Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
pseudorandom name
May 6, 2007

the new thing is to locate devices that don’t have cell modems or are “off”

Adbot
ADBOT LOVES YOU

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Vomik posted:

so I'm hanging out in bar with my raspberry pi zero W :smug:

surrounded by hotspots and yet zero connection

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
cbp data breach
https://twitter.com/snlyngaas/status/1138190170912673794

https://twitter.com/pinboard/status/1138195461188145152

flakeloaf
Feb 26, 2003

Still better than android clock


loving :laffo: irl

influx.
Dec 16, 2007

Nice pants!

Nice!

Shame Boy
Mar 2, 2010

from an nmap scan of some box at work I was trying to figure out the ports of:

code:
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
:bravo:

Squinky v2.0
Nov 16, 2006

Behind you! A three headed monkey!

College Slice
“to protect the privacy of all involved we will not be naming the vendor responsible, tennessee based perceptics llc, at this time.”

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

from an nmap scan of some box at work I was trying to figure out the ports of:

code:
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
:bravo:

the absolute best 1998 has to offer

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

the absolute best 1998 has to offer

it's an active directory server running 2008 R2 SP1 lmao

Shame Boy
Mar 2, 2010

to be clear it's not ours, we use that :yayclod: active directory thing so we don't have to deal with this bullshit

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

it's an active directory server running 2008 R2 SP1 lmao

lol you have to go out of your way to pull that poo poo

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
is that some ancient-rear end pci dss mode or did someone actually do a GPO to limit it like that on purpose?

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

lol you have to go out of your way to pull that poo poo

infernal machines posted:

is that some ancient-rear end pci dss mode or did someone actually do a GPO to limit it like that on purpose?

i have no idea, we get shipped hardware by clients and i have to make stuff work with it. some of the other things they shipped us are ancient yellowed-beige boxes (though it's running win 7 somehow) so i'm guessing somewhere lurking on their network is some ancient-rear end poo poo that needed this enabled at one point

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I don't think there is any point in pci dss's existence when that would have been acceptable, maybe for 1995 up to 96-98 to give sslv3 a little bit of adoption time but it was basically poo poo from the word go

e: yeah pci dss was formed in 2006, no chance in hell this was ever valid for that.

evil_bunnY
Apr 2, 2003

oh look tavis at it again

https://twitter.com/taviso/status/1138469651799728128?s=21

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i don't know how that guy isn't waking up with a horse's head in his bed every day

Soricidus
Oct 21, 2010
freedom-hating statist shill
taviso is an ai. no bed.

pseudorandom name
May 6, 2007

Tavis too busy putting horse heads in everybody else’s beds.

in other news, Rowhammer can be used to read memory and extract secrets

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
and ecc won't save you

https://arstechnica.com/information-technology/2019/06/researchers-use-rowhammer-bitflips-to-steal-2048-bit-crypto-key/

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

ONLY TRUST YOUR PUNCHCARDS

ECC WILL NEVER HELP YOU

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Lutha Mahtin posted:

ONLY TRUST YOUR PUNCHCARDS

ECC WILL NEVER HELP YOU

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

Soricidus posted:

taviso is an ai. no bed.

tavis obviously sleeps in the shower

Kazinsal
Dec 13, 2011

Lutha Mahtin posted:

ONLY TRUST YOUR PUNCHCARDS

ECC WILL NEVER HELP YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


lol ecc makes it 2x worse by leaking a side-channel

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Lutha Mahtin posted:

ONLY TRUST YOUR PUNCHCARDS

ECC WILL NEVER HELP YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

buy hardware from good vendors that ensure TRR is enabled on their memory instead of whitebox specials I guess

quote:

The statement also advises using DRAM that's resistant to Rowhammer attacks. That generally includes using DDR4 chips that offer ECC or a feature known as targeted row refresh. This advice is helpful, but it's not the last word for two reasons. First, RAMBleed can bypass ECC protections. Second targeted row refresh isn't an automatic defense against Rowhammer.

"TRR makes it more difficult to find bit flips," Kwong, the University of Michigan researcher, wrote in an email. "Not all DDR4 has TRR enabled, and implementations vary substantially by vendor, so it is difficult to pinpoint exactly how much safer TRR is against Rowhammer. TRR's susceptibility to RAMBleed is an open research question."

suffix
Jul 27, 2013

Wheeee!
i have a feeling a lot of rowhammer stuff is held because no one knows htf to fix it
like we know it works in javascript and there are still barely any hardware or software mitigations so where are the drive by browser exploits

suffix
Jul 27, 2013

Wheeee!
proposal: ecc ram with a small explosive charge that triggers after a set number of correctable errors
the counter persists after restarts ofc

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

suffix posted:

i have a feeling a lot of rowhammer stuff is held because no one knows htf to fix it
like we know it works in javascript and there are still barely any hardware or software mitigations so where are the drive by browser exploits

browsers mitigated by reducing the resolution on you can achieve with time sampling in javascript to the point that it wasn't possible to execute the attack. You need to be running outside the browser sandbox these days so you can go hog-wild with memory access. Or exploit the lovely JRE that a bunch of people still have installed

Truga
May 4, 2014
Lipstick Apathy
https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

lmao

spankmeister
Jun 15, 2008







Gonna get some good privesc with this.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:eyepop:

Hexyflexy
Sep 2, 2011

asymptotically approaching one

in band communication is a hell of a thing. also, now rewriting many .vimrc, I don't even use the bloody thing any more.

Partycat
Oct 25, 2004

Well if your processors are busted , and your ram is busted - the only winning move is not to play

and outsource your poo poo with a big insurance policy

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BangersInMyKnickers posted:

browsers mitigated by reducing the resolution on you can achieve with time sampling in javascript to the point that it wasn't possible to execute the attack. You need to be running outside the browser sandbox these days so you can go hog-wild with memory access. Or exploit the lovely JRE that a bunch of people still have installed

isn't oracle doing a thing where you can't use the newer versions of the jre for anything on pain of death, oh and btw every previous release ever has critical exploits

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

infernal machines posted:

isn't oracle doing a thing where you can't use the newer versions of the jre for anything on pain of death, oh and btw every previous release ever has critical exploits

It's the Oracle JRE on servers, for end users they dgaf. But they did kill off Java Webstart in latest version, so a net good was done by them imo.

burning swine
May 26, 2004



yeah

however as long as you've made it past jre/jdk 8 the differences between oracle and openjdk are basically nil

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

infernal machines posted:

isn't oracle doing a thing where you can't use the newer versions of the jre for anything on pain of death, oh and btw every previous release ever has critical exploits

as long as you don't click Larry's EULA you're fine. grab an openJDK and you're good

(mods plz namechange to LARRYS EULA CLICKER)

Shame Boy
Mar 2, 2010

Lutha Mahtin posted:

as long as you don't click Larry's EULA you're fine. grab an openJDK and you're good

(mods plz namechange to LARRYS EULA CLICKER)

LARRYS EULAGY

Adbot
ADBOT LOVES YOU

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

infernal machines posted:

isn't oracle doing a thing where you can't use the newer versions of the jre for anything on pain of death, oh and btw every previous release ever has critical exploits

they are up to java 12 but only java 8 will work in a browser (IE 11 is the only java capable browser now)
they still patch java 8 but it is behind an oracle login now

since oracle is incompetent and evil to this day you need ie11, java8 and ActiveX to install vpn software to get at their remote training environment

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply