Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Westie
May 30, 2013



Baboon Simulator

OSI bean dip posted:

https://srsly.de/

this is unnecessarily cruel and funny

(also don't gently caress with something on here)

srsly

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

OSI bean dip posted:

yeah people don't expose vnc/rdp to the internet

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Captain Foo posted:

SQLi is the most common secfuck there is, c/d

think C buffer overflows win because C has been around since the dinosaurs

Nintendo Kid
Aug 4, 2011

by Smythe

Powercrazy posted:

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

a vpn

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Powercrazy posted:

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

teamviewer or something I reckon

Jewel
May 2, 2009

Powercrazy posted:

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

i mean the thing is if you can do it so can literally anyone else in the world so the best chance you have is to never put the ip anywhere and also use a super strong password via keepass or lastpass or w/e and hope to hell whatever you're using doesn't have an insecurity vOv

I mean the other good option is "why do you need to"

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...



I'm the "lol"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i'm the "what" after finding out there's no apt

Illusive Fuck Man
Jul 5, 2004
RIP John McCain feel better xoxo 💋 🙏
Taco Defender

Powercrazy posted:

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

chrome remote desktop works well enough

jadeddrifter
Feb 18, 2014

uncurable mlady posted:

teamviewer or something I reckon

Teamviewer is the easiest

mogggg
Jul 18, 2012

jadeddrifter posted:

Teamviewer is the easiest

Dynamic DNS + RDP?

jadeddrifter
Feb 18, 2014

mogggg posted:

Dynamic DNS + RDP?

You can access more systems. I guess if you are only accessing one system it is about the same. But I remote to my parents, my sister, some friends to help them with problems. All made very easy with teamviewer

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

mogggg posted:

Dynamic DNS + RDP?
if you're going to open rdp to the internet why bother with dynamic dns? that site from the last page will help you find the computer you were on

Shaggar
Apr 26, 2006
Are there any services that provide 2 factor auth for individual consumers?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

Are there any services that provide 2 factor auth for individual consumers?
google authenticato
r

EMILY BLUNTS
Jan 1, 2005

apparently RSA resellers offer a "starter kit" and then you can give yourself the 10 fobs, cards, and software authenticator licenses :v:

i'm not sure i have the correct info because they say the auth manager vm is free and you just tack on the user licenses??

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Erwin posted:

why isn't it srslydu.de?

i assumed it was going for srsly.die

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
as in what this thread is supposed to do when you touch the poop honeypot

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
the, srsly.the

devtesla
Jan 2, 2012


Grimey Drawer

jadeddrifter posted:

Teamviewer is the easiest

I'm trying to find the lady who men paid to wreck their computers using teamviewer but I can't find them

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

The Devil Tesla posted:

I'm trying to find the lady who men paid to wreck their computers using teamviewer but I can't find them

you can pay me to do it if that helps

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?



(from when Viss did his VNC dump)

Daman
Oct 28, 2011

uncurable mlady posted:

teamviewer or something I reckon

using teamviewer is the same level as using any standard vnc server with a user/password, except now you've gone closed source so you're definitely owned by the NSA

Winkle-Daddy
Mar 10, 2007

Powercrazy posted:

This is good policy of course, but as a home user, what is the best way to get remote access to your desktop? Obviously I don't have a 2 factor RSA services or anything crazy like that.

put a neckbeard approved OS on a little box that runs a vpn server and then vpn before you rdp

you can google up some copy/paste steps.

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

prefect posted:

we'll be fine; all we have to do is get into a boat. they're terrified of boats
nah people in boats get put in a concentration camp

:rip:

Storysmith
Dec 31, 2006

the thing to keep in mind here is that this isn't taking advantage of an exploit, this is literally passwordless vnc

so if you want to not be on that list use literally any password at all

but yeah, leaving the port exposed to the world is suboptimal from a security fuckup perspective, but what we're seeing here is the goddamn biggest fuckup of not even having auth

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Daman posted:

using teamviewer is the same level as using any standard vnc server with a user/password, except now you've gone closed source so you're definitely owned by the NSA
if you're worried about being owned by the nsa why would you install teamviewer on your openbsd desktop

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Storysmith posted:

the thing to keep in mind here is that this isn't taking advantage of an exploit, this is literally passwordless vnc

so if you want to not be on that list use literally any password at all

but yeah, leaving the port exposed to the world is suboptimal from a security fuckup perspective, but what we're seeing here is the goddamn biggest fuckup of not even having auth

there's a password bypass on some vnc servers too if it's old enough

@viss' windows 9x example there is probably a likely candidate for such

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Daman posted:

using teamviewer is the same level as using any standard vnc server with a user/password, except now you've gone closed source so you're definitely owned by the NSA

lol if a TLA is after you OPEN SORES TITEVNC isnt gonna save u

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
yeah, you need to use a safe system like rdp

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
please leave the shaggaring to shaggar

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Shaggar posted:

Are there any services that provide 2 factor auth for individual consumers?

yah google auth. not just for goog.le. my bank uses it too

Jewel
May 2, 2009

anthonypants posted:

please leave the shaggaring to shaggar

got the moves like shaggar

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

IPvSH6T posted:

yah google auth. not just for goog.le. my bank uses it too

no, if I set up RDP at home and want it to use 2FA, what does the server side part of that for me?

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Subjunctive posted:

no, if I set up RDP at home and want it to use 2FA, what does the server side part of that for me?

https://github.com/google/google-authenticator/

the algorithm is public (so you could might be able to find something in a more convenient form for whatever you're doing), but there's a PAM that's pluggable into basically anything that supports that particular format of authentication plugins.

a cyberpunk goose
May 21, 2007

just ssh tunnel?? use pem keys and do 2fa with your OpenLDAP poo poo if you wanna go hyper nerd

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Aleksei Vasiliev posted:

yeah, you need to use a safe system like rdp

nah you see,

Daman posted:

now you've gone closed source so you're definitely owned by the NSA

pseudorandom name
May 6, 2007

Subjunctive posted:

no, if I set up RDP at home and want it to use 2FA, what does the server side part of that for me?

Google Authenticator is just an implementation of the RFC 6238 Time-based One Time Password Algorithm, it doesn't have a server component.

No clue how you make Windows do it, it probably involves giving Microsoft a lot of money.

edit: the answer is ICredentialProvider which is very nearly undocumented

pseudorandom name fucked around with this message at 07:42 on Dec 30, 2014

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


finally done the canary alerts stuff for the page itself. once i can rely on the alerter tool to do its job (trying to get around some quirks) and write some more godawful documentation, i'll be able to update the site

  • Locked thread