<erno> hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is.
<erno> hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is.
It had an open file share, containing some Delphi books and from which we got the computer name too. So we walked over to the Delphi team's side, and kept yelling the computer name until some dude said "Hey, that's me!"
Turns out he was running a test-case, in an infinite loop until it worked (because that's how test cases worked), and he thought he was pointed at QA, but he somehow had it set up to target Prod.
Our job was done at that point, we left the rest to management (who made sure he didn't get fired but didn't do it again).
I try to tell people: "You don't need AI security, you need a checklist." Colonial Pipeline reused passwords, shared passwords, used the same password for all VPN users, failed to rotate it when people left. (that's 4 insanely basic violations of password security). ANY human who did a security review would have caught that. Even an intern who knew nothing and furiously googled "information security review" on the bus on the way in to kick off the review. (no disrespect to interns in over their heads, my point is they didn't prioritize security so they didn't get security)
Capital One used an admin privileged instance profile attached to a publicly accessible admin interface for a security tool (which tool, by the way, had no need of admin credentials). They were hit by an SSRF vuln and leaked their admin credentials. They also failed to alert of unexpected use of those credentials (try it, use of admin credentials is rare enough you won't have a lot of noise) failed to alert on large outbound connection (this one is subtle, but worth doing if you can figure it out)
Equifax failed to apply security updates regularly (just turn on automatic security updates. People suck at chores) Failed to deploy a SIEM, failed to conduct periodic security reviews, failed to put capable security people in place.
The above are not my clients, just public reports to illustrate that everyone can benefit from a security review to catch the obvious errors.
"net send <host> 'If you can read this, please call IT SUPPORT at ... and tell us'".
It worked :)
The whole system falls apart when you have no idea where in the building the end device is, if you are lucky there may be a managed switch on the network route somewhere that may help you narrow down the location somewhat.
So yes, it did happen sometimes that the only way to find a box was to send a desktop alert and hope the admin of that box contacted you.
Network documentation in this case? No way. The only option is to pull it all out for recycling, and start over.
Some IT security departments have very confused ideas.
It’s often the case that somebody slapped something together in an area that wasn’t their expertise, it’s been noticed that it’s a real problem, and someone has been hired to fix that problem. The “not knowing” is often the reason they’ve been hired. Trying to sort out a real world scenario (while also handling other needs of the org) is almost definitionally Taking Responsibility. So let’s not shit on people trying to cleanup a bad situation by calling them irresponsible for not knowing.
The more senior I get, the more I realize there are often a multitude of reasons things are the way they are, and many times those are valid reasons, when seeing something that is broken.
Taking a beat before pontificating and making a fool of yourself will save a ton of heartache in your career.
When you see something so broken, ask yourself why? Then ask somebody else. Some highlights from my career:
1) Last guy got cancer in the middle of a build.
2) Last guy worked his way up from one man help desk to Linux guru over 15 years all on his own, but was so busy putting out fires, he never had the chance to improve things.
3) Project started out as a proof of concept and was intended to be torn down.
4) Due to government contracts, the system has to be maintained exactly as delivered, no labels even allowed, and obviously no IT staff(?!) To make spreadsheets. Everything was paper notes by operators.
5) Pure laziness and incompetence as you alluded to.
All this to say, more often than not there is a good reason something is fucked up, finding out why may help you fix it (like in the case of politics, budget issues, firefighting, priorities, etc..)
If you’re hired because the old person didn’t follow basic maintenance procedures, you’re still ignorant until you rewire or trace the whole company’s network.
A Physical keystroke logger if you want to think of it that way.
[1] https://www.theverge.com/2019/7/14/20692471/logitech-mouseja...
Even if the data stream itself is encrypted there's still a little bit of data leakage. Your keyboard isn't constantly sending data, it really only chirps when there's an actual keypress event. So if you look at the actual physical RF, you 'll notice patterns related to the user's typing. There is some research in trying to guess key presses based on typing cadence, although I'm not sure exactly how effective it really is.
I say all of this typing on a Logitech Unifi keyboard amd routinely use bluetooth keyboards. As others have mentioned it really depends on your threat profile, and in the case of wireless keyboards you probably aren't near the level where this paranoia is justified. Are you typing state secrets that a foreign government body really wants in a public place? Probably want to have a wired keyboard...or maybe just not type such things in such places. Are you typing out a comment on Hacker News in a private space? Probably have nothing to worry about with a wireless keyboard.
Such features could alleviate some of the parent poster's concerns.
Sure, in an ideal world that would be possible - but we didn't even have access to the switches. So either it's trying to hunt down the other department in another building who /might/ solve that riddle in an unspecified amount of time... or just do it :)
ejectHe sent one to “*” saying something about the FBI or some such, and evidently it ended up reaching computers across the entire local school system (not just our public school).
He was called out of class days later after they looked up the IP and library computer access logs.
We now have a process that routinely scans our entire IP space for machines that somehow get lost from our inventory system.
I had to use my firewall to monitor the network traffic of the IP to determine what the device was. It turned out to be a long-forgotten smartwatch collecting dust on a charger tucked away somewhere.
I have something that sends me an occasional email. I haven't needed it in years, but it's not in any of the AWS regions I remember ever using. Nor in the obvious places I might have put it playing around with azure or google cloud or whatever. I'm sure I could find it if I really tried but t only emails me once or twice a year so I just let it be.