4 ms·
While not titled as a cyber-security professional, I am a System Admin/Engineer who has worn that hat a few times when there was no one else available. In my e
by than3 3y ago
While not titled as a cyber-security professional, I am a System Admin/Engineer who has worn that hat a few times when there was no one else available.
In my experience, it seems like vendor disclosures, and measures that might impact correcting vulnerable components are insufficient, and slow, if they happen at all.
The larger brands are getting pretty good about disclosing in a timely manner but you always have cost cutting happening unbenowst to you organizationally where inventory as you said isn't accounted for, and then those devices may or may not have disclosed vulnerabilities or had a fix within a reasonable time after public disclosure. Not vetted hardware but consumer, or semi-professonal brands that are much smaller.
I've run into areas where mitigations also were extremely costly because some simple circumstance was overlooked.
As an example, almost 8 years ago I was brought in to help a client who had suffered a ransomware attack where their previous IT staff were non-responsive and they were desperate.
They had Mcafee's DLP deployed organization wide, and the local DLP server that generated the unlock codes was among several other assets that had been encrypted but not documented or inventoried (so that didn't have a backup). The software product true to their word prevented even authorized system administrators from being able to make any mitigative changes without that unlock code which was not possible, their support for resolution was ineffective and useless. Even in safe mode, everything was locked down, and after exhausting all other options even accessing the system physically from a Linux live disk failed, the HDD would hang after trying to access certain parts of the disk (at an extremely low level). We were never able to figure out exactly what caused the hangs, but it happened regularly for long-running processes and we verified SMART passed. We had a guess that they were doing something funky with NTFS where separate files under a certain size get conglomerated into the same sector block which wasn't supported by Linux at the time, but we were never able to confirm definitively.
What could have been a few hour turnaround ended up turning into a week of downtime (where everyone was shut down, 10 days). Fortunately it was during the holidays which was their slowest time when they normally shut down for a week but it could have been much worse.
After exhausting options, we ended up having migrate data, wipe and reimage with almost a completely new infrastructure. We corrected a number of additional issues (misconfigurations) we found during the process but there was a good portion of time where we were just spinning our wheels with the vendor who was useless.
We went to contingency and stood up new infrastructure after we hit a certain threshold on man hours trying to work with them without any progress.
- cookiengineer 3y ago> In my experience, it seems like vendor disclosures, and measures that might impact correcting vulnerable components are insufficient, and slow, if they happen at all. SAP has a CVE dispute rate of exactly 100%. Just as a fun fact. It gets worse when you look deeper into hardware vendors, where they mark things as fixed even though they aren't. And Debian as a feature frozen distribution has sooo many tags that are similar to "code diverged too much from upstream", yet they mark the CVEs as fixed; even though they are still affected and the old code from 6 years ago on exploitdb still works. That is what led me to building a vulnerability scraper that scrapes and correlates all linux security trackers, and rates them with a confidence value (with Debian obviously having the lowest) in order to be able to discover those issues that have been correctly tagged, deployed and fixed in other distros (e.g. Arch Linux). > They had Mcafee's DLP deployed organization wide(...) Holy shit, that's like every sysadmin's nightmare. I feel for you, man. With a pentester's voice I always like to say that the biggest castle walls are useless when you have an ADFS server running inside it. A lot of DMZ approaches are useless because they underestimate the attack surface of their core IAM infrastructure.
- than3 3y ago> that's like every sysadmin's nightmare. Not worst case scenario, but it definitely was up there. I'll always remember it, both because nothing you normally had access for would work because no access, and my contingencies really paid off. I had just come off a project fully automating configuration and deployment for our more common infrastructure components; auditing and meeting various security baselines. Its nice seeing hard work you had just finished and tested in action working better than you thought. Most of our time spent was ensuring all relevant data was migrated from the sprawl of endpoints to a central fileshare with integrity intact with no malware. Entrypoint turned out to be one of the employees using a dropbox file-share. The previous admin had been directed to allow it by a person in upper management on a one-time basis for WFH. Their home PC had been infected and spread laterally. It was a brief blank stare/mental facepalm moment finding that out. Ultimately everything was back up and running, We made recommendations; and their IT wrapped everything else up.