Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jre
Sep 2, 2011

To the cloud ?



Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

:drat: son

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

:perfect:

Sharktopus
Aug 9, 2006

notices email server is down
uses rdp to access windows 2000 computer in the closet and restart email server process
"hmm I wonder why calculator.exe was open"

surebet
Jan 10, 2013

avatar
specialist


friend of the boss' friend got hit with a cryptolocker so backup strategy is being re-evaluated today

current strategy: "never back up, hope really hard that nothing hits us ever"

i'm fairly sure i want to write to worm lto but i'm not sure what software is good these days

is there a thing out there à la git that would take an initial snapshot then update changes very frequently? like i'd love having weekly full backups with like hourly-ish change snapshots or whatever, so that every tape has at least a full image.

that would work especially well since we're at a point where we store about 60% of an lto-6 tape, and the remainder would dictate the snapshot freq or whatever

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

COACHS SPORT BAR posted:

Lol this is older but I must have missed it. This was the sandbox escape ormandy discovered in bromium:

https://twitter.com/taviso/status/741063403985240064

holy gently caress that's great

Tatsujin
Apr 26, 2004

:golgo:
EVERYONE EXCEPT THE HOT WOMEN
:golgo:

Chris Knight posted:

holy gently caress that's great

at least they're good sports about it, they paid the bug bounty, tavis donated it to Amnesty International, and they matched the donation.

yoloer420
May 19, 2006

Will you be at unrestcon?

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

lmao

spankmeister
Jun 15, 2008






http://www.bleepingcomputer.com/news/security/the-educrypt-ransomware-tries-to-teach-you-a-lesson/

quote:

A new ransomware (eduware?) called EduCrypt was discovered by AVG security researcher Jakub Kroustek that tries to teach its victims a lesson about ransomware. Like other encrypting malware, EduCrypt will encrypt a victim's files, but instead of demanding a ransom, it gives the victim the password for free along with a reprimand.



:laffo:

Jewel
May 2, 2009

http://www.sciencealert.com/new-algorithm-will-help-make-sure-random-numbers-really-are-random

quote:

Scientists find a way to make computers generate totally random numbers

New algorithm will help make sure random numbers really are random.

:rolleyes:

Shame Boy
Mar 2, 2010


That's adorable :3:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

:allears:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

a++

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

read this as person of color, I think it still works

FlapYoJacks
Feb 12, 2009

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

https://www.sadtrombone.com/?autoplay=true

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/bcarr/status/748193104004452352

uh oh

Shaggar
Apr 26, 2006
works fine for me. someone probably misconfigured some regional dns settings

spankmeister
Jun 15, 2008






did anyone say SYSTEMantec yet?

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

spankmeister posted:

did anyone say SYSTEMantec yet?

you did already like 20 mins ago

Winkle-Daddy
Mar 10, 2007
wheres that one poster who kept demanding "non-academic" examples of anti-virus software loving up big? Because I think today's posts are for him.

Wiggly Wayne DDS
Sep 11, 2010



Winkle-Daddy posted:

wheres that one poster who kept demanding "non-academic" examples of anti-virus software loving up big? Because I think today's posts are for him.
they were shown non-academic examples then, it won't change someone's mind

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Winkle-Daddy posted:

wheres that one poster who kept demanding "non-academic" examples of anti-virus software loving up big? Because I think today's posts are for him.
was it this guy

jre
Sep 2, 2011

To the cloud ?



Who was the yosposter who had a massive meltdown and bought all the red text in that thread ?

bicycle
Oct 23, 2013

Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

fantastic

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

jre posted:

Who was the yosposter who had a massive meltdown and bought all the red text in that thread ?

osi got a gift card and decided to spend all his :10bux: on shaming people

Wiggly Wayne DDS
Sep 11, 2010



ultramiraculous posted:

osi got a gift card and decided to spend all his :10bux: on shaming people
really? i heard it was shaggar

FlapYoJacks
Feb 12, 2009
https://major.io/2013/04/15/seriously-stop-disabling-selinux/

The comments are amazing. :allears:

90% of the comments are: "It's too hard/I don't want to learn it" or "I did something incredibly stupid and SELinux told me no so gently caress SELinux!"

FlapYoJacks fucked around with this message at 21:18 on Jun 29, 2016

jre
Sep 2, 2011

To the cloud ?



SELinux is too complex. I have 100+ servers to manage. Do you think I have the time to set the policy, domain, type and level for a directory tree. Now I have to upgrade 25 servers tonight with a 2 hour maintenance window... If I only had 4 or 6 servers I could do stuff with SELinux.... Honestly, it's too complex for the time + number of systems I manage. It's like having a fleet of cars and I have to fine tune the fuel injection port on each cylinder, change the amperage going into the radio and polish all the windows by hand. Too complex to be useful.

Shame Boy
Mar 2, 2010

Winkle-Daddy posted:

wheres that one poster who kept demanding "non-academic" examples of anti-virus software loving up big? Because I think today's posts are for him.

uhh no this is clearly still an academic vulnerability (by their stupid standard) because it was found by an academic rather than being a zero-day exploited in the wild already :colbert:

jre
Sep 2, 2011

To the cloud ?



That is a loving awesome honey pot for incompetent admins

quote:

You manage 100+ servers and you're not using something like Ansible/Chef/Puppet? I agree SELinux is a huge pain in the arse (and I'm here searching something related) but come on, only you can make your job easier!

quote:

Lots of us have been managing 100's and 100's of Linux system long before Chef/Puppet/etc... and honestly they are no easier to use for an experienced Linux system admin than a couple bash scripts. Plus I don't have to deal with the overhead putting up an entire Ruby stack just to copy a couple freggin public keys.

Besides, what is the point of keeping SELinux enabled if your going to "gem install" a package dependency that does a direct git clone from an unsigned github repository. It's not like you are configuring these systems with security as the primary concern at that point.

My experience, and it just my opinion btw, is that the vast majority of developers who use one of the mentioned tools are generally Apple developers who don't actually know how to do Linux things on Linux systems because they don't actually regularly use the systems they build their software to run on.

Shame Boy
Mar 2, 2010

jre posted:

SELinux is too complex. I have 100+ servers to manage. Do you think I have the time to set the policy, domain, type and level for a directory tree. Now I have to upgrade 25 servers tonight with a 2 hour maintenance window... If I only had 4 or 6 servers I could do stuff with SELinux.... Honestly, it's too complex for the time + number of systems I manage. It's like having a fleet of cars and I have to fine tune the fuel injection port on each cylinder, change the amperage going into the radio and polish all the windows by hand. Too complex to be useful.

think of how much time and money we could save if our drivers never buckled their seatbelts and we remove those pesky airbags!

FlapYoJacks
Feb 12, 2009

quote:

SElinux bites again. Here's what I was talking about above. I get an error message like this:

ERROR: CFG Error in "workdir", line 8: Working directory /var/www/mrtg does not exist

Well, the directory does too exist and I've even made it world-writeable (a bad idea), yet the error persists.

[root@ww2 mail]# ls -l /var/www | grep mrtg
drwxrwxrwx. 2 root web 339968 Nov 6 08:46 mrtg

Based on the above information, you would be justified in thinking you were crazy or something was completely broken. There's nothing in dmesg, /var/log/messages or /var/log/secure that would clue someone in that SElinux was breaking things.

Until the logs start saying "Access denied by SElinux" instead of "directory doesn't exist" SElinux breaks more than it fixes in most situations.

:allears:

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Parallel Paraplegic posted:

think of how much time and money we could save if our drivers never buckled their seatbelts and we remove those pesky airbags!
fortunately, no one commenting is working on anything that could be life threatening and the greater world won't care when your "uber for ___" app shits itself when it's backend servers get cryptolockered

Shame Boy
Mar 2, 2010

quote:

What I can grasp of SElinux: like a house I protect my windows and doors with good locks and keys (IPtables) but SElinux now tags every item in my house and when I move a chair from one room to another I'm no longer allowed to sit in it. So fundamentally SElinux is wrong. If you want a better or safer system, put an extra layer on the outside of your house, or let a daemon like an inti-viral software sweep the system real-time, but please leave the content as is.

we need some combo of :allears: and :stare:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

we need some combo of :allears: and :stare:
maybe :stonklol: or :stwoon:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ratbert90 posted:

https://major.io/2013/04/15/seriously-stop-disabling-selinux/

The comments are amazing. :allears:

90% of the comments are: "It's too hard/I don't want to learn it" or "I did something incredibly stupid and SELinux told me no so gently caress SELinux!"
Honestly, the use of derogatory language in the post is despicable. Just like SELinux... systemd provides most (all?) the functionality of SELinux, but does it an a way that is easily understandable and approachable for most system administrators. In contrast, there are very few people who understand (or even have the time to invest to begin understanding) all of the cryptic and archaic options that SELinux brings to the table.

At the end of the day, SELinux is dying, and will continue to die explicitly because of posts and attitudes like this. While SELinux may provide better security than other options, its difficulty and obscurity for use, and the sanctimonious attitude of the SELinux community will ensure it continuous demise


e: i'm the guy hit-and-run posting the privilege escalation for seandroid

anthonypants fucked around with this message at 21:58 on Jun 29, 2016

FlapYoJacks
Feb 12, 2009

anthonypants posted:

e: i'm the guy hit-and-run posting the privilege escalation for seandroid

Specifically this one?

Anon posted:

Just thought i'd leave this here.

https://github.com/informationextraction/core-android-native

An privilege escalation that uses the selinux software to gain root privs. Have fun.

Major Hayden posted:

On an old version of Android. Using SEAndroid, which is a slightly different implementation.


It's a entire treasure trove of idiots. :allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ultramiraculous posted:

osi got a gift card and decided to spend all his :10bux: on shaming people

nope

also

quote:

I was being way over the top, but again, the loving statement "LOL DON"T RUN AV IT IS INSECURE" is still not an acceptable stance/answer for a good portion of people, and parroting it like the secbros does not change the fact that a bunch of people in this thread still have to have AV to be within whatever compliance standard.

"secbros"

Shame Boy
Mar 2, 2010

oh man someone change the baud dudes gangtags to SECBROS

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
he mad

  • Locked thread