Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. This one beats them all and it’s going to make me laugh until tonight:

This one beats them all and it’s going to make me laugh until tonight:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
sysadminhorrorstories
28 Indlæg 16 Posters 6 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mkj@social.mkj.earthM mkj@social.mkj.earth

    In all fairness security shouldn't depend on any one layer of protection, but yes, this is really rather ridiculous. So yes, Stefano, I'm pretty sure you understood the request correctly.

    Let's also make sure indeed that they also have login credentials that will let them log in as root. Maybe email them the SSH host private keys while we're at it?

    😆

    @mms @stefano

    stefano@mastodon.bsd.cafeS This user is from outside of this forum
    stefano@mastodon.bsd.cafeS This user is from outside of this forum
    stefano@mastodon.bsd.cafe
    wrote sidst redigeret af
    #17

    @mkj @mms sure. But disabling the layers won't help anyway 🙂

    1 Reply Last reply
    0
    • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

      This one beats them all and it’s going to make me laugh until tonight:

      “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

      I had to read it three times just to make sure I’d understood it properly.

      #IT #SysAdmin #HorrorStories

      beecycling@wandering.shopB This user is from outside of this forum
      beecycling@wandering.shopB This user is from outside of this forum
      beecycling@wandering.shop
      wrote sidst redigeret af
      #18

      @stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

      stefano@mastodon.bsd.cafeS 1 Reply Last reply
      0
      • clf@mastodon.bsd.cafeC clf@mastodon.bsd.cafe

        @stefano "please open an attack vector for me. I need to get paid"

        stefano@mastodon.bsd.cafeS This user is from outside of this forum
        stefano@mastodon.bsd.cafeS This user is from outside of this forum
        stefano@mastodon.bsd.cafe
        wrote sidst redigeret af
        #19

        @clf or "open an attack vector, otherwise I don't know how to proceed"

        1 Reply Last reply
        0
        • beecycling@wandering.shopB beecycling@wandering.shop

          @stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

          stefano@mastodon.bsd.cafeS This user is from outside of this forum
          stefano@mastodon.bsd.cafeS This user is from outside of this forum
          stefano@mastodon.bsd.cafe
          wrote sidst redigeret af
          #20

          @beecycling officially, "how the services are vulnerable from the Internet"

          1 Reply Last reply
          0
          • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

            This one beats them all and it’s going to make me laugh until tonight:

            “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

            I had to read it three times just to make sure I’d understood it properly.

            #IT #SysAdmin #HorrorStories

            anparker@mastodon.bsd.cafeA This user is from outside of this forum
            anparker@mastodon.bsd.cafeA This user is from outside of this forum
            anparker@mastodon.bsd.cafe
            wrote sidst redigeret af
            #21

            @stefano At my previous job company hired someone for such test. One of requirements was to install their a server on our network for duration of test. So they can better understand network topology and services to test.

            stefano@mastodon.bsd.cafeS 1 Reply Last reply
            0
            • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

              This one beats them all and it’s going to make me laugh until tonight:

              “I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

              I had to read it three times just to make sure I’d understood it properly.

              #IT #SysAdmin #HorrorStories

              justine@snac.smithies.me.ukJ This user is from outside of this forum
              justine@snac.smithies.me.ukJ This user is from outside of this forum
              justine@snac.smithies.me.uk
              wrote sidst redigeret af
              #22
              You couldn't make that up. 🙄🤣🤣🤣
              1 Reply Last reply
              0
              • anparker@mastodon.bsd.cafeA anparker@mastodon.bsd.cafe

                @stefano At my previous job company hired someone for such test. One of requirements was to install their a server on our network for duration of test. So they can better understand network topology and services to test.

                stefano@mastodon.bsd.cafeS This user is from outside of this forum
                stefano@mastodon.bsd.cafeS This user is from outside of this forum
                stefano@mastodon.bsd.cafe
                wrote sidst redigeret af
                #23

                @anparker this makes some sense. They can study the network from inside. But still...

                1 Reply Last reply
                0
                • stefano@mastodon.bsd.cafeS stefano@mastodon.bsd.cafe

                  @mms You deserve it much more than them

                  _elena@mastodon.social_ This user is from outside of this forum
                  _elena@mastodon.social_ This user is from outside of this forum
                  _elena@mastodon.social
                  wrote sidst redigeret af
                  #24

                  @stefano @mms you two are making me laugh out loud on the crowded train 😂

                  Who are these people? Getting strong 🤡 vibes

                  stefano@mastodon.bsd.cafeS 1 Reply Last reply
                  0
                  • pertho@mastodon.bsd.cafeP pertho@mastodon.bsd.cafe

                    @stefano yeah these are ridiculous. Why the hell would you disable your firewall? Also these aren't penetration tests, they're just vulnerability scanners.

                    raymaccarthy@mastodon.ieR This user is from outside of this forum
                    raymaccarthy@mastodon.ieR This user is from outside of this forum
                    raymaccarthy@mastodon.ie
                    wrote sidst redigeret af
                    #25

                    @pertho @stefano
                    It's a phishing attack, not a vulnerability test!

                    stefano@mastodon.bsd.cafeS 1 Reply Last reply
                    0
                    • lfa@hostux.socialL lfa@hostux.social

                      @stefano Give him your user and the root password just to make sure the pen test goes as expected 😂

                      _elena@mastodon.social_ This user is from outside of this forum
                      _elena@mastodon.social_ This user is from outside of this forum
                      _elena@mastodon.social
                      wrote sidst redigeret af
                      #26

                      @lfa 😂😂😂😂😂 @stefano

                      1 Reply Last reply
                      0
                      • _elena@mastodon.social_ _elena@mastodon.social

                        @stefano @mms you two are making me laugh out loud on the crowded train 😂

                        Who are these people? Getting strong 🤡 vibes

                        stefano@mastodon.bsd.cafeS This user is from outside of this forum
                        stefano@mastodon.bsd.cafeS This user is from outside of this forum
                        stefano@mastodon.bsd.cafe
                        wrote sidst redigeret af
                        #27

                        @_elena @mms Totally. Later today I'll have a call with the person who hired them and explain a thing or two 🙂
                        This is a good person - just doesn't understand the implications.

                        1 Reply Last reply
                        0
                        • raymaccarthy@mastodon.ieR raymaccarthy@mastodon.ie

                          @pertho @stefano
                          It's a phishing attack, not a vulnerability test!

                          stefano@mastodon.bsd.cafeS This user is from outside of this forum
                          stefano@mastodon.bsd.cafeS This user is from outside of this forum
                          stefano@mastodon.bsd.cafe
                          wrote sidst redigeret af
                          #28

                          @raymaccarthy @pertho Extremely appropriate definition!

                          1 Reply Last reply
                          0
                          • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                          Svar
                          • Svar som emne
                          Login for at svare
                          • Ældste til nyeste
                          • Nyeste til ældste
                          • Most Votes


                          • Log ind

                          • Har du ikke en konto? Tilmeld

                          • Login or register to search.
                          Powered by NodeBB Contributors
                          Graciously hosted by data.coop
                          • First post
                            Last post
                          0
                          • Hjem
                          • Seneste
                          • Etiketter
                          • Populære
                          • Verden
                          • Bruger
                          • Grupper