Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
code:
PATCH NOTES FOR v10.0

* decided that 8 and 9 were bad numbers and skipping to '10' would make us look cooler.
* js crypto added in for the sake of an internet argument

PATCH NOTES FOR v7.69

* Added 1.2 billion passwords from Russian hacker forums

PATCH NOTES FOR v7.2 "BoringSFM"

* The name is aspirational and not yet a promise

PATCH NOTES FOR V1.0.1g

* changed version number

PATCH NOTES FOR V0.9.8

* once again removed LF and Fishmech corruption from the last thread
* added a new feature that enables the mods/admins to go ahead and probate/ban as necessary if LF'n poo poo happens
* added heartbeat feature to non-existent SSL layer on the forums

PATCH NOTES FOR V69

* removed LF and Fishmech corruption from last thread
* new "hello" service for conference attendees
* blocking of js crypto through message relay services like twitter

PATCH NOTES FOR V1.2

* made more efficient for version 1.2 after having removed fishmeching and talk about credit card contracts

PATCH NOTES FOR V1.1

* don't loving use any of these goddamn exploits you dumbshits
join us on irc: irc.synirc.net #yossec

useful news resource for information security professionals: http://reddit.com/r/netsec/

here are some old threads that haven't been archived:
Security Fuckup Megathread - v7.69 (stay safe security ghost) (aug-nov 2014)
Security Fuckup Megathread - v7.2 "BoringSFM" (jun-aug 2014)

Alereon posted:

seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything

Lain Iwakura fucked around with this message at 01:33 on Nov 29, 2014

Adbot
ADBOT LOVES YOU

triple sulk
Sep 17, 2014



:firstpost:

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
sulk's here, thread already compromised

Luigi Thirty
Apr 30, 2006

Emergency confection port.

stay safe security thread

Vicas
Dec 9, 2009

Sweet tricks, mom.

Jonny 290 posted:

sulk's here, thread already compromised

Necc0
Jun 30, 2005

by exmarx
Broken Cake
sooo.... what was that that got the last thread closed?

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

quote:

a bunch of routers with default username + password exposed to the open internet

Peanut and the Gang
Aug 24, 2009

by exmarx
A new thread means another successful hack. Good job everyone! :)

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

I'm actually not the security fuckup that for the old thread closed

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

hey yossec

Necc0
Jun 30, 2005

by exmarx
Broken Cake

oh man i figured it was a video shames thing. yeah that post should be scrubbed :|

Peanut and the Gang posted:

A new thread means another successful hack. Good job everyone! :)

:toot:

Vicas
Dec 9, 2009

Sweet tricks, mom.
v10.0, a very nice choice

Alereon
Feb 6, 2004

Dehumanize yourself and face to Trumpshed
College Slice

Necc0 posted:

oh man i figured it was a video shames thing. yeah that post should be scrubbed :|
yeah i already did. seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything

vOv
Feb 8, 2014

i remember when google was rolling out mandatory ssl i read an op ed about how it might be unethical to force it on people because some dumb reasons. anybody have any idea what i'm talking about

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

vOv posted:

i remember when google was rolling out mandatory ssl i read an op ed about how it might be unethical to force it on people because some dumb reasons. anybody have any idea what i'm talking about

self signed certs

Randel Candygram
Jun 21, 2008

College Slice

Alereon posted:

yeah i already did. seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything

woop my bad. won't happen again

vOv
Feb 8, 2014

Captain Foo posted:

self signed certs

nah this was about them doing mandatory ssl on their own stuff

Alereon
Feb 6, 2004

Dehumanize yourself and face to Trumpshed
College Slice

vOv posted:

i remember when google was rolling out mandatory ssl i read an op ed about how it might be unethical to force it on people because some dumb reasons. anybody have any idea what i'm talking about
Google to Gmail customers: You WILL use HTTPS

quote:

I'm a big believer in offering protections for personal privacy online, but Google's decision to force all Gmail subscribers to use HTTPS encryption goes too far.

vOv
Feb 8, 2014


quote:

Since when is removing consumer choice a good thing? Does Google really know better than you do what your security posture should be for your Gmail accounts? ... In taking this step Google joins the ranks of other dubious "we know what's good for you" initiatives, such as former New York City Mayor Michael Bloomberg's now infamous ban on the sale of large-sized soft drinks in the Big Apple.

lmao jesus christ it's just as dumb as i remembered

DONT THREAD ON ME
Oct 1, 2002

by Nyc_Tattoo
Floss Finder
gonna try to keep up with the security thread this time

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

vOv
Feb 8, 2014


syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Jonny 290 posted:

sulk's here, thread already compromised

Acer Pilot
Feb 17, 2007
put the 'the' in therapist

:dukedog:

anime? mods?

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind


im the dangar

Westie
May 30, 2013



Baboon Simulator

Peanut and the Gang posted:

A new thread means another successful hack. Good job everyone! :)

surprised the thread lasted as long as it did

Peanut and the Gang
Aug 24, 2009

by exmarx
+---------------------------------------------------+
| An impromptu security story: Defeating the hackers. |
+---------------------------------------------------+

Oh no! The hackers are here!




They're stealing our lunch money!


         Gimme ur lunch money, punk!
                        \



     Noo! Noooooo!
          ]



 Ha ha ha! I'm downloading your lunch money as we speak!
                       \



          Somebody, please save us!! Somebody help!
                                       \



Don't worry guys! Linux is here to save the day!


I know how to use iptables to defeat the hackers!
      \




# sudo iptables --policy INPUT DROP



  Now they can't attack us!
        \



                    eff you, hackers!
                           \



Good job linux! you saved the day!



                              Thank you LInux. Thank you computer.
                                     \

Forums Terrorist
Dec 8, 2011

That was a great story. :)

Base Emitter
Apr 1, 2012

?
just noticed a closed thread with 3000+ unread in bookmarks, better get in on the ground floor

Sharktopus
Aug 9, 2006

same

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Forums Terrorist posted:

That was a great story. :)

that post was good as heck

theadder
Dec 30, 2011


cool how did the last one die

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

theadder posted:

cool how did the last one die

it was just a google search that highlighted routers that had default passwords

remember when we used to have whole threads for publicly accessible webcams :allears:

mattrophy
Sep 8, 2014
"Last Christmas" by Wham

Last christmas
you rooted my box
and the very next day
't was spamming away
This year
I give you a stick
A botnet for someone special

Jewel
May 2, 2009

i hope security ghost is safe..

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

can we continue the discussion about why security people tend towards being dicks?

Vicas
Dec 9, 2009

Sweet tricks, mom.

has science gone too far

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Subjunctive posted:

can we continue the discussion about why security people tend towards being dicks?

hey i don't take kindly to people making GBS threads on pr0zac

Vicas
Dec 9, 2009

Sweet tricks, mom.

Jewel posted:

i hope security ghost is safe..

well

he's dead

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



Vicas posted:

well

he's dead

but is he secure? :ohdear:

  • Locked thread