Jump to content

rrrrr

Members
  • Posts

    314
  • Joined

  • Last visited

Everything posted by rrrrr

  1. A pic of Kuala Lumpur i took this week
  2. The 1st mountain and black beach were used in game of thrones
  3. Went to iceland a couple of weeks ago, a few pics from my trip (iphone shots)
  4. Yep done that. I was more talking about you can add also add a school account. Im not sure what extra this gives. I assume access to school email and possibly school published apps?
  5. Hi all, Just bought my daughter in KS1 a chromebook for xmas present as i know her school use google classroom/chromebooks and want to give her a head start and familiarise herself with them before she starts to use in school. Ive been out the school IT support role for a few years now, so thought id ask you all. Is there any apps/software you would recommend i install that she may use at school in the near future? Would it be worth me asking the school if she has a school account i can link to, as she is probably to young to be given an account of her own at the moment. Thanks in advance,
  6. Is there any software/apps recommendations that she may use in early years? She hasnt used them at school yet and is very confident with her ipad, just want to give her some exposure and a bit of a head start
  7. Hi, With schools out, i wanted to buy my daughter a chromebook for home learning and to give her a bit of a head start. She is at KS1 level and i know her primary school use chromebooks/google classroom etc. I wanted to give her a typical setup to what she will use in school in terms of both hardware and software. Could you guys and girls give me some guidance on what chomebook hardware/software a typical primary school setup would be running? I havent been a NM for about 5 years so a bit out of the loop. Thanks
  8. If you are suspicious about the files have you checked for steganography?
  9. One thing that concerned me when i was in a similar position was the tombstone date of my AD forest and how DC’s will behave after a long turn off period. Just one thing to maybe read on https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc784932(v=ws.10)
  10. There are 3 good tools you can use on your mac. Nmap, arpscan and masscan Nmap is a port scanner. If you want to look for windows boxes on your network do a syn scan on smb Nmap -p 445 —open If you want to find systems that dont respond to ping use -Pn but will be a bit slower Arp-scan —local will enumerate all systems on your vlan by arp requests If your looking for systems site wide use masscan. Its very fast but only really works on a /16 range Masscan -p 445 —rate=1000
  11. A local admin password should never be shared across devices. Changing the username from administrator provides little security benefit as usernames are easily enumerated. Never set by gpo as this is easily decrypted. Shouldnt even be possible now as Microsoft have disabled this feature. Implement LAPS (Microsoft local admin password solution) its the safest way, or completely disable them
  12. One server needs to be restored authoritative and the other needs to be non-authoritative otherwise you will get RID mismatch and syncing issues https://www.manageengine.com/ad-recovery-manager/authoritative-and-non-authoritative-restoration.html
  13. By the sounds of it, both servers were restored using an authoritative restore causing the RID mismatch. If it was me, i would restore again doing the PDC as an authoritative restore first, then do the SDC as a non authoritative restore. This will cause the SDC to update all its records from the PDC and realign the RIDs
  14. How many dcs did you have in total originally? How many dcs failed and required restore? How many working dcs do you currently have?
  15. When you did the system state restore did you do an authoritative or non authoritative restore?
  16. FN-GM is correct on this. Also never set local admin passwords using GPO GPPreferences. The xml for this gpo is readable by all domain users and the password is easily reversed.
  17. Best thing to do is look at online training videos that go through the syllabus (eg cbtnuggets or similar) then just do some practice exams before taking. Usually Microsoft do regular offers of free second attempt if fail. Something to look out for. Dont waste a ton of money on those training providers. Just a heads up, Microsoft look like they are moving to a new recertification model, moving from every 3yrs to annually. Might make you rethink the worth of the cert
  18. Have you checked there is enough free disk space both on the host and vm's? If the disk space is maxed out it would stop them from booting
  19. This is the correct way. Domain admin accounts should only be used when required, not for daily use. Each team member should have their own accounts for accountability. If you use local admin accounts for administration, make sure each device has its own unique complex password for this account
  20. But wasnt ms09-050 a similar vuln in smb2?
  21. Why is everyone rushing to disable smbv1? Isnt applying ms17-010 patch the fix?
  22. https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
  23. The patch had been out since march and would have been part of the windows update process. Reporting of missing patches is made easy by wsus and sccm. Keeping on top of this is basic network management It will be far easier making sure your devices are protected than dealing with the aftermath.
  24. 2003 onwards is affected including 10
  25. It can come in over the internet by a number of means, most likely phishing emails. Once in it is spreading around network by the exploit in smbv1 ms17-010. This was patched by microsoft around march time. Below is some of the inbuilt C2 hosts. http://gx7ekbenv2riucmf.onion http://57g7spgrzlojinas.onion http://xxlvbrloxvriy2c5.onion http://76jdd2ir2embyv47.onion http://cwwnhwhlz52maqm7.onion Below is filetypes it hunts for and encrypts
×
×
  • Create New...