Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3
networkn
Networkn
32349 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2671063 10-Mar-2021 13:47
Send private message

It's worth noting, that just because someone patches, and didn't get hacked, this doesn't get them out of the woods in terms of risk for this particular threat.

 

Exfiltrated data, and address books, means highly targeted Phishing and related email messages will be flooding around the world in the coming 12 months. They may pass spam filters, because they will contain sections of messages that were legitimately sent and received earlier.

 

 




BlakJak
1275 posts

Uber Geek

Trusted

  #2672429 12-Mar-2021 19:54
Send private message

nztim:

 

Just completed the 4 remaining clients of ours with on-prem exchange, as a temporarily measure we blocked 443 outside of NZ and port 25 is only open to our MX gateway 

 

What a pain! these updates take so long to run!

 

 

I just want to point out that blocking 443 for sources outside of NZ is not actually a useful protective measure.  Bad actors can originate their actions from NZ just as easily. I've also seen botnet activity where an 'International nullroute' did not fully stop said activity - and that was years ago.  I hope you've patched _and_ looked for IOC's.





No signature to see here, move along...

freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2675420 16-Mar-2021 12:14
Send private message




Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup




networkn
Networkn
32349 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2678194 22-Mar-2021 09:34
Send private message

Acer apparently hit by 50m ransomware attack related to this.


freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2678196 22-Mar-2021 09:36
Send private message

Expect next Acer BIOS updates to come with built-in malware...





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


networkn
Networkn
32349 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2678201 22-Mar-2021 09:43
Send private message

freitasm:

 

Expect next Acer BIOS updates to come with built-in malware...

 

 

Egads, imagine if they were able to load a remote control agent into the bios.  Nek Minit every Acer notebook is ransomwared.

 

At this point, so much of peoples personal data is already on the internet as a result of these leaks, and exfiltrations etc etc, that at some point, you may as well give up the concept of private information and just hope that they don't mind yours in the sea of everyone else's.

 

 

 

 


evilonenz
/dev/urandom
287 posts

Ultimate Geek

ID Verified
Trusted
Lifetime subscriber

  #2692512 14-Apr-2021 10:55
Send private message




Smokeping

 

Referral Links:

 

Quic - Use code R536299EPGOCN at checkout for free setup
Contact Energy - Use code FRTQDXB for $100 credit


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
Lias
5589 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2692525 14-Apr-2021 11:27
Send private message

evilonenz:

 

Yet another patch has been released by MS, looks like two of the vulnerabilities are exploitable without authentication:

 

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617 
https://www.cert.govt.nz/it-specialists/advisories/updates-released-for-new-critical-vulnerabilities-in-microsoft-exchange/ 

 

 

Emergency change already logged and currently installing.. woo!





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.


evilonenz
/dev/urandom
287 posts

Ultimate Geek

ID Verified
Trusted
Lifetime subscriber

  #2692571 14-Apr-2021 11:36
Send private message

Lias:

 

evilonenz:

 

Yet another patch has been released by MS, looks like two of the vulnerabilities are exploitable without authentication:

 

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617 
https://www.cert.govt.nz/it-specialists/advisories/updates-released-for-new-critical-vulnerabilities-in-microsoft-exchange/ 

 

 

Emergency change already logged and currently installing.. woo!

 

 

Nice! I did the same when the CERT advisory came though, not worth waiting until a maintenance window!





Smokeping

 

Referral Links:

 

Quic - Use code R536299EPGOCN at checkout for free setup
Contact Energy - Use code FRTQDXB for $100 credit


Lias
5589 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2692685 14-Apr-2021 14:30
Send private message

evilonenz:

 

Nice! I did the same when the CERT advisory came though, not worth waiting until a maintenance window!

 

 

Yep.. I'd already started when I saw that advisory, but I flicked it to my manager and said "If anyone grumbles about me patching Exchange, point them at this' lol.

 

 





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.


r0bbie
244 posts

Master Geek


  #2692694 14-Apr-2021 14:49
Send private message

Lias:

 

evilonenz:

 

Nice! I did the same when the CERT advisory came though, not worth waiting until a maintenance window!

 

 

Yep.. I'd already started when I saw that advisory, but I flicked it to my manager and said "If anyone grumbles about me patching Exchange, point them at this' lol.

 

 

 

 

 

 

How did your install go? Some people reported issues with ECP

 

 

 

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617

 

 


gjm

gjm
808 posts

Ultimate Geek


  #2692696 14-Apr-2021 14:52
Send private message

Lias:

 

evilonenz:

 

Nice! I did the same when the CERT advisory came though, not worth waiting until a maintenance window!

 

 

Yep.. I'd already started when I saw that advisory, but I flicked it to my manager and said "If anyone grumbles about me patching Exchange, point them at this' lol.

 

 

 

 

Did you run into any issues installing the patch or smooth sailing?





Do surveys for Beer money (referral link) - Octopus Group 

 

Link for buying beer (not affiliated, just like beer) - Good George


Lias
5589 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2692700 14-Apr-2021 14:54
Send private message

gjm:

 

Did you run into any issues installing the patch or smooth sailing?

 

 

Installed fine in Non prod.. Prod not so much... *joy*





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup.


evilonenz
/dev/urandom
287 posts

Ultimate Geek

ID Verified
Trusted
Lifetime subscriber

  #2692701 14-Apr-2021 14:54
Send private message

Patch install went fine for me.
The previous patch apparently caused issues for people, too, but that was also smooth sailing, some issues did appear to be related to DAG servers on non-matching CU levels, though.





Smokeping

 

Referral Links:

 

Quic - Use code R536299EPGOCN at checkout for free setup
Contact Energy - Use code FRTQDXB for $100 credit


gjm

gjm
808 posts

Ultimate Geek


  #2692737 14-Apr-2021 15:24
Send private message

ok thanks. No Exchange test environment here apart from my home lab so I think Ill hold off for a day or two. I see that people who have a special character in the account name that they use when installing the patch are having some problems. Doesn't apply to me but also not confidence inspiring in terms of quality





Do surveys for Beer money (referral link) - Octopus Group 

 

Link for buying beer (not affiliated, just like beer) - Good George


1 | 2 | 3
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.