5 ms·
Simple and straightforward article that exposes one of many usual misbehaviors of so called sysadmins these days: they think they know their tools, but haven't
by pecg 9y ago
Simple and straightforward article that exposes one of many usual misbehaviors of so called sysadmins these days: they think they know their tools, but haven't even completely read the manual for the programs they rely on production environments. Systems administration is something to be taken seriously; recently a friend of mine, that knows nothing about network perimeter security and didn't enforced adequate credentials on production environments, got a RANSOMWARE on a machine with a critical for business instance of a CRM database, chiefs on the organization refused to pay for the bitcoins asked, and probably my friend will be fired for incompetence; the infrastructure department personnel doesn't even have backups of such server, it's clear the information is lost forever.
- empath75 9y agoNobody has time to read the manuals for everything, come on.
- eesmith 9y ago"These days"? What you describe has happened for decades, though of course with different details. You never knew about sys admins who put "." in the PATH for root? That was one of the warnings that I remember learning back in the early 1990s. Remember the good old days when someone's .finger could be used for an escape sequence injection? Even if you read the manual for your terminal, that doesn't mean you change all your habits. Or sys admins using "xhost +" for easy access to other machines in the local network? And sys admins forgetting to do backups? That's certainly nothing new.
- icedchai 9y agoEarly SGI systems, maybe as late as IRIX 5.x, actually shipped with "xhost +" as the default! I remember people putting these on the internet with no firewall (of course... this was the mid 90's) not realizing they could be key logged remotely...
- eesmith 9y agoI had a IRIX 5.x box and I remember having to do "xhost +". Which I did, because ... easy.
- liveoneggs 9y agoand what of those so called developers who wrote the code in the first place and never documented anything? :)
- tachion 9y agoWhat you described is not a sysadmin, but a bad sysadmin instead. Also, if you look at the situation 'these days' it's not even a bad sysadmins, it's mostly developers who don't even really know how their computers or operating systems work, but they're allowed to build entire infrastructures using cloud/terraform/k8s/toy-of-the-week ;)