Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Page / 5
Link Posted: 12/18/2020 11:17:21 PM EDT
[#1]
When you buy everything from Red China or give their scientists total access to US tech..and get the back doors they planted?
Link Posted: 12/18/2020 11:19:00 PM EDT
[#2]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
When you buy everything from Red China or give their scientists total access to US tech..and get the back doors they planted?
View Quote


It is probably unfair to ignore the importance of home grown incompetence.
Link Posted: 12/18/2020 11:19:40 PM EDT
[#3]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Well, at least the dominion voting machines were secure.
View Quote

Attachment Attached File
Link Posted: 12/18/2020 11:19:50 PM EDT
[#4]
It's a massive Coordinated Chinese-Russian cyber attack.
Link Posted: 12/18/2020 11:22:36 PM EDT
[#5]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
@navvet89

My exposure to .gov IT is much more limited than yours (3 years here), but I'm utterly fucking astounded and how much 'zero fucks given' is taken to IT security where I work.  It wasn't until we got hit with a virus that my boss went "how did this happen?!" like it was some fucking surprise.

I won't list the details, but guessable passwords, deprecated unpatched OS's running in the LE side of things, passwords written on post it notes, you name it were abound.  Hell we still have an ASA running code from 10 years ago that has never been patched, and that's our primary firewall.

View Quote

Domain admin membership doesn't depend on your role or competence, it shows how politically important you are.
Link Posted: 12/18/2020 11:23:25 PM EDT
[#6]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
i wonder what the actual fallout from this will wind up looking like.

it's incredible.
View Quote

The fallout:


The taxpayers will fund a multi-year, multi-million dollar study that will say mistakes were made but overall everybody involved was great and did the best they could, and More money needs to be spent on cyber security, but spent in the exact same manner as before the attack.

No .gov employees will be fired or reprimanded.

The most responsible SES employees will be promoted.


Link Posted: 12/18/2020 11:24:40 PM EDT
[#7]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Ya think?  I putty'd into it one day about 3 years ago to look at some logs.
I discovered the last reboot was 2012.

I brought it up to my supervisor.  He said "yeah, I know.  I'm afraid if we reboot it, it won't come back up."
My response "Why the fuck is it in production then?!"

It's still in production.  Still unpatched and still not rebooted since 12.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:




Ya think?  I putty'd into it one day about 3 years ago to look at some logs.
I discovered the last reboot was 2012.

I brought it up to my supervisor.  He said "yeah, I know.  I'm afraid if we reboot it, it won't come back up."
My response "Why the fuck is it in production then?!"

It's still in production.  Still unpatched and still not rebooted since 12.


not the worst I worked for a company once that did that crap.  They had a production database that were MS SQL 6.5 on W2K boxes, also connected to the internet this was in 2017 for a major fast food chain.  I couldn't believe it. I told the boss of the firm that was the most idiotic security risks I ever saw. He told me they didn't see the point upgrading.  I quit after 3 weeks.


Link Posted: 12/18/2020 11:26:44 PM EDT
[#8]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


not the worst I worked for a company once that did that crap.  They had a production database that were MS SQL 6.5 on W2K boxes, also connected to the internet this was in 2017 for a major fast food chain.  I couldn't believe it. I told the boss of the firm that was the most idiotic security risks I ever saw. He told me they didn't see the point upgrading.  I quit after 3 weeks.


View Quote
They never seem to care until I give that look and say "You lost everything".

Link Posted: 12/18/2020 11:27:30 PM EDT
[#9]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I do a lot of contract work with an international Fortune 500 company.

I would routinely find things like Windows servers with domain admin users left logged in indefinitely. VNC (and there's part of the problem) into a server expecting to log in, get someone else's open session.

Or log into a server and see it's waiting to install cumulative security updates from 6+ months ago. Someone should have seen this in SCCM, received an alert or anything.. Nope, ignored.

Passwords on almost every account never changed.

So when they got hacked this year, almost lost all their DCs and infra to ransomware, and had passwords reset on almost all domain admin users, I was not surprised. Then all of their data went up for sale on the dark web. They even wiped all tape backups that were inserted into backup servers worldwide. Backups to NAS? Stored on public shares, now all encrypted and worthless

Tip off that something was coming... All of the infosec team members had unpronouncable Indian names and accents to match. Those guys don't give a fuck.
View Quote



And if a few of them were any good at their careers, they were likely in on it.  Those Patels are a sneaky bunch of fraudsters.
Link Posted: 12/18/2020 11:28:09 PM EDT
[#10]
I'm game for martial law until this shit gets sorted and a new election takes place.  Meanwhile we need to go red hot on Russia and China until the rest of the world pisses their pants at the mention of USA. Release the SSBNs.
Link Posted: 12/18/2020 11:30:42 PM EDT
[#11]
Very few organizations are willing to pay for the manpower it takes to keep sytems upgraded and patched.  
How often should you patch your servers?  Once a week?
Once a month?  We restarted a couple servers the other dat that had updates waiting,  It took 2 hours to complete.
Now multiply that by 100 for us.
Its a full time job, after hours, in itself.

And if you were current with your Solarwinds updates/upgrades, you downloaded the malicious updates.
So are patches/upgrades good or bad?

The sad reality is that our reliance and utilization of technology has outpaced our ability to keep it secure.

Link Posted: 12/18/2020 11:31:00 PM EDT
[#12]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
They never seem to care until I give that look and say "You lost everything".

View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:


not the worst I worked for a company once that did that crap.  They had a production database that were MS SQL 6.5 on W2K boxes, also connected to the internet this was in 2017 for a major fast food chain.  I couldn't believe it. I told the boss of the firm that was the most idiotic security risks I ever saw. He told me they didn't see the point upgrading.  I quit after 3 weeks.


They never seem to care until I give that look and say "You lost everything".




lol the other problem that shit you had to run it on was so old it belonged in a museum and was constantly breaking .  I hadn't seen those servers types since 1999
Link Posted: 12/18/2020 11:32:04 PM EDT
[#13]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

The fallout:


The taxpayers will fund a multi-year, multi-million dollar study that will say mistakes were made but overall everybody involved was great and did the best they could, and More money needs to be spent on cyber security, but spent in the exact same manner as before the attack.

No .gov employees will be fired or reprimanded.

The most responsible SES employees will be promoted.


View Quote


You misspelled "most responsible SES employees will take positions at IT services companies that sell solutions to government organizations".
Link Posted: 12/18/2020 11:33:27 PM EDT
[#14]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Very few organizations are willing to pay for the manpower it takes to keep sytems upgraded and patched.  
How often should you patch your servers?  Once a week?
Once a month?  We restarted a couple servers the other dat that had updates waiting,  It took 2 hours to complete.
Now multiply that by 100 for us.
Its a full time job, after hours, in itself.

And if you were current with your Solarwinds updates/upgrades, you downloaded the malicious updates.
So are patches/upgrades good or bad?

The sad reality is that our reliance and utilization of technology has outpaced our ability to keep it secure.

View Quote


we didn't let germany or japan build tanks or ships for us in WWII, but we don't seem to mind letting the 3rd world design critical pieces of our infrastructure now. Maybe shipping all those jobs and manufacturing overseas wasn't such a good idea, in hindsight.
Link Posted: 12/18/2020 11:33:53 PM EDT
[#15]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Agreed with it's not an attack.  Yet.
What it is though could allow someone to severely fuck with our country at the core.
I'm talking Defensive, Power, Commerce, Comms, you name it.

We go tossing a nuke at this perp, and they might be able turn off the power.
I'm not saying they can do it, I'm saying whoever did this knows what the fuck they're doing, and they spent a shit ton of time and capital to make it happen.  The payload however, nobody knows.

View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
I think this is less an attack and more someone keeps leaving doors open or outright uplinking shit to sites to allow access. Is it no wonder they can't stop it if people are actively allowing it?
Agreed with it's not an attack.  Yet.
What it is though could allow someone to severely fuck with our country at the core.
I'm talking Defensive, Power, Commerce, Comms, you name it.

We go tossing a nuke at this perp, and they might be able turn off the power.
I'm not saying they can do it, I'm saying whoever did this knows what the fuck they're doing, and they spent a shit ton of time and capital to make it happen.  The payload however, nobody knows.




Not an attack?

NOT AN ATTACK?!?

You sound like Trump, and that's probably why this is happening.

We need a President with some fucking balls not just bluster and hot air.
I'm doesn't matter the cost, you destroy the country involved and take it as your own.

It won't happen again, for a long, long time... Buy nah, let's just slap some sanctions out there and talk a lot of shit.
Link Posted: 12/18/2020 11:35:30 PM EDT
[#16]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
World War 3 will start with computer hacks.  The Chicoms could probably take down our power grid at anytime

Completely fuck our nationwide commerce network

View Quote


Maybe some of the power grids but not all
Link Posted: 12/18/2020 11:36:02 PM EDT
[#17]
So China releases a super flu, and while to US is distracted, they start cracking into everything right on up to our nukes?

Who won the Cold War again?
Link Posted: 12/18/2020 11:38:34 PM EDT
[#18]
Don't worry guys, at least our banking system is secure

Sad to think what would happen if swift and ach transactions were stopped
Link Posted: 12/18/2020 11:39:01 PM EDT
[#19]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Very few organizations are willing to pay for the manpower it takes to keep sytems upgraded and patched.  
How often should you patch your servers?  Once a week?
Once a month?  We restarted a couple servers the other dat that had updates waiting,  It took 2 hours to complete.
Now multiply that by 100 for us.
Its a full time job, after hours, in itself.

And if you were current with your Solarwinds updates/upgrades, you downloaded the malicious updates.
So are patches/upgrades good or bad?

The sad reality is that our reliance and utilization of technology has outpaced our ability to keep it secure.

View Quote
Monthly and I automated it all with PowerShell and SCCM.
It can be done, it just doesn't get done.

Link Posted: 12/18/2020 11:39:26 PM EDT
[#20]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
@navvet89

My exposure to .gov IT is much more limited than yours (3 years here), but I'm utterly fucking astounded and how much 'zero fucks given' is taken to IT security where I work.  It wasn't until we got hit with a virus that my boss went "how did this happen?!" like it was some fucking surprise.

I won't list the details, but guessable passwords, deprecated unpatched OS's running in the LE side of things, passwords written on post it notes, you name it were abound.  Hell we still have an ASA running code from 10 years ago that has never been patched, and that's our primary firewall.

View Quote


Do you even STIG, bro?
Link Posted: 12/18/2020 11:41:42 PM EDT
[#21]
This election was a fraud, and this is the proof.
Link Posted: 12/18/2020 11:41:53 PM EDT
[#22]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



lol the other problem that shit you had to run it on was so old it belonged in a museum and was constantly breaking .  I hadn't seen those servers types since 1999
View Quote


Where do you think you go for work if your skillsets still involve ancient things like HP-UX, Solaris and VMS
Link Posted: 12/18/2020 11:42:12 PM EDT
[#23]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Well if they're in the DOD's network and have been for 9 months, they might know an uncomfortable amount about where our forces are stationed around the world. I have no idea if something like the locations and course data for our nuclear subs is something they would have had access to, but boy howdy that sure would suck.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Why doesn't Congress declare war?
Well if they're in the DOD's network and have been for 9 months, they might know an uncomfortable amount about where our forces are stationed around the world. I have no idea if something like the locations and course data for our nuclear subs is something they would have had access to, but boy howdy that sure would suck.


Nobody should have any idea where our subs are aside from the sub itself.
Link Posted: 12/18/2020 11:45:05 PM EDT
[#24]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
This election was a fraud, and this is just more proof.
View Quote

Fixed it for you.
Link Posted: 12/18/2020 11:47:56 PM EDT
[#25]
Act of war.
Link Posted: 12/18/2020 11:48:49 PM EDT
[#26]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Do you even STIG, bro?
View Quote

Why yes, yes I do.
Link Posted: 12/18/2020 11:50:29 PM EDT
[#27]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Monthly and I automated it all with PowerShell and SCCM.
It can be done, it just doesn't get done.

View Quote


How long would it take you to patch 100 virtual servers, reboot them, comfirm they are all back online, After hours?
At a 24/7/365 operation.
Who does your firewalls?  All your switch firmwares?
How about your vcenter servers?  Nimble SAN arrays.
Cisco UCS chassis and host firmwares?
Load balancers?  
Like I said,  its a full time job just to manage updates and most IT staff is just trying to troubleshoot the day to day and meet the ever demanding needs of the sheeple .
Link Posted: 12/18/2020 11:51:04 PM EDT
[#28]
Will the ATF servers remain unscathed?  Oh thank goodness.


Link Posted: 12/18/2020 11:51:58 PM EDT
[#29]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

Fixed it for you.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
This election was a fraud, and this is just more proof.

Fixed it for you.


I agree with your edit.
Link Posted: 12/18/2020 11:52:30 PM EDT
[#30]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Not an attack?

NOT AN ATTACK?!?

You sound like Trump, and that's probably why this is happening.

We need a President with some fucking balls not just bluster and hot air.
I'm doesn't matter the cost, you destroy the country involved and take it as your own.

It won't happen again, for a long, long time... Buy nah, let's just slap some sanctions out there and talk a lot of shit.
View Quote
Simmer down Rambo.

Link Posted: 12/18/2020 11:55:52 PM EDT
[#31]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Do you even STIG, bro?
View Quote
Hard when management won't let you work on it.
Link Posted: 12/18/2020 11:56:08 PM EDT
[#32]
Did Q predict this?
Link Posted: 12/18/2020 11:56:51 PM EDT
[#33]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


How long would it take you to patch 100 virtual servers, reboot them, comfirm they are all back online, After hours?
At a 24/7/365 operation.
Who does your firewalls?  All your switch firmwares?
How about your vcenter servers?  Nimble SAN arrays.
Cisco UCS chassis and host firmwares?
Load balancers?  
Like I said,  its a full time job just to manage updates and most IT staff is just trying to troubleshoot the day to day and meet the ever demanding needs of the sheeple .
View Quote
Preaching to the choir brother.  Redundancy.
Link Posted: 12/18/2020 11:58:44 PM EDT
[#34]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Where do you think you go for work if your skillsets still involve ancient things like HP-UX, Solaris and VMS
View Quote


The IRS.  Seriously

Either way we win.  
Link Posted: 12/18/2020 11:58:56 PM EDT
[#35]
Discussion ForumsJump to Quoted PostQuote History
View Quote

Ha! I knew you'd be a ham.
Link Posted: 12/19/2020 12:03:58 AM EDT
[#36]
Link Posted: 12/19/2020 12:04:31 AM EDT
[#37]
Nothing is happening. This is all just another 'breaking news' story to distract people from reality.
Another red herring...another nothing burger.

Wake me up when there is a single, tangible outcome that impacts any of us directly.
Link Posted: 12/19/2020 12:07:31 AM EDT
[#38]
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.
Link Posted: 12/19/2020 12:10:55 AM EDT
[#39]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.
View Quote
Yeah I think you're dead wrong on this one.
Link Posted: 12/19/2020 12:17:47 AM EDT
[#40]
This better end with some people hanging from yard arms.
Link Posted: 12/19/2020 12:21:08 AM EDT
[#41]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Which 3 states?
View Quote


Given the potato sites they have I'd not be surprised if Virginia is one of them. That and NOtVA is slam full of Chi-Coms.
Link Posted: 12/19/2020 12:22:42 AM EDT
[#42]
Quoted:
Nothing is happening. This is all just another 'breaking news' story to distract people from reality.
Another red herring...another nothing burger.

Wake me up when there is a single, tangible outcome that impacts any of us directly.
View Quote

Quoted:
Government networks get attacked every day multiple times a day.

They got more at the link? Otherwise I'm going with sensational nothing burger.
View Quote


You two don't have a fucking clue what you're talking about. This is, quite possibly, the biggest cyber attack in history. Certainly the most sophisticated.
Link Posted: 12/19/2020 12:24:57 AM EDT
[#43]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Very few organizations are willing to pay for the manpower it takes to keep sytems upgraded and patched.  
How often should you patch your servers?  Once a week?
Once a month?  We restarted a couple servers the other dat that had updates waiting,  It took 2 hours to complete.
Now multiply that by 100 for us.
Its a full time job, after hours, in itself.

And if you were current with your Solarwinds updates/upgrades, you downloaded the malicious updates.
So are patches/upgrades good or bad?

The sad reality is that our reliance and utilization of technology has outpaced our ability to keep it secure.

View Quote


We patch almost 500 servers every month.  It can be done with one guy in a couple days with automation.
Link Posted: 12/19/2020 12:29:20 AM EDT
[#44]
I have a feeling this was all set up as a nuclear option for the CCP/Swamp if the ballot fraud plan failed and Trump was still reelected. If bidet takes office next month then this will all go away and back to normal. Well, back to the democrats selling us off to China normal.
Link Posted: 12/19/2020 12:34:06 AM EDT
[#45]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Very few organizations are willing to pay for the manpower it takes to keep sytems upgraded and patched.  
How often should you patch your servers?  Once a week?
Once a month?  We restarted a couple servers the other dat that had updates waiting,  It took 2 hours to complete.
Now multiply that by 100 for us.
Its a full time job, after hours, in itself.

And if you were current with your Solarwinds updates/upgrades, you downloaded the malicious updates.
So are patches/upgrades good or bad?

The sad reality is that our reliance and utilization of technology has outpaced our ability to keep it secure.

View Quote


So just don't patch anything for fear of trusted update sources having malicious injections?

If users cannot deal with scheduled maintenance and you are truly 24/7 you should be doing clustering and cluster aware updates.

Users don't like scheduled maintenance but they will like unscheduled maintenance even less.
Link Posted: 12/19/2020 12:36:29 AM EDT
[#46]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



And if a few of them were any good at their careers, they were likely in on it.  Those Patels are a sneaky bunch of fraudsters.
View Quote


Those guys are a revolving door and I wouldn't be surprised at all
Link Posted: 12/19/2020 12:36:46 AM EDT
[#47]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Why doesn't Congress declare war?
View Quote


They haven't figured out how to profit off of it yet.
Link Posted: 12/19/2020 12:37:55 AM EDT
[#48]
Link Posted: 12/19/2020 12:43:32 AM EDT
[#49]
Link Posted: 12/19/2020 12:45:03 AM EDT
[#50]
Page / 5
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top