Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

im updating the firmware on a point of sale system right now. the new firmware came in the form of a zip archive on some rando dropbox, and i upload it by running an anomalous bat file that, so far, has just printed an endless stream of periods to the console window

sounds like its working, op

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

ate all the Oreos posted:

im updating the firmware on a point of sale system right now. the new firmware came in the form of a zip archive on some rando dropbox, and i upload it by running an anomalous bat file that, so far, has just printed an endless stream of periods to the console window

the dot product of an attack vector

Diva Cupcake
Aug 15, 2005

This is fine.

https://twitter.com/PabloTorre/status/831160445536964608

Shame Boy
Mar 2, 2010

lol i unplugged the loving thing and the dots didn't stop

Shame Boy
Mar 2, 2010


idk people know who the guy who holds the football is and have for a while, he's generally easy to spot

or is the scary part that they found his facebook and he's being an idiot on his facebook?

e: oh if you go up one tweet from the one that got embedded it's much more lol

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

flakeloaf posted:

the dot product of an attack vector

Diva Cupcake
Aug 15, 2005

ate all the Oreos posted:

e: oh if you go up one tweet from the one that got embedded it's much more lol
Yeah, I was trying to post the thread.

I feel like rando Mar-A-Lago members posting national security operations to social media in real-time might need to be addressed.

Shame Boy
Mar 2, 2010

lol i figured out how to get it to actually upload: you have to completely erase everything in its local storage, the entire OS, and then it enters download mode

this device accepts goddamn credit cards

Shame Boy
Mar 2, 2010

oh hey it's checking signatures that's nice

the signatures were included with the zip it uploaded so it's completely worthless but it's a nice try, good job

e: the signatures failed lol

e2: failed signatures did nothing, it kept right on going :toot:

Shame Boy fucked around with this message at 17:06 on Feb 13, 2017

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
what vendor? I mess with POS stuff sometimes

Shame Boy
Mar 2, 2010

wyoak posted:

what vendor? I mess with POS stuff sometimes

i don't really want to post the vendor publicly in case there's an NDA I don't know about that comes back to bite me in the rear end but suffice it to say it's VERy Interesting FOr someoNE like me

Shaggar
Apr 26, 2006
VeriFone is fuckin everywhere that's terrifying.

Shame Boy
Mar 2, 2010

ok a bit more investigating and talking with them and the signing key is actually baked into the hardware and the reason those sigs failed is because they signed it with the wrong release key, and actual important functionality doesn't work without the sigs matching up, so it's actually not too bad

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that's actually quite reassuring

cinci zoo sniper
Mar 15, 2013




im coming to your help, stuck post of subjunctive

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

ok a bit more investigating and talking with them and the signing key is actually baked into the hardware and the reason those sigs failed is because they signed it with the wrong release key, and actual important functionality doesn't work without the sigs matching up, so it's actually not too bad
can you verify the file using the signatures included in the zip though

Shame Boy
Mar 2, 2010

anthonypants posted:

can you verify the file using the signatures included in the zip though

i poked one with openssl and openssl didn't know what to do with it so who knows

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
maybe it was just a hash of the file lol

burning swine
May 26, 2004



flakeloaf posted:

the dot product of an attack vector

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

ate all the Oreos posted:

im updating the firmware on a point of sale system right now. the new firmware came in the form of a zip archive on some rando dropbox, and i upload it by running an anomalous bat file that, so far, has just printed an endless stream of periods to the console window

:woop:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
we have ICS vendors who distribute zip files via box.com which contain unsigned firmware updates

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

ate all the Oreos posted:

oh hey it's checking signatures that's nice

the signatures were included with the zip it uploaded so it's completely worthless but it's a nice try, good job

e: the signatures failed lol

e2: failed signatures did nothing, it kept right on going :toot:

:woop::woop:

vOv
Feb 8, 2014

ate all the Oreos posted:

lol i unplugged the loving thing and the dots didn't stop

my router has a progress bar that's just updated via setTimeout

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i get that this isn't the place for it, but is there a thread we can use to talk about the ongoing comically terrifying opsec fuckups of the american administration? cause boy howdy there's a humdinger today.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

cinci zoo sniper posted:

im coming to your help, stuck post of subjunctive

thanks pal!

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

infernal machines posted:

i get that this isn't the place for it, but is there a thread we can use to talk about the ongoing comically terrifying opsec fuckups of the american administration? cause boy howdy there's a humdinger today.

yeah someone start an opsec thread i don't want to get yelled at again :ohdear:

(not me i don't start threads)

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

infernal machines posted:

i get that this isn't the place for it, but is there a thread we can use to talk about the ongoing comically terrifying opsec fuckups of the american administration? cause boy howdy there's a humdinger today.

i would like a middle ground between this thread and D&D because i really don't want to go to D&D

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

OSI bean dip posted:

I'll close this thread if this D&D stuff continues.

Alright, so as a constant lurky dude in this thread who actually enjoys some of the political-tech conversations but also understands the justification for asking people "GTFO to D&D" here, I'm gonna go ahead and take this into my own hands and create a thread for tech/political discussion poo poo over there now.

OSI can slap people in the face with the link or something whenever somebody mentions "omg trump tweets" in here:

https://forums.somethingawful.com/showthread.php?threadid=3809849

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i also did a thing: https://forums.somethingawful.com/showthread.php?threadid=3809850

race to see who gets gassed first

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Rooney McNibnug posted:

Alright, so as a constant lurky dude in this thread who actually enjoys some of the political-tech conversations but also understands the justification for asking people "GTFO to D&D" here, I'm gonna go ahead and take this into my own hands and create a thread for tech/political discussion poo poo over there now.

OSI can slap people in the face with the link or something whenever somebody mentions "omg trump tweets" in here:

https://forums.somethingawful.com/showthread.php?threadid=3809849

infernal machines posted:

i get that this isn't the place for it, but is there a thread we can use to talk about the ongoing comically terrifying opsec fuckups of the american administration? cause boy howdy there's a humdinger today.

Come hither, my dude.

Shame Boy
Mar 2, 2010


i like yours better because it's not in D&D so i can say funy computer things

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Rooney McNibnug posted:

Come hitler, my dude.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

https://twitter.com/DKMatai/status/831250823757848576

loving rsa in a nutshell

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
algorithms? why didn't i think of that!

Malcolm XML
Aug 8, 2009

I always knew it would end like this.

watch out for IS-IS

burning swine
May 26, 2004



some bored college student hijacked his own campus' IoT devices and used them for a DDOS against said uni's DNS servers

http://www.zdnet.com/article/how-iot-hackers-turned-a-universitys-network-against-itself/


quote:


In this instance, all of the DNS requests were attempting to look up seafood restaurants -- and it wasn't because thousands of students all had an overwhelming urge to eat fish -- but because devices on the network had been instructed to repeatedly carry out this request.

"We identified that this was coming from their IoT network, their vending machines and their light sensors were actually looking for seafood domains; 5,000 discreet systems and they were nearly all in the IoT infrastructure,"


Default credentials, as always

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.




what the poo poo has augmented reality got to do even a little bit with security?

I guess a hacker could gently caress with your headset and make you puke?

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Deep Dish Fuckfest posted:

algorithms? why didn't i think of that!

"algorithms" is a buzzword for "squeezing blood from a rock big data"

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

COACHS SPORT BAR posted:

some bored college student hijacked his own campus' IoT devices and used them for a DDOS against said uni's DNS servers

http://www.zdnet.com/article/how-iot-hackers-turned-a-universitys-network-against-itself/


Default credentials, as always

at least the systems were discreet

Adbot
ADBOT LOVES YOU

invision
Mar 2, 2009

I DIDN'T GET ENOUGH RAPE LAST TIME, MAY I HAVE SOME MORE?
keyword: #slingo

  • Locked thread