Category: Infosec

  • CrowdStrike – there but for the grace…

    , ,

    I’m writing this a few days after the global IT outage that pulled TV stations off the air, grounded planes, and made it tricky to purchase your morning coffee. And more seriously prevented 911 calls from working in Alaska. Where I work was largely unaffected. Our servers kept running, payments kept being processed, and staff…

  • Disable “stale” user accounts for Office 365 and on-prem hybrid

    , ,

    We recently had a cyber audit at work – and one of the recommendations was to ensure that any user accounts not used within 90 days were disabled. Prior to us moving to Office 365 hybrid we did have an on-prem tool that would do this for us, checking on-prem domain controllers for last login…

    Screenshot of Notepad++ showing the code for my DisableStaleAccounts.ps1 script
  • SQL backup to Azure URL Blob: “Operating system error 50(The request is not supported.)”

    ,

    I wanted to setup an on-premises SQL server to backup directly to Azure Blob storage, using Microsoft’s walk-through: https://learn.microsoft.com/en-us/sql/relational-databases/tutorial-use-azure-blob-storage-service-with-sql-server-2016?view=sql-server-ver16. However, there is a mistake in the provided Powershell script – so things won’t work as expected. TLDR; Script truncates Shared Access Signature – add “s” at start of SECRET The script on the above page…

    Snippet of code
  • My supplier has been compromised – should I still use them?

    , ,

    One of our suppliers was recently hit with a ransomware attack (or “cyber incident” as the new euphemism has it). As a result their systems were offline for several weeks. During this time they were relatively open to their customers about what had happened – they acknowledged it was ransomware, that they were in discussions…

  • Password advice

    ,

    These days we need passwords for everything – from accessing our work PCs, to reading messages on Gmail, to buying things on Amazon. It used to be the case that as long as you avoided easily guessable passwords you’d be fine – unfortunately those days are long gone.  Read on for some advice on what…