Started By
Message
locked post

.

Posted on 5/18/23 at 7:57 pm
Posted by MrLSU
Yellowstone, Val d'isere
Member since Jan 2004
28288 posts
Posted on 5/18/23 at 7:57 pm
.
This post was edited on 8/12/23 at 12:22 am
Posted by RedFoxx
New Orleans, LA
Member since Jan 2009
6469 posts
Posted on 5/18/23 at 8:00 pm to
And the same amount of work still got done…
Posted by fallguy_1978
Best States #50
Member since Feb 2018
51755 posts
Posted on 5/18/23 at 8:03 pm to
Well, we can be certain they won't go out of business.
Posted by Breauxsif
Member since May 2012
22291 posts
Posted on 5/18/23 at 8:20 pm to
Doesn’t the State implement MFA’s, and perform a port scan on their external facing servers and close them up to only allow specific IPs?

They need to turn on auditing for O365 or Azure, AWS, GC services (whichever they utilize as a cloud vendor) to alert when someone signs in from two different locations in a short amount of time from the US to London in one hour time frame, (as an example) could be anywhere in the world. Locking down remote tools such as TeamViewer and similar applications to cut the head off the snake. Years ago I recall Teamviewer had a vulnerability to bypass passwords. About 10 years ago VNC had a similar vulnerability.

The State needs to build an audit to report back any domain joined machines that don't have antivirus installed to prevent this shite from happening again.
Posted by mahdragonz
Member since Jun 2013
7048 posts
Posted on 5/18/23 at 8:27 pm to
So what you're saying is hackers are sending emails to state agencies with this title

Update your Tigerdroppings password now!!!

And the state workers are clicking and getting the data locked

Well played hackers
Well played ??
Posted by ThatMakesSense
Fort Lauderdale
Member since Aug 2015
15190 posts
Posted on 5/18/23 at 8:29 pm to
quote:

Doesn’t the State implement MFA’s, and perform a port scan on their external facing servers and close them up to only allow specific IPs? They need to turn on auditing for O365 or Azure, AWS, GC services (whichever they utilize as a cloud vendor) to alert when someone signs in from two different locations in a short amount of time from the US to London in one hour time frame, (as an example) could be anywhere in the world. Locking down remote tools such as TeamViewer and similar applications to cut the head off the snake. Years ago I recall Teamviewer had a vulnerability to bypass passwords. About 10 years ago VNC had a similar vulnerability. The State needs to build an audit to report back any domain joined machines that don't have antivirus installed to prevent this shite from happening again.


Seriously
Posted by GreenRockTiger
vortex to the whirlpool of despair
Member since Jun 2020
53616 posts
Posted on 5/18/23 at 8:31 pm to
quote:

Doesn’t the State implement MFA’s, and perform a port scan on their external facing servers and close them up to only allow specific IPs?
implementing this would line whose pockets? That’s the important thing
Posted by fallguy_1978
Best States #50
Member since Feb 2018
51755 posts
Posted on 5/18/23 at 8:34 pm to
It's usually an email and there will always be users that click on it and get compromised.

They obviously need more east/west traffic visibility
Posted by junkfunky
Member since Jan 2011
35075 posts
Posted on 5/18/23 at 8:37 pm to
quote:

Well, we can be certain they won't go out of business.


Yeah, they've got insurance.

"We need to raise taxes to pay for this. What do you mean you shouldn't have to pay extra tax for this?"

Posted by bhtigerfan
Baton Rouge
Member since Sep 2008
32401 posts
Posted on 5/18/23 at 8:38 pm to
quote:

They need to turn on auditing for O365 or Azure, AWS, GC services (whichever they utilize as a cloud vendor) to alert when someone signs in from two different locations in a short amount of time from the US to London in one hour time frame, (as an example) could be anywhere in the world. Locking down remote tools such as TeamViewer and similar applications to cut the head off the snake. Years ago I recall Teamviewer had a vulnerability to bypass passwords. About 10 years ago VNC had a similar vulnerability.

Posted by junkfunky
Member since Jan 2011
35075 posts
Posted on 5/18/23 at 8:41 pm to
quote:

Doesn’t the State implement MFA’s, and perform a port scan on their external facing servers and close them up to only allow specific IPs?

They need to turn on auditing for O365 or Azure, AWS, GC services (whichever they utilize as a cloud vendor) to alert when someone signs in from two different locations in a short amount of time from the US to London in one hour time frame, (as an example) could be anywhere in the world. Locking down remote tools such as TeamViewer and similar applications to cut the head off the snake. Years ago I recall Teamviewer had a vulnerability to bypass passwords. About 10 years ago VNC had a similar vulnerability.

The State needs to build an audit to report back any domain joined machines that don't have antivirus installed to prevent this shite from happening again.


"Sorry, we had to do some employee juggling recently. The guy that was working on it was done with his current workload before 10 this morning and the new guy we have leading this project wears a helmet. Please bear with us in these tumultuous times."
Posted by Righteous Dude
Member since Oct 2017
1466 posts
Posted on 5/18/23 at 9:07 pm to
quote:

How in the hell does Jacques Berry still have a job?


Why would a spokesperson be in charge of internet security?
Posted by LSUFanHouston
NOLA
Member since Jul 2009
39228 posts
Posted on 5/18/23 at 9:10 pm to
quote:

Doesn’t the State implement MFA’s, and perform a port scan on their external facing servers and close them up to only allow specific IPs? They need to turn on auditing for O365 or Azure, AWS, GC services (whichever they utilize as a cloud vendor) to alert when someone signs in from two different locations in a short amount of time from the US to London in one hour time frame, (as an example) could be anywhere in the world. Locking down remote tools such as TeamViewer and similar applications to cut the head off the snake. Years ago I recall Teamviewer had a vulnerability to bypass passwords. About 10 years ago VNC had a similar vulnerability. The State needs to build an audit to report back any domain joined machines that don't have antivirus installed to prevent this shite from happening again.


I have no idea what you are saying but it sounds legit to me!!
Posted by fallguy_1978
Best States #50
Member since Feb 2018
51755 posts
Posted on 5/18/23 at 9:13 pm to
He's asking if the state has basic, modern security controls in place. I doubt that they do.

They probably don't have much budget for it to be honest. They might after they keep getting hit though.
This post was edited on 5/18/23 at 9:15 pm
Posted by Twenty 49
Shreveport
Member since Jun 2014
20094 posts
Posted on 5/18/23 at 9:19 pm to
Try rebooting.
Posted by Order88
Member since Sep 2010
61 posts
Posted on 5/18/23 at 9:22 pm to
An automatic outcome: crawfish prices will go up
Posted by Wabbit7
Member since Aug 2018
1807 posts
Posted on 5/18/23 at 9:45 pm to
It wasn’t a hack
Posted by The Boat
Member since Oct 2008
172080 posts
Posted on 5/18/23 at 9:46 pm to
quote:

the Louisiana Department of Wildlife and Fisheries

Fantastic. Looks like my social is signing up for midget butthole porn.

And my identity was stolen!!
Posted by Wabbit7
Member since Aug 2018
1807 posts
Posted on 5/18/23 at 9:48 pm to
That’s just the list of agencies that went down.
Posted by redstickrick
Member since May 2019
383 posts
Posted on 5/18/23 at 10:08 pm to
This was a decent post until you said the spokesperson should be fired because the internet system had an issue. Jacques Berry is just a spokesperson, he’s never really done anything to draw attention to himself and does his job. No research needed, think through it and be sure before calling for someone to be fired.
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram