Help - Search - Members - Calendar
Full Version: What's wrong with this graph?
Vault9 Forums > Tech Den > Binary Refinery > The Backdoor

Custom Search
rurounikenshin
I.S. sent me a little present.

He he he.

My managers don't understand the problem, but I am shi!tting myself.
cyfermaster
blimey.
rurounikenshin
OK.

Now look at this.
cyfermaster
OMFG, WTF are they doing there? actually, wtf are they not doing?
rurounikenshin
I've been sent to my new companies "Problem Child" client.
I've been here about 5 weeks gathering data for a report on the site.

So far my report has generated about 1/4 of a paper reem of printing.

They've been running their Small Business Server on an uncapped ADSL line for almost 2 years with no firewall and a non functional anti-virus installaton (not downloading updates, not pushing the updates to clients and not running any anti-virus scans).

They seemed to think that I am responsible for the viruses suddenly attacking their LAN, until I pointed out that the viruses had always been there, they just didn't know about it until I fixed their Anti-Virus software.

Personally, I think that this Trend Office Scan is the biggest heap of sh!t under the sun and would like to replace it with a Symantec Solution or even maybe a Kapersky one.

Something that works in other words...



Paul
nod32 has a lan management console that distributes updates either directly to each client, or makes your server act as a definition update distributing server.

I use it at most of my clients and the only work I have done in 2 years is renew licences
rurounikenshin
I've heard alot about Nod32.

Maybe I should propose it as a possible solution.

Thanks Paul.
Paul
pleasure dude, I am totally sold on them for a number of reasons.

I'll take a gazzilion rand bet with anyone that nod uses less resources than 99% of other AV's
cyfermaster
eish, I would definately stay away from a Symantec solution. I have nothing but bad experience with them. While I haven't used no32, I have heard many good things about it.
rurounikenshin
Looky here...
Gitano
Hahahahaha, have fun!
rurounikenshin
Eish! It's been a trying week last week.

But we're slowly starting to come right.

I've been encouraging the users to run, Virus scan's every week in an effort to clean the LAN of all the infections.

Look at this, this is a screenshot of one machines Spyware content.

This is actually the LOWEST I've seen at this site.

One user had over 900 running instances of spyware and her machine was slooooooooooooooooooooooooooooooooow!

After the spyware was removed things were alot better.
Fishfly
crazy company! I'd fire the IT staff ASAP!
rurounikenshin
They did...

That's why my company has stepped in.

We're getting ontop of things now.

W.S.U.S is running properly.
We've upgraded the Clients Trend package to a more up-to-date version.
ISA Firewall is now in place and running.

And this morning we fixed the backup system and sorted all that kak out (backups hadn't finished successfuly in over 14months according to the logs we could find).

I am gonna be loading some website block lists to stop all the porn and warez browsing tomorrow.
rurounikenshin
What's wrong with this picture?

Please note that this is the clients "server room" thumbdown.gif

(I physically felt sick the first time I saw this).

Look carefully, apart from the obvious problem there are 3 major problems.

What are they?

1.)
2.)
3.)
cyfermaster
Can I get back to you on that, that cabling takes my mind off everything else. sad.gif

Is there aircon in that room?

p.s. I threw up a little in my mouth. sad.gif puke.gif
rurounikenshin
No worries mate.

Yeah that cabling is a frikkin nightmare!

And they're still arguing with me about fixing/replacing the LAN.

They reckon the condition of the cabling has nothing to do with all the problems that they constantly have.
I naturally argue that with the cabling in this state it is impossible to trouble shoot and repairt problems with any real degree of accuracy.

But it's their problem. My SLA allows me to assist as far as the hardware allows me to.
Once the we're at a point where cablig/equipment needs to be replaced and they refuse - I go upstairs to my office and relax.

Aaaaaaaaaaaah, SLA FTW!
rurounikenshin
He he, let me help you guys out.

The problems are as follows:

1.) The server and UPS are OUTSIDE the server cabinet.
2.) All the Backup tapes are stored ontop of the server out in the open.
3.) The router is wireless and had no security key (this was the trick question).

So basically, If some one had broken into this "Server Room" they could've made off with the backup tapes, or the server itself!
And anyone who happened to be browsing for wireless networks in range could've connected directly to the clients LAN with out any problems.
They would've seen the the network printers and any shares the users have.

I've secured the backup tapes and the Wireless router for now.
The Server Cabinet is going to be stripped and completely rebuilt over the week end. So that should hopefully sort out some of the problems to some degree.

I honestly haven't seen sites this bad in my life.

I've been to over 68 Hospitals during my time at my previous company (when they bought the hospitals we'd completely remove all the old infrastructure and bring the site up to UK Hospital Standards (ISO27001)) and I have never seen stuff like this. Not even at the most remote sites I've been to.

Crazy this place!
Paul
lol, wait till I upload a picture of the cabinets here,

you'll fall on your face

Fishfly
hahahah you should see the server cabinents at my old company...

the only pretty thing we had was the cabling biggrin.gif

and I was about ot guess that the server's are outside the cabinent and no aircon and backup tapes... tho I thought that wireless was some receiver...

also what's what that 1 cable doing some hang 10 there?
cyfermaster
QUOTE
So basically, If some one had broken into this "Server Room" they could've made off with the backup tapes, or the server itself!
And anyone who happened to be browsing for wireless networks in range could've connected directly to the clients LAN with out any problems.
They would've seen the the network printers and any shares the users have.


If they broke into that server room, they would have been so put off they wouldn't want to take anything. sad.gif
rurounikenshin
True that!

That cable hanging in mid air is for a phone int the room.

It's basically a converted store room.

They have an old extractor fan that has recently seized.

As an extra piece of trivia, that PABX system hanging on the wall is a Nortel Meridian... a PABX my father helped bring into the country almost 15 years ago...
rurounikenshin
Thank god!

The client has accepted the quote on the Cable clean-up.

The guys are coming on friday and saturday to do the work!

Fan f#cking tastic!
cyfermaster
Just make sure they can't get their grubby paws on that cabinet come Monday. Otherwise it will be back in the same state it is now.
Valheru
Fact: Some people are designed/engineered to fuck things up.

Fact 2: That's why people like us have jobs
rurounikenshin
Amen to that brother!
rurounikenshin
Aaaaaaaaaaaaaaah!

2 week ends and alot of swearing later...

Things are starting to look up!

I need to bring in a tape measure to measure the bottom of the cabinet, there's no base plate so I'll need to get one made for the cabinet.
Once that's done the server is moving inside.

Thank god!

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Custom Search
Invision Power Board © 2001-2008 Invision Power Services, Inc.