Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
trigger warning this poo poo, jesus christ

byte compiled perl dependency hell, it's the closest i ever came to literally walking out the door to work on a farm and raise goats

Adbot
ADBOT LOVES YOU

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
https://twitter.com/mjg59/status/755062671418929152
https://twitter.com/mjg59/status/755064357671755776

edit: oh yeah, he started a patreon to review lovely iot devices for security holes: https://www.patreon.com/mjg59

Mr.Radar fucked around with this message at 17:26 on Jul 18, 2016

bicycle
Oct 23, 2013

yessss

Shaggar
Apr 26, 2006

rad. thanks, Linux.

Shame Boy
Mar 2, 2010

Shaggar posted:

rad. thanks, Linux.

don't worry libupnp runs on wandows too and i'm betting is compiled into lots of cross-platform stuff

Shaggar
Apr 26, 2006
yes it was sarcasm. its linuxes fault that this will affect windows users.

spankmeister
Jun 15, 2008






Shaggar posted:

yes it was sarcasm. its linuxes fault that this will affect windows users.

Thats Our Shaggar! :iamafag:

Shaggar
Apr 26, 2006
also there are bound to be lots of affected linuxes lurking in places innocent users never expect like toasters or fridges

Truga
May 4, 2014
Lipstick Apathy
speaking of fridges, a friend of mine is working on an internet of thing, and today he found out the process of getting said thing connected to your psk wpa2 wifi:
1. install app on phone
2. connect phone to desired wifi, hit "connect" button in said app
3. thing is now connected to wifi.

the trick for this working is: your phone sends random data to your AP that is the exactly correct length, for the duration 802.11 header to spell out your password to the IoT device, prepended by the magic number that signals the start.

you absolutely cannot make this poo poo up

FlapYoJacks
Feb 12, 2009

Truga posted:

speaking of fridges, a friend of mine is working on an internet of thing, and today he found out the process of getting said thing connected to your psk wpa2 wifi:
1. install app on phone
2. connect phone to desired wifi, hit "connect" button in said app
3. thing is now connected to wifi.

the trick for this working is: your phone sends random data to your AP that is the exactly correct length, for the duration 802.11 header to spell out your password to the IoT device, prepended by the magic number that signals the start.

you absolutely cannot make this poo poo up

Jesus loving Christ. Where do these loving idiots come from? My FIRST embedded device was WiFi enabled and I just had it puke out a SSID that you had to connect to and then change the credentials from the web interface. Why is that so hard for these morons to do?

Whenever I see a product say "to setup, download our App" I don't buy it and write it off as dumpster-fire garbage.

Truga
May 4, 2014
Lipstick Apathy
iot poo poo is aimed for the end user, you can't tell them to just connect this box and then log into it and holy poo poo what my brain is melting this other device that does the same thing from the competing company has "install app, everything works"

at least, that's what I think the thinking behind it is. said friend is still in shock

Hunter2 Thompson
Feb 3, 2005

Ramrod XTreme
Yes it's all for "user experience".

There's this wifi camera made by Amcrest that my coworker bought. It does crazy side-channel poo poo to get onto your wifi network too, possibly the same as mentioned above.

Edit: I think this system of connecting to an end-user's home network was created by TI.

fins
May 31, 2011

Floss Finder

meatpotato posted:

Yes it's all for "user experience".

There's this wifi camera made by Amcrest that my coworker bought. It does crazy side-channel poo poo to get onto your wifi network too, possibly the same as mentioned above.

Edit: I think this system of connecting to an end-user's home network was created by TI.


The one I'm familiar with from TI's IoT stuff is SimpleLink, and it certainly doesn't do it this way, although it could be implemented somehow reading raw packets

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Parallel Paraplegic posted:

don't worry libupnp runs on wandows too and i'm betting is compiled into lots of cross-platform stuff

doubt it, windows already has a upnp service

Shaggar
Apr 26, 2006
I think he means like 3rd party junkware like failfox that uses its own busted libs instead of the system

Shame Boy
Mar 2, 2010

hackbunny posted:

doubt it, windows already has a upnp service

I doubt cross platform programs that use libupnp everywhere else are rewritten specifically for Windows. I mean I'm sure a few switch the deps out at compile time but probably not most.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Parallel Paraplegic posted:

I doubt cross platform programs that use libupnp everywhere else are rewritten specifically for Windows. I mean I'm sure a few switch the deps out at compile time but probably not most.

I know little about upnp (it's, like, xml over multicast http, right?), but it sounds like the vulnerability is in the server side of the protocol. being multicast i.e. datagram of course client endpoints can receive packets from anywhere, what I don't know is, do clients expect and process requests?

spankmeister
Jun 15, 2008






Truga posted:

https://httpoxy.org/

Yay, another vuln with a name

Lol this is one and a half years old

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
try again

spankmeister
Jun 15, 2008







:eyepoop:

Proteus Jones
Feb 28, 2013




LOL!

surebet
Jan 10, 2013

avatar
specialist


half secfuck, half need an opinion

we have a remote office that's outside of any domain or network auth, for all intents and purposes it's it infrastructure is completely seperate

we need to print a report over there every morning, so some genius decided to whack the ids & firewall enough times on the head that i let pretty much anything come in on port 9100 straight through the dmz and into an accounting box

we put an end to that poo poo the minute we heard about it

now, the original need is still there, we need to remote print a thing

am i wrong in thinking that a fax is needs suiting here?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


surebet posted:

half secfuck, half need an opinion

we have a remote office that's outside of any domain or network auth, for all intents and purposes it's it infrastructure is completely seperate

we need to print a report over there every morning, so some genius decided to whack the ids & firewall enough times on the head that i let pretty much anything come in on port 9100 straight through the dmz and into an accounting box

we put an end to that poo poo the minute we heard about it

now, the original need is still there, we need to remote print a thing

am i wrong in thinking that a fax is needs suiting here?

is sftp an option?


edit maybe not to inside the dmz

surebet
Jan 10, 2013

avatar
specialist


i'm seriously not finding anything as simple and stupid proof as a fax, especially since all it involves is wrenching a voip line to one of the computer on my end

Shaggar
Apr 26, 2006

surebet posted:

half secfuck, half need an opinion

we have a remote office that's outside of any domain or network auth, for all intents and purposes it's it infrastructure is completely seperate

we need to print a report over there every morning, so some genius decided to whack the ids & firewall enough times on the head that i let pretty much anything come in on port 9100 straight through the dmz and into an accounting box

we put an end to that poo poo the minute we heard about it

now, the original need is still there, we need to remote print a thing

am i wrong in thinking that a fax is needs suiting here?

set up a vpn tunnel and print thru the tunnel

Proteus Jones
Feb 28, 2013



Shaggar posted:

set up a vpn tunnel and print thru the tunnel

Shaggar
Apr 26, 2006
or email the report as a pdf which is probably more useful to them anyway. they can still print it out if they need to

surebet
Jan 10, 2013

avatar
specialist


in most contexts pdf over email would be best, but this needs to print on the production floor, everything is still pen to paper over there

it was routed through accounting because the printer is there

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

surebet posted:

everything is still pen to paper over there

are you sending documents back in time or something?

have you tried a teletype?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shaggar posted:

or email the report as a pdf which is probably more useful to them anyway. they can still print it out if they need to

Hate to say it but this is probably the real solution.

If it has to be raw data to a server, VPN.

surebet
Jan 10, 2013

avatar
specialist


YeOldeButchere posted:

are you sending documents back in time or something?

have you tried a teletype?

faxes are very well and alive in tyool 2016

they've been the bane of my existence, i figure it's time i inflict them on other people

Shaggar
Apr 26, 2006
we still fax a lot of doctors offices cause they cant deal w/ secure transport mechanisms

MiniFoo
Dec 25, 2006

METHAMPHETAMINE

gently caress fax

fux

A Man With A Plan
Mar 29, 2010
Fallen Rib

Shaggar posted:

we still fax a lot of doctors offices cause they cant deal w/ secure transport mechanisms

the funny part is faxes aren't secure either unless you get encrypting fax machines, which your standard commodity devices are not. Oh well!

Shaggar
Apr 26, 2006
yeah they're grandfathered in under hipaa. some larger hospital groups have "banned" their use tho

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
can you not scp the file to a server on the other domain and then set up a cron job to scan for new files and print them automatically?

Notorious b.s.d.
Jan 25, 2003

by Reene

Ur Getting Fatter posted:

can you not scp the file to a server on the other domain and then set up a cron job to scan for new files and print them automatically?

there are two standards for fax-over-ip, t.37 and t.38

you basically just described encrypted t.37

(nobody uses either standand)

Notorious b.s.d.
Jan 25, 2003

by Reene
whoa cool how am i the first person to post the dumbest juniper cve vever

quote:

When a peer device presents a self-signed certificate as its end entity certificate with its issuer name matching one of the valid CA certificates enrolled in Junos, the peer certificate validation is skipped and the peer certificate is treated as valid. This may allow an attacker to generate a specially crafted self-signed certificate and bypass certificate validation.

https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10755&actp=search

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1280

Raluek
Nov 3, 2006

WUT.


same thing, yea?

Adbot
ADBOT LOVES YOU

mod saas
May 4, 2004

Grimey Drawer

Notorious b.s.d. posted:

whoa cool how am i the first person to post the dumbest juniper cve vever

dont quit your b.s.day job

  • Locked thread