As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…
Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
101–110 of 404 posts
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#102Earlier quoted context omitted.
We sync content to MS hosted Sharepoint using rsync. When the file arrives, they change the internal metadata inside the file, which changes the checksum, which causes rsync to think the content is different and needs syncing again. Edit to say: this is for MS files like Excel docs
Is that a supported method?
If a file server breaks basic Unix tools it should be unplugged and put in the garbage.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#103As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#104As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…
How many organizations on the planet require their Exchange server to support 150k users? I doubt most manufacturing plants fall into this category.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#105As usual with all these types of posts, people go "HA HA, MICRO$OFT SUCKS" without understanding business practices that keep them afloat. Don't use Exchange? Cool, what should we use instead? Does it support 15 people all the way up to 150000 people? I used to run Exchange cluster for 70k people, is there other mail software out there complete with non-shared disk redundancy? Where the users connect to single endpoi…
I see you build a case for traditional MS product in Exchange, yet this issue is about Sharepoint. Just like with Windows, Microsoft has built a moat with Exchange, but the question is why do all the companies buy into their full ecosystem, especially for anything relating to web technologies (you even bring up Exchange Web Services), because this they do really badly, and Sharepoint seems to be the worst. However, I…
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#106(btw, this story is more about unintended consequences instead of MSFT)
- I own an alerting system
- For log based alerts, it looks for a keyword e.g. "alert_log"
- I make a spreadsheet to track data about alerts and call one of the sheets "alert_log"
- Alert system starts going crazy: using tons of CPU, number of alerts processed goes through the roof but not a lot of alerts generated
- Turns out that I was using the cloud version of Excel so any text entered transited the firewall
- Firewall logs store the text "alert_log"
- Alert system thinks it's an alert BUT it's not a real alert so triggers an alert processing alert
- That second alert contains the text from the firewall log and so cycle begins
In other words, systems can operate in weird ways and then cause things to happen you didn't anticipate. It's why things like audits, red teaming and defense in depth all matter.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#107Earlier quoted context omitted.
Ah yes, " likely air-gapped", what a high-confidence statement. Any competently designed air-gap must be precisely auditable and demonstrably, positively air-gapped. The only world where "likely" is a reasonable word is in reference to possible physical taps or a precise enumeration of physical access points that went unaudited, but have reliably followed safe access control/configuration procedures. Anything else is…
They have multiple networks. One of them is definitely airgapped (red for RD). The medium security one is protected by annoyingly strict network ACLs (yellow for ITAR). Then there's a low security one for stuff like sharepoint (green). This article is full of nonsense and speculation.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#108Whoever puts a nuclear fission facility on the internet should be put behind bars.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#109There needs to be a law that all nuclear and nuclear-adjacent facilities have no connection to the Internet. The fact it's allowed is unbelievable.
Being airgapped didn't help Iran avoid Stuxnet.
Re: Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
#110So I once brought down an alerting system using Excel (btw, this story is more about unintended consequences instead of MSFT) - I own an alerting system - For log based alerts, it looks for a keyword e.g. "alert_log" - I make a spreadsheet to track data about alerts and call one of the sheets "alert_log" - Alert system starts going crazy: using tons of CPU, number of alerts processed goes through the roof but not a l…