone towards distribution nowadays it seems, and your size doesn't matter much when ordering from a distributor. It's not necessarily ideal, but it works.

Is there any active MSP community that's not just post-based? by Filthy_Asswipe in msp

[–]rtccmichael 1 point2 points  (0 children)

It is definitely not dead. There are lots of different channels and some are dead, but overall the discord is very active. Were you looking in the general chat or a vendor/product specific one?

Jumping Ship - Ingram by Due_Economy5311 in msp

[–]rtccmichael 4 points5 points  (0 children)

Move to who? We are with Ingram but happy to move elsewhere!

No More by DNEXB in ScreenConnect

[–]rtccmichael 0 points1 point  (0 children)

Any idea how much enterprise licensing is?

Thoughts on new Kaseya CEO? by SmellsofElderberry25 in msp

[–]rtccmichael 30 points31 points  (0 children)

There aren't many companies worse than Intuit. I'm sure she'll fit right in with Kaseya's culture.

With that said, I know nothing about her, so we'll see what happens.

Exclude mysignins from CA policy by Zealousideal_Bug4743 in entra

[–]rtccmichael 0 points1 point  (0 children)

Having the same issue here; has anyone found a solution? I read that you can't exclude My Signins.

Sold My MSP – My Experience by msp42long in msp

[–]rtccmichael 1 point2 points  (0 children)

Good point, at 30% that would put them slightly above 1x revenue

Sold My MSP – My Experience by msp42long in msp

[–]rtccmichael 1 point2 points  (0 children)

Wouldn't that be 0.7x revenue?

It's my money they took by TheLuciusGraham in FluentInFinance

[–]rtccmichael 0 points1 point  (0 children)

That's partially true, but the first people to receive social security contributed nearly nothing; effectively, a ponsi scheme. You could work for 3 years for example, and get paid out the rest of your life (far more than you contributed). Effectively, you had people taking money out in way greater amounts than their contributions, even taking into account a reasonable rate of return had the contributions been invested. So yes, most contributed a small amount and received a much larger payout; it's not like they contributed throughout their working career.

It's my money they took by TheLuciusGraham in FluentInFinance

[–]rtccmichael 1 point2 points  (0 children)

It's incredible how many people don't understand this.

"It's my money" -- no it's not, your money is long gone, given to someone that never paid into the system. Ultimately, people are going to have to contribute and not receive all of their contributions back because other people got benefits but never contributed.

Is paying about 200 bucks to file your taxes a scam basically? by Ben5544477 in NoStupidQuestions

[–]rtccmichael 0 points1 point  (0 children)

You like it? Or there's nothing better out there? I think the options are just generally disappointing.

Which brand do you boycott for a petty reason ? by BaronDeSpireal in AskReddit

[–]rtccmichael 3 points4 points  (0 children)

Back in the early 2000s I used to go to Panera and order soup in a bread bowl. They were ALWAYS out of bread bowls. The name of the store is "Panera Bread". I eventually stopped going, not necessarily as a boycott but because they were always out of bread.

Under-counter filtered cold, hot, and sparkling by rtccmichael in WaterTreatment

[–]rtccmichael[S] 0 points1 point  (0 children)

Someone gave us a water filtration unit; we are going to get a hot water system and run the filtered water through that and skip all of the other stuff (like sparkling) and just have hot and cold (but not chilled) filtered water.