Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

This one beats them all and it’s going to make me laugh until tonight:

“I’ve been assigned to carry out a penetration test on a server you manage. The test will be performed from the outside, since the perimeter security needs to be assessed. In order to perform the test, I therefore ask you to disable any firewall, protection, blacklist. If any of these are in place, the server might not be reachable and could prevent the assessment.”

I had to read it three times just to make sure I’d understood it properly.

#IT #SysAdmin #HorrorStories

#horrorstories #sysadmin #it
  • Copy link
  • Flag this post
  • Block
Paolo Redaelli
Paolo Redaelli
@paoloredaelli@mastodon.uno  ·  activity timestamp last month

@stefano
The good old social engineering. Never gone out of fashion, since the time of "The sneakers" movie 😃

  • Copy link
  • Flag this comment
  • Block
skua
skua
@skua@mastodon.social  ·  activity timestamp last month

@stefano

I fear my knowledge level is far closer to some IT managers' than I wish.

Please make your life easier and give them access via Anydesk.

  • Copy link
  • Flag this comment
  • Block
Erik Ableson
Erik Ableson
@erik@mastodon.infrageeks.social  ·  activity timestamp last month

@stefano OK. after that, I'd set up a network segment filled with Thinkst Canary Honeypots open to the internet and let them waste their time there while you produce the log report showing them playing in your sandbox

  • Copy link
  • Flag this comment
  • Block
Tim Chase
Tim Chase
@gumnos@mastodon.bsd.cafe  ·  activity timestamp last month

@stefano

"Yeah, I just need to know which IPv4 & IPv6 addresses your testing will come from so that I can adjust firewall rules"

block drop in on egress proto tcp from <pentest_ips> to any

:dusts off hands and sips coffee:

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@gumnos yes, this makes sense

  • Copy link
  • Flag this comment
  • Block
Anton Piatek
Anton Piatek
@sldrant@mastodon.social  ·  activity timestamp last month

@stefano @neil tbf this is pretty standard to actually test a service or server. (yes you also test the firewall effectiveness, but the core vulnerabilities are also usually specifically tested without it)

  • Copy link
  • Flag this comment
  • Block
EnigmaRotor
EnigmaRotor
@EnigmaRotor@mastodon.bsd.cafe  ·  activity timestamp last month

@stefano clown power ! 🤡

  • Copy link
  • Flag this comment
  • Block
no brain no pain
no brain no pain
@nobrainnopain@social.tchncs.de  ·  activity timestamp last month

@stefano similar here from a leader of a red team: we need further privileges to exploit the vulnerability we assume from the *version number the application reports* 🤡

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp last month

@stefano maybe an AI sent it? 😅

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@IAmDannyBoling I don't think so. There were some errors.

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp last month

@stefano I'll say! 😉 Regardless, I hope things go well tonight. Maybe you could edit your post with the results so we all get notified, if it's not too much trouble. We'll all be rooting for you.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@IAmDannyBoling eheh thanks. But it won't be tonight - it seems it's been delayed ad the committer has some doubts about their skills.

  • Copy link
  • Flag this comment
  • Block
Danny Boling ☮️
Danny Boling ☮️
@IAmDannyBoling@mstdn.social  ·  activity timestamp last month

@stefano That could be your lucky break. 👍

  • Copy link
  • Flag this comment
  • Block
Nick Bergen Computer Quest
Nick Bergen Computer Quest
@NickBergenComputerQuest@mastodon.social  ·  activity timestamp last month

@stefano I love how they asked you to disable any “protection.” What protections? Any protections, just protections in general, anything that protects… don’t worry about it, you don’t need it…

To be fair, I think they are actually doing a pen test. They’re just trying to see how easy it is to penetrate the intelligence, or lack there of, of the sys admin.

  • Copy link
  • Flag this comment
  • Block
AskPippa🇨🇦
AskPippa🇨🇦
@AskPippa@c.im  ·  activity timestamp last month

@stefano I'll leave the car doors unlocked and the keys in the ignition. See if you can steal it.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@AskPippa yes, exactly

  • Copy link
  • Flag this comment
  • Block
dazfuller :rickwhoah:
dazfuller :rickwhoah:
@dazfuller@mstdn.social  ·  activity timestamp last month

@stefano I remember reviewing a pen test like that once. The report said that they were able to access a database server and copy the data files.

When I looked into it, it was because they’d asked for access to the server and an rdp account to connect with. And they were running the test from a device on the same network.

  • Copy link
  • Flag this comment
  • Block
Parade du Grotesque 💀
Parade du Grotesque 💀
@ParadeGrotesque@mastodon.sdf.org  ·  activity timestamp last month

@stefano

That is both hilarious and ridiculous.

My reply would be: "that's not how you do penetration testing, my boy"... 😉

  • Copy link
  • Flag this comment
  • Block
Tariq
Tariq
@rzeta0@mathstodon.xyz  ·  activity timestamp last month

@stefano

Years ago, many years ago, I was a junior technology person in the UK public sector.

Disaster recovery/ failover was a thing. And needed to be tested annually I think.

Anyway the It was outsourced to one of those large global evil incompetent corporations that were very competent at profiteering from the public purse.

The test didn't involve intentionally taking servers/services/network things offline.

I demanded it.

They protested and took it up several levels to override my "assurance".

Yeah. I learned a lot about capitalism and the public sector during that era.

  • Copy link
  • Flag this comment
  • Block
Michael Dexter
Michael Dexter
@dexter@bsd.network  ·  activity timestamp last month

@stefano Also known as a “Russian Ceasefire Agreement”?

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@dexter yes, probably 🙂

  • Copy link
  • Flag this comment
  • Block
Mira
Mira
@mira@shark.community  ·  activity timestamp last month

@stefano Surprised they didn’t ask for the admin/root password

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@mira maybe that is the next step

  • Copy link
  • Flag this comment
  • Block
Robin Barton
Robin Barton
@Robo105@mastodon.social  ·  activity timestamp last month

@stefano Well, you gotta give it to them for creativity but I suspect it works on some people

  • Copy link
  • Flag this comment
  • Block
Anarchic Teapot ⚧️
Anarchic Teapot ⚧️
@anarchic_teapot@oc.todon.fr  ·  activity timestamp last month

@stefano I think you'd pass the test with flying colours by simply responding to the message with a hearty "The fuck I will".

  • Copy link
  • Flag this comment
  • Block
Christmas Tree
Christmas Tree
@christmastree@mastodon.social  ·  activity timestamp last month

@stefano I mean... maybe that's part of the test? Probably just wishful thinking on my part

  • Copy link
  • Flag this comment
  • Block
Josh Dinsdale
Josh Dinsdale
@joshdinsdale@mastodon.iow.social  ·  activity timestamp last month

@stefano Yeha when i was doing outsourced support we used to get this for PCI compliance scans all the time, totally pointless.

  • Copy link
  • Flag this comment
  • Block
Nate
Nate
@nenos@fosstodon.org  ·  activity timestamp last month

@stefano You should pay them with a few boxes of clown shoes. If this is supposed to be an external network penetration test, it may be polite to also include some brightly colored wigs and big red noses as well.

  • Copy link
  • Flag this comment
  • Block
Isaac Ji Kuo
Isaac Ji Kuo
@isaackuo@spacey.space  ·  activity timestamp last month

@stefano Needs an AI generated picture of a friendly nerd wearing Louvre robber safety vests.

  • Copy link
  • Flag this comment
  • Block
Lenora
Lenora
@FaithinBones@mastodon.social  ·  activity timestamp last month

@stefano and there are people who will fall for it

  • Copy link
  • Flag this comment
  • Block
חנן כהן • Hanan Cohen
חנן כהן • Hanan Cohen
@hananc@tooot.im  ·  activity timestamp last month

@stefano
true story.
him: The Ministry of Education hired me to assess the security of your app.
me: please show me an ID and a letter from the Ministry.
him: no one has never asked me to show them.

  • Copy link
  • Flag this comment
  • Block
Fubaroque
Fubaroque
@fubaroque@mastodon.social  ·  activity timestamp last month

@stefano This must the social engineering part of the pentest. Just report a security incident and let them deal with it. 🥸

  • Copy link
  • Flag this comment
  • Block
Matt Lacey
Matt Lacey
@Lacey@mastodon.gamedev.place  ·  activity timestamp last month

@stefano I've been there before. Company hired to do a pen test but complained when they couldn't get access to the internal network to get to the server.

  • Copy link
  • Flag this comment
  • Block
kamme
kamme
@kamme@mastodon.xyz  ·  activity timestamp last month

@stefano reminds me of the time I was contacted by an angry new IT director of a customer because 'we wasted a lot of money'. He hired a company that did phishing exercises and our mail scanning gateway blocked it all. He wanted us to disable it completely, but then we showed the volume or spam/phishing/junk/... we blocked and asked them if he was really sure and wanted to put that in writing, with the CISO in cc. Never heard from him again.

  • Copy link
  • Flag this comment
  • Block
Ben Tasker
Ben Tasker
@ben@mastodon.bentasker.co.uk  ·  activity timestamp last month

@stefano ooof

I remember getting almost exactly the same request years back.

They'd pointed Nessus at the box (without telling us... rude) and our protections had _quite rightly_ identified and blocked their source IP.

So, they contacted us and said that we needed to turn the firewall off so that they could check security.

In that case, the test was being done as part of assessing the customer's PCI-DSS compliance.

  • Copy link
  • Flag this comment
  • Block
Mad Alex
Mad Alex
@madalex@fosstodon.org  ·  activity timestamp last month

@stefano Did they also ask a network diagram, otherwise the way to the server wasn't clear enough?

  • Copy link
  • Flag this comment
  • Block
bmaxv
bmaxv
@bmaxv@noc.social  ·  activity timestamp last month

@stefano Hey, it doesn't hurt to ask. They're instructed to test the environment and you're part of the environment.

  • Copy link
  • Flag this comment
  • Block
Morgan
Morgan
@kaidenshi@exquisite.social  ·  activity timestamp last month

@stefano It still blows my mind that our merchant account provider will say basically the same thing before they run a PCI compliance check. Like, no thanks, I'm not going to open up our network and make it vulnerable just so you can scan it to see if it's vulnerable. That makes no sense.

We pass every time so yeah, that's not how it works.

  • Copy link
  • Flag this comment
  • Block
Nils Wloka
Nils Wloka
@nils@mastodon.nilswloka.com  ·  activity timestamp last month

@stefano Maybe the pen test has already started and they are trying to social engineer you 😉

  • Copy link
  • Flag this comment
  • Block
mhoye
mhoye
@mhoye@mastodon.social  ·  activity timestamp last month

@stefano Some real "please lower your shields to enjoy the premium photon-torpedo experience" here.

  • Copy link
  • Flag this comment
  • Block
Ricardo Tavares
Ricardo Tavares
@t_var_s@phpc.social  ·  activity timestamp last month

@stefano @justine It's common to ask for IPs to be whitelisted 🤷

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@t_var_s @justine which is more understandable but not totally: an hacker won't have the ip whitelisted. But still, I can see the point.

  • Copy link
  • Flag this comment
  • Block
anparker
anparker
@anparker@mastodon.bsd.cafe  ·  activity timestamp last month

@stefano At my previous job company hired someone for such test. One of requirements was to install their a server on our network for duration of test. So they can better understand network topology and services to test.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@anparker this makes some sense. They can study the network from inside. But still...

  • Copy link
  • Flag this comment
  • Block
BeeCycling
BeeCycling
@beecycling@wandering.shop  ·  activity timestamp last month

@stefano Are they testing the equipment or are they testing the staff? (Though anyone who falls for someone asking them to do that deserves to be sacked.)

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@beecycling officially, "how the services are vulnerable from the Internet"

  • Copy link
  • Flag this comment
  • Block
Tom
Tom
@pertho@mastodon.bsd.cafe  ·  activity timestamp last month

@stefano yeah these are ridiculous. Why the hell would you disable your firewall? Also these aren't penetration tests, they're just vulnerability scanners.

  • Copy link
  • Flag this comment
  • Block
Ray McCarthy
Ray McCarthy
@raymaccarthy@mastodon.ie  ·  activity timestamp last month

@pertho @stefano
It's a phishing attack, not a vulnerability test!

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@raymaccarthy @pertho Extremely appropriate definition!

  • Copy link
  • Flag this comment
  • Block
Laurent Cimon
Laurent Cimon
@clf@mastodon.bsd.cafe  ·  activity timestamp last month

@stefano "please open an attack vector for me. I need to get paid"

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@clf or "open an attack vector, otherwise I don't know how to proceed"

  • Copy link
  • Flag this comment
  • Block
Jim Spath
Jim Spath
@jspath55@chaos.social  ·  activity timestamp last month

@stefano "little pig, little pig, let me come in?"

"That's not how pen testing works, big bad wolf."

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@jspath55 yes, exactly!

  • Copy link
  • Flag this comment
  • Block
greem
greem
@greem@cyberplace.social  ·  activity timestamp last month

@stefano Is "outside" in this specific case the pen tester standing in the car park shouting obscenities at the building because they can't get in?

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@greem Yes, it probably is 😂

  • Copy link
  • Flag this comment
  • Block
Carson Chittom
Carson Chittom
@carson@social.chittom.family  ·  activity timestamp last month

@stefano In a previous role, I used to sometimes triage what were generously called vulnerability reports on our software product. I wish I had a dollar for every one which began "Step 1: Become the administrative user."

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@carson This is funny! But yes, this happens. When those asstments start with “if a superuser will start a vulnerable service running as root, and opens a firewall port, and gives the address to others, and and and and…”

  • Copy link
  • Flag this comment
  • Block
LFA :emacs: :tux: :freebsd:
LFA :emacs: :tux: :freebsd:
@lfa@hostux.social  ·  activity timestamp last month

@stefano Give him your user and the root password just to make sure the pen test goes as expected 😂

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@lfa Wise idea. I will 😂

  • Copy link
  • Flag this comment
  • Block
no brain no pain
no brain no pain
@nobrainnopain@social.tchncs.de  ·  activity timestamp last month

@_elena @stefano @mms similar here: we need further privileges to exploit the vulnerability we assume from the version number the application reports 🤡

  • Copy link
  • Flag this comment
  • Block
Deborah Hartmann Preuss, pcc
Deborah Hartmann Preuss, pcc
@deborahh@cosocial.ca  ·  activity timestamp last month

@stefano @_elena @mms omg, that was *serious*? 🤦‍♀️🤦‍♀️🤦‍♀️

  • Copy link
  • Flag this comment
  • Block
The Penguin of Evil
The Penguin of Evil
@etchedpixels@mastodon.social  ·  activity timestamp last month

@stefano @_elena @mms Also sounds a brilliant thing to send to the less clueful admin of a site you are pentesting to see how gullible they are 8)

  • Copy link
  • Flag this comment
  • Block
mkj
mkj
@mkj@social.mkj.earth  ·  activity timestamp last month

@_elena Careful, don't give away half the scoop. ;-)

@stefano @mms

  • Copy link
  • Flag this comment
  • Block
cuan_knaggs
cuan_knaggs
@mensrea@freeradical.zone  ·  activity timestamp last month

@stefano @_elena @mms wait, this isn't just a bad phishing attempt

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@_elena @mms Totally. Later today I'll have a call with the person who hired them and explain a thing or two 🙂
This is a good person - just doesn't understand the implications.

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@mkj @mms sure. But disabling the layers won't help anyway 🙂

  • Copy link
  • Flag this comment
  • Block
mkj
mkj
@mkj@social.mkj.earth  ·  activity timestamp last month

In all fairness security shouldn't depend on any one layer of protection, but yes, this is really rather ridiculous. So yes, Stefano, I'm pretty sure you understood the request correctly.

Let's also make sure indeed that they also have login credentials that will let them log in as root. Maybe email them the SSH host private keys while we're at it?

😆

@mms @stefano

  • Copy link
  • Flag this comment
  • Block
Stefano Marinelli
Stefano Marinelli
@stefano@mastodon.bsd.cafe  ·  activity timestamp last month

@mms You deserve it much more than them

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.35 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct