@TrendsterO@techspence Sadly even some Microsofts own wizards and Powershell scripts doesn't work correctly if you use protected Users group on your admin account... 🤦♂️
@CyberWarship •Activate complexes password requirements & all rules for it
•deactivate IPMI
•define IP-Range from where idrac is reachable
•deactivate Serial over LAN
•block HTTP/80
•force TLS1.2
•disable RACADM
•disable RedFish
@CyberWarship I've some idrac best practice settings would be interesting what you'll say about this... basically default credentials is a No-Go of course! Honestly there are a lot more hidden settings per-default activated that might can get exploited!
@nullenc0de There a couple more "exe" You need to block... Like powershell, CMD etc too... Normal users , normally don't need them to connect to the internet! Another very important part you need to block these tools from running elsewhere then original location with applocker
@buttahsan@MSFTExchange Good move because then you most probably will be able to upgrade to ex2025! Downside could be the used winsrv.. have u used server 2022 already? server 2019 is be supported a little longer then exchange 2019, only downside could be OS support for ex2025 that's not known yet...
@Sopbeen22@MSFTExchange That's not true... "Completely" is kinda stretch able... But at least not a full exchange is needed (no exchange services are running) from a security perspective this is perfect already..
. You still need exchange mgmt tools... But that's not a problem.
@TeslaClubAT It depends... Check my calculations in TFF forum.... When you only charge to around 80% and the charging rates are ok, but we all know this might depend on many factors, and you have to have long slow charging rates it costs easily twice as much!
@ThomasVrhydn I did see the option IRL in endpoint settings... But looks like it's rolled out on waves, as other tenants that have preview enabled didn't have the option yet...
@vxunderground But if you could edit hkey_classes_root you wouldn't need to hide this that way... And as long as ah normal User can't run anything outside program files or Windows it's also relatively safe...
@JimSycurity @JosephRyanRies @DanielUlrichs Same as i thought too while Reading this.... Again its not needed to take control of ah particular object and change it, you can propaply just use an existing non Windows Computer object, or get into the system of such machine and exploit from there
@JosephRyanRies 1 – Compatibility mode. Windows domain controllers will require that Netlogon clients use RPC Seal if they are running Windows, or if they are acting as either domain controllers or Trust accounts.
2/2
@JosephRyanRies does it make any difference whats the operating system for ah computer account is in AD? as we had Netapp's that where set as "Windows 10" Operating system and had issues... after changing type to Netapp it started working... in KB this is mentioned: 1/2
@arstechnica thats ah fucking nightmare... i mean moved to my own Bitwarden Vault but basically you've to change all passwords after this Lastpass disaster...
@samilaiho did you read about this allready?