Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

Jonad posted:

if you're talking about 'dingus.com' i'm afraid your name is already on it

no it's not that one, but


:eyepop:

also


NICE!

Adbot
ADBOT LOVES YOU

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
hi tanya!

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://yvrctf.ctfd.io/

we're live if you're interested in playing

a cyberpunk goose
May 21, 2007

how Tanya get domain ???

Bloody
Mar 3, 2013

OSI bean dip posted:

https://yvrctf.ctfd.io/

we're live if you're interested in playing

how does the difficulty of this compare to the difficulty of the yospos crypto challenge

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Bloody posted:

how does the difficulty of this compare to the difficulty of the yospos crypto challenge

depends on your skillset

ahmeni
May 1, 2005

It's one continuous form where hardware and software function in perfect unison, creating a new generation of iPhone that's better by any measure.
Grimey Drawer

OSI bean dip posted:

depends on your skillset

:jerkbag:

pseudorandom name
May 6, 2007

Matthew Garrett @mjg59 · Mar 13
Impressive. Oracle have released a signed kernel that implements none of the features that make a signed kernel in any way worthwhile.

Matthew Garrett @mjg59 · Mar 13
eg, kexec_load() is still enabled

Matthew Garrett @mjg59 · Mar 13
Basically the Oracle Unbreakable Enterprise Kernel is not a kernel that you should let near any Secure Boot systems

Matthew Garrett @mjg59 · Mar 13
The only kernel Oracle supply with any meaningful security is the one that's just a direct copy of the Red Hat kernel source

Matthew Garrett @mjg59 · Mar 13
Both the broken UEK kernel and the good Red Hat clone kernel are signed with the same key

Matthew Garrett @mjg59 · Mar 13
So you can just replace the good kernel with the broken kernel, own the system and then kexec() into a backdoored good kernel

Matthew Garrett @mjg59 · Mar 13
Basically https://blogs.oracle.com/wim/entry/secure_boot_support_with_oracle is loving pointless

Matthew Garrett @mjg59 · Mar 13
.@Oracle delete your signing key

Matthew Garrett @mjg59 · Mar 13
The really fun thing is that Oracle called their signing key "oracle301". Because the RH one ends 301. Because that was its serial number.

Matthew Garrett @mjg59 · Mar 13
Security implemented by running sed without understanding what's actually going on.

Matthew Garrett @mjg59 · Mar 13
Also, only releasing this with 7.1 is kind of admitting "we didn't even try to solve this problem until we could just copy Red Hat"

Matthew Garrett @mjg59 · Mar 13
With respect to the lovely people I know at Oracle: Unbreakable Linux is a bad product and you should feel bad

Matthew Garrett @mjg59 · 27m
Of course my first attempt to download OEL 7.1 ends up with a corrupt ISO

Matthew Garrett @mjg59 · 22m
Deeply impressed to discover that Oracle Linux installs its bootloader in EFI/redhat

Matthew Garrett @mjg59 · 19m
I mean to be fair who would want to install RHEL and Oracle Linux on the same computer anyway

Matthew Garrett @mjg59 · 19m
But how lovely is your sed job of a Linux distribution if you can't even find all the places to sed?

Matthew Garrett @mjg59 · 12m
Booted Oracle Linux 7 on a Secure Boot system, RH-derived kernel has appropriate lockdowns. Installed UEK kernel, rebooted, no lockdowns.

Matthew Garrett @mjg59 · 10m
Describing this as a cargo cult version of a Secure Boot implementation is an insult to actual cargo cults

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

pseudorandom name posted:

Matthew Garrett @mjg59 · Mar 13
Impressive. Oracle have released a signed kernel that implements none of the features that make a signed kernel in any way worthwhile.

Matthew Garrett @mjg59 · Mar 13
eg, kexec_load() is still enabled

Matthew Garrett @mjg59 · Mar 13
Basically the Oracle Unbreakable Enterprise Kernel is not a kernel that you should let near any Secure Boot systems

Matthew Garrett @mjg59 · Mar 13
The only kernel Oracle supply with any meaningful security is the one that's just a direct copy of the Red Hat kernel source

Matthew Garrett @mjg59 · Mar 13
Both the broken UEK kernel and the good Red Hat clone kernel are signed with the same key

Matthew Garrett @mjg59 · Mar 13
So you can just replace the good kernel with the broken kernel, own the system and then kexec() into a backdoored good kernel

Matthew Garrett @mjg59 · Mar 13
Basically https://blogs.oracle.com/wim/entry/secure_boot_support_with_oracle is loving pointless

Matthew Garrett @mjg59 · Mar 13
.@Oracle delete your signing key

Matthew Garrett @mjg59 · Mar 13
The really fun thing is that Oracle called their signing key "oracle301". Because the RH one ends 301. Because that was its serial number.

Matthew Garrett @mjg59 · Mar 13
Security implemented by running sed without understanding what's actually going on.

Matthew Garrett @mjg59 · Mar 13
Also, only releasing this with 7.1 is kind of admitting "we didn't even try to solve this problem until we could just copy Red Hat"

Matthew Garrett @mjg59 · Mar 13
With respect to the lovely people I know at Oracle: Unbreakable Linux is a bad product and you should feel bad

Matthew Garrett @mjg59 · 27m
Of course my first attempt to download OEL 7.1 ends up with a corrupt ISO

Matthew Garrett @mjg59 · 22m
Deeply impressed to discover that Oracle Linux installs its bootloader in EFI/redhat

Matthew Garrett @mjg59 · 19m
I mean to be fair who would want to install RHEL and Oracle Linux on the same computer anyway

Matthew Garrett @mjg59 · 19m
But how lovely is your sed job of a Linux distribution if you can't even find all the places to sed?

Matthew Garrett @mjg59 · 12m
Booted Oracle Linux 7 on a Secure Boot system, RH-derived kernel has appropriate lockdowns. Installed UEK kernel, rebooted, no lockdowns.

Matthew Garrett @mjg59 · 10m
Describing this as a cargo cult version of a Secure Boot implementation is an insult to actual cargo cults

Matt Garrett owns, oracle is lol

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

pseudorandom name posted:

Matthew Garrett @mjg59 · 10m
Describing this as a cargo cult version of a Secure Boot implementation is an insult to actual cargo cults

:vince:

Bloody
Mar 3, 2013

pseudorandom name posted:

Matthew Garrett @mjg59 · Mar 13
Impressive. Oracle have released a signed kernel that implements none of the features that make a signed kernel in any way worthwhile.

Matthew Garrett @mjg59 · Mar 13
eg, kexec_load() is still enabled

Matthew Garrett @mjg59 · Mar 13
Basically the Oracle Unbreakable Enterprise Kernel is not a kernel that you should let near any Secure Boot systems

Matthew Garrett @mjg59 · Mar 13
The only kernel Oracle supply with any meaningful security is the one that's just a direct copy of the Red Hat kernel source

Matthew Garrett @mjg59 · Mar 13
Both the broken UEK kernel and the good Red Hat clone kernel are signed with the same key

Matthew Garrett @mjg59 · Mar 13
So you can just replace the good kernel with the broken kernel, own the system and then kexec() into a backdoored good kernel

Matthew Garrett @mjg59 · Mar 13
Basically https://blogs.oracle.com/wim/entry/secure_boot_support_with_oracle is loving pointless

Matthew Garrett @mjg59 · Mar 13
.@Oracle delete your signing key

Matthew Garrett @mjg59 · Mar 13
The really fun thing is that Oracle called their signing key "oracle301". Because the RH one ends 301. Because that was its serial number.

Matthew Garrett @mjg59 · Mar 13
Security implemented by running sed without understanding what's actually going on.

Matthew Garrett @mjg59 · Mar 13
Also, only releasing this with 7.1 is kind of admitting "we didn't even try to solve this problem until we could just copy Red Hat"

Matthew Garrett @mjg59 · Mar 13
With respect to the lovely people I know at Oracle: Unbreakable Linux is a bad product and you should feel bad

Matthew Garrett @mjg59 · 27m
Of course my first attempt to download OEL 7.1 ends up with a corrupt ISO

Matthew Garrett @mjg59 · 22m
Deeply impressed to discover that Oracle Linux installs its bootloader in EFI/redhat

Matthew Garrett @mjg59 · 19m
I mean to be fair who would want to install RHEL and Oracle Linux on the same computer anyway

Matthew Garrett @mjg59 · 19m
But how lovely is your sed job of a Linux distribution if you can't even find all the places to sed?

Matthew Garrett @mjg59 · 12m
Booted Oracle Linux 7 on a Secure Boot system, RH-derived kernel has appropriate lockdowns. Installed UEK kernel, rebooted, no lockdowns.

Matthew Garrett @mjg59 · 10m
Describing this as a cargo cult version of a Secure Boot implementation is an insult to actual cargo cults

lol

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
The OpenSSL project team would like to announce the forthcoming release
of OpenSSL versions 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf.

These releases will be made available on 19th March. They will fix a
number of security defects. The highest severity defect fixed by these
releases is classified as "high" severity.

OpenSSL Security Policy posted:

high severity issues. This includes issues affecting common configurations which are also likely to be exploitable. Examples include a server DoS, a significant leak of server memory, and remote code execution.

Shame Boy
Mar 2, 2010

now let's see who can be the first to find and exploit them before we actually release the fix, off to the races

Also jfc Oracle :cmon:

Winkle-Daddy
Mar 10, 2007
loving oracle, i hate them so much

also

Shaggar posted:

lol @ people still using scrub teir frameworks and languages.

shaggar is right

JawnV6
Jul 4, 2004

So hot ...

Aleksei Vasiliev posted:

The OpenSSL project team would like to announce the forthcoming release
of OpenSSL versions 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf.
is this the BSD folks who promised to rewrite the entire thing But More Professional

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
the bsd version is libressl, the google version is boringssl

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
some finnish guy figured that he could make a email address "Hostmaster@live.fi"

he was then able to request the domain's certificate from comodo, no questions asked.

microsoft has revoked the certificate and as thanks, they closed the guys microsoft account, locking him out of his email, lumia phone and xbox.

i haven't found an english story yet.

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
apparently he did try to contact the finnish communications regulatory authority and microsoft through several email addresses

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

gently caress oracle and gently caress openssl god drat

EAT THE EGGS RICOLA
May 29, 2008

Wheany posted:

some finnish guy figured that he could make a email address "Hostmaster@live.fi"

he was then able to request the domain's certificate from comodo, no questions asked.

microsoft has revoked the certificate and as thanks, they closed the guys microsoft account, locking him out of his email, lumia phone and xbox.

i haven't found an english story yet.

http://arstechnica.com/security/2015/03/man-who-obtained-windows-live-cert-said-his-warnings-went-unanswered/

quote:

"I noticed the other day that Microsoft's new e-mail service allows to make a number of aliases, or alternate email addresses to the same account," he says. "I tried, just for fun, I could create a similar domain [unintelligible translation] address."

Surprisingly, the account was created successfully. Thus inspired, he decided to try the registrars of data security. Despite the suspicions of the man managed to ask Comodo certificate without any queries.

According to him, the vulnerability was revealed in January. He immediately informed the Finnish Communications Regulatory Authority, but did not get a proper solution to the problem of assistance.

After this, he informed Microsoft to multiple recipients, but none of the company did not respond to queries.

Finally, last week Thursday, the company suddenly announced his frozen Live.fi e-mail address, and as a result, inter alia, the Lumia phone, Xbox account and e-mail going out of business.

lol

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://colin.keigher.ca/2010/04/who-letting-me-become-ssladmin.html

been there done that

(it was lol as gently caress when i did it)

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Wheany posted:

apparently he did try to contact the finnish communications regulatory authority and microsoft through several email addresses

unfortunately he only ever got through to other bozos who'd managed to snag reserved localparts

(my employers list of reserved usernames is over 30k entries long after someone managed to have quite a lot of fun with addresses like biIIing@)

duTrieux.
Oct 9, 2003

goddamnedtwisto posted:

unfortunately he only ever got through to other bozos who'd managed to snag reserved localparts

(my employers list of reserved usernames is over 30k entries long after someone managed to have quite a lot of fun with addresses like biIIing@)

lol please tell me that list was manually built by some poor fuckign intern

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

duTrieux. posted:

lol please tell me that list was manually built by some poor fuckign intern

it was a committee

there were conference calls

so many conference calls

(i think the actual list decided on was only about 200 long, then they had a script to cover all the likely typos and intentional deceptions, plus they added in all the names from the staff directory and a bunch of other names associated with the company because the coprorate and customer domain names are so similar)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i should dig up that private key i had for ovi.com, nokia's failed attempt at an app store environment for symbian

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

OSI bean dip posted:

i should dig up that private key i had for ovi.com, nokia's failed attempt at an app store environment for symbian

:rip: nokia, you had the best phones and this shittest os(es)

now you have poo poo phones on a poo poo os and even your new corporate overlords love your competitors more than you

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

goddamnedtwisto posted:

unfortunately he only ever got through to other bozos who'd managed to snag reserved localparts

(my employers list of reserved usernames is over 30k entries long after someone managed to have quite a lot of fun with addresses like biIIing@)

biIIing upy our rear end

JawnV6
Jul 4, 2004

So hot ...
4cc0unts_r3c31vabl3

mod saas
May 4, 2004

Grimey Drawer
biIIing and its done

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

JawnV6 posted:

4cc0unts_r3c31vabl3

kornfeld in the hizzy

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

Chris Knight posted:

kornfeld in the hizzy

EAT THE EGGS RICOLA
May 29, 2008

I just gave someone an API Key with write access to my service and they also went and just posted it publicly. This is the second time this has happened in a couple months.

Deacon of Delicious
Aug 20, 2007

I bet the twist ending is Dracula's dick-babies
hmm. i would recommend not doing that again

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

EAT THE EGGS RICOLA posted:

I just gave someone an API Key with write access to my service and they also went and just posted it publicly. This is the second time this has happened in a couple months.

tell their boss

EAT THE EGGS RICOLA
May 29, 2008

ChickenOfTomorrow posted:

tell their boss

They cc'ed their boss on the email sending everyone a link to the API key.

duTrieux.
Oct 9, 2003

EAT THE EGGS RICOLA posted:

They cc'ed their boss on the email sending everyone a link to the API key.

did you follow up to that thread announcing the revocation of said key

Mr. Nice!
Oct 13, 2005

bone shaking.
soul baking.

duTrieux. posted:

did you follow up to that thread announcing the revocation of said key

EAT THE EGGS RICOLA
May 29, 2008

duTrieux. posted:

did you follow up to that thread announcing the revocation of said key

Yes, yes I did.

Broken Machine
Oct 22, 2010

Here's my private GPG key for sending encrypted e-mail (as me).

Adbot
ADBOT LOVES YOU

duTrieux.
Oct 9, 2003


Good man.

  • Locked thread