News: 1626076029

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ah, I see you found my PowerShell script called 'SiteReview' – that does not mean what you think it means

(2021/07/12)


Who, Me? Monday is upon us, the weekend is receding, and the rest of the week is stretching out into an unbroken chain of managerial mayhem. Take a moment to watch a newly minted member of management come unstuck in today's [1]Who, Me?

"Your stupid PowerShell script is broken" was the subject of an email that marked the beginning of the brief relationship between our hero, "Vincenzo" (not his name), and a newly hired manager. The newbie had already gained a reputation as being "difficult", but Vincenzo had yet to make a judgement. Right up until the shouty email arrived, cc'ed to pretty much every bigwig in the company.

A top priority ticket was swiftly opened to deal with the shoutiness.

[2]

Vincenzo couldn't understand what his innocuous bit of PowerShell script had done to cause such an outburst. PowerShell is, after all, a handy tool for admins seeking to automate tasks. This script, called " SiteReview ", was an example of the breed: "You type in your email address and the internal AD [Active Directory] OU [Organisation Unit] site you wanted queried," he told us, "and it sends you the group member list of the AD Groups in that site via email."

[3]

[4]

Pretty simple stuff, and used by the company's security auditors to ensure the right accounts were in the right OUs. Vincenzo hadn't bothered with a readme – those who needed to use it were trained on its use; it was just a handy bit of script.

It was also lurking in a folder available to the company's management, which was our hero's downfall.

[5]

He shared the prompts as they appeared in the PowerShell window:

**** Site Review v1.02 ****

**** In case of issues contact [Vincenzo's name and email] ****

Email:

Site:

Again, pretty simple stuff. However, the email was of the very angry type. We imagine an awful lot of capitalisation was involved:

[6]

"The email," recalled Vincenzo, "said that this manager could not get 'any usable output' from my script then went on to berate me for 'wasting their time' with 'such unproductive software' ."

[7]One good deed leads to a storm in an Exchange Server

[8]Hmmmmm, how to cool that overheating CPU, if only there was a solution...

[9]Updating in production, like a boss

[10]Do you come from a land Down Under? Where diesel's low and techies blunder

Vincenzo was taken aback. The script had been used without complaint once a quarter for the past three years. Dutifully, he began looking into the problem, starting with the log files. Yes, a readme might have been too much effort but, like all good IT pros, he had ensured logging existed to dump the results into a folder accessible by IT.

He opened up the .log file to see what had enraged the manager so.

"The first part of the SiteReview.log file was typical," he told us, "my early tests and past security output; so I slid down to the more recent time/date stamps…"

This is what he found:

Email: [Manager's email]

Site: [hardcore pr0n]

Error message: "Get-ADSite : Directory Object not found..."

Email: [Manager's email]

Site: [hardcore pr0n]

Error message: "Get-ADSite : Directory Object not found..."

Email: [Manager's email]

Site: [hardcore pr0n]

Error message: "Get-ADSite : Directory Object not found..."

Email: [Manager's email]

Site: [hardcore pr0n]

Error message: "Get-ADSite : Directory Object not found..."

And so it went on. There were another 22 entries and four distinct sites of the most distressing smut listed.

Vincenzo's boss swung by his desk for an update on the investigation. Our hero merely arched an eyebrow and forwarded on the log. Shortly thereafter he was told to close the ticket and "not to worry about it."

So what happened? Vincenzo's best guess was that manager was seeking the best-reviewed sites of salaciousness, but why Captain Terse should think there was a handy script on company servers to do just that thing is anyone's guess.

The sender of the shouty email never did complete his probation. Trying to access a grumble flick on company time (and company hardware) was likely a career-limiting move. As, we hope, was yelling at the support staff when one's desires were dashed.

We're almost afraid to ask, but have you ever come across a manager's secret stash? Or been the one to look at the logs and seen things you can't unsee? Tell all with an email to [11]Who, Me? ®

Get our [12]Tech Resources



[1] https://www.theregister.com/Tag/who-me

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOwSwBtkt0EHOGbSnz6YjwAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOwSwBtkt0EHOGbSnz6YjwAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOwSwBtkt0EHOGbSnz6YjwAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOwSwBtkt0EHOGbSnz6YjwAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOwSwBtkt0EHOGbSnz6YjwAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/07/05/who_me/

[8] https://www.theregister.com/2021/06/28/who_me/

[9] https://www.theregister.com/2021/06/21/who_me/

[10] https://www.theregister.com/2021/06/14/who_me/

[11] mailto:whome@theregister.com

[12] https://whitepapers.theregister.com/



gryphon

Was asked to do a review of files on servers across Europe for capacity planning, we didn't have disk quotas as such set up back then.

e.g. How much was video, picture, Excel etc., free space and so on.

Found a large porn stash on a users personal drive in Italian office. Going by the file names it was very hardcore.

Passed findings on to my management who passed it on to this guys' manager who didn't see the problem. :-)

We had to couch it to say he was taking up too much space on the servers which was leaving everyone else short then it got some action.

knottedhandkerchief

Casting couch?

Potemkine!

When you create that kind of command, it's always a good idea to implement an answer to '-?', '/?' or in that case 'Get-Help'. Powershell provides an handy way to deal with that with its comment-based help functionality. Doing this a developer can always asks the user if it looked at the syntax and examples provided with the command's help.

help?

Sandtitz

If the user cannot be bothered to check the adjacent README file, then he won't even try to access any help option either. And the story seems to star a particularly thick manager.

A few years ago ...

Alan J. Wylie

much the same: [1]Staff sacked after security sees 'suspect surfer' script of shame , including [2]my memories of red faces when the contents of the squid logs were read out at a sales meeting

[1] https://www.theregister.com/2018/12/26/who-me/

[2] https://forums.theregister.com/forum/all/2018/12/26/who-me/#c_3684075

Easy way out

Pete 2

> This is what he found:

>

> Email: [Manager's email]

> Site: [hardcore pr0n]

> Error message: "Get-ADSite : Directory Object not found..."

So the quickest way to get someone sacked at this company is to run the script, enter their email address and the name of a choice website and then report them!

Re: Easy way out

Shalghar

"So the quickest way to get someone sacked at this company is to run the script, enter their email address and the name of a choice website and then report them!"

But you would still have to fake several complaints of the "logged" person, if you stick to the story.

After all, the log was only reviewed after the prospective researcher on excessive poverty (noone has any money for clothes and everyone does gymnastics to keep warm) complained about the unuseability of the script.

Planted "evidence" rarely bears fruit. Especially when the victim is more competent on keeping records than the planter on creating made up "proof".

Re: Easy way out

b0llchit

Ehm, yes? Isn't that the BOFH way?

Oh wait, you need to add an open window on the high floor towards the parking lot. Then it is pure genius.

Re: Easy way out

Doctor Syntax

I think the manger shouting something to the effect of "Me, me, me" might also have been a factor.

URL autocomplete

adfh

Windows XP.

Working on computer that belonged to senior person in recently merged branch of company I used to work for.

Win+R happy tap colon slash slash www.you autocompletes with porn video link :)

I screen snapped the autocomplete, sent it to my boss (tech head) for a laugh, and moved on.

indeed a bad person

Anonymous Coward

"Right up until the shouty email arrived, cc'ed to pretty much every bigwig in the company."

First red alert of complete ***hole ! Then the rest, of course.

"It was also lurking in a folder available to the company's management, which was our hero's downfall."

Indeed, never put admin stuff, including inoffensive, in a mgmt accessible folder.

Mooseman

We had a similar manager when working for /international package delivery company/

Back in the days when internet access was not universal, managers had to apply to get internet access on their work computer (the drones had no such luxury). Newly arrived manager insisted he needed t'internet to assist him in customs clearance, etc, and the application was duly approved by his manager, so we set him merrily on his way into the world wide web. Log files of internet sites accessed were routinely kept in a folder on the server. Two weeks later the same manager arrived in very shouty mood at the IT office door, demanding to know why we had shut off his internet access, he was going to complain to the CEO who was a close personal friend, etc etc. Our jobs were on the line. So we showed him the list of, erm, inadvisable Russian pr0n sites he had been accessing in the wee small hours (it was a 24/7 operation), and the email revoking his internet access from his line manager. No more was said, although he was allowed access to the web again a few months later when a new customs system was implemented.

Hands on...

big_D

No scripts in my case.

I was working in the office late one evening, along with 4 or 5 other people, when the Big Boss came round and asked us to leave... Immediately.

We protested, that we had a deadline the next day. He said, it couldn't be helped and the customer would be informed, that it was management's fault that the deadline would be missed, now GET OUT!

It turned out that one of the little bosses had gone up to the BB's secretary, opened his trousers and asked, what she could do with its contents... She immediately called her boss for a second opinion.

After we left, he was allegedly marched to his desk, his personal possessions gathered, ID card removed and marched out of the building.

I'm not sure how he explained to his fiance that he no longer had a job and why he was dismissed with no notice.

I've absolutely no idea, what he was thinking, when he exposed himself... Probably not thinking, to be honest.

My respect for the secretary for going straight to her boss and for him for not trying to "cover up" the problem, but tackle it head-on and dismiss the culprit.

Time is but the stream I go a-fishing in.
-- Henry David Thoreau