Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

This one beats them all and it’s going to make me laugh until tonight:

“I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

I had to read it three times just to make sure I’d understood it properly.

#IT #SysAdmin #HorrorStories

  • Copy link
  • Flag this post
  • Block
Paolo Redaelli
Paolo Redaelli
@paoloredaelli@mastodon.uno  ·  activity timestamp 4 weeks ago

@stefano
The good old social engineering. Never gone out of fashion, since the time of "The sneakers" movie 😃

  • Copy link
  • Flag this comment
  • Block
skua
skua
@skua@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano

I fear my knowledge level is far closer to some IT managers' than I wish.

Please make your life easier and give them access via Anydesk.

  • Copy link
  • Flag this comment
  • Block
Erik Ableson
Erik Ableson
@erik@mastodon.infrageeks.social  ·  activity timestamp 4 weeks ago

@stefano OK. after that, I'd set up a network segment filled with Thinkst Canary Honeypots open to the internet and let them waste their time there while you produce the log report showing them playing in your sandbox

  • Copy link
  • Flag this comment
  • Block
Tim Chase
Tim Chase
@gumnos@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano

"Yeah, I just need to know which IPv4 & IPv6 addresses your testing will come from so that I can adjust firewall rules"

block drop in on egress proto tcp from <pentest_ips> to any

:dusts off hands and sips coffee:

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@gumnos yes, this makes sense

  • Copy link
  • Flag this comment
  • Block
Anton Piatek
Anton Piatek
@sldrant@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano @neil tbf this is pretty standard to actually test a service or server. (yes you also test the firewall effectiveness, but the core vulnerabilities are also usually specifically tested without it)

  • Copy link
  • Flag this comment
  • Block
EnigmaRotor
EnigmaRotor
@EnigmaRotor@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano clown power ! 🤡

  • Copy link
  • Flag this comment
  • Block
no brain no pain
no brain no pain
@nobrainnopain@social.tchncs.de  ·  activity timestamp 4 weeks ago

@stefano similar here from a leader of a red team: we need further privileges to exploit the vulnerability we assume from the *version number the application reports* 🤡

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp 4 weeks ago

@stefano maybe an AI sent it? 😅

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@IAmDannyBoling I don't think so. There were some errors.

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp 4 weeks ago

@stefano I'll say! 😉 Regardless, I hope things go well tonight. Maybe you could edit your post with the results so we all get notified, if it's not too much trouble. We'll all be rooting for you.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@IAmDannyBoling eheh thanks. But it won't be tonight - it seems it's been delayed ad the committer has some doubts about their skills.

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp 4 weeks ago

@stefano That could be your lucky break. 👍

  • Copy link
  • Flag this comment
  • Block
Nick Bergen Computer Quest
Nick Bergen Computer Quest
@NickBergenComputerQuest@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano I love how they asked you to disable any “protection.” What protections? Any protections, just protections in general, anything that protects… don’t worry about it, you don’t need it…

To be fair, I think they are actually doing a pen test. They’re just trying to see how easy it is to penetrate the intelligence, or lack there of, of the sys admin.

  • Copy link
  • Flag this comment
  • Block
AskPippa🇨🇦
AskPippa🇨🇦
@AskPippa@c.im  ·  activity timestamp 4 weeks ago

@stefano I'll leave the car doors unlocked and the keys in the ignition. See if you can steal it.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@AskPippa yes, exactly

  • Copy link
  • Flag this comment
  • Block
dazfuller :rickwhoah:
dazfuller :rickwhoah:
@dazfuller@mstdn.social  ·  activity timestamp 4 weeks ago

@stefano I remember reviewing a pen test like that once. The report said that they were able to access a database server and copy the data files.

When I looked into it, it was because they’d asked for access to the server and an rdp account to connect with. And they were running the test from a device on the same network.

  • Copy link
  • Flag this comment
  • Block
Parade du Grotesque 💀
Parade du Grotesque 💀
@ParadeGrotesque@mastodon.sdf.org  ·  activity timestamp 4 weeks ago

@stefano

That is both hilarious and ridiculous.

My reply would be: "that's not how you do penetration testing, my boy"... 😉

  • Copy link
  • Flag this comment
  • Block
Tariq
Tariq
@rzeta0@mathstodon.xyz  ·  activity timestamp 4 weeks ago

@stefano

Years ago, many years ago, I was a junior technology person in the UK public sector.

Disaster recovery/ failover was a thing. And needed to be tested annually I think.

Anyway the It was outsourced to one of those large global evil incompetent corporations that were very competent at profiteering from the public purse.

The test didn't involve intentionally taking servers/services/network things offline.

I demanded it.

They protested and took it up several levels to override my "assurance".

Yeah. I learned a lot about capitalism and the public sector during that era.

  • Copy link
  • Flag this comment
  • Block
Michael Dexter
Michael Dexter
@dexter@bsd.network  ·  activity timestamp 4 weeks ago

@stefano Also known as a “Russian Ceasefire Agreement”?

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@dexter yes, probably 🙂

  • Copy link
  • Flag this comment
  • Block
Mira
Mira
@mira@shark.community  ·  activity timestamp 4 weeks ago

@stefano Surprised they didn’t ask for the admin/root password

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@mira maybe that is the next step

  • Copy link
  • Flag this comment
  • Block
Robin Barton
Robin Barton
@Robo105@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano Well, you gotta give it to them for creativity but I suspect it works on some people

  • Copy link
  • Flag this comment
  • Block
Anarchic Teapot ⚧️
Anarchic Teapot ⚧️
@anarchic_teapot@oc.todon.fr  ·  activity timestamp 4 weeks ago

@stefano I think you'd pass the test with flying colours by simply responding to the message with a hearty "The fuck I will".

  • Copy link
  • Flag this comment
  • Block
Christmas Tree
Christmas Tree
@christmastree@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano I mean... maybe that's part of the test? Probably just wishful thinking on my part

  • Copy link
  • Flag this comment
  • Block
Josh Dinsdale
Josh Dinsdale
@joshdinsdale@mastodon.iow.social  ·  activity timestamp 4 weeks ago

@stefano Yeha when i was doing outsourced support we used to get this for PCI compliance scans all the time, totally pointless.

  • Copy link
  • Flag this comment
  • Block
Nate
Nate
@nenos@fosstodon.org  ·  activity timestamp 4 weeks ago

@stefano You should pay them with a few boxes of clown shoes. If this is supposed to be an external network penetration test, it may be polite to also include some brightly colored wigs and big red noses as well.

  • Copy link
  • Flag this comment
  • Block
Isaac Ji Kuo
Isaac Ji Kuo
@isaackuo@spacey.space  ·  activity timestamp 4 weeks ago

@stefano Needs an AI generated picture of a friendly nerd wearing Louvre robber safety vests.

  • Copy link
  • Flag this comment
  • Block
Lenora
Lenora
@FaithinBones@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano and there are people who will fall for it

  • Copy link
  • Flag this comment
  • Block
חנן כהן • Hanan Cohen
חנן כהן • Hanan Cohen
@hananc@tooot.im  ·  activity timestamp 4 weeks ago

@stefano
true story.
him: The Ministry of Education hired me to assess the security of your app.
me: please show me an ID and a letter from the Ministry.
him: no one has never asked me to show them.

  • Copy link
  • Flag this comment
  • Block
Fubaroque
Fubaroque
@fubaroque@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano This must the social engineering part of the pentest. Just report a security incident and let them deal with it. 🥸

  • Copy link
  • Flag this comment
  • Block
Matt Lacey
Matt Lacey
@Lacey@mastodon.gamedev.place  ·  activity timestamp 4 weeks ago

@stefano I've been there before. Company hired to do a pen test but complained when they couldn't get access to the internal network to get to the server.

  • Copy link
  • Flag this comment
  • Block
kamme
kamme
@kamme@mastodon.xyz  ·  activity timestamp 4 weeks ago

@stefano reminds me of the time I was contacted by an angry new IT director of a customer because 'we wasted a lot of money'. He hired a company that did phishing exercises and our mail scanning gateway blocked it all. He wanted us to disable it completely, but then we showed the volume or spam/phishing/junk/... we blocked and asked them if he was really sure and wanted to put that in writing, with the CISO in cc. Never heard from him again.

  • Copy link
  • Flag this comment
  • Block
Ben Tasker
Ben Tasker
@ben@mastodon.bentasker.co.uk  ·  activity timestamp 4 weeks ago

@stefano ooof

I remember getting almost exactly the same request years back.

They'd pointed Nessus at the box (without telling us... rude) and our protections had _quite rightly_ identified and blocked their source IP.

So, they contacted us and said that we needed to turn the firewall off so that they could check security.

In that case, the test was being done as part of assessing the customer's PCI-DSS compliance.

  • Copy link
  • Flag this comment
  • Block
Mad Alex
Mad Alex
@madalex@fosstodon.org  ·  activity timestamp 4 weeks ago

@stefano Did they also ask a network diagram, otherwise the way to the server wasn't clear enough?

  • Copy link
  • Flag this comment
  • Block
bmaxv
bmaxv
@bmaxv@noc.social  ·  activity timestamp 4 weeks ago

@stefano Hey, it doesn't hurt to ask. They're instructed to test the environment and you're part of the environment.

  • Copy link
  • Flag this comment
  • Block
Morgan
Morgan
@kaidenshi@exquisite.social  ·  activity timestamp 4 weeks ago

@stefano It still blows my mind that our merchant account provider will say basically the same thing before they run a PCI compliance check. Like, no thanks, I'm not going to open up our network and make it vulnerable just so you can scan it to see if it's vulnerable. That makes no sense.

We pass every time so yeah, that's not how it works.

  • Copy link
  • Flag this comment
  • Block
Nils Wloka
Nils Wloka
@nils@mastodon.nilswloka.com  ·  activity timestamp 4 weeks ago

@stefano Maybe the pen test has already started and they are trying to social engineer you 😉

  • Copy link
  • Flag this comment
  • Block
mhoye
mhoye
@mhoye@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano Some real "please lower your shields to enjoy the premium photon-torpedo experience" here.

  • Copy link
  • Flag this comment
  • Block
Ricardo Tavares
Ricardo Tavares
@t_var_s@phpc.social  ·  activity timestamp 4 weeks ago

@stefano @justine It's common to ask for IPs to be whitelisted 🤷

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@t_var_s @justine which is more understandable but not totally: an hacker won't have the ip whitelisted. But still, I can see the point.

  • Copy link
  • Flag this comment
  • Block
anparker
anparker
@anparker@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano At my previous job company hired someone for such test. One of requirements was to install their a server on our network for duration of test. So they can better understand network topology and services to test.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@anparker this makes some sense. They can study the network from inside. But still...

  • Copy link
  • Flag this comment
  • Block
BeeCycling
BeeCycling
@beecycling@wandering.shop  ·  activity timestamp 4 weeks ago

@stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@beecycling officially, "how the services are vulnerable from the Internet"

  • Copy link
  • Flag this comment
  • Block
Tom
Tom
@pertho@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano yeah these are ridiculous. Why the hell would you disable your firewall? Also these aren't penetration tests, they're just vulnerability scanners.

  • Copy link
  • Flag this comment
  • Block
Ray McCarthy
Ray McCarthy
@raymaccarthy@mastodon.ie  ·  activity timestamp 4 weeks ago

@pertho @stefano
It's a phishing attack, not a vulnerability test!

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@raymaccarthy @pertho Extremely appropriate definition!

  • Copy link
  • Flag this comment
  • Block
Laurent Cimon
Laurent Cimon
@clf@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano "please open an attack vector for me. I need to get paid"

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@clf or "open an attack vector, otherwise I don't know how to proceed"

  • Copy link
  • Flag this comment
  • Block
Jim Spath
Jim Spath
@jspath55@chaos.social  ·  activity timestamp 4 weeks ago

@stefano "little pig, little pig, let me come in?"

"That's not how pen testing works, big bad wolf."

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@jspath55 yes, exactly!

  • Copy link
  • Flag this comment
  • Block
greem
greem
@greem@cyberplace.social  ·  activity timestamp 4 weeks ago

@stefano Is "outside" in this specific case the pen tester standing in the car park shouting obscenities at the building because they can't get in?

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@greem Yes, it probably is 😂

  • Copy link
  • Flag this comment
  • Block
Carson Chittom
Carson Chittom
@carson@social.chittom.family  ·  activity timestamp 4 weeks ago

@stefano In a previous role, I used to sometimes triage what were generously called vulnerability reports on our software product. I wish I had a dollar for every one which began "Step 1: Become the administrative user."

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@carson This is funny! But yes, this happens. When those asstments start with “if a superuser will start a vulnerable service running as root, and opens a firewall port, and gives the address to others, and and and and…”

  • Copy link
  • Flag this comment
  • Block
LFA :emacs: :tux: :freebsd:
LFA :emacs: :tux: :freebsd:
@lfa@hostux.social  ·  activity timestamp 4 weeks ago

@stefano Give him your user and the root password just to make sure the pen test goes as expected 😂

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@lfa Wise idea. I will 😂

  • Copy link
  • Flag this comment
  • Block
God Emperor of Mastodon
God Emperor of Mastodon
@mms@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@stefano the assessment: "adding firewall, some protection, and blacklist would significantly improve security of the server".

Can I send them my bank account number?

  • Copy link
  • Flag this comment
  • Block
mkj
mkj
@mkj@social.mkj.earth  ·  activity timestamp 4 weeks ago

In all fairness security shouldn't depend on any one layer of protection, but yes, this is really rather ridiculous. So yes, Stefano, I'm pretty sure you understood the request correctly.

Let's also make sure indeed that they also have login credentials that will let them log in as root. Maybe email them the SSH host private keys while we're at it?

😆

@mms @stefano

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@mkj @mms sure. But disabling the layers won't help anyway 🙂

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@mms You deserve it much more than them

  • Copy link
  • Flag this comment
  • Block
no brain no pain
no brain no pain
@nobrainnopain@social.tchncs.de  ·  activity timestamp 4 weeks ago

@_elena @stefano @mms similar here: we need further privileges to exploit the vulnerability we assume from the version number the application reports 🤡

  • Copy link
  • Flag this comment
  • Block
Deborah Hartmann Preuss, pcc
Deborah Hartmann Preuss, pcc
@deborahh@cosocial.ca  ·  activity timestamp 4 weeks ago

@stefano @_elena @mms omg, that was *serious*? 🤦‍♀️🤦‍♀️🤦‍♀️

  • Copy link
  • Flag this comment
  • Block
The Penguin of Evil
The Penguin of Evil
@etchedpixels@mastodon.social  ·  activity timestamp 4 weeks ago

@stefano @_elena @mms Also sounds a brilliant thing to send to the less clueful admin of a site you are pentesting to see how gullible they are 8)

  • Copy link
  • Flag this comment
  • Block
mkj
mkj
@mkj@social.mkj.earth  ·  activity timestamp 4 weeks ago

@_elena Careful, don't give away half the scoop. ;-)

@stefano @mms

  • Copy link
  • Flag this comment
  • Block
cuan_knaggs
cuan_knaggs
@mensrea@freeradical.zone  ·  activity timestamp 4 weeks ago

@stefano @_elena @mms wait, this isn't just a bad phishing attempt

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp 4 weeks ago

@_elena @mms Totally. Later today I'll have a call with the person who hired them and explain a thing or two 🙂
This is a good person - just doesn't understand the implications.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct