Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. the rm -rf's will continue until morale improves

the rm -rf's will continue until morale improves

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
123 Indlæg 85 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • womble@infosec.exchangeW womble@infosec.exchange

    @jrdepriest @jztusk @paco @neurovagrant "oh, it's only data exfil, that's not so bad" Some people have very limited imaginations, and need an unequivocal demonstration.

    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.town
    wrote sidst redigeret af
    #85

    @womble @jrdepriest @jztusk @paco @neurovagrant "Limited?"

    1 Reply Last reply
    0
    • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

      @jztusk @womble @paco @neurovagrant

      Like leaving an empty file called pwned on /.

      drwho@masto.hackers.townD This user is from outside of this forum
      drwho@masto.hackers.townD This user is from outside of this forum
      drwho@masto.hackers.town
      wrote sidst redigeret af
      #86

      @jrdepriest @jztusk @womble @paco @neurovagrant Also fun.

      1 Reply Last reply
      0
      • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

        @jztusk @womble @paco @neurovagrant

        Mission accomplished with the table drop, then?

        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.town
        wrote sidst redigeret af
        #87

        @jrdepriest @jztusk @womble @paco @neurovagrant Yep. Sometimes that's the only way to make them understand. Or using a loop and ssh to power down an entire rack.

        "Are you sure? This is fatal," during a meeting with a client is not an idle threat, and a lot of clients think we're bluffing.

        1 Reply Last reply
        0
        • rail@social.flufftech.netR rail@social.flufftech.net

          @paco @neurovagrant wouldn't that be a criminal offense at that point as well

          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.town
          wrote sidst redigeret af
          #88

          @rail @paco @neurovagrant Depends on how aggro the client wants to be.

          benaveling@infosec.exchangeB 1 Reply Last reply
          0
          • adamhotep@infosec.exchangeA adamhotep@infosec.exchange

            @neurovagrant people still haven't learned after all that ransomware. Back it up and/or employ snapshots. I'm a big fan of ZFS snapshots.

            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.town
            wrote sidst redigeret af
            #89

            @adamhotep @neurovagrant Because they were lucky enough to have usable backups.

            Stress "lucky."

            1 Reply Last reply
            0
            • quinn@social.circl.luQ quinn@social.circl.lu

              @Viss @neurovagrant Letsss goooooo

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote sidst redigeret af
              #90

              @quinn @Viss @neurovagrant

              viss@mastodon.socialV 1 Reply Last reply
              0
              • drwho@masto.hackers.townD drwho@masto.hackers.town

                @quinn @Viss @neurovagrant

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote sidst redigeret af
                #91

                @drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot

                dude doesnt know what a sandbox is.

                if the shit can reach your home directory, its not in a sandbox.

                drwho@masto.hackers.townD 1 Reply Last reply
                0
                • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                  the rm -rf's will continue until morale improves

                  p@hj.9fs.netP This user is from outside of this forum
                  p@hj.9fs.netP This user is from outside of this forum
                  p@hj.9fs.net
                  wrote sidst redigeret af
                  #92
                  #neverslop
                  1 Reply Last reply
                  0
                  • dch@bsd.networkD dch@bsd.network

                    @neurovagrant also, people still not doing backups/restore testing, no zfs, no jails / containers / other restrictions. Kids these days.

                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.townD This user is from outside of this forum
                    drwho@masto.hackers.town
                    wrote sidst redigeret af
                    #93

                    @dch @neurovagrant There are folks who don't even know what removable storage is, let alone file systems or files.

                    "Just rebuild."

                    Great. That's the OS. What about the data?

                    There's probably a "chased by an angry goose" meme to make here.

                    1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot

                      dude doesnt know what a sandbox is.

                      if the shit can reach your home directory, its not in a sandbox.

                      drwho@masto.hackers.townD This user is from outside of this forum
                      drwho@masto.hackers.townD This user is from outside of this forum
                      drwho@masto.hackers.town
                      wrote sidst redigeret af
                      #94

                      @Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.

                      quinn@social.circl.luQ 1 Reply Last reply
                      0
                      • drwho@masto.hackers.townD drwho@masto.hackers.town

                        @Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.

                        quinn@social.circl.luQ This user is from outside of this forum
                        quinn@social.circl.luQ This user is from outside of this forum
                        quinn@social.circl.lu
                        wrote sidst redigeret af
                        #95

                        @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                        viss@mastodon.socialV drwho@masto.hackers.townD 2 Replies Last reply
                        0
                        • quinn@social.circl.luQ quinn@social.circl.lu

                          @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.social
                          wrote sidst redigeret af
                          #96

                          @quinn @drwho @neurovagrant oh, hes a cryptobro. no wonder

                          1 Reply Last reply
                          0
                          • quinn@social.circl.luQ quinn@social.circl.lu

                            @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

                            drwho@masto.hackers.townD This user is from outside of this forum
                            drwho@masto.hackers.townD This user is from outside of this forum
                            drwho@masto.hackers.town
                            wrote sidst redigeret af
                            #97

                            @quinn @Viss @neurovagrant Same.

                            1 Reply Last reply
                            0
                            • paco@infosec.exchangeP paco@infosec.exchange

                              @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

                              Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

                              me@mastodon.seahousen.euM This user is from outside of this forum
                              me@mastodon.seahousen.euM This user is from outside of this forum
                              me@mastodon.seahousen.eu
                              wrote sidst redigeret af
                              #98

                              @paco @neurovagrant imho, if LLMs are what make developers finally care about cybersecurity, that's the first thing about them one might consider 'good'

                              1 Reply Last reply
                              0
                              • drwho@masto.hackers.townD drwho@masto.hackers.town

                                @rail @paco @neurovagrant Depends on how aggro the client wants to be.

                                benaveling@infosec.exchangeB This user is from outside of this forum
                                benaveling@infosec.exchangeB This user is from outside of this forum
                                benaveling@infosec.exchange
                                wrote sidst redigeret af
                                #99

                                Also depends on how well written your contact with the client is.

                                @drwho @rail @paco @neurovagrant

                                1 Reply Last reply
                                0
                                • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                                  the rm -rf's will continue until morale improves

                                  catboycody@tech.lgbtC This user is from outside of this forum
                                  catboycody@tech.lgbtC This user is from outside of this forum
                                  catboycody@tech.lgbt
                                  wrote sidst redigeret af
                                  #100

                                  @neurovagrant I'm pushed to use claude at work... Three possible takeaways from this:

                                  1. Don't use auto mode and review the commands.
                                  2. Sandbox claude so that the fallout of such an oppsie is more limited.
                                  3. Do nothing and have a claude-free afternoon while I restore my profile.

                                  1 Reply Last reply
                                  0
                                  • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

                                    @jztusk @paco @neurovagrant

                                    A simple select * from users would've been fine just to prove the point.

                                    jackeric@beige.partyJ This user is from outside of this forum
                                    jackeric@beige.partyJ This user is from outside of this forum
                                    jackeric@beige.party
                                    wrote sidst redigeret af
                                    #101

                                    @jrdepriest @jztusk @paco @neurovagrant that shows access but not, whatsit, that the injected query has `drop table` privileges, I forget the term for it

                                    1 Reply Last reply
                                    0
                                    • computernut43@nexto.myC computernut43@nexto.my

                                      @neurovagrant thats why dev machines are VM's for me and before I start to "dev" you make a backup. I think its time we teach about backups now.

                                      epic_null@infosec.exchangeE This user is from outside of this forum
                                      epic_null@infosec.exchangeE This user is from outside of this forum
                                      epic_null@infosec.exchange
                                      wrote sidst redigeret af
                                      #102

                                      @computernut43 @neurovagrant You mean one of the things that AI has just made unreasonably expensive?

                                      computernut43@nexto.myC 1 Reply Last reply
                                      0
                                      • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                                        the rm -rf's will continue until morale improves

                                        crowbriarhexe@tech.lgbtC This user is from outside of this forum
                                        crowbriarhexe@tech.lgbtC This user is from outside of this forum
                                        crowbriarhexe@tech.lgbt
                                        wrote sidst redigeret af
                                        #103

                                        @neurovagrant still waiting for the bad news

                                        1 Reply Last reply
                                        0
                                        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                                          @paco oh no

                                          webhat@infosec.exchangeW This user is from outside of this forum
                                          webhat@infosec.exchangeW This user is from outside of this forum
                                          webhat@infosec.exchange
                                          wrote sidst redigeret af
                                          #104

                                          @neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production

                                          davep@infosec.exchangeD paco@infosec.exchangeP 2 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper