ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What Are You Doing Right Now

    Scheduled Pinned Locked Moved Water Closet
    time waster
    88.9k Posts 285 Posters 42.9m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @dbeato
      last edited by

      @dbeato said in What Are You Doing Right Now:

      @scottalanmiller said in What Are You Doing Right Now:

      Another fun day of ransomware remediation.

      Another one?

      Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

      Internally, it was AD to spread. So they've removed AD to secure the environment.

      siringoS nadnerBN dbeatoD 3 Replies Last reply Reply Quote 1
      • siringoS
        siringo @scottalanmiller
        last edited by

        @scottalanmiller said in What Are You Doing Right Now:

        @dbeato said in What Are You Doing Right Now:

        @scottalanmiller said in What Are You Doing Right Now:

        Another fun day of ransomware remediation.

        Another one?

        Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

        Internally, it was AD to spread. So they've removed AD to secure the environment.

        which ransomeware is it?

        1 Reply Last reply Reply Quote 0
        • nadnerBN
          nadnerB @scottalanmiller
          last edited by

          @scottalanmiller said in What Are You Doing Right Now:

          @dbeato said in What Are You Doing Right Now:

          @scottalanmiller said in What Are You Doing Right Now:

          Another fun day of ransomware remediation.

          Another one?

          Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

          Internally, it was AD to spread. So they've removed AD to secure the environment.

          If you mark admin accounts as sensetive in AD, you CAN slow it down/ stop it in its tracks as it can't impersonate admins and spread further/as fast

          1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller
            last edited by

            Just hung up the phone. My part is done, at least for now.

            1 Reply Last reply Reply Quote 0
            • dbeatoD
              dbeato @scottalanmiller
              last edited by

              @scottalanmiller said in What Are You Doing Right Now:

              @dbeato said in What Are You Doing Right Now:

              @scottalanmiller said in What Are You Doing Right Now:

              Another fun day of ransomware remediation.

              Another one?

              Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

              Internally, it was AD to spread. So they've removed AD to secure the environment.

              AD like a VPN or RDS?

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @dbeato
                last edited by

                @dbeato said in What Are You Doing Right Now:

                @scottalanmiller said in What Are You Doing Right Now:

                @dbeato said in What Are You Doing Right Now:

                @scottalanmiller said in What Are You Doing Right Now:

                Another fun day of ransomware remediation.

                Another one?

                Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

                Internally, it was AD to spread. So they've removed AD to secure the environment.

                AD like a VPN or RDS?

                Nope, Just AD.

                dbeatoD DashrenderD 2 Replies Last reply Reply Quote 0
                • dbeatoD
                  dbeato @scottalanmiller
                  last edited by

                  @scottalanmiller said in What Are You Doing Right Now:

                  @dbeato said in What Are You Doing Right Now:

                  @scottalanmiller said in What Are You Doing Right Now:

                  @dbeato said in What Are You Doing Right Now:

                  @scottalanmiller said in What Are You Doing Right Now:

                  Another fun day of ransomware remediation.

                  Another one?

                  Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

                  Internally, it was AD to spread. So they've removed AD to secure the environment.

                  AD like a VPN or RDS?

                  Nope, Just AD.

                  a non-IT vendor I get it but it is so vague lol

                  1 Reply Last reply Reply Quote 0
                  • WrCombsW
                    WrCombs
                    last edited by

                    Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                    dafyreD 1 Reply Last reply Reply Quote 0
                    • dafyreD
                      dafyre @WrCombs
                      last edited by

                      @WrCombs said in What Are You Doing Right Now:

                      Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                      Hope you are feeling better!

                      WrCombsW 1 Reply Last reply Reply Quote 0
                      • WrCombsW
                        WrCombs @dafyre
                        last edited by

                        @dafyre said in What Are You Doing Right Now:

                        @WrCombs said in What Are You Doing Right Now:

                        Just getting back in due to being out sick for last 3 days last week, Had my brothers wedding this last weekend.

                        Hope you are feeling better!

                        lots better, I started feeling better Friday , after i was up half the night Thursday. Crazy stomach bug.

                        1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender @scottalanmiller
                          last edited by

                          @scottalanmiller said in What Are You Doing Right Now:

                          @dbeato said in What Are You Doing Right Now:

                          @scottalanmiller said in What Are You Doing Right Now:

                          @dbeato said in What Are You Doing Right Now:

                          @scottalanmiller said in What Are You Doing Right Now:

                          Another fun day of ransomware remediation.

                          Another one?

                          Same one, got hit again because they didn't go to full scorched earth. It was a calculated risk. They know the attack vector now, though, it was identified as one of their non-IT vendors who is also in the same boat.

                          Internally, it was AD to spread. So they've removed AD to secure the environment.

                          AD like a VPN or RDS?

                          Nope, Just AD.

                          How was this and AD issue?

                          1 Reply Last reply Reply Quote 0
                          • hobbit666H
                            hobbit666
                            last edited by

                            Wondering if this would make an OK(ish) Lab server.
                            2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @hobbit666
                              last edited by

                              @hobbit666 said in What Are You Doing Right Now:

                              Wondering if this would make an OK(ish) Lab server.
                              2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                              Sure - but why have your own box? why not just spin up some Vultr instances?

                              hobbit666H travisdh1T 2 Replies Last reply Reply Quote 0
                              • hobbit666H
                                hobbit666 @Dashrender
                                last edited by

                                @Dashrender Main reason is i want to test, Apps, Servers OS, Logging, Security, Pen Testing, stuff easily between all the VM in a isolated "Lab"

                                Have just found a HP Server for £150 (2x Xeon Hex Core, 128GB RAM )

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender @hobbit666
                                  last edited by

                                  @hobbit666 said in What Are You Doing Right Now:

                                  @Dashrender Main reason is i want to test, Apps, Servers OS, Logging, Security, Pen Testing, stuff easily between all the VM in a isolated "Lab"

                                  Have just found a HP Server for £150 (2x Xeon Hex Core, 128GB RAM )

                                  The problem with any server class machine will be the noise of the fans.

                                  hobbit666H 1 Reply Last reply Reply Quote 0
                                  • hobbit666H
                                    hobbit666 @Dashrender
                                    last edited by

                                    @Dashrender I've got a server room to hide it in 🙂

                                    1 Reply Last reply Reply Quote 0
                                    • travisdh1T
                                      travisdh1 @Dashrender
                                      last edited by

                                      @Dashrender said in What Are You Doing Right Now:

                                      @hobbit666 said in What Are You Doing Right Now:

                                      Wondering if this would make an OK(ish) Lab server.
                                      2019_03_04_14_43_31_Dell_R610_2x_X5690_3.46GHz_Hex_Core_96GB_5.4TB_HDD_Configurable_PowerEdge_Server.png

                                      Sure - but why have your own box? why not just spin up some Vultr instances?

                                      Because he's like me, and wants to run about 50 different things, which adds up quicker than you'd think.

                                      @hobbit666 That looks like an ok home lab box. I recently picked up a used server for a home lab myself. Mine is an R620, 2x E5-2660, 96GB RAM (24x4GB) PERC H710. I picked up 4 500GB SSD to put in it. It's frankly overkill for what I'm doing and have planned for it, but that just means I can experiment with more things. I say go for it.

                                      hobbit666H 1 Reply Last reply Reply Quote 1
                                      • hobbit666H
                                        hobbit666 @travisdh1
                                        last edited by

                                        @travisdh1 Spot on 🙂
                                        I've been looking into Elsatic Stack, Cyber Security, Pen Testing etc etc. Doing this on a laptop/desktop soon bombs out.
                                        Don't want to do this on works network incase 🙂

                                        So i thought buy a "Lab" Server and do what i want

                                        1 Reply Last reply Reply Quote 1
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          Morning conference call.

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller
                                            last edited by

                                            Dealing with Merchants & Professional Collection Bereau who is committing financial and medical fraud.

                                            dafyreD WrCombsW 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 4443
                                            • 4444
                                            • 1 / 4444
                                            • First post
                                              Last post