Priston wrote: » I work in a lab environment, most engineers don't even turn SSH on (which really annoys me when I try to SSH and can't).
DevilWAH wrote: » you work in a bank and they let unrestricted application manage the IT?
DevilWAH wrote: » I would love to see that get a financial audit!! are we talking a bank branch network or the banks datacenters?
DevilWAH wrote: » Every bank/major company I have had as a client has used OOB management from devices that are either restricted from access the internet or often completely air gapped from it.
DevilWAH wrote: » System that have multi billion dollar transaction running though them every second you generally don't take chances. People shown the door for having an out of place MP3.
colemic wrote: » and to clarify, no we do NOT use telnet. mainly putty.
DevilWAH wrote: » how do you mean you don't use telnet you use putty? Telnet is a protocol putty is a client application that supports telent/ssh and other protocols?
xiny wrote: » Admins should be aware enough to download tools from credible sources. You wouldn't download HP Printer drives from a random website would you? Of course not. Am i saying all Admins are impervious to making bad decisions, heck no! I work for a bank as well and I took the "painful" approach to this and blocked all websites and only white listed what employees needed to use. Very painful, very angry employees, but the malware and potentially malicious software being downloaded dropped by roughly 98%. I also use Application Control to enhance this further when SSL Sites want to pull a fast one. I even block communication to all countries (beside the US) since by law US Bank information cannot leave the US (unless you do international business). I also use putty, but am I going to go and download putty from Pirates Bay? obviously not.
DevilWAH wrote: » you work in a bank and they let unrestricted application manage the IT? System that have multi billion dollar transaction running though them every second you generally don't take chances. People shown the door for having an out of place MP3.
colemic wrote: » You seriously whitelisted Internet sites? Kudos to you, sir! We use Ironport for that. Although our new CIO is probably going to change things up a bit, he's all about UX and right now it's pretty awful and painful for users, across the board.