Page 1
Page 1
Started By
Message

SELU Outage

Posted on 2/27/23 at 7:02 am
Posted by GrammarKnotsi
Member since Feb 2013
9840 posts
Posted on 2/27/23 at 7:02 am
From what my daughter can tell me, they have essentially been locked out of systems and even buildings since about mid day friday..Oddly enough, they cant even take tests, etc on sites that are not specifically hosted by SELU..

Sounds to me like something has happened with their AD system and maybe its not credentialling out to other sites..

Ideas ? Theories ?
Posted by BruslyTiger
Waiting on 420...
Member since Oct 2003
4717 posts
Posted on 2/27/23 at 11:01 am to
A friend of mine is a professor there and was telling me about this Friday. I was telling them about the alert from CISA stating that last Friday was the 1 year anniversary of the invasion of Ukraine and were expecting attacks. I'm not saying this is the case...

The Advocate
This post was edited on 2/27/23 at 11:04 am
Posted by wileyjones
Member since May 2014
2583 posts
Posted on 2/27/23 at 2:40 pm to
It’s always dns


Unless it’s ransomware
Posted by titmouse
a tree branch above your car
Member since May 2006
6562 posts
Posted on 2/27/23 at 4:40 pm to
It's almost certainly ransomware. Universities are among the least secure areas for them to phish and get access.
Posted by tigerband6971
hammond,la
Member since Sep 2018
127 posts
Posted on 2/28/23 at 2:42 pm to
See the OT board for discussion on this
I posted my thoughts there
Posted by GrammarKnotsi
Member since Feb 2013
9840 posts
Posted on 2/28/23 at 2:50 pm to
quote:

See the OT board for discussion on this
I posted my thoughts there


I started this one well before that one, as actual intelligence is posted here more than there
Posted by LemmyLives
Texas
Member since Mar 2019
10007 posts
Posted on 2/28/23 at 3:31 pm to
I still think that it's border routers or proxies that were improperly updated. And like everyone known to man, no config backup was taken, "cause it's just a minor update." No sane person would touch production equipment in the middle of a work day, but the DNS theory could also hold water as the propagation of changes would take some time.

People are almost always surprised how "locally hosted" software and services make extensive calls to the Internet for "things" like authentication, licenses checks, etc. At least part of their site uses Google Authentication. Peoplesoft, which seems to power much of Leonet could be down, but that wouldn't explain the building lockouts, which should be an entirely different system. This, kids, are why we create segregation of duties for administrative roles and don't assign excessive privileges to those roles.

I'm sure there were multiple admin or admin like accounts that didn't have MFA, too.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram