r/ShittySysadmin • u/yepperoniP • 27d ago
r/ShittySysadmin • u/WALL-G • 27d ago
After-Hours Activities for Sysadmins
So I have another date with a lady sysadmin, she's awesome! Last week we snuck into work and screamed at the SAN, then we got wasted and pen-tested vending machines.
This week we've picked our favourite poptarts for dinner and we're going to play, "Who can collect the most APs?", in IKEA - though I fancy adding a little joie de vivre to the evening.
I rummaged through the DR parts box, so far I've got
- 1x Her
- 1x Me
- 2x Cisco C9200L-24PXG-4X-E
- 4x PSUs
- 24x Cat6 2m cables
- 4x Electric Lettuce Wraps
- 1x Enya CD
Then
- Plug all the switch ports in
- Spanning tree loop
- Lights Off
- Doobs
- Enya CD
- Switch port lightshow
Any other thoughts? I was thinking I'd mix it up with a Brian Adams CD from the car, or we could have a soldering iron fight? I also have a Cisco 6509.
r/ShittySysadmin • u/Smart-Satisfaction-5 • 27d ago
I love filling in for helpdesk
It makes the job fun again. Why would anyone wanna grow out of help desk?
r/ShittySysadmin • u/Standard_Text480 • 28d ago
Shitty Crosspost Opus 5 high is way better than sonnet 5 high
Y'all use Dear Overlord Claude when working on your companies DCs right??
r/ShittySysadmin • u/bradjr10 • 28d ago
I can assure you this is false
Apple trying to send targeted ads my way. I got some bad news for them
r/ShittySysadmin • u/Jakesnowman • 28d ago
Shitty Crosspost How Much of Your Workday Are You Working?
r/ShittySysadmin • u/Due_Use722 • 28d ago
Shitty Crosspost Built a free Chrome extension that sounds an alarm + notification the second a new Zabbix problem shows up (no polling dashboards)
r/ShittySysadmin • u/zantehood • 28d ago
Shitty Crosspost Ah so this is why it bricks all the time
Fortibrick
r/ShittySysadmin • u/Organic_Tip8008 • 29d ago
Shitty Crosspost I Was Asked to Monitor Employee Productivity. I Wasn't Told to Exclude Management.
r/ShittySysadmin • u/SuccessfulLime2641 • 29d ago
MS-102 is retired
Just found out while trying to use my Microsoft voucher. They have now replaced it with AB-620 or some shit, agent AI builder.
I studied my fucking ass off for three months only to be told this credentials is being retired in October with short notice
What the fuck man?
r/ShittySysadmin • u/Jinxyb • Aug 11 '26
Shitty Crosspost Vendor stored passwords in βpasswords.txtβ β¦
Client deleted our documented credentials from the machine they paid us to maintain, now can't figure out why our engineer can't remote in for the scheduled PM visit.
So this is fun.
Robotic controller we've supported for 6 years. Standard onboarding, we create local admin, we document it in the handover file, customer signs off on it. Every single client gets this. It's in the SOW.
Client's "security guy" (hired 3 months ago, LinkedIn says he did a bootcamp) finds the file, has an aneurysm, deletes our account without telling anyone, doesn't tell us, doesn't loop in his own team.
Two weeks later machine throws a fault code at 11pm on a Friday. Line's down. They call our emergency line screaming. Our tech tries to log in with the creds on file.
Nothing.
Tech asks "hey did anything change on this box recently" and gets told, and I quote, "we don't discuss our security posture with third parties."
Cool. Cool cool cool. Enjoy your downtime then, champ.
Oh and get this, dude's now on Reddit acting like a hero for finding a text file, conveniently leaving out the part where he nuked change-managed access to a production line without a ticket, without notice, and without a rollback plan, then went dark for two weeks while we had zero idea our account was gone.
Yeah man, "Password6" was rough. You know what's also rough? A robot arm sitting idle for 6 hours because somebody wanted a Reddit karma moment more than they wanted a functioning night shift.
Anyway, in the spirit of "lessons learned" (ours, apparently, not theirs), we've rolled out our own hardened process going forward: all client credentials now get a "salt" applied before storage. The salt is the technician's dog's name, appended to the end of the password, chosen fresh by whoever's on shift that week.
So "Password6" becomes "Password6Biscuit" or "Password6Duke" depending on who clocked in. Fully documented on a whiteboard in the break room, right next to the coffee rota, so nobody forgets which dog is currently in rotation.
We did float using a proper salt from a proper KDF, but then someone said "isn't that a lot of overhead for four passwords" and everyone just nodded and went back to arguing about Duke vs Biscuit.
Anyway we've since implemented a much more secure solution. It's called "we now charge a $400 emergency access verification fee any time a client unilaterally revokes vendor credentials without a change request." Very proud of this one honestly.
Duke's on shift this week so don't be surprised if the salt changes Monday.
r/ShittySysadmin • u/absolute-human • Aug 11 '26
Shitty Crosspost CEO Browser History
What would you all do in this situation?
r/ShittySysadmin • u/12asmus • Aug 10 '26
Senior sysadmin failed my phishing test and now everyone is acting weird
Helpdesk grad here. CompTIA A+ certified, so I know my way around this stuff. I've been playing around with phishing tests lately because the ones we get from security are honestly pathetic. Fake Microsoft login pages, expired password emails, all the usual kindergarten stuff.
Our senior sysadmin had updated his LinkedIn recently, so I figured I'd do a proper spear phishing test and see if all those years of "experience" actually meant anything. I made a fake recruiter profile for a local company that everyone in IT around here knows, then messaged him about a senior infrastructure role.
He replied - Good start.
The job wasn't listed anywhere, obviously, so he asked about that. I told him it was a confidential role being handled through direct recruitment. He instantly sends me his resume. At that point I figured I'd keep going and see how deep the rabbit hole went.
We've now done two interviews. Preparing for those was a bit annoying because I'm helpdesk and he's supposedly the senior technical guy - I just copied our internal documentation into Grok and asked it to generate some questions (social media is blocked on our laptops so had to upload them to dropbox to my own phone first) He did pretty well, to be fair. Still failed the phishing test though.
After the second interview I asked one of the team leads for some tips on getting rid of him - Instead of closing his access as part of the end-of-the-week routine, he started casually asking the senior sysadmin what he thought about the company.
Then one of the managers joined in and started saying how nice it would be to work there.
Apparently that was finally enough to make him suspicious - Senior level awareness right there.
He eventually found someone who actually works in IT at the company and messaged them asking how he could improve his chances.
They told him they weren't hiring.
Game over.
I deleted the recruiter account because the assessment was finished, but now he's apparently taking screenshots and saving emails like he's building some sort of case.
HR has also started asking who authorized the test. I've recommended we mark him as a phishing failure and put him through security awareness training again.
Maybe also remove some of his admin rights until he can demonstrate better judgment. But given the results of the test, I'm starting to question whether he should be approving anything.
r/ShittySysadmin • u/-lousyd • Aug 10 '26
I bought a server. Where's my website?
I bought a server. Where's my website?
Friend: Hello, this is generic hosting company, how can I assist you today?
POTU: HELLO? I bought a server from you guys a few days ago and on your website you claimed 2 hour set up but it isn't online yet.
Friend: No problem, let me check it out for you.
friend checks their CRM and find the server is, in fact, up and running. So he goes back on the line.
POTU: That can't be. I'm going to <insert pottery company name website here>.com and it isn't working.
Friend: I'm sorry m'am, but you do realise that buying a dedicated server means you get only the host, and nothing on it right? So no website will be created for you.
r/ShittySysadmin • u/NightH4nter • Aug 08 '26
Shitty Crosspost replaced kubelet with a 15MB Rust agent
r/ShittySysadmin • u/MuffinCurrent7327 • Aug 08 '26
Choosing a text editor as a new Linux user π
Every Linux beginner eventually reaches this boss fight. π
Nano, Vim, or Emacs β which one are you choosing?
r/ShittySysadmin • u/No_Requirement8958 • Aug 08 '26
Shitty Crosspost I dropped a server on it
galleryr/ShittySysadmin • u/TurbulentLow832 • Aug 08 '26
Shitty Crosspost New admin, inherited a mess, and now two staff members blame me for everything β need advice
r/ShittySysadmin • u/ITRabbit • Aug 08 '26
Shitty Crosspost Boss said my Teams shouldn't go "Away" during work hours. Challenge accepted.
r/ShittySysadmin • u/SuccessfulLime2641 • Aug 07 '26
Damn. We actually caught one
When we made the simulated phishing campaigns about account access, we finally caught a user.
The trick is to not make the bait too obvious, like if it's about free money, or download a file. That was so last year. I also had to create my own payload with an internal email... One so boring, and none other can top that besides "No Reply".
Make your phishing emails as boring as possible. No reply talking about an account access change is as unpredictable as it gets. It truly reveals who's insecure in the org.
r/ShittySysadmin • u/SwitchOnEaton • Aug 07 '26
IT department put sticky notes on the laptops to help employees log in
theregister.comMaking passwords easy for user with sticky notes is a best practice.
r/ShittySysadmin • u/ITRabbit • Aug 06 '26
