Conversation
@cR0w That's peak #YOLOsec right here!
0
0
1

@cR0w i read this and it makes me want to grab the hoe and spade and go offline forever.

0
1
0

@da_667 @cR0w @Dio9sys well, good news, bad news.
Good news: you are DEFINITELY going to be employed for a very long time.
Bad news: this isn't even the start of Infoblox's colossal fuckups under the hood.

0
0
0

@cR0w @da_667 @Dio9sys ha ha ha, oh boy, you haven't even begun to see it.

Let me put it this way. I had one of their VM IPAM boxes at one point. I think it took me 5 minutes to get root.

0
0
0

@cR0w This is even bigger clownshoes: https://<NETMRI_HOST>/webui/application/get_saml_request?saml_id=1%26http://$(whoami)

Are you kidding me

2
1
0

@cR0w @da_667 @Dio9sys
I know one way was:

1. reboot
2. single user
3. victory

1
0
0

@cR0w @da_667 @Dio9sys
I think they fixed 'oh hey the first admin user is just root.' Maybe.
... okay yeah probably not.

0
0
0

@cR0w @da_667 @Dio9sys hey, at least we moved on from vCenter!

("lol python shell brb going to be root to unfuck systemd stupidity now.")

0
0
0

@nerdpr0f @cR0w And that's assuming CS degrees are involved. Coding bootcamps, etc. mention the word "security" and move on

0
1
0

@cR0w @nerdpr0f Sigh, don't I know it. Currently trying to address that shortcoming internally.

0
1
0

@mttaggart @cR0w I GET FREE ROOT YOU GET FREE ROOT EVERYBODY GETS FREE ROOT

1
1
0

@cR0w i might have once coded root ssl key, company root to license products, in a binary, because Java is a shitshow, the Apache frameworkr are shitshows, the libraries are shitshows. Then why not coding shitshow... it was PR and Reviewed by two Seniors and the Lead, approved by the PM, and all the Company shitshow. I still can't believe it.

0
0
0