Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Hugh G. Rectum
Mar 1, 2011

Adbot
ADBOT LOVES YOU

Share Bear
Apr 27, 2004

please update the dns for security.yospos.net thanks

Pinterest Mom
Jun 9, 2009

Segmentation Fault posted:

reddit mods were le? color me shocked

this is a good joke.

BombermanX
Jan 13, 2011

I'm afraid of other people's opinions when they differ from my own. Please do not hurt my feelings.

FCKGW posted:

reddit has a subreddit for buying fake ids
https://www.reddit.com/r/fakeid

yesterday half their mod staff was changed, a bunch of people supposedly got arrested and the mods were probably LE.

the posts are a clusterfuck right now and it's tough to confirm anything but lol @ doing this poo poo out in the open

here's some archival posts from yesterday

http://archive.today/4bjc3
http://archive.today/FADOo
http://archive.today/gZYpJ

This is glorious.

vOv
Feb 8, 2014

[–]MousseNuckle 8 points 38 minutes ago Elite offered me a free ID in exchange for a pic of my real one about two weeks ago. Now my address seems to be flagged by customs. PM me for more info permalinksavereportgive goldreply

Beeftweeter
Jun 28, 2005

OFFICIAL #1 GNOME FAN

vOv posted:

[–]MousseNuckle 8 points 38 minutes ago Elite offered me a free ID in exchange for a pic of my real one about two weeks ago. Now my address seems to be flagged by customs. PM me for more info permalinksavereportgive goldreply

lmao

at first i figured most of the people on there would have been dumb teenagers looking for fake ids so they could get alcohol but now that i think about it it was probably just a bunch of older people (apparently with real ids of their own even) using them for i dont even want to know what

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

vOv posted:

[–]MousseNuckle 8 points 38 minutes ago Elite offered me a free ID in exchange for a pic of my real one about two weeks ago. Now my address seems to be flagged by customs. PM me for more info permalinksavereportgive goldreply

jesus christo

Jewel
May 2, 2009

i pmmed some random reddit user my credit card details and they stole money from me what to heck :eyepop:

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Jewel posted:

i pmmed some random reddit user my credit card details and they stole money from me what to heck :eyepop:

it's like bitcoin but with real money

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Nintendo Kid posted:

your conspiracy theory is that samsung will come back to a tv in 2 years to change the ads and make it upload everything you ever say to the nsa. noted.
lol if u think the firmware has to come from sarnsung themselves instead of the nsa or russian business network or w/e


but yeah

Main Paineframe posted:

why would they bother adding audio sniffing functionality to tvs when you carry around a device with a microphone and network capabilities literally all day long

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

http://www.tentonhammer.com/node/65475

Jewel
May 2, 2009

Saw someone tweet this just a little bit ago:

quote:

logging into a mysql shell prints password to logs.

NICE

:coffeepal:

cinci zoo sniper
Mar 15, 2013




Jewel posted:

Saw someone tweet this just a little bit ago:


:coffeepal:
:vince:

spankmeister
Jun 15, 2008






Jewel posted:

Saw someone tweet this just a little bit ago:


:coffeepal:

depends on how you do it

if you do it like a chump then yeah

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

spankmeister posted:

depends on how you do it

if you do it like a chump then yeah

if there's a chump way that does it there shouldn't be

jre
Sep 2, 2011

To the cloud ?



Jewel posted:

Saw someone tweet this just a little bit ago:


:coffeepal:

What ? do you mean the shell history ?

univbee
Jun 3, 2004




Beeftweeter posted:

lmao

at first i figured most of the people on there would have been dumb teenagers looking for fake ids so they could get alcohol but now that i think about it it was probably just a bunch of older people (apparently with real ids of their own even) using them for i dont even want to know what

actually i can't think of what you could use them for other than underage drinking, since anything else would almost certainly be background checked and they would very quickly find out you're not the real hugh jazz

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

univbee posted:

hugh jazz

Immanuel Percius Freely TYVM

Pinterest Mom
Jun 9, 2009

univbee posted:

actually i can't think of what you could use them for other than underage drinking, since anything else would almost certainly be background checked and they would very quickly find out you're not the real hugh jazz

in some parts of the us, pharmacies limit the amount of certain drugs and things (that contain precursors to meth - cough syrup, nail polish, whatever) that each individual can buy. you have to show photo id, and they keep track of how much everyone buys.

so meth cookers.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
also to give fake info when you trade in your buttcoins tho you wouldnt really need a physical id for that just a photoshopped one

Winkle-Daddy
Mar 10, 2007

Jewel posted:

Saw someone tweet this just a little bit ago:


:coffeepal:

it also shows up in ps if you do it the wrong way. idiot cjs.

Michael Transactions
Nov 11, 2013

gonna hack this panini haha. but no im really hungry! haha

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

https://www.whitehouse.gov

Main Paineframe
Oct 27, 2010

Winkle-Daddy posted:

it also shows up in ps if you do it the wrong way. idiot cjs.

list of circumstances where a program should be outputting the password in plaintext to a log file:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Main Paineframe posted:

list of circumstances where a program should be outputting the password in plaintext to a log file:

do you keep .bash_history turned off or do you just know better than to run 'command --username:root --password:p4ssw0rd!' from the terminal

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
also make sure you turn off sshd logs in case someone accidentally types their password into a username field by accident

Winkle-Daddy
Mar 10, 2007

Main Paineframe posted:

list of circumstances where a program should be outputting the password in plaintext to a log file:

MySQL isn't what's writing the password. Passing the password to MySQL as an argument gets it written to the .bash_history

Winkle-Daddy
Mar 10, 2007
maybe the os should just recognize it looks like a password and not write it to any logs???

spankmeister
Jun 15, 2008






mysql itself at least is smart enough to scrub it from the command environment so you can't see it in ps or /proc

Winkle-Daddy
Mar 10, 2007
You're right! I thought that used to show up
code:
$ ps fauxwww | grep mysql | grep -v grep
+ 15846  0.0  0.0 239896  7328 pts/6    S+   10:39   0:00      |   |   \_ mysql -u root --password=x xxxxxx --host=myhost.com --port=3306

computer toucher
Jan 8, 2012

why the hell would you type your password on the command line when you can mysql -u root -p and then tell it when it asks.

This is not a secfuckup but a user fuckup.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
you know it's because a bunch of people just have shell scripts all over the place with "mysql -u root -p hunter2" in them

Main Paineframe
Oct 27, 2010

anthonypants posted:

do you keep .bash_history turned off or do you just know better than to run 'command --username:root --password:p4ssw0rd!' from the terminal

sorry, i use a real os, not a child's toy

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

daft punk railroad posted:

you know it's because a bunch of people just have shell scripts all over the place with "mysql -u root -p hunter2" in them

you can find plenty of those in github

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
my favorite github security fuckup i've personally found was some french website's repo that used a (non-scrubbed) hardcoded password for the admin panel and also made the password the default contents of the password entry field on the live version of the site

(i'm not going to actually name the site but it seems to be suspended now. i can't imagine why)

e: it was also SQL injection city but that probably goes without saying

Meat Beat Agent fucked around with this message at 19:57 on Feb 13, 2015

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

quote:

Hello Chris Knight

Thank you for registering with TicketBreak.com! Below you will find your username and password which will allow you to purchase tickets with the click of a button.

Your username is: ck@whatever.com
Your password is: ******************

yeah they put the asterisks lmao

EAT THE EGGS RICOLA
May 29, 2008

Chris Knight posted:

yeah they put the asterisks lmao

maybe that's your password tho

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender
There's some guy who uses youtube URLs for his passwords because he can bookmark them and if anyone ever finds them (like if he accidentally pastes one into a chat window) then people will just assume he just accidentally copy/pasted it.

spankmeister
Jun 15, 2008






minato posted:

There's some guy who uses youtube URLs for his passwords because he can bookmark them and if anyone ever finds them (like if he accidentally pastes one into a chat window) then people will just assume he just accidentally copy/pasted it.

that's pretty clever actually

Adbot
ADBOT LOVES YOU

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
brb adding all common youtube urls to my cracking dicts

  • Locked thread