Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

someone's ddos'ing my friends' university's paper submission system which has caused everyone to get two extra days to finish their homework

Adbot
ADBOT LOVES YOU

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
this feels like a weird Rick and Morty ep

"ITS A DDOS PLANET MORTY! SUMMER STOP TRYING TO DDOS ME!"

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

stuxnet was so cool.

the best part was how absolutely none of the other vendors took it seriously for years because "we're not seimens why should we care"

Phone
Jul 30, 2005

親子丼をほしい。
brianna wu has weighed in on the meitu thing ITS A MATTER OF NATIONAL SECURITY

keep challenging state actors to a street fighter 2 battle to the death lol

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

the best part was how absolutely none of the other vendors took it seriously for years because "we're not seimens why should we care"

lol

salted hash browns
Mar 26, 2007
ykrop

ate all the Oreos posted:

I had a friend do this to an air force base once and he got a very scary visit from a super angry military guy within a week

what is going on in that pic?

Shaggar
Apr 26, 2006
my bro was telling me about some of the PLCs at a plant he was managing and he was telling me they have a separate internet connection (DSL, lol) for letting the vendor on to do work. It didn't occur to him that leaving this open all the time was a bad idea cause he didn't realize that theres effectively no security on the PLCs.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ate all the Oreos posted:

someone's ddos'ing my friends' university's paper submission system which has caused everyone to get two extra days to finish their homework

does he go to rutgers lol

salted hash browns posted:

what is going on in that pic?

someone's illegally using their 5GHz on the weather bands

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

my bro was telling me about some of the PLCs at a plant he was managing and he was telling me they have a separate internet connection (DSL, lol) for letting the vendor on to do work. It didn't occur to him that leaving this open all the time was a bad idea cause he didn't realize that theres effectively no security on the PLCs.

the best control I've seen on them that's basically idiot-proof is a turn key on each to put them in program, off, or run mode and it will refuse to accept modifications unless in program mode where it can't execute. I wish more vendors did that, but its seen as a undesirable feature for large-scale deployments where people don't want to walk across the floor to unlock a plc to make changes

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Phone posted:

brianna wu has weighed in on the meitu thing ITS A MATTER OF NATIONAL SECURITY

keep challenging state actors to a street fighter 2 battle to the death lol

brianna who?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

my bro was telling me about some of the PLCs at a plant he was managing and he was telling me they have a separate internet connection (DSL, lol) for letting the vendor on to do work. It didn't occur to him that leaving this open all the time was a bad idea cause he didn't realize that theres effectively no security on the PLCs.

this is far from uncommon

Shame Boy
Mar 2, 2010

Captain Foo posted:

does he go to rutgers lol

nah he lives in the netherlands

Captain Foo posted:

someone's illegally using their 5GHz on the weather bands

yeah in my friends' case they had a point to point link misaligned, so basically a directional antenna pointing right towards a big important radar, on a band that was causing interference

spankmeister
Jun 15, 2008






ate all the Oreos posted:

nah he lives in the netherlands

Which university?

if it's a proper uni they should have internet via the Dutch NREN and those guys have proper DDoS mitigation.

So he's probably at a poo poo-tier one.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

spankmeister posted:

Which university?

if it's a proper uni they should have internet via the Dutch NREN and those guys have proper DDoS mitigation.

So he's probably at a poo poo-tier one.

even then DDoS mitigation can be predicated on the backend actually being able to handle things

like if it's a slow rear end J2EE poo poo with lots of remote stuff and talking to something slow like oracle or mysql you don't need to D your DoS between more than like six attackers that send HTTPS requests

spankmeister
Jun 15, 2008






Cocoa Crispies posted:

even then DDoS mitigation can be predicated on the backend actually being able to handle things

like if it's a slow rear end J2EE poo poo with lots of remote stuff and talking to something slow like oracle or mysql you don't need to D your DoS between more than like six attackers that send HTTPS requests

Yeah an L7 attack could work but they have stuff to deal with that as well.

Raere
Dec 13, 2007

crosspost from jobs thread:

Is there a market for independent PCI or some other standard auditors/assessors? I think I have the skills and I wonder if I can make more than my salaried job securing and auditing :nsa:

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Raere posted:

crosspost from jobs thread:

Is there a market for independent PCI or some other standard auditors/assessors? I think I have the skills and I wonder if I can make more than my salaried job securing and auditing :nsa:

geonetix
Mar 6, 2011


Raere posted:

crosspost from jobs thread:

Is there a market for independent PCI or some other standard auditors/assessors? I think I have the skills and I wonder if I can make more than my salaried job securing and auditing :nsa:

Serious answer: yes. Most actual auditing orgs that I know hire independents to do the actual auditing - barring the largest like KPMG/Deloitte/The rest of the "big 4", who have strange internal structures anyway. Not necessarily PCI, but the ISO ones. I doubt it'd be a lot different for other standards/auditing type of things.

Minor note, this is Europe based. Not sure how it goes wherever you are.

e: oh, yeah, don't underestimate the amount of effort you're going to be putting into getting and keeping yourself certified and accredited; by the way. I'm not assuming anything re your current position, but there's a lot of red tape to get through.

geonetix fucked around with this message at 23:45 on Jan 20, 2017

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

https://lavabit.com/

Lavabit has relaunched after having to shutdown post trolling the fbi by printing it's key super small

yoloer420
May 19, 2006

ate all the Oreos posted:

someone's ddos'ing my friends' university's paper submission system which has caused everyone to get two extra days to finish their homework

Same, but normally the DDoS is just lots of students trying to upload to the bloated Java PoS blackboard which knocks it over.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
http://edition.cnn.com/2017/01/22/travel/united-grounds-domestic-flights-because-of-it-issue/index.html?adkey=bn

quote:

United Airlines grounds domestic flights because of IT issue


not copying the article because there's literally no other useful info

bets on it being

a) cryptolockered servers

b) someone hosed around with that exploit of the booking system that let you change reservations

c) ddos

d) Russian hacking

e) node.js comedy option

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Ur Getting Fatter posted:

http://edition.cnn.com/2017/01/22/travel/united-grounds-domestic-flights-because-of-it-issue/index.html?adkey=bn



not copying the article because there's literally no other useful info

bets on it being

a) cryptolockered servers

b) someone hosed around with that exploit of the booking system that let you change reservations

c) ddos

d) Russian hacking

e) node.js comedy option

https://twitter.com/pr1ntf/status/823322800194666497

Proteus Jones
Feb 28, 2013




From out of nowhere comes Aging and Poorly Maintained Back End Systems for the win!

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Ur Getting Fatter posted:

http://edition.cnn.com/2017/01/22/travel/united-grounds-domestic-flights-because-of-it-issue/index.html?adkey=bn



not copying the article because there's literally no other useful info

bets on it being

a) cryptolockered servers

b) someone hosed around with that exploit of the booking system that let you change reservations

c) ddos

d) Russian hacking

e) node.js comedy option

f) data center caught on fire like delta or whoever's did

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

that's the same system that had issues in October

sysadmins gonna get fired

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy
my latest flight was delayed because they overloaded the plane and we needed to sit there and burn off exactly 140l of fuel.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
eyepyramid update: I'm now 99% sure that the sample I was given is just a download-and-execute and that the real payload is elsewhere. bummer. all it does outside of executing other components downloaded from the c&c is to disable various os and office security features, attempt to kill antivirus software, and open windows firewall

writeup on the string encryption/self-protection hybrid later. man, what a drag

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Fuzzy Mammal posted:

my latest flight was delayed because they overloaded the plane and we needed to sit there and burn off exactly 140l of fuel.

ERROR: TOO MANY MIDWESTERNERS

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Munkeymon posted:

ERROR: TOO MANY MIDWESTERNERS

hahahaha i get it, the passengers were the overloading because they were fat. fat people are awful.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



LeftistMuslimObama posted:

hahahaha i get it, the passengers were the overloading because they were fat. fat people are awful.

well, there's a stereotype people around here do tend to fall into so :shrug:

duTrieux.
Oct 9, 2003

Fuzzy Mammal posted:

my latest flight was delayed because they overloaded the plane and we needed to sit there and burn off exactly 140l of fuel.

i was traveling this week and i noticed a small wheeled tank on the runway labeled "USED FUEL"

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer
i bet it was really someone's big ole donger. some guy on the plane had to buy another seat in which to sling his truly gargantuan and yet somehow tenderly beautiful meat monster and the captain radioed down to the tarmac "houston we have the biggest drat darn ding donger i ever did see were gonna need to burn some fuel so we can get this elegant creature there iykwim"

Bulgakov
Mar 8, 2009


рукописи не горят

LeftistMuslimObama posted:

i bet it was really someone's big ole donger. some guy on the plane had to buy another seat in which to sling his truly gargantuan and yet somehow tenderly beautiful meat monster and the captain radioed down to the tarmac "houston we have the biggest drat darn ding donger i ever did see were gonna need to burn some fuel so we can get this elegant creature there iykwim"

a large wing wanger ding tim dang'er? asking for friends

Shame Boy
Mar 2, 2010

duTrieux. posted:

i was traveling this week and i noticed a small wheeled tank on the runway labeled "USED FUEL"

for sale: used jet fuel, never flown

:smith:

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

ate all the Oreos posted:

for sale: used jet fuel, unable to melt steel beams

:smith:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

fishmech posted:

f) data center caught on fire like delta or whoever's did

g) incompatible update installed to wrong part of the fleet

Jewel
May 2, 2009

:gonk:

http://www.itwire.com/enterprise-solutions/76513-the-great-australian-citizen-28m-active-directory-domain.html

"A Reddit posting says the Australian Government may be looking at Active Directory to authenticate 28 million Australian citizens in a future public-facing website."

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
what could possibly go wrogn?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

What should they use instead? openldap? NIS+?

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Subjunctive posted:

What should they use instead? openldap? NIS+?

a custom handmade implementation designed by 8 different contractors whose only contact with each other is via semaphore flags, you know like all government contracting

  • Locked thread