if you ever stumble across a folder called 'temp' on a file share on any corporate network, nine times out of ten it's 24 years old and contains everything you need to assume ownership over both the network and the company
@SecureOwl used to do this sort of thing with college ftp servers Japan in the early 00's.
@SecureOwl
I assume the second and third Temp folders are just decoys, right?
@SecureOwl Either that or a folder called "Dan's Stuff" inside a folder called "Accounts", inside a folder called "Old D Drive", all with zero security.
@phs @SecureOwl no no that folder contains some really choice anime.
@SecureOwl And a file "initpwds.txt" of the same vintage contains the initial but to this day unchanged administrator credentials for any core servers, routers and switches from when it was first set up, readablw by anyone...
@SecureOwl @vaurora mine are called “tmp”, though.
@SecureOwl I feel so seen damnit 🤔
@SecureOwl ouch! I feel so called out.

@SecureOwl

Keep drilling. The best stuff is often in /temp/temp.

@SecureOwl Once a sysadmin almost killed me because I deleted temp folder on the department's file server.
He was extremely pissed of at me and said: Don't you know the real meaning of 'temp'? It's DO NOT DELETE!.
@SecureOwl I recently bought a Thinkpad R40 in a flea market (literally called "Dumpster Divers' market") , and after examining the hard drive I discovered it was used in the 00s as a thin client in some corporate network but in a temp folder there were multiple gigabytes of corporate emails, promo materials, internal memos, names, emails, phone numbers etc. I wonder what would an exhaustive search find...
@SecureOwl Joke's on you. I name my temporary folders tmp instead.
@SecureOwl I once authorized a folder named linux to be deleted from a fileshare. Inside of that Linux folder, buried in folder after folder ultimately labeled as “ice cream” was a VHD that was the email server. Thanks to that, we slowly started implementing “better practices” for managing Microsoft Windows servers. I can’t say best practices but they did get better.
@SecureOwl my SMB share is in this picture and I don't like it.
@SecureOwl @Lundemo I named it “junk” so I guess I’m safe
@SecureOwl
There is also a 2nd case that is less "helful":
It may just contains a single "thumbs.de" file or has missconfigured ACLs that allowed it be renamed but not deleted or similar