the rm -rf's will continue until morale improves
-
@jztusk @womble @paco @neurovagrant
Like leaving an empty file called
pwnedon/.@jrdepriest @jztusk @womble @paco @neurovagrant Also fun.
-
@jztusk @womble @paco @neurovagrant
Mission accomplished with the table drop, then?
@jrdepriest @jztusk @womble @paco @neurovagrant Yep. Sometimes that's the only way to make them understand. Or using a loop and ssh to power down an entire rack.
"Are you sure? This is fatal," during a meeting with a client is not an idle threat, and a lot of clients think we're bluffing.
-
@paco @neurovagrant wouldn't that be a criminal offense at that point as well

@rail @paco @neurovagrant Depends on how aggro the client wants to be.
-
@neurovagrant people still haven't learned after all that ransomware. Back it up and/or employ snapshots. I'm a big fan of ZFS snapshots.
@adamhotep @neurovagrant Because they were lucky enough to have usable backups.
Stress "lucky."
-
@Viss @neurovagrant Letsss goooooo
-
@drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot
dude doesnt know what a sandbox is.
if the shit can reach your home directory, its not in a sandbox.
-
the rm -rf's will continue until morale improves
-
@neurovagrant also, people still not doing backups/restore testing, no zfs, no jails / containers / other restrictions. Kids these days.
@dch @neurovagrant There are folks who don't even know what removable storage is, let alone file systems or files.
"Just rebuild."
Great. That's the OS. What about the data?
There's probably a "chased by an angry goose" meme to make here.
-
@drwho @quinn @neurovagrant so i just went and squinted at the screenshot inside the screenshot
dude doesnt know what a sandbox is.
if the shit can reach your home directory, its not in a sandbox.
@Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.
-
@Viss @quinn @neurovagrant Given his previous business history, this surprises not at all.
@drwho @Viss @neurovagrant he probably makes more in a month than i will ever make
-
@drwho @Viss @neurovagrant he probably makes more in a month than i will ever make
@quinn @drwho @neurovagrant oh, hes a cryptobro. no wonder
-
@drwho @Viss @neurovagrant he probably makes more in a month than i will ever make
@quinn @Viss @neurovagrant Same.
-
@neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran
drop table users;via injection.Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.
@paco @neurovagrant imho, if LLMs are what make developers finally care about cybersecurity, that's the first thing about them one might consider 'good'
-
@rail @paco @neurovagrant Depends on how aggro the client wants to be.
Also depends on how well written your contact with the client is.
-
the rm -rf's will continue until morale improves
@neurovagrant I'm pushed to use claude at work... Three possible takeaways from this:
- Don't use auto mode and review the commands.
- Sandbox claude so that the fallout of such an oppsie is more limited.
- Do nothing and have a claude-free afternoon while I restore my profile.

-
A simple
select * from userswould've been fine just to prove the point.@jrdepriest @jztusk @paco @neurovagrant that shows access but not, whatsit, that the injected query has `drop table` privileges, I forget the term for it
-
@neurovagrant thats why dev machines are VM's for me and before I start to "dev" you make a backup. I think its time we teach about backups now.
@computernut43 @neurovagrant You mean one of the things that AI has just made unreasonably expensive?
-
the rm -rf's will continue until morale improves
@neurovagrant still waiting for the bad news
-
@neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production
-
@neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production
I once took out Nespresso's factory by DoSing its firewall until it fell over. On a Friday at 5pm. With no one on call. Oops.
