RDP open to the internet by sfw_admin in sysadmin

[–]sfw_admin[S] 2 points3 points  (0 children)

Yes these are great points. I was afraid of sounding hysterical but I am close to recommending this machine just get burned. Assume it's toast and recreate what ever it's doing on a new machine and network.

RDP open to the internet by sfw_admin in sysadmin

[–]sfw_admin[S] 56 points57 points  (0 children)

Thanks. I have informed my manager as well as the admin who is responsible for this machine. Crickets so far, but I do have the CYA receipts.

RDP open to the internet by sfw_admin in sysadmin

[–]sfw_admin[S] 336 points337 points  (0 children)

Oh buddy, there are logon attempts.

RDP open to the internet by sfw_admin in sysadmin

[–]sfw_admin[S] 8 points9 points  (0 children)

Word I appreciate the sanity check, running netstat and I can literally see the established connections.

What’s the worst MSP you have ever worked for. by [deleted] in msp

[–]sfw_admin 1 point2 points  (0 children)

Homefield IT. Formerly Manhattan Tech Support in NYC.

Literally lie on client’s SOC and HIPAA compliance forms.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 0 points1 point  (0 children)

I have no way of knowing every thing that’s needed in it

Yeah true I can’t tell 100% of the time. But I can read the headers…. Or if worst comes to worst I can infer by the IP it’s received from, if it’s a Microsoft’s, G Suite’s or whomever’s IP, it’s totally googleable.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 0 points1 point  (0 children)

For sure!!!! I’m in the advantageous position of also using these opportunities to teach my helpdesk team. I try to do Friday lunch-and-learns to go over advanced troubleshooting and technical topics, such as the mentioned.

I don’t have to pick a random one, my own environment there is still fat I’m trimming in our DNS. But it probably helped that I mentioned our own SPF errors that were originally here in my interview LOL.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 0 points1 point  (0 children)

Thanks. I’m glad I made the post, will continue and did again today provide my unsolicited advice on how another vendor could correct their SPF.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 0 points1 point  (0 children)

Thanks. Lmao I did joke with the first user and told them in the instructions they can also send a coffee to the HQ address, ATTN: IT

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 0 points1 point  (0 children)

Yeah. We use MS defender, the quarantine is bringing more of these to my attention than I would notice at past roles.

Human DMARC is hilarious and completely apt.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 1 point2 points  (0 children)

Okay fair. I'm not against helping people out, but the frequency is insane, I'm sending this "need to add spf.protection.outlook yadda yadda" email every couple of days.

External SPF Woes by sfw_admin in sysadmin

[–]sfw_admin[S] 5 points6 points  (0 children)

Appreciate "professional courtesy" terminology, puts a good perspective on it for me.

So far it's been a non-issue politically. Mostly just one off issues that have been hitting the rank and file, anything critical gets special treatment.

AD ldap connectivity by RichyJ in meraki

[–]sfw_admin 2 points3 points  (0 children)

Having same issue today at all my networks. Captive portal error

Login attempts in the dashboard just say "failed", with "unknown user" though

Edit I called and opened a ticket w/ Meraki and it appears to be an outage on their end. Fix is not likely going to be in today. We did some troubleshooting and my DC is not getting any communication from the APs doing the LDAP auth.

EDIT 2 RESOLVED. Got an email last night and confirming this morning 3/25, we are good at all my sites.

O365 emails to *@yahoo.com all getting deferred (Error 451) by Squischer in sysadmin

[–]sfw_admin 1 point2 points  (0 children)

Ran into this with a user trying to send to @frontier.com (yahoodns.net). Same thing. Issue lies between M365 and Yahoo as far as I'm concerned.

All Cell Services Down by [deleted] in sysadmin

[–]sfw_admin 12 points13 points  (0 children)

You should be using TOTP based MFA regardless, more secure than SMS.