GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Lelouche ? (lelouchebag@shitposter.club)'s status on Saturday, 17-Jun-2023 07:46:40 JST Lelouche ? Lelouche ?
    Everyone's enjoying the fridey but I have to work all weekend :saddest:
    In conversation Saturday, 17-Jun-2023 07:46:40 JST from shitposter.club permalink
    • Embed this notice
      Lelouche ? (lelouchebag@shitposter.club)'s status on Saturday, 17-Jun-2023 07:46:39 JST Lelouche ? Lelouche ?
      in reply to
      Basically
      >get call from IT that a shit ton of data is being uploaded out of the server
      >tell him to chill and it's just us pushing everything to the git server
      >"no man this is like 500GB trickling out all day"
      >check the logs
      >rando IPs ssh'ing in
      >ask the guy why the hell that's occuring since the first thing I did was disable password auth in ssh in favor of keys
      >says he put it back on so he could get into the server
      >credentials are a combo you'd guess easily
      >I legit call him a retard over the phone
      >management finds out and gets all buttmad
      >turn everything off, airgap it from everything else
      >now have to come in early tomorrow to re-image ALLLL the machines and harden the servers all over again
      I swear to god if he tops this off by reporting me to hr for calling him a retard I will play minecraft. Also I'm already scoping out alternative IT support since this company is dogshit and genuinely doesn't know linux
      In conversation Saturday, 17-Jun-2023 07:46:39 JST permalink

      Attachments


      1. https://static.banky.club/shitposter.club/0daa86a3137fadc92b10ddbc70ec867b32cea2c0f8cc8d46ff8362a423ea8ee1.png?name=1534828781975.png
      georgia likes this.
    • Embed this notice
      minty (minty@poa.st)'s status on Sunday, 18-Jun-2023 02:20:21 JST minty minty
      in reply to
      @lelouchebag windows people are the worst lol.
      In conversation Sunday, 18-Jun-2023 02:20:21 JST permalink
      Lelouche ? likes this.
    • Embed this notice
      minty (minty@poa.st)'s status on Sunday, 18-Jun-2023 02:20:22 JST minty minty
      in reply to
      @lelouchebag why are you even allowing these retards permissions to do stuff like this?

      He knew how to edit ssh config but not how to copy a public key to authorized_keys? Also fail2ban may have helped to prevent the password login.
      In conversation Sunday, 18-Jun-2023 02:20:22 JST permalink
    • Embed this notice
      Lelouche ? (lelouchebag@shitposter.club)'s status on Sunday, 18-Jun-2023 02:20:22 JST Lelouche ? Lelouche ?
      in reply to
      • minty
      @minty >permission
      Not my choice, corporate's. The IT company we "outsource" our security to has some sort of insurance agreement. If their solutions are bad and cause harm, they'll insure the losses. Their mentality is that it's a "full time job" to run security yet the firm is literally running like every tech company in the area's security and constantly breaking stuff in my servers
      >he knew how to edit ssh config
      Maybe, I don't know much about windows servers (which the firm claims to be experts at) so maybe he knew from that? Or Windows server has some other way to secure stuff like ssh connections without keys? I know there's some 2fa you can set up with your phone. But I honestly think he just googled it since he knew I was able to disable it when I had him get his key sorted out

      And I was the one who put his public key into authorized_keys for him. And proceeded to give him the exact command and instructions (rename it to id_rsa and all that) to ssh in using the key. Maybe he wanted to access it from a machine and didn't want to move his key over? Maybe he messed something up and thought the ssh key login was busted, so he added password auth back during his last walkthrough? I really don't know. I have to call him tomorrow anyway for the loss report
      In conversation Sunday, 18-Jun-2023 02:20:22 JST permalink
    • Embed this notice
      minty (minty@poa.st)'s status on Sunday, 18-Jun-2023 02:20:23 JST minty minty
      in reply to
      @lelouchebag how did he reenable password auth if he couldnt get into the server?
      In conversation Sunday, 18-Jun-2023 02:20:23 JST permalink
    • Embed this notice
      Lelouche ? (lelouchebag@shitposter.club)'s status on Sunday, 18-Jun-2023 02:20:23 JST Lelouche ? Lelouche ?
      in reply to
      • minty
      @minty He comes by the office for IT setup, fixing printers, routine walkthroughs, etc. I keep an ethernet cord plugged in since the time a guy wiped the iptables
      In conversation Sunday, 18-Jun-2023 02:20:23 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.