Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. This one beats them all and it’s going to make me laugh until tonight:

This one beats them all and it’s going to make me laugh until tonight:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
sysadminhorrorstories
28 Indlæg 16 Posters 6 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • stefano@mastodon.bsd.cafeS This user is from outside of this forum
    stefano@mastodon.bsd.cafeS This user is from outside of this forum
    stefano@mastodon.bsd.cafe
    wrote sidst redigeret af
    #1

    This one beats them all and it’s going to make me laugh until tonight:

    “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

    I had to read it three times just to make sure I’d understood it properly.

    #IT #SysAdmin #HorrorStories

    mms@mastodon.bsd.cafeM carson@social.chittom.familyC lfa@hostux.socialL greem@cyberplace.socialG jspath55@chaos.socialJ 11 Replies Last reply
    1
    0
    • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

      This one beats them all and it’s going to make me laugh until tonight:

      “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

      I had to read it three times just to make sure I’d understood it properly.

      #IT #SysAdmin #HorrorStories

      mms@mastodon.bsd.cafeM This user is from outside of this forum
      mms@mastodon.bsd.cafeM This user is from outside of this forum
      mms@mastodon.bsd.cafe
      wrote sidst redigeret af
      #2

      @stefano the assessment: "adding firewall, some protection, and blacklist would significantly improve security of the server".

      Can I send them my bank account number?

      stefano@mastodon.bsd.cafeS mkj@social.mkj.earthM 2 Replies Last reply
      0
      • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

        This one beats them all and it’s going to make me laugh until tonight:

        “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

        I had to read it three times just to make sure I’d understood it properly.

        #IT #SysAdmin #HorrorStories

        carson@social.chittom.familyC This user is from outside of this forum
        carson@social.chittom.familyC This user is from outside of this forum
        carson@social.chittom.family
        wrote sidst redigeret af
        #3

        @stefano In a previous role, I used to sometimes triage what were generously called vulnerability reports on our software product. I wish I had a dollar for every one which began "Step 1: Become the administrative user."

        stefano@mastodon.bsd.cafeS 1 Reply Last reply
        0
        • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

          This one beats them all and it’s going to make me laugh until tonight:

          “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

          I had to read it three times just to make sure I’d understood it properly.

          #IT #SysAdmin #HorrorStories

          lfa@hostux.socialL This user is from outside of this forum
          lfa@hostux.socialL This user is from outside of this forum
          lfa@hostux.social
          wrote sidst redigeret af
          #4

          @stefano Give him your user and the root password just to make sure the pen test goes as expected 😂

          stefano@mastodon.bsd.cafeS _elena@mastodon.social_ 2 Replies Last reply
          0
          • mms@mastodon.bsd.cafeM mms@mastodon.bsd.cafe

            @stefano the assessment: "adding firewall, some protection, and blacklist would significantly improve security of the server".

            Can I send them my bank account number?

            stefano@mastodon.bsd.cafeS This user is from outside of this forum
            stefano@mastodon.bsd.cafeS This user is from outside of this forum
            stefano@mastodon.bsd.cafe
            wrote sidst redigeret af
            #5

            @mms You deserve it much more than them

            _elena@mastodon.social_ 1 Reply Last reply
            0
            • carson@social.chittom.familyC carson@social.chittom.family

              @stefano In a previous role, I used to sometimes triage what were generously called vulnerability reports on our software product. I wish I had a dollar for every one which began "Step 1: Become the administrative user."

              stefano@mastodon.bsd.cafeS This user is from outside of this forum
              stefano@mastodon.bsd.cafeS This user is from outside of this forum
              stefano@mastodon.bsd.cafe
              wrote sidst redigeret af
              #6

              @carson This is funny! But yes, this happens. When those asstments start with “if a superuser will start a vulnerable service running as root, and opens a firewall port, and gives the address to others, and and and and…”

              samir@mastodon.functional.computerS 1 Reply Last reply
              0
              • lfa@hostux.socialL lfa@hostux.social

                @stefano Give him your user and the root password just to make sure the pen test goes as expected 😂

                stefano@mastodon.bsd.cafeS This user is from outside of this forum
                stefano@mastodon.bsd.cafeS This user is from outside of this forum
                stefano@mastodon.bsd.cafe
                wrote sidst redigeret af
                #7

                @lfa Wise idea. I will 😂

                1 Reply Last reply
                0
                • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                  This one beats them all and it’s going to make me laugh until tonight:

                  “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                  I had to read it three times just to make sure I’d understood it properly.

                  #IT #SysAdmin #HorrorStories

                  greem@cyberplace.socialG This user is from outside of this forum
                  greem@cyberplace.socialG This user is from outside of this forum
                  greem@cyberplace.social
                  wrote sidst redigeret af
                  #8

                  @stefano Is "outside" in this specific case the pen tester standing in the car park shouting obscenities at the building because they can't get in?

                  stefano@mastodon.bsd.cafeS 1 Reply Last reply
                  0
                  • greem@cyberplace.socialG greem@cyberplace.social

                    @stefano Is "outside" in this specific case the pen tester standing in the car park shouting obscenities at the building because they can't get in?

                    stefano@mastodon.bsd.cafeS This user is from outside of this forum
                    stefano@mastodon.bsd.cafeS This user is from outside of this forum
                    stefano@mastodon.bsd.cafe
                    wrote sidst redigeret af
                    #9

                    @greem Yes, it probably is 😂

                    1 Reply Last reply
                    0
                    • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                      @carson This is funny! But yes, this happens. When those asstments start with “if a superuser will start a vulnerable service running as root, and opens a firewall port, and gives the address to others, and and and and…”

                      samir@mastodon.functional.computerS This user is from outside of this forum
                      samir@mastodon.functional.computerS This user is from outside of this forum
                      samir@mastodon.functional.computer
                      wrote sidst redigeret af
                      #10

                      @stefano @carson Raymond Chen @ Microsoft occasionally posts stories about “the other side of this airtight hatchway”, or security vulnerability reports which require escalation first, which always give me a chuckle.

                      I don’t think there’s an index, but you can search “site:devblogs.microsoft.com other side of the airtight hatchway” to find them.

                      1 Reply Last reply
                      0
                      • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                        This one beats them all and it’s going to make me laugh until tonight:

                        “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                        I had to read it three times just to make sure I’d understood it properly.

                        #IT #SysAdmin #HorrorStories

                        jspath55@chaos.socialJ This user is from outside of this forum
                        jspath55@chaos.socialJ This user is from outside of this forum
                        jspath55@chaos.social
                        wrote sidst redigeret af
                        #11

                        @stefano "little pig, little pig, let me come in?"

                        "That's not how pen testing works, big bad wolf."

                        stefano@mastodon.bsd.cafeS 1 Reply Last reply
                        0
                        • mms@mastodon.bsd.cafeM mms@mastodon.bsd.cafe

                          @stefano the assessment: "adding firewall, some protection, and blacklist would significantly improve security of the server".

                          Can I send them my bank account number?

                          mkj@social.mkj.earthM This user is from outside of this forum
                          mkj@social.mkj.earthM This user is from outside of this forum
                          mkj@social.mkj.earth
                          wrote sidst redigeret af
                          #12

                          In all fairness security shouldn't depend on any one layer of protection, but yes, this is really rather ridiculous. So yes, Stefano, I'm pretty sure you understood the request correctly.

                          Let's also make sure indeed that they also have login credentials that will let them log in as root. Maybe email them the SSH host private keys while we're at it?

                          😆

                          @mms @stefano

                          stefano@mastodon.bsd.cafeS 1 Reply Last reply
                          0
                          • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                            This one beats them all and it’s going to make me laugh until tonight:

                            “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                            I had to read it three times just to make sure I’d understood it properly.

                            #IT #SysAdmin #HorrorStories

                            clf@mastodon.bsd.cafeC This user is from outside of this forum
                            clf@mastodon.bsd.cafeC This user is from outside of this forum
                            clf@mastodon.bsd.cafe
                            wrote sidst redigeret af
                            #13

                            @stefano "please open an attack vector for me. I need to get paid"

                            stefano@mastodon.bsd.cafeS 1 Reply Last reply
                            0
                            • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                              This one beats them all and it’s going to make me laugh until tonight:

                              “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                              I had to read it three times just to make sure I’d understood it properly.

                              #IT #SysAdmin #HorrorStories

                              pertho@mastodon.bsd.cafeP This user is from outside of this forum
                              pertho@mastodon.bsd.cafeP This user is from outside of this forum
                              pertho@mastodon.bsd.cafe
                              wrote sidst redigeret af
                              #14

                              @stefano yeah these are ridiculous. Why the hell would you disable your firewall? Also these aren't penetration tests, they're just vulnerability scanners.

                              raymaccarthy@mastodon.ieR 1 Reply Last reply
                              0
                              • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                                This one beats them all and it’s going to make me laugh until tonight:

                                “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                                I had to read it three times just to make sure I’d understood it properly.

                                #IT #SysAdmin #HorrorStories

                                oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
                                oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
                                oxyhyxo@mastodon.bsd.cafe
                                wrote sidst redigeret af
                                #15

                                @stefano "my nmap isnt coming back with anything and I need something to put in my report"

                                1 Reply Last reply
                                0
                                • jspath55@chaos.socialJ jspath55@chaos.social

                                  @stefano "little pig, little pig, let me come in?"

                                  "That's not how pen testing works, big bad wolf."

                                  stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                  stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                  stefano@mastodon.bsd.cafe
                                  wrote sidst redigeret af
                                  #16

                                  @jspath55 yes, exactly!

                                  1 Reply Last reply
                                  0
                                  • mkj@social.mkj.earthM mkj@social.mkj.earth

                                    In all fairness security shouldn't depend on any one layer of protection, but yes, this is really rather ridiculous. So yes, Stefano, I'm pretty sure you understood the request correctly.

                                    Let's also make sure indeed that they also have login credentials that will let them log in as root. Maybe email them the SSH host private keys while we're at it?

                                    😆

                                    @mms @stefano

                                    stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                    stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                    stefano@mastodon.bsd.cafe
                                    wrote sidst redigeret af
                                    #17

                                    @mkj @mms sure. But disabling the layers won't help anyway 🙂

                                    1 Reply Last reply
                                    0
                                    • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                                      This one beats them all and it’s going to make me laugh until tonight:

                                      “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

                                      I had to read it three times just to make sure I’d understood it properly.

                                      #IT #SysAdmin #HorrorStories

                                      beecycling@wandering.shopB This user is from outside of this forum
                                      beecycling@wandering.shopB This user is from outside of this forum
                                      beecycling@wandering.shop
                                      wrote sidst redigeret af
                                      #18

                                      @stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

                                      stefano@mastodon.bsd.cafeS 1 Reply Last reply
                                      0
                                      • clf@mastodon.bsd.cafeC clf@mastodon.bsd.cafe

                                        @stefano "please open an attack vector for me. I need to get paid"

                                        stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                        stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                        stefano@mastodon.bsd.cafe
                                        wrote sidst redigeret af
                                        #19

                                        @clf or "open an attack vector, otherwise I don't know how to proceed"

                                        1 Reply Last reply
                                        0
                                        • beecycling@wandering.shopB beecycling@wandering.shop

                                          @stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

                                          stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                          stefano@mastodon.bsd.cafeS This user is from outside of this forum
                                          stefano@mastodon.bsd.cafe
                                          wrote sidst redigeret af
                                          #20

                                          @beecycling officially, "how the services are vulnerable from the Internet"

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper