Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Aquarium of Lies
Feb 5, 2005

sad cutie
:justtrans:

she/her
Taco Defender

Storysmith posted:

well that's two reasons not to work there then
unless youre heading up a "get us off of mongo" project

thankfully I'd be in a position to address both issues if I get/take the job

Adbot
ADBOT LOVES YOU

30 TO 50 FERAL HOG
Mar 2, 2005



DuckConference posted:

SA got banned from paypal a long time ago, the bittorrent forums or chargebacks or the katrina donation drive or something I don't really remember anymore.

:thejoke:

Storysmith
Dec 31, 2006

so what's going to be the next security punching bag nosql database

I would bet redis except it would have to actually keep useful data in it long enough for a hacker to connect

ate shit on live tv
Feb 15, 2004

by Azathoth
Paypal is trash for idiots qtiyd

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

ate poo poo on live tv posted:

Paypal is trash for idiots qtiyd

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




:agreed: microsoft hell fucker

spankmeister
Jun 15, 2008






Aquarium of Lies posted:

lol a company I'm interviewing at had an unsecured mongo instance get ransomewared very recently

They got what was coming to them imo

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

spankmeister posted:

They got what was coming to them imo

if you're running mongo you have to assume all your data could just vanish at any point, so it probably wasn't even a big deal

spankmeister
Jun 15, 2008






An acquaintance of mine took a sabattical and scanned the internet for unsecured mongos for 15 hrs a day for a year. He found thousands and did hundreds of disclosures to whomever owned the databases. About half were fixed I think.

I'm not 100% sure but still fairly certain he would have found the same db and disclosed it to the owners.

redleader
Aug 18, 2005

Engage according to operational parameters

Subjunctive posted:

just post your resume here and a steadfast operator will notice it in the database

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


please don't post pictures containing my first and last name without censoring them in mspaint first

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
https://twitter.com/sweatyinbkk/status/819072551687045124

ticketmaster about not using https:

chestnut santabag
Jul 3, 2006


wow their site even redirects you to plain http if you try to use https to access it

Proteus Jones
Feb 28, 2013



That 29,000 mongo database ransom attack? Well, apparently paying ransom isn't getting the key to decrypt.

quote:

Merrigan and Gevers are maintaining a public Google Drive document (read-only) that is tracking the various victims and ransom demands. Merrigan said it appears that at least 29,000 MongoDB databases that were previously published online are now erased. Worse, hardly anyone who’s paid the ransom demands has yet received their files back.

Here's Krebs article:
https://krebsonsecurity.com/2017/01/extortionists-wipe-thousands-of-databases-victims-who-pay-up-get-stiffed/

Here's Google Drive list of victims:
https://docs.google.com/spreadsheets/d/1QonE9oeMOQHVh8heFIyeqrjfKEViL0poLnY8mAakKhM/edit#gid=2122582863

Proteus Jones fucked around with this message at 13:04 on Jan 11, 2017

Truga
May 4, 2014
Lipstick Apathy
and thus begins the fall of ransomware

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Truga posted:

and thus begins the fall of ransomware

alternatively: Here ends ransomware as a way to extract value from idiots with computers, here also starts using ransomware to hamper your competitors. Think industrious espionage but instead of stealing your competitors secrets you lock them away behind a wall of crypto and cyber.

Proteus Jones
Feb 28, 2013



Boiled Water posted:

alternatively: Here ends ransomware as a way to extract value from idiots with computers, here also starts using ransomware to hamper your competitors. Think industrious espionage but instead of stealing your competitors secrets you lock them away behind a wall of crypto and cyber.

Maybe this will also occasion a rise in good backup discipline so companies can rapidly recover from...

:rolleyes:

Sorry. I tried but couldn't keep a straight face.

Workaday Wizard
Oct 23, 2009

by Pragmatica
i don't know any company that backs up workstations lol

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

nothing of value should be lost if a workstation is blown away

Westie
May 30, 2013



Baboon Simulator

Subjunctive posted:

nothing of value should be lost if a workstation is blown away

:agreed:

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Subjunctive posted:

nothing of value should be lost if a workstation is blown away

we had a contractor that lost '3months of work' because she stored everything on the c drive and the machine was reimaged to upgrade to win 7

nothing of value was lost as her work was garbage so they just terminated her contract lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Subjunctive posted:

nothing of value should be lost if a workstation is blown away

Workaday Wizard
Oct 23, 2009

by Pragmatica

Subjunctive posted:

nothing of value should be lost if a workstation is blown away

how much disk quota do your employees have on the file server?

e: not defending saving files locally btw

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shinku ABOOKEN posted:

how much disk quota do your employees have on the file server?

e: not defending saving files locally btw

when last I cared about workstations, dozens of terabytes if they wanted it

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
The mongodb ransomwares aren't working because the dbs are still open to the world after the data is dropped so copycats are rolling in, blowing away the original ransom note and putting in their own, and repeat nine times so there's no way to pay the attacker that actually has your data

In other news, back a while I referenced fears that Russia had access to Telegram, but didn't have much more than speculation to back it up, one thing hidden in the trumppissgate docs is confirmation that yes, Russia has access to Telegram

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
In other Telegram sucks news, nadim going to grad school has done good things

https://twitter.com/kaepora/status/819181464369577984

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
what is trumppissgate?

Fake edit: my phone autocorrected trumppissgate to trumpageddon

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

A Pinball Wizard posted:

what is trumppissgate?

Fake edit: my phone autocorrected trumppissgate to trumpageddon

Look man, if you're gonna do the joose and forget the last three days don't look at us to fill in the details

(Trump likes watching hookers pee on each other, Russia has docs/video on this and other blackmail material, it is the only thing anyone on twitter, TV news, etc has been talking about the last couple days)

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



pr0zac posted:

Look man, if you're gonna do the joose and forget the last three days don't look at us to fill in the details

(Trump likes watching hookers pee on each other, Russia has docs/video on this and other blackmail material, it is the only thing anyone on twitter, TV news, etc has been talking about the last couple days)

news is depressing af lately and I don't blame anyone for avoiding it :\

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



pr0zac posted:

Look man, if you're gonna do the joose and forget the last three days don't look at us to fill in the details

(Trump likes watching hookers pee on each other, Russia has docs/video on this and other blackmail material, it is the only thing anyone on twitter, TV news, etc has been talking about the last couple days)

i think it's less "piss on each other" and more "piss on a bed that obama slept in"

fins
May 31, 2011

Floss Finder
Other nugget in there is

quote:

reported that over the period March-September 2016
a company called XBT/Webzilla and its affiliates had been using botnets
and porn traf?c to transmit viruses, plant hugs, steal data and conduct
?altering operations" against the Democratic Party leadership.

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Munkeymon posted:

news is depressing af lately and I don't blame anyone for avoiding it :\

I haven't actively watched the news since like last spring, for every nugget of real news there was 2 hours of "OBAMA AND HILLARY CONSPIRED TO PAINT THE OVAL OFFICE A SHADE OF GREEN THAT IS USED ON THE ISIS FLAG" or some poo poo. most of the real news filters through from other sources, like in this case, same with twitter

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



fins posted:

Other nugget in there is

plant hugs?

this was copied out of a PDF wasn't it

WrenP-Complete
Jul 27, 2012

Munkeymon posted:

plant hugs?

this was copied out of a PDF wasn't it

Aw, plant hugs. :kimchi:

30 TO 50 FERAL HOG
Mar 2, 2005



Shinku ABOOKEN posted:

how much disk quota do your employees have on the file server?

e: not defending saving files locally btw

the last time i dealt with this was in like 2004, how exactly are roaming profiles handled now that everything is a laptop on the road or in a home office over vpn

spankmeister
Jun 15, 2008






pr0zac posted:

In other news, back a while I referenced fears that Russia had access to Telegram, but didn't have much more than speculation to back it up, one thing hidden in the trumppissgate docs is confirmation that yes, Russia has access to Telegram

Care to elaborate?

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

spankmeister posted:

Care to elaborate?

Sorry, I'm on phone waiting for my wife's car to be fixed thus lack of details.

http://www.theverge.com/2017/1/11/14237136/trump-leak-telegram-security-cracked-russia-encryption

quote:

An FSB [Russian secret service] cyber operative flagged up the ‘Telegram’ enciphered commercial system as having been of especial concern and therefore heavily targeted by the FSB, not least because it was used frequently by Russian internal political activists and oppositionists. His/her understanding was that the FSB now successfully had cracked this communications software and therefore it was no longer secure to use.

Truga
May 4, 2014
Lipstick Apathy
security pissup megathread - much hacking, hacking is bad, shouldn't be done

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
every single one of the claims made against trump is completely unverifiable, and buzzfeed believes that journalism means publishing every claim so that the american people can figure out what's real and what's not by themselves. everything in those highlighted printouts is bullshit, and you would be a humongous gullible idiot for taking any of those claims seriously.

  • Locked thread