- My Forums
- Tiger Rant
- LSU Recruiting
- SEC Rant
- Saints Talk
- Pelicans Talk
- More Sports Board
- Fantasy Sports
- Golf Board
- Soccer Board
- O-T Lounge
- Tech Board
- Home/Garden Board
- Outdoor Board
- Health/Fitness Board
- Movie/TV Board
- Book Board
- Music Board
- Political Talk
- Money Talk
- Fark Board
- Gaming Board
- Travel Board
- Food/Drink Board
- Ticket Exchange
- TD Help Board
Customize My Forums- View All Forums
- Show Left Links
- Topic Sort Options
- Trending Topics
- Recent Topics
- Active Topics
Started By
Message
re: Is the whole hacker / IT security / upgrade loop just a system to keep people employed?
Posted on 8/6/18 at 10:33 am to ell_13
Posted on 8/6/18 at 10:33 am to ell_13
quote:
Emails and their contents can be scanned before delivery, yes. But the scanning server/software... get this... has to be updated/patched, too.
Yeah I understand that, but it seems like a filter that only lets through internal emails is pretty straightforward. If external email is far more likely to be malicious, it would make sense to limit where/what that email can access on the network.
I have no clue if that's possible, just wondering.
Posted on 8/6/18 at 10:35 am to ell_13
quote:
, if I have a vendor who has approved remote access to my system and their employees have their accounts hacked, how do I know it's really my vendor contacting me about scheduling their next remote session?
I get it..I've spent many a Monday morning in a hotel, calling all the branches to remind them that my service tech from ABC will be coming around over the next few days..We have also found that the younger kids (opposite the old ones that open emails) do not question anything..They see random people walking around and are cool with that..I printed a badge one time with the name spot saying "Shouldn't Behere"...Again, the biggest threat to IT today is the user..
Posted on 8/6/18 at 10:35 am to weagle99
quote:
I don’t see how all these ‘upgrades’ to my desktop at work have radically improved my efficiency
How much downtime would you say you have to where you can’t access networks, programs, or databases that you need to access in order to do your job?
Posted on 8/6/18 at 10:36 am to slackster
quote:It's an active practice. Often, external emails are flagged and a banner is added. Some are blocked completely. Attachments from external emails are blocked. Hyperlinks are removed.
Yeah I understand that, but it seems like a filter that only lets through internal emails is pretty straightforward. If external email is far more likely to be malicious, it would make sense to limit where/what that email can access on the network.
I have no clue if that's possible, just wondering.
Lots of steps can be taken to prevent stupidity from being a factor. But that doesn't stop people from being stupid and smart people will find a way to exploit that. If emails don't work, there are other methods.
Posted on 8/6/18 at 10:36 am to Kracka
quote:
Someone hacked into the customers network, and in turn found a backdoor into the company providing the portal
A/C and other temperature monitoring software are fricking atrocious.. This is also a favorite
ETA: edited the link to less "uninstall adblock" site
This post was edited on 8/6/18 at 10:44 am
Posted on 8/6/18 at 10:38 am to GrammarKnotsi
quote:Younger generations are much less social in the real sense. They don't get to know their coworkers and they are often conditioned to not ask questions. It's a real problem.
We have also found that the younger kids (opposite the old ones that open emails) do not question anything..They see random people walking around and are cool with that..I printed a badge one time with the name spot saying "Shouldn't Behere"
Posted on 8/6/18 at 10:39 am to slackster
quote:
I have no clue if that's possible, just wondering.
It's possible. This all goes to the point of how stupid the OP's post was. There will always be a need for IT, and even though you may walk into their office and they are playing world of warcraft, doesn't mean that they aren't there until 2 or 3 in the morning a lot of nights fixing shite that retards caused.
Posted on 8/6/18 at 10:41 am to GrammarKnotsi
quote:Network printers and copy machines. Easiest targets that no one wants to manage.
This, is also a favorite
A fish tank is just awesome though. Respect.
This post was edited on 8/6/18 at 10:42 am
Posted on 8/6/18 at 10:42 am to ell_13
quote:
Network printers and copy machines. Easiest targets that no one wants to manage.
We get a lot of DVR systems on the public side too..Super easy to frick up your location if someone has access to the cameras..(I know this sounds like movie shite, but I promise its that easy..there are even sites that list available targets if you're bored)
Posted on 8/6/18 at 10:47 am to Centinel
quote:
We STILL have a 10-15% click rate, with some quarters being as high as 30%.
This sounds low based on the amount of folks here that don't understand what's a blind link.
Posted on 8/6/18 at 10:49 am to ell_13
quote:
And those hacked vendors allow the hackers to create more realistic phishing attempts.
I'm seeing this a ton these days. Mainly Office365 compromises. So our attorneys will get emails from legit clients or other attorneys that have been compromised. Thankfully it's usually additional phishing account harvesting.
Lesson here is that if you're using a cloud-based application that you're accessing from outside your network and you're not using MFA, you're wrong.
I strait up halted our O365 rollout here until we had MFA in place.
Posted on 8/6/18 at 10:50 am to GrammarKnotsi
quote:
.there are even sites that list available targets if you're bored
Good ole Shodan.
Posted on 8/6/18 at 10:53 am to Centinel
quote:
accessing from outside your network and you're not using MFA, you're wrong.
so hard to force this on clients..They'll check facebook and text religiously but can't be bothered to install an app that sends them a code
quote:
Good ole Shodan.
that site is scary
Posted on 8/6/18 at 10:55 am to Centinel
quote:We rolled out our MFA about 4 years ago for both our internal and corporate networks. It's a headache for remote support, but it's worth it. Cisco vpn + secureauth and then a separate EI-based app for remoting. No more remote desktop because of how easy it is for remote code execution.
Lesson here is that if you're using a cloud-based application that you're accessing from outside your network and you're not using MFA, you're wrong.
Posted on 8/6/18 at 10:58 am to GrammarKnotsi
quote:
ETA: edited the link to less "uninstall adblock" site
Your link is blocked by my work filters. Was this a test?
Posted on 8/6/18 at 11:00 am to slackster
quote:
Your link is blocked by my work filters. Was this a test?
maybe from your work IT...
google fish tank hack
Posted on 8/6/18 at 11:02 am to GrammarKnotsi
quote:
so hard to force this on clients..They'll check facebook and text religiously but can't be bothered to install an app that sends them a code
Oh we had people bitching up a storm once we rolled it out. Our response was "Do you want to keep this multi-million dollar client? Yes? Well then shut up because they're the one requiring this."
Client requirements and ISO/HITRUST certification has made ramming through good security practices SO much easier.
Posted on 8/6/18 at 11:03 am to GrammarKnotsi
quote:
We get a lot of DVR systems on the public side too..Super easy to frick up your location if someone has access to the cameras..(I know this sounds like movie shite, but I promise its that easy..there are even sites that list available targets if you're bored)
Every site we have that have DVR's that want access to view from the outside each have a separate internet circuit just for the DVR. Has no access to our network, and doesn't even pass through any of our appliances.
Posted on 8/6/18 at 11:03 am to Centinel
quote:
they're the one requiring this
lot of people don't get this either...We can't let X connect in because they don't meet our own internal requirements..Fix their shite and get back to us
Posted on 8/6/18 at 11:38 am to weagle99
Here's why ITSEC is so important
Variant of WANNACRY virus briefly shuts down major Apple supllier
Cliffs:
Supplier installs new equipment
New equipment arrived on site with virus "preinstalled"
virus propagates once it is connected to suppliers network
causes $170M in lost revenue
Variant of WANNACRY virus briefly shuts down major Apple supllier
Cliffs:
Supplier installs new equipment
New equipment arrived on site with virus "preinstalled"
virus propagates once it is connected to suppliers network
causes $170M in lost revenue
Popular
Back to top


2




