Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

surebet posted:

the partner vaguely hinted that they could add support for the missing feature for an additional cost. rummaging through some more with ida i can see that the code to subscribe us to stuff is in there, but it's just not enabled.

Have you ever heard of Feature Flags?

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

pseudorandom name posted:

berth certificates, duh.

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

yeah an old toolset is likely - why expose a fresh set from an active hostile actor? the auction part is very fishy, nothing around this you'd want connected to someone financially. maybe they never intend to actually sell it just to send a message, which makes some sense for another actor

Yeah agreed the whole auction thing is very fishy. I'm fairly sure that some other nation is behind this.

bicycle
Oct 23, 2013
Looks like the github has been taken down but the tumblr is still up

https://theshadowbrokers.tumblr.com/

Really interested to see if this is bullshit or not

Daman
Oct 28, 2011
so I know the US govt names poo poo random junk like this, but do other countries? did some dev server for the NSA actually get pwned? loving hilarious

Trabisnikof
Dec 24, 2005

Could they have just used the :nsa: ANT catalog to make the sample? There are certainly a few matches between the two....

bicycle
Oct 23, 2013
https://twitter.com/riskbased/status/765243212843790336

lol/yikes if true

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
if its fake then someones put an absolutely insane amount of effort into making all this

Trabisnikof
Dec 24, 2005

Nah gently caress it my money is now that Digital Network Technologies got owned

They make BANANAGLEE so it makes sense

cinci zoo sniper
Mar 15, 2013




callback as in it does leak info to dod or from dod

Wiggly Wayne DDS
Sep 11, 2010



Daman posted:

so I know the US govt names poo poo random junk like this, but do other countries? did some dev server for the NSA actually get pwned? loving hilarious
more like a pivot box they used elsewhere got popped, then whoever did that found a pattern and captured a bunch more boxes expanding the compromised toolset

toolset is too varied to be from a single box. the tools are infrastructure-specific but are far too specific e.g. topsecos. you'd only put tools like that on an untrusted device if you were sure it existed on the other end to attack

there's interesting parts to their documentation such as:
https://twitter.com/tristanc/status/765194943258365954





want to see the crypto in their tools analysed as well

kalstrams posted:

callback as in it does leak info to dod or from dod
well it'd be to the ip to say it's an active device - then again i'd wager it's a placeholder ip given the pattern, really dumb to fix it on a range directly tied to your org either way

Trabisnikof
Dec 24, 2005

I'd be curious if the SECONDDATE client is entirely boring



also NIGHTHUNTER is a newly public codename afaik

Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror
let's all kick in some bitcoins and buy the nsa dump massdrop-style

Wiggly Wayne DDS
Sep 11, 2010



best breakdown so far: https://www.riskbasedsecurity.com/2016/08/the-shadow-brokers-lifting-the-shadows-of-the-nsas-equation-group/

spankmeister
Jun 15, 2008






Rufus Ping posted:

if its fake then someones put an absolutely insane amount of effort into making all this

yeah massive amounts of work, although might be worth it for heaps and heaps of bitcoin? probably not


one thing that i noticed is the level of english proficiency is very different between their announcement and the files, so that may be a clue

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
the english proficiency is so stilted in the announcement that it feels deliberate

spankmeister
Jun 15, 2008






Bhodi posted:

the english proficiency is so stilted in the announcement that it feels deliberate

yeah right?

AWWNAW
Dec 30, 2008

if i'd made off with all that and wanted to write anything non-trivial about it, I sure wouldn't use my default writing voice

spankmeister
Jun 15, 2008







also 30.40.50.60... obviously a poorly chosen placeholder ip

bicycle
Oct 23, 2013

spankmeister posted:

also 30.40.50.60... obviously a poorly chosen placeholder ip

Agreed on this one.

some seem too coincidental to be true though. some of the following are DoD, UK mod, etc.

quote:

Edit: actually im scared of breaking thread rules, grep the dump for "my_ret_addr_snmp"

but then again, as posted before, why callback to a gov/associated org ip?

bicycle fucked around with this message at 21:17 on Aug 15, 2016

surebet
Jan 10, 2013

avatar
specialist


auction not going so well for now
https://blockchain.info/address/19BY2XCgbDe6WtTVbTyzM9eR3LYr6VitWK

surebet
Jan 10, 2013

avatar
specialist


Volmarias posted:

Have you ever heard of Feature Flags?

i wouldn't mind all of the upselling if they actually were clear with their intent, and i take offence to the fact that they keep referring to activating a feature as ~bespoke artisan integration~

spankmeister
Jun 15, 2008






who's gonna bid .219 butts?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


surebet posted:

i wouldn't mind all of the upselling if they actually were clear with their intent, and i take offence to the fact that they keep referring to activating a feature as ~bespoke artisan integration~

lol if your config files aren't all ~~~bespoke~~~~

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Powerful Two-Hander posted:

lol if your config files aren't all ~~~bespoke~~~~

i used to have a 3.5" floppy called das boot

my config.sys and command.com met all my doom playing needs

(jeez it took me hours to figure out what i could trim and what i needed without any internet help)

spankmeister
Jun 15, 2008






does anyone use let's encrypt with a custom csr (to use your own private key for hpkp purposes) and have auto renew working? If i use the --csr option then it just dumps the cert in the current directory and it doesn't do the nice symlinks in /etc/letsencrypt

I could script around it but I think the client should be able to handle this use case?

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

syscall girl posted:

i used to have a 3.5" floppy called das boot

my config.sys and command.com met all my doom playing needs

(jeez it took me hours to figure out what i could trim and what i needed without any internet help)

fe:

autoexec.bat not command.com derr

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Bhodi posted:

the english proficiency is so stilted in the announcement that it feels deliberate

i was thinking about this earlier, it reads like they're writing from the voice of a parody of a chinese-american person

ate shit on live tv
Feb 15, 2004

by Azathoth

syscall girl posted:

i used to have a 3.5" floppy called das boot

my config.sys and command.com met all my doom playing needs

(jeez it took me hours to figure out what i could trim and what i needed without any internet help)

I actually read the DOS manual about what all those system files actually did, as well as which options I should use. himem.sys and emm386 were pretty much all you needed it turns out.

spankmeister
Jun 15, 2008






DEVICEHIGH C:\DOS\VAPE.SYS
LOADHIGH C:\DOS\WEED.EXE

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Powercrazy posted:

I actually read the DOS manual about what all those system files actually did, as well as which options I should use. himem.sys and emm386 were pretty much all you needed it turns out.

it depended on if you had enough hdd or you had to run off of a cd

myst and t7g you needed to have cdrom.sys

i actually mailed a request to the makers of the seventh guest so they could mail me back a graphics driver update

and they did it :3:

Diva Cupcake
Aug 15, 2005

lol what bitches

https://twitter.com/wikileaks/status/765342384821534722

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Powercrazy posted:

I actually read the DOS manual about what all those system files actually did, as well as which options I should use. himem.sys and emm386 were pretty much all you needed it turns out.

DOS=HIGH,UMB

Crusader
Apr 11, 2002




anyway, would suck if this is the start of a NSA vs. GRU hackathon

Trabisnikof
Dec 24, 2005


Lol what. that's such a joke

Celexi
Nov 25, 2006

Slava Ukraini!

:dogbutton:

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

pseudorandom name posted:

berth certificates, duh.

signed by the port authority

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

julian assange is currently trying to figure out how to make sure metasploit stops identifying itself as "metasploit"

apseudonym
Feb 25, 2011


Christ WikiLeaks is awful

Adbot
ADBOT LOVES YOU

duTrieux.
Oct 9, 2003

apseudonym posted:

Christ WikiLeaks is awful

  • Locked thread