Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
hrm i wonder if shaggar has strong feelings about $usStandard versus $metricStandard and whihc side he comes down on????

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://www.youtube.com/watch?v=FUyaItsRInQ

Raere
Dec 13, 2007


Great marketing, they've actually made me less likely to buy their product now

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
that was aggressively terrible

Midjack
Dec 24, 2007



uncurable mlady posted:

that was aggressively terrible

edit: i'm the guy in the rabbit mask who immediately takes it off and walks away at the end

Midjack fucked around with this message at 02:10 on Jan 30, 2017

Proteus Jones
Feb 28, 2013




Holy poo poo that's bad.

Thinking about sending this to a coworker who has a meeting with one of their engineers next week and ask him to add this to the agenda.

big shtick energy
May 27, 2004


sec fuckup: some guy making six figgies at home manipulates the market, contributes to or maybe causes the flash crash, tells investigators to kiss his rear end, keeps doing it for five more years
https://www.bloomberg.com/view/articles/2015-04-21/guy-trading-at-home-caused-the-flash-crash

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/whitequark/status/825944162180677633

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
eight contiguous blocks: 7022-7940, 7973-7975, 7983-7986, 7992-7993, 8574-8575, 5202-5205, 5341-5342, 5482-5486

what the hell

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
did they add one cve for every time a vulnerable function was called in their code or something, wtf

spankmeister
Jun 15, 2008







I didn't know tcpdump was an adobe product.

Pollyzoid
Nov 2, 2010

GRUUAGH you say?
just a big pile of buffer overflows (and one integer overflow)

https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1494526.html

flakeloaf
Feb 26, 2003

Still better than android clock

Wild EEPROM posted:

And don't even get me started on intel's cpu naming scheme

got nothin on video cards

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Pollyzoid posted:

just a big pile of buffer overflows (and one integer overflow)

https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1494526.html

tcpdump/wireshart are just big piles of vulnerable, since their goal is to be able to decrypt all the protocols

attack/defense CTF players like to find new 0-days before games to crash opponents

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Cocoa Crispies posted:

tcpdump/wireshart are just big piles of vulnerable, since their goal is to be able to decrypt all the protocols

a rust port of tcpdump would be a life's work, but so much nicer

tcpdump is of course usually run as root

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



DuckConference posted:

sec fuckup: some guy making six figgies at home manipulates the market, contributes to or maybe causes the flash crash, tells investigators to kiss his rear end, keeps doing it for five more years
https://www.bloomberg.com/view/articles/2015-04-21/guy-trading-at-home-caused-the-flash-crash

the fuckup is programming computers that touch money to make the same panicky iditotic decisions that people make but faster and then blaming it on some random guy

flakeloaf
Feb 26, 2003

Still better than android clock

quote:

You have been selected for the [four-day] McAfee Policy Ochestrator administrator course

it's me, i'm the secfuck

Jewel
May 2, 2009

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852751

cryptkeeper set all passwords to the character 'p' (and your original password no longer worked) because encfs changed the way the stdin bridge was parsed

fins
May 31, 2011

Floss Finder
Not really a secfuck, (unless you are running your scada system from Pokemon Stadium somehow), but an interesting read nonetheless:
https://github.com/MrCheeze/pokestadium-ace

Shame Boy
Mar 2, 2010

fins posted:

Not really a secfuck, (unless you are running your scada system from Pokemon Stadium somehow), but an interesting read nonetheless:
https://github.com/MrCheeze/pokestadium-ace

im unknown_but_usually_89

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Midjack posted:

edit: i'm the guy in the rabbit mask who immediately takes it off and walks away at the end

i too enjoyed Donnie Darko

Shame Boy
Mar 2, 2010

Internet Famous SA goons slowbeef & diabeetus have found a fun new security kickstarter:

https://www.youtube.com/watch?v=xcIwCbvmxsU

flakeloaf
Feb 26, 2003

Still better than android clock

i'm seriously not sure if that's a real thing or an attempt to be funny or both

Shame Boy
Mar 2, 2010

flakeloaf posted:

i'm seriously not sure if that's a real thing or an attempt to be funny or both

i'm pretty sure it's a real thing, i mean they even showed the arduino prototype!!!

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

ate all the Oreos posted:

Internet Famous SA goons slowbeef & diabeetus have found a fun new security kickstarter:

https://www.youtube.com/watch?v=xcIwCbvmxsU

wow, I thought it would be something like the USB condom except it enables the data pins when a passcode is entered, which would be a somewhat useful thing, but this is so much dumber

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ymgve posted:

wow, I thought it would be something like the USB condom except it enables the data pins when a passcode is entered, which would be a somewhat useful thing, but this is so much dumber

yeah really

i have a micro-usb cable from i think google's gift bag at enigma 2016 that you can toggle between power only and data (although i've forgotten which is which)

be kinda slick except no devices of value support micro usb

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this needs to be on security snake oil

Wiggly Wayne DDS
Sep 11, 2010



ate all the Oreos posted:

Internet Famous SA goons slowbeef & diabeetus have found a fun new security kickstarter:

https://www.youtube.com/watch?v=xcIwCbvmxsU
may 2017? just in time for yosmas

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Wiggly Wayne DDS posted:

may 2017? just in time for yosmas

not once you add in kicksharter delays

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cocoa Crispies posted:

not once you add in kicksharter delays

six months of saying it's coming
four months of delays
four months of delays with promises that it'll come next month
two months of photos while still delaying with promises of it coming within six weeks
200 units shipped in one month while 15,000 units promised still pending
7,000 units shipped across three months
remaining units never shipped or produced and the founders run off citing that a business partner squandered the money

Wiggly Wayne DDS
Sep 11, 2010



perfect for yosmas.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

OSI bean dip posted:

six months of saying it's coming
four months of delays
four months of delays with promises that it'll come next month
two months of photos while still delaying with promises of it coming within six weeks
200 units shipped in one month while 15,000 units promised still pending
7,000 units shipped across three months
remaining units never shipped or produced and the founders run off citing that a business partner squandered the money

i'd say a bonus every quarter qirex-style but they probably won't have the foresight to first move ks funds to the caymans and then wait until knockoffs show up on aoliexpress

flakeloaf
Feb 26, 2003

Still better than android clock

yes, "knockoffs"

Trabisnikof
Dec 24, 2005

DC police had their CCTV system knocked offline for 4 days due to ransomware:

quote:

Networked digital video recorders have been harnessed for all sorts of ill intent over the past few months, including use in a botnet that disrupted large swaths of the Internet. But a different sort of malware hit the DVRs used by the District of Columbia’s closed-circuit television (CCTV) surveillance system just one week before Inauguration Day. The Washington Post reports that 70 percent of the DVR systems used by the surveillance network were infected with ransomware, rendering them inoperable for four days and crippling the city’s ability to monitor public spaces.

The CCTV system, operated by the District’s Metropolitan Police Department and supported by the DC Office of the Technology Officer (OCTO), began to be affected on January 12. Police noticed they could not access video from four DVRs. Washington DC Chief Technology Officer Archana Vemulapalli told the Post that two forms of malware were found on the four systems, and a system-wide sweep discovered additional DVR clusters that were infected.

The infections were limited to the local networks that the DVRs ran on, and this ransomware did not extend to the District’s internal networks. While the investigation is ongoing, the malware likely was able to take over the systems because each site was connected to the public Internet for remote access. Vemulapalli told the paper no ransom was paid and the system was restored to full functionality before Inauguration Day.

https://arstechnica.com/security/2017/01/dc-police-surveillance-cameras-were-infected-with-ransomware-before-inauguration/

invision
Mar 2, 2009

I DIDN'T GET ENOUGH RAPE LAST TIME, MAY I HAVE SOME MORE?

Pollyzoid posted:

just a big pile of buffer overflows (and one integer overflow)

https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1494526.html

Anyone seen a PoC for any of these yet?

Fuzzy Mammal
Aug 15, 2001

Lipstick Apathy

quote:

As captured in our private mail exchange last week, Symantec's report fails
to meaningfully address each or any of the questions I raised. Google
considers it of utmost urgency that Symantec share the answers to these
questions, posed a week ago, and based on Symantec's multiple public
statements regarding the previous misissuance. Please confirm your receipt
of these questions and your intent to provide an answer to the community by
end of day, so that we can consider Symantec's answers when considering
appropriate next steps to protect our users. In the absence of timely
information from a CA following a misissuance, it's both necessary and
reasonable to consider the worst as plausible.

it may be happening

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

my body is ready

jre
Sep 2, 2011

To the cloud ?



Fuzzy Mammal posted:

it may be happening

What was the background to this again, Symantec issuing certs for google domains ?

Bonfire Lit
Jul 9, 2008

If you're one of the sinners who caused this please unfriend me now.

misissued certs for test.com and example.com (and some other certs/precerts that contain obviously bogus data)

again

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



Bonfire Lit posted:

misissued certs for test.com and example.com (and some other certs/precerts that contain obviously bogus data)

again

Oh, test korea best korea. Cool :suspense:

  • Locked thread