If I'd not worked out it was nmap that shit would have been secure wiped and reinstalled, possible even replaced completely, if I'd suspect malware but not found anything.there's no way it would have been handed back as was if it had crossed my desk.
User crippled a network while trying to learn Nmap
WHO, ME? Welcome to the working week, dear reader, which as always we open with a fresh instalment of “Who, Me?” – the reader-contributed column that offers an education in how not to do things at work. This week, meet a reader we’ll Regomize as “Roger” who told us that a decade or so back he managed teams that designed …
COMMENTS
-
-
-
-
Monday 13th July 2026 17:47 GMT David 132
Yep, I commented on an article yesterday (circa 2AM UK time?) and my comment didn't show up, completely vanished. So I posted it again. Now I fear it's there twice and making me look like an idiot (I don't need the Register's help to do that, dammit!)
Still, I'm sure the other commentards will make allowances and treat my faux pas with the forbearance, tolerance, gentle good-humour and forgiveness for which they're so well known... :)
-
-
-
-
Wednesday 15th July 2026 11:33 GMT Anonymous Coward
Why some take security seriously
A colleague tells a tale of someone who got permission to go to China to give a presentation. You might tell from the following that we take security "rather seriously", and guess why posting as AC ...
Said person, we'll call him DS had his mandatory pre-trip briefing, during which he was told to get a brand new laptop from the store, load only the presentation onto it, take no other tech with him, and after the visit to securely destroy it (i.e. drop it in the shredder.) On return (and I'll cut out a lot for brevity), DS went for his debrief and was asked about the laptop - which he had with him. This caused "some ire", and the laptop was quickly put into a metal (screened) box and taken to a screened room where it was opened up ... to reveal ...
... some additional bits of electronics that had been added while he was away. These were disconnected, and the whole lot dropped in the shredder.
DS was lucky to keep his job given that he'd ignored a very explicit instruction about destroying the laptop, and given bits of the story left out, lucky to have gone home alive.
.
Why DS, well he was a bit of a dipstick.
In our industry, certain countries are no-go areas even for personal holidays - and you need a good justification for being given permission to go. Go without permission, and your next stop is the job centre.
-
-
Thursday 16th July 2026 16:16 GMT Dr Dan Holdsworth
Hard disks are cheap, fried networks much less so. In this situation I would have concluded initially that the user's story of a virus was indeed true and I would have removed and replaced the disk, reinstalling with a known-clean image. I might've kept the disk for later analysis or I might have had it destroyed but that disk would not be going back into that machine.
Should the problem recur then the user would be under suspicion, as would the machine (to a lesser extent).
-
-
Monday 13th July 2026 10:44 GMT trevorde
Trashed PC learning AutoCAD Animator
In the dim, dark ages of DOS, I was starting to learn AutoCAD Animator. I setup an animation and set it to render whereupon the hard disk went crazy! After about 15 mins of nervous waiting, I pulled the plug on my PC. Not sure what the program was doing but the PC refused to boot. IT support sent it to a data recovery firm who recovered it and diagnosed a 'virus'. I kept schtum and nodded in agreement. I never managed to learn AutoCAD Animator.
-
Monday 13th July 2026 12:53 GMT Acme Tech Support
Re: Trashed PC learning AutoCAD Animator
Sorry to be pedantic - did you mean AutoDesk Animator?
If so, I remember that - I worked for a VAR company in the UK that sold that software as well as Autodesk 3D Studio.
I don't remember the 2D software too much, but the 3D stuff would take hours if not days to render.
-
-
Tuesday 14th July 2026 17:55 GMT DoctorPaul
Re: Trashed PC learning AutoCAD Animator
Was that the software that stored animations as a "flic file"? The format that AutoDesk discontinued just before it would have been a brilliant alternative to Flash for animations on the early(ish) internet?
Still, I earned a few quid back in the day writing the FlicPlayer component for Dephi, someone from IBM even bought a copy! Happy days.
-
-
-
-
-
Monday 13th July 2026 10:45 GMT Evil Auditor
What worries me, more than Roger not confessing (something that hardly ever did me any harm), is that after not finding the alleged Chinese malware, they didn't properly purge Roger's laptop, possibly involving a partial physical destruction. My math might be off, but I believe this happened in the 2010s and not the 90s or so. Even in the naughties we were given burner laptops when visiting certain countries (which may or may not have included China); although, that was a bank, but the threats had been well understood for quite some time.
-
Monday 13th July 2026 13:41 GMT Anonymous Coward
The mention of banks and data reminds me of an incident at my last workplace, an independent boarding school
Our bursor gave me a stack of his old laptops to wipe the drives, they were between 5 and 20 years old, from when he was a senior manager in a private bank.
I checked each laptop that would turn on before wiping the drives. The laptops had no passwords, and some of them had account details for some very prominent people.
They'd been sitting on a shelf in his office since he moved from the bank to the school.
One of the laptops was old enough to have an IDE drive, and one Dell had a 1.8" drive with a bespoke connector, neither of these would fit into our drive wiper, so I took them all down to the engineering department and dropped them in the metal shredder.
-
Monday 13th July 2026 15:49 GMT mtp
Destroying HDDs
I had something similar. I had a pile of old HDDs of unknown origin and worthless capacity so instead of going through the hassle of finding a way to wipe them and demonstrate that they are left fully clean I just bashed them all with a big hammer until it was obvious that they would never spin again. The first hit destroyed the PCB making data retrieval almost impossible but a bit more targetted hammering on the bearings finished the job.
-
Monday 13th July 2026 16:38 GMT CountCadaver
Re: Destroying HDDs
Mine involves a drill press and a hss drill bit putting multiple holes though the drive and it's platters
Anything with anything I want to make sure no one nefarious gets their hands on, gets the platters a meeting with a an angle grinder (destroy the disk surface physically)
Though I have wondered if throwing some weld beads down would be effective.....clamp return lead on platter, put welding rod in holder and throw some hot passes down, let the electric arc scramble the magnetism,.the heat to demagnitise the surface and warp the platters
-
-
-
Tuesday 14th July 2026 06:53 GMT trindflo
Re: Destroying HDDs
I like to take them apart. I save the magnets for kids to play with, and save the PC board. I have occasionally had a PC board go out and was able to swap it to another drive. Not perfect as the bad sector map will trash some files, but it allowed me to recover most of the data.
Once you've removed the platters from a drive it is unlikely anyone is going to get the data back; the sector alignment is gone. NSA and M5 can get it back as can some commercial firms, but you have to ask yourself what that data is worth and who would go through the herculean effort. So if you have spy secrets or crypto wallets, sure throw the platters into the fires of Mordor. Once out of the drive, I use the platters as coasters or bin them
-
Wednesday 15th July 2026 11:38 GMT I could be a dog really
Re: Destroying HDDs
you have to ask yourself what that data is worth and who would go through the herculean effort
Exactly, some people do have a rather heightened idea of what they think their data is worth to others.
And of course, there's always the obligatory XKCD
-
Thursday 13th August 2026 16:02 GMT Robert Carnegie
Re: Destroying HDDs
Super-powerful magnets are not safe toys, if we're talking about those. I think one of the nasty scenarios is that a small child swallows two magnets and the magnets decide to stick together, being in different inside parts of the child, but making their way together regardless. But an imaginative teenager probably could find something terrible to do with them too, possibly to someone else. Such as to someone else's bank card.
-
-
-
Tuesday 14th July 2026 07:53 GMT that one in the corner
Re: Destroying HDDs
> The first hit destroyed the PCB making data retrieval almost impossible
A few years back, the magic smoke came out of the controller chip of one of my hard drives, wrecking the PCB quite nicely. That weekend, popped over to a local junk parts sale, bought a handful of "dead" drives. Few minutes with a screwdriver, tada, fully working hard drive. Unless by "PCB" you mean the tiddly one on the inside which just carries a bit of decoupling - but even then, swappable. The drive won't run long if you don't have a clean room, but doable in a techie workshop to get a backup off.
> but a bit more targetted hammering on the bearings finished the job.
Now you've put it into "data recovery firm with decent clean room" territory; tricky, but a quick thumbing through the Yellow Pages...
You really need to do a number on the platters if you want to render a drive unreadable. Drill presses (see other comments) are fun, but if you don't have easy access to one of those, a quiet evening with a set of screwdriver bits from Maplins will get the thing apart. THEN smack the platters once - if they shatter, job done, otherwise 12V into the motor and sandpaper: you can hear the bits screaming, mwahaha.
-
Wednesday 15th July 2026 09:57 GMT Eric 9001
Re: Destroying HDDs
Smacking the bearings with a hammer would throw the platter alignment off and/or shatter at least some platters.
Maybe the NSA could get some of the data off, but 99% of data recovery firms would take one look at the drive and say to forget it (they wouldn't want to fill their clean room up with metal shards from drilling out bent screws and then shattered platters would they?).
>The drive won't run long if you don't have a clean room, but doable in a techie workshop to get a backup off.
With a modern HDD, unless you have at least some kind of clean room box in the workshop, any opened HDD will immediately head crash from microscopic dust fragments.
It's easiest to just unscrew all the screws and remove the platters and magnets to play with - as soon as those platters are misaligned, only NSA-tier funding will get anything.
-
-
-
Thursday 16th July 2026 16:27 GMT Dr Dan Holdsworth
The only tale more frightening than that was one told by a former boss of mine, a nuclear chemist by training. He was in a university (not the one I work for!) when a rather elderly academic had to be forcibly retired because he was getting rather forgetful and making silly slip-ups. Ordinarily a slightly dotty academic isn't unusual, nor would be that he was a Nobel laureate.
Unfortunately this chap worked with radio-actives, so carelessness in his line of work could be lethal to him and everyone around him. So he was pressured into retirement and his lab carefully checked for all the highly dangerous chemicals he had checked out. Everything was eventually accounted for save for one entry: 50 grams of plutonium. Cue great nervousness because that isotope of plutonium is a proliferation risk and lethal to humans in the microgram ranges. The lab was searched again, and again with no result.
Finally someone thought to check under the sink and found two carboys of darkly dangerous solution which contained the plutonium. Luckily for everyone the cleaners hadn't chucked this rather dubious liquid down the sink, for there were no hazard labels on the bottles, indeed no labelling at all.
-
-
-
Monday 13th July 2026 10:45 GMT Flightmode
Just fess up.
It's been discussed before in these comments, but when you've done something like this - through best intentions gone wrong or through recklessness (as in the case here): Just Fess Up. Especially if it's happened while straying into territories that you don't really know; and as such can not be expected to understand the potential consequences of your actions in. Even if you might lose face right then and there, I find that most managers / companies are forgiving enough if you screw up once and openly admit to it. (If you do it repeatedly, however, that's another story.)
Instead of losing your laptop and tying up IT resources for a week doing all sorts of scanning and forensic investigation, probably also raising an investigation into espionage since there was cross-border travel involved - simply admit what you've done and take the slap on the wrist for it. Perhaps you can even use it as a springboard to say "hey, I'm actually developing an interest in networking - any chance you have junior positions opening soon, or could I possibly tag along one of you guys for a couple of hours a week to see if it's something I'd want to explore further?" - whereas now "Roger" will probably end up forever in the "oh hell no, we're not letting him anywhere near the network admin tools" category; not to mention all the new travel guidelines and laptop usage policies that may come from this non-incident - all based on wrong assumptions. (Oh, and don't forget the overtime for the on-call network engineers, and escalation conference calls...)
-
This post has been deleted by its author
-
Monday 13th July 2026 10:46 GMT Phil O'Sophical
Back around 1991 I remember a friend who discovered nmap and similarly left it running over the weekend to scan the company network. In those days it was a reasonable-sized company with 10k+ employees across international offices.
He had not realised that the way the network was configured allowed his exploration to leave the internal network and reach the wider internet (simpler times).
He came back on Monday morning to find a much larger database than he had expected, and a shocking number of 'interesting' systems discovered. He (just) resisted the temptation to send spoof jobs to the many printers discovered as well. As far as we know, IT never noticed.
-
Monday 13th July 2026 17:51 GMT David 132
Back in the very early 2000s, at a large semiconductor company, I downloaded a well-known hacking toolkit out of pure curiousity. I was young and gauche (whereas now I'm just old and bitter).
After a few days I received a weary-sounding email from the IT dept, asking if I wouldn't mind deleting the BackOrifice installer. No fuss, no repercussions, just "please delete that".
More innocent times!
-
Thursday 16th July 2026 16:34 GMT Dr Dan Holdsworth
Many, many years ago at a certain university whom I'll not name the students decided upon a prank. They had discovered the magic of buffer overflows in Postscript and had worked out that the departmental printers (which were isolated from and different from the general university printing systems) were vulnerable to Postscript hacking.
So, they obtained a fingerprint or two of the Head of Department and ran the hack on a Friday evening. For all that weekend, printed as lightly as the printers could do, every sheet of every printout had at least one fingerprint of the Head of Department on it. They re-ran the hack on the Sunday night to remove the hack.
-
-
-
Monday 13th July 2026 15:43 GMT Not Yb
Banned because nmap can be a stress test (among other things) on networking hardware...
nmap can fairly easily be told to hammer a network badly enough that most other data transmission either slows down or stops entirely.
Back in the day, running nmap on a network could also cause badly programmed networking devices (or some common OSes) to halt until power-cycled.
-
-
Wednesday 15th July 2026 11:42 GMT I could be a dog really
Re: Banned because nmap can be a stress test (among other things) on networking hardware...
And I'd guess that finding and reporting that would get someone a slap on the wrist - whereas what should happen is they get a thanks (for finding it before someone with bad intent does) and the relevant team can fix the problem.
-
-
-
-
-
Tuesday 14th July 2026 08:03 GMT that one in the corner
Re: Who, me too.
> the new problem is that it's almost redundant with this one.
Send it in anyway; if El Reg has such a slim slush pile it gets it go too soon you can point out other commentards need to step up to get the variety. Otherwise, in x months/years time there will be a new set of wet-behind-the-ears readers who'll benefit.
The old guard will complain that they've heard that story before, but we always do. Then we'll fall asleep in our rocking chairs again. 'Til them durn kids get on the lawn agin, anyways.
-
-
Monday 13th July 2026 10:48 GMT BartyFartsLast
If I'd not worked out it was NMap and I'd not found a virus there is no way that would have been back ony network without a secure wiped and full rebuild or even full replacement.
But how did the network team manage to track it to a single laptop and not realise the prat who "owns" it was running a network scan?
-
Wednesday 15th July 2026 10:10 GMT Eric 9001
I figure they saw ???? traffic from the laptop, so they unplugged it and the network starting working again.
Many "IT workers" are not very competent and can't work out tcpdump or wireshark and it's not uncommon for garbage proprietary network software to stop working in response to correct, valid traffic from a computer, or even by coincidence when an unrelated computer is unplugged.
That combined with how a virus was not found and reinstalling things on a WC is a real pain in the neck, means they just handed back the laptop with the malware OS back, on not finding any non-approved malware.
All nmap sent was valid network packets, as fast as the laptop NIC allowed (I would expect a 1000BASE-T link), thus the issue was not with the laptop - it was broken proprietary software hosting the network.
-
Wednesday 15th July 2026 11:59 GMT I could be a dog really
Many "IT workers" are not very competent
Hmm, most of us fitted that category at one time, and some of us have not improved all that much [sfx: commentard whistling innocently into the air]
I've killed a few networks in my time, I've also fixed a few networks where others have killed them. I don't consider myself the "expert"* many current/ex colleagues do, but I'd agree that far too many "network engineers" just don't have any diagnostics skills. To be fair, if no-one has ever shown you how to diagnose some of these faults, they can be "interesting" to diagnose and fix :
* "Helpful" user found a loose network cable end, so helpfully plugged it into a spare port on the switch on the desktop. The small switch was there because the building didn't have enough ports, and the loose cable end was there for a laptop user (not common in those days). I got called when the "network expert" couldn't diagnose why nothing worked in the presence of a line-rate broadcast storm.
* A colleague had been experimenting with the mobile hotspot on his phone. I think there must have been a bug, because he'd turned if off, but it was now connected to the office WiFi using the same IP address as the router - so the flapping IP-MAC table entry made network performance flap between terrible and non-existent.
* And then there's manually configuring a server with the same IP address as a production server that nearly everyone in the company relies on (oops, whistles again).
* - and then finding that Windows is utter s**t and even when you've corrected the mistake, won't find the correct device without a reboot. This was back in the Win 3.11 & 95 era.
* And one of my favourites, re-purposing an old router as a network switch - but forgetting to disable the DHCP in it. Thing is, the network will continue to work, for days, weeks, even months - but one day when the on-site server is down, all the clients then realise there's another DHCP server they can get an address from and the network is broken and no-one remembers the "quick fix" for not enough ports.
* And I think this comes into the "there are 10 types of network admin/IT slave" category: you arrive at a site, and someone decided to move stuff around, so they just unplugged everything, you have no documentaiton on how it was previously set up (or supposed to be set up - not always the same), there's at least 2 routers, and you have no passowrds to anything, ...
-
Thursday 16th July 2026 01:17 GMT Eric 9001
>Windows is utter s**t and even when you've corrected the mistake, won't find the correct device without a reboot. This was back in the Win 3.11 & 95 era.
Still the case with windows 11, even when no mistake was made - WC's will fail to find an IPP printer without refreshing multiple times and then if you try to add the IPP printer, it fails and will not output as to why - the only thing that works is rebooting and trying again, up to several times.
-
-
-
-
Monday 13th July 2026 10:49 GMT jake
One wonders ...
... is this a confession about the state of ElReg's network over the weekend?
With that said, who working in IT hasn't seen the effects of a neophyte with nmap causing havoc on the corporate network?
Those of us who are a trifle older may remember Nessus, in the hands of idiots, causing similar trouble from the mid '90s to the early '00s.
And before that was the Security Administrator Tool for Analyzing Networks in the middle '90s that the DOJ got into a complete tizzy over.
Prior to that, most of us had scripts to do pretty much the same things ... but we were clueful enough not to blow up the corporate network with them.
-
Monday 13th July 2026 10:51 GMT Anonymous Coward
The opposite....
Many years ago I was working for NHS PASA (The purchasing and supply agency, which ironically neither purchases nor supplies anything).
The whole setup was thin clients talking to a set of about 5 fairly beefy servers in the basement of one office - had all the normal benefits of being location independent, and of being able to burst heavier workloads.
I was doing some reasonably substantial database work which for some unknown reason (incompetence) one of the big four had decided should be broken into a handful of access databases rather than using one real database (I believe the data exceeded the limits of access at the time, so it was logically split and then a summary db was the final output).
So I knew full well that what I was about to kick off was going to take significant resources, and take a significant amount of time... As a responsible, IT literate worker, I contacted IT and told then what I was about to do, and would they like me to start my session on a particular server (preferably one that didn't have other people on it whose work could be affected.
"It'll be fine, just run it"
OK - so I ran it, and within about 5 minutes there was a wave of panic across the office as about 20% of people lost connection to their sessions... Oh, including me, so I couldn't stop the process either.
Phoned IT back... explained what the issue was that they were about to get rather alot of phone calls about... I don't actually remember if they had to log in locally (presumably via an IP KVM) or whether they were able to kill my processes remotely.
However they did then give me access to a test server, which didn't have other people working on it, and my jobs took a few hours each time, but did complete.
-
Monday 13th July 2026 11:03 GMT Anonymous Coward
I was on a hacking course at HP (back in the good old Pinewood days). I was bored, and actually managed to compile some code to hack NFS (anyone who knows HP-UX will remember getting code to compile can be a bit of a challenge).
Imagine my surprise when the instructor came over and questioned what I had been up to. Apparently no-one had managed to get the code compiled, let alone working, during the course before. First time ever!
I miss those days.
-
Monday 13th July 2026 13:03 GMT Bebu sa Ware
anyone who knows HP-UX will remember getting code to compile can be a bit of a challenge
Even with HP's c89 on HPUX 10.20. Wasn't the compilers - just HP-UX was just weird — seemed like a jumble of System III, BSD, System V, OSF/1 and whatnot† so getting anything vaguely system dependent to compile was definitely "a bit of a challenge."
I usually tried the HP-UX Porting and Archive Centre first. Fortunately most of the system stuff could be found there. I do recall trying to build isc-dhcp without the least success.
Fun times. /s
† including Apollo Domain. I remember a Win2k virus futilely hammering the DCE/RPC port(s) on our HP workstations.
-
-
Tuesday 14th July 2026 00:06 GMT Denarius
HPUX compiling
IMHO, HPUX9.x was "difficult" So many libraries missing. However, once the packags were installed worked ok mostly.. HPUX10.0/10 better. Didnt have problems on 10.20 but was using the full licensed compiler, not the OS only linker compiler. Linker/compiler would build gcc successfully.
-
-
-
Monday 13th July 2026 18:14 GMT Stuart Castle
A few years ago, I did lab based tech support for my Uni. The lab had two networks. One for general use and one for teaching communications, hacking and digital forensics. The second network was isolated from the internet (and main university network), and ws only accessible from a second install of windows on each machines. Each machine had dual ethernet ports, with each install of windows disabling the port connected to the network it wasn't supposed to have access to. That arrangement generally worked as we'd somehow locked down each install of windows so it was impossible for students to control the ethernet ports. Even swapping the cables didn't work because the MAC addresseses for the comms network ethernet cards were not registered with the main network dhcp server.
One day, one of the academics had arranged for some school kids to come in and spend a day trying out the equipment. I was supporting the lab along with a couple of other techs. Around lunch time, the network started to become sluggish, with increasing numbers of PCs losng their connections. The lecturer arranging the day was furious, started complaining, and we agreed that she shoud send the pupils for lunch, so we could resolve the problem.
After about 45 minutes of working (including rebooting the switch connecting all the PCs on the isolated network several times, which only worked for a couple of minutes), one of the techs noted that there was a *lot* of traffic coming from one port. So, he went to investigate the PC.
As an exercise, the class had been given the ip of a local webserver. One pupil had entered the wrong ip into their tool, and as a result, flooded the switch with incorrect ip requests, overloading it's cpu. When he stopped the tool, and rebooted the switch, all was well..
-
Monday 13th July 2026 18:45 GMT BPontius
Nobody looked to see what the laptop was doing, they just shut it down? Couldn't have been too difficult to see that Nmap was running, network logs would have clearly shown port and ip scanning. They bought his virus story even with no virus found, no investigation into other causes. The admins are severely lacking in investigative and troubleshooting skills, with zero curiosity.
-
Wednesday 15th July 2026 12:09 GMT I could be a dog really
We don't know exactly when this was, but even these days, many networks still do not have that wort of logging. I'd go so far as to say that even today, the majority of small/medium business networks won't have it.
Yes, a network admin with a few brain cells turned on could use the port tap function built into most managed switches to look at the traffic and see what's going on, but other than that, all they'd see would be "lots of traffic".
As an aside, I find the most powerful network diagnostics tool is ... the blinking lights on the network switches. Step into the server room/network closet/random purloined space and look at the lights - often you can narrow down the source of the problem just from that. If nothing else, it narrows down where to start with the technical tools.
-
-
Monday 13th July 2026 19:43 GMT steviebuk
MFD
I was looking at the Ricoh server 10 years ago now where I was last. Spotted a feature "purge jobs on logout". We used follow me printing. Oo, that sounds more secure I thought and instead of doing a request for change, decided to turn it on.
About an hour later ticket came in that someones print job stopped half way through printing. Then another, and another and another.
Oops. I realised and quickly logged into the server and turned it off.
I suddenly remembered. People would send the print jobs, sign in to release them, not wait for them to finish, and sign out which of course, that purged the print job. Oops.
I kept quiet. No one else noticed as I'd grabbed all the tickets.
-
Monday 13th July 2026 21:21 GMT Scott 26
Re: MFD
we have something similiar - except it has a small agent on the user device to send the job to the follow-me queue (don't ask why... something something cloud based, probbably).
But we were getting tickets "my print job doesn't show up in the queue".....
hmmmm.... weird one, but eventually one of the team spotted the culprit - every ticket had something in common (and took a while to ask the right question to discover this)... the users would send the print job, then shut down their device (cos they were finishing for the day, or moving between floors/buildings/whatever)... that meant the agent on the laptop would close as well, and not send the job.....
-
-
Monday 13th July 2026 20:38 GMT stiine
That's news?
Every admin does this once. The question is how long do you let it run once you know what its doing? Do you wait for a call on a different day, from corporate security in another office in another timezone? Did you really accept the defaults in HP OpenView and then let it try to discover every machine in a /8 network as quickly as possible?
-
Monday 13th July 2026 23:03 GMT timmy 2
some of us should be as lucky as the OP
I did something similar ~2010. Part of my duties involved unlocking AD accounts in a rather large domain with multiple sub-domains having 1500+ each users each. Every few months we'd have to pull overnight duty and respond to unlock-account requests from night-shift users who would lock themselves out. Problem was, the notification system really didn't work well...at all. So rather than hear about it the next day of why wasn't I doing my job from the micro-managing nitpicking screaming btch of an incompetent manager who knew the notification system was broken, I decided to have a little script find the locked accounts and I'd unlock them.
So I created a script, tested it, but it didn't seem to be working, and I ran it a number of times against our sub-domain. Finally figured out the script was working but wasn't finding any locked accounts because there weren't any (unusually)! Yay me! Running against another sub-domain found locked accounts. Proof it works, ready for my next overnight shift in a week or so.
I come in the next day, need to check a few things requiring Admin privileges so try to login with my Admin account...but it's not letting me. OK, login normally. That's weird, my Admin account is locked out but my regular account is not? Send off an email to the SWMNBN btch manager (She Who Must Not Be Named; yes, this was one of our official references we used to refer to her) saying my Admin account is locked out. She calls back 3 HOURS LATER to ask why I was running scripts against AD. Ummm, because I was searching for locked out accounts to make sure I didn't miss locating any when I had to look for them? "No one gave you authorization*, <blah blah blah> <rant rant rant>... don't do it again" ..... "Sorry <that I ever decided to take the job working for a sanctimonious btch like you>"
*actually, my job and my responsibilities grant me authorization you moronic bint
Used the script from thereon, waking up a few times during the night for 5 minutes to run the script. Was worth getting interrupted sleep instead of dealing with her stupid self-righteousness. She never knew the effing difference (and I was finally out of there 12 months later).
-
Tuesday 14th July 2026 01:58 GMT Anonymous Coward
nmap oopsies
Not as dramatic at the main story, but I discovered that running nmap against the 3com NBX100 switch would get it to lock up tight. I think it needed a reboot to start handling calls again.
Cool discovery in the lab. Much less cool if you're depending on said NBX100 for office phone calls.
-
Tuesday 14th July 2026 08:19 GMT Anonymous Coward
Early Internet Years
Back in the later 1990s worked for a company where we developed a network discovery tool. Nothing fancy. Ping a network, run some SNMP, NPMP and other fingerprint detection. We were mainly looking for printers to setup.
Now this was in the more innocent era before everyone was hiding behind firewalls. So whole companies and universities were sitting there on the fully accessible internet.
Unknown to me some of my team were finding external networks to test on. Probing their old Universities and the like. I remember getting to work one day to the rather annoyed boss who had been called by one of these universities who were accusing us of attempting to hack them.
After talking with the other devs, what surprised me is the range of places they went for. And how many clearly didn't even notice. I'm talking the military bases and the like. Or the cheeky guy who not only found printers at the White House but sent print jobs to them(!)
-
Tuesday 14th July 2026 09:28 GMT Pirate Peter
network doom
the other good one is the network version of the original doom game
if there were 4 of you on the network playing, alll with the cheats for the BFG9000 with unlimited ammo shooting the heck out of one of the hard to kill baddies you could bring a network to its knees
as the network version of Doom 1 was sillily in that every bullet fired was a separate packet on the network, so 4 players with unlimited ammo finger down on the trigger constant sent hundreds and even thousands of packets out into the network, and it was more fun if you were on different network segments as well
we used to use it for out of hours network testing while having some fun as well, if the network coped and survived all was good :)
-
Tuesday 14th July 2026 11:36 GMT Jellied Eel
Re: network doom
we used to use it for out of hours network testing while having some fun as well, if the network coped and survived all was good :)
Been there, done that, got the headshots. Favourite experience was detecting a player was trying to flood ping us. Cheats seldom prosper, especially when they're on a 56kbps dial-up connection, and we were bored netengs doing a spot of inter-company rivalry. We had pretty much all the UK's Internet capacity that wasn't BT at our fingertips, and BFRs with.. like all the bandwidth to flood ping them into oblivion. Poor lil user didn't realise they were trying to ping real Caco-Demons..
-
-
Thursday 16th July 2026 01:29 GMT druck
It's the garage calling
A few years ago I was working for a spin off of an F1 team, and we found that every other Friday something was buggering with our test rig. We knew the IP address, but not what the machine doing it was or where it was located, to be able to politely ask the owner to stop. I set off an nmap -A scan on the IP address and went off to lunch, only to return and find my colleague very perturbed as IT had come up from the depths of the basement wanting a stern word, thinking he was the culprit and not me. After explain to IT why I was doing it, both him and I were off the hook, and they helped us locate the rogue machine, which was actually a misconfigured strategists laptop in the pit garage track side, which explained why it only happed on the Friday of race weekends.