Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

this should be probatable
imho if they didn't want a probe they wouldn't have posted the ip address of their server to the secfuck thread

Adbot
ADBOT LOVES YOU

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
tbf you'd think windows users are pretty fine with randomly having ads appear in something that used to just work fine without them

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

anthonypants posted:

imho if they didn't want a probe they wouldn't have posted the ip address of their server to the secfuck thread

YOUR IP ADDRESS MAY BE LEAKING

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

negromancer posted:

if you don't think mobaxterm isn't leaps and bounds ahead of fuckin putty, I don't know what to tell you.

Wheany posted:

that does look good, but i don't feel like paying over $50 per year(?) to replace putty (and to a lesser extent, winscp)

:confused:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

You could always compile it yourself: http://download.mobatek.net/sources/

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

No it doesn't.

You are right. It is 12 sessions and I am limited to two SSH tunnels. It is a terrible SSH client otherwise.

negromancer
Aug 20, 2014

by FactsAreUseless
If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

Shame Boy
Mar 2, 2010

negromancer posted:

If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

look at this noob who doesn't have 80 different terminals showing completely worthless but cool-looking stats at all times

negromancer
Aug 20, 2014

by FactsAreUseless
I have VMs for that there, good sir.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

it's the ssh tunnels that kill me more than the 12 sessions

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

negromancer posted:

If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

i thought that it meant that you can only have 12 saved sessions, not 12 sessions open at the same time.

negromancer
Aug 20, 2014

by FactsAreUseless

Wheany posted:

i thought that it meant that you can only have 12 saved sessions, not 12 sessions open at the same time.

that's what it means, but I'm letting him have his fun. I've had more than 20 sessions open at once on the free version before.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
enough chat about garbage ssh clients

https://www.assetstore.unity3d.com/en/#!/content/27938
https://www.gofundme.com/buy-secure-http-without-https

:psyduck:

FlapYoJacks
Feb 12, 2009

Wait what? Why would anybody want this?

Shame Boy
Mar 2, 2010

ratbert90 posted:

Wait what? Why would anybody want this?

because the $1 a month shared hosting I bought for my vidyagame server doesn't support HTTPS

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.semographics.com/smaes/

quote:

Your plain URL text.

code:
http://www.yourdomain.com/smaes/test_get.php?returnval=Secure_HTTP_without_HTTPS!
Encrypted URL text with "Secure HTTP without HTTPS"
(you may use SMUtil.encryptURL(str) in client.)

code:
http://www.yourdomain.com/smaes/test_get.php?deviceid=4b46360202cfc0bb2c9924c5f0441cf4c2593131&returnval=LNzFB2E5cDj26AnYpbAHywucM0U/dfte+oytIMCfuGE=$&returnval_PC=3A4pJwrOgL4Aw2welnT7NE51HO4TqSsVxPyPWIXQ4oM=$


Server accepts the request and sends the result encrypted text.

code:
LNzFB2E5cDj26AnYpbAHywucM0U/dfte+oytIMCfuGE=$
Decrypted result text in Client
(You may use SMAES.decryptIf(str) in client)

Secure_HTTP_without_HTTPS!

:psypop:

Westie
May 30, 2013



Baboon Simulator

anthonypants posted:

imho if they didn't want a probe they wouldn't have posted the ip address of their server to the secfuck thread

it's a vm on my own personal server - don't have anything i can gently caress about with at work that i'm sure won't affect anything else

MononcQc
May 29, 2007


haha holy poo poo here's the signing to prevent tampering:

quote:

If you don’t have hash (md5) module in php


Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
wasn't there some thing about the filezilla guy being an absolute rear end in a top hat for not patching known, ancient, bugs or some poo poo about him being stupidly arrogant?

MononcQc
May 29, 2007

there was the opencart guy

https://github.com/opencart/opencart/issues/1534
https://github.com/opencart/opencart/issues/1269

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
the filezilla guy was very aggressively okay with adware being snuck into the installer, iirc

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Migishu posted:

wasn't there some thing about the [any oss project] guy being an absolute rear end in a top hat for not patching known, ancient, bugs or some poo poo about him being stupidly arrogant?

anyway he has an apk

http://www.semographics.com/smaes_webplayer/secure_http.apk

if i had time i'd probably tear it apart

too bad nothing seems to use it on github

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

MononcQc posted:

haha holy poo poo here's the signing to prevent tampering:
they call hash an optional module, but mcrypt is required!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
by default it looks like the /smaes/test_console.php file is visible to the world, which is a log of everything his php thing is doing

in fact, that's the way he's got it set up on his website. and if you visit any of the php sites in this screenshot


you'll see your ip address show up here http://www.semographics.com/smaes/test_console.php

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
Wait. Are you saying my computer is broadcasting an IP address???

Thanks Ants
May 21, 2004

#essereFerrari


:psyduck:

there's reinventing the wheel and then there's this

spankmeister
Jun 15, 2008






Migishu posted:

wasn't there some thing about the filezilla guy being an absolute rear end in a top hat for not patching known, ancient, bugs or some poo poo about him being stupidly arrogant?

at some point he removed support for a deprecated protocol thing that a significant portion of the servers still needed. His answer was "The servers should just follow spec". He could have just made a configuration option, but no.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
http://www.csoonline.com/article/3155397/security/esea-hacked-1-5-million-records-leaked-after-alleged-failed-extortion-attempt.html oops

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
https://twitter.com/alt_kia/status/818609521928998912

:madmax:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

:agreed:

hobbesmaster
Jan 28, 2008


embedded device security: now on desktops!

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

lol i used to use that site

it didn't used to have ssl on any pages (not even login) except for a self-signed cert, and you had to manually use https because it didn't redirect

i posted about it and was like "hey this is hosed up, if a bunch of people from ESEA go to a LAN they could get their credentials stolen"

a bunch of people responded like "lol u dont know anything" and "what does it matter they don't store payment info"

bunch of dipshits on there

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
also today i found out that chrome "supports" ECC certs in that i was able to install one for nginx but no combination of ssl_protocol and ssl_ciphers statements made it work

cool internet

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

abraham linkedin posted:

lol i used to use that site

it didn't used to have ssl on any pages (not even login) except for a self-signed cert, and you had to manually use https because it didn't redirect

i posted about it and was like "hey this is hosed up, if a bunch of people from ESEA go to a LAN they could get their credentials stolen"

a bunch of people responded like "lol u dont know anything" and "what does it matter they don't store payment info"

bunch of dipshits on there
the esea was the one with a secret bitcoin miner in the client so i don't feel too bad for them

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

anthonypants posted:

the esea was the one with a secret bitcoin miner in the client so i don't feel too bad for them

i remember that one

iirc there story was "we put a secret bitcoin miner in the client that we only used for testing, and then a rogue employee turned it on for everyone", which didn't exactly inspire confidence

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

the esea was the one with a secret bitcoin miner in the client so i don't feel too bad for them

honestly it's loving hilarious they got popped

the russians can have the password i don't use on anything and the email address i'm rapidly phasing out because it's on a domain i never use anymore

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

quote:

Update:


In an emailed statement, a spokesperson for ESL Gaming (parent company to Turtle Entertainment) confirmed that the hacker did in fact attempt to extort money, but the sum demanded was "substantially higher" than the $50,000 previously mentioned.

quote:

Update 2:


In an official statement posted to their website, ESEA says that the hacker demanded a $100,000 ransom.

vOv
Feb 8, 2014


jtag over usb? what the actual hell

Adbot
ADBOT LOVES YOU

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

ate all the Oreos posted:

because the $1 a month shared hosting I bought for my vidyagame server doesn't support HTTPS

my vps cost 1.29 USD a month

  • Locked thread