Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

the most gartner slide

Munkeymon posted:

what the poo poo has augmented reality got to do even a little bit with security?

I guess a hacker could gently caress with your headset and make you puke?

they're both concepts from William Gibson books

Adbot
ADBOT LOVES YOU

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer
do any of you know much about Carbon Black? it's apparently an application whitelisting program for windows that they're rolling out here at work. i'm just curious how many ways it inadvertently links other user activity to the admins or vendor, as it sounds like the vendor has to actually help our local admins add things to the whitelist from the internal memo.

Carbon dioxide
Oct 9, 2012

LeftistMuslimObama posted:

do any of you know much about Carbon Black? it's apparently an application whitelisting program for windows that they're rolling out here at work. i'm just curious how many ways it inadvertently links other user activity to the admins or vendor, as it sounds like the vendor has to actually help our local admins add things to the whitelist from the internal memo.

i can tell you all about carbon.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
cabrón black

invision
Mar 2, 2009

I DIDN'T GET ENOUGH RAPE LAST TIME, MAY I HAVE SOME MORE?

Cocoa Crispies posted:

cabrón black

Pile Of Garbage
May 28, 2007



https://twitter.com/larao68/status/831297085496401920

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Gonna be at rsa this week, any good things to do there or good party recommendations for thursday?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

*NSA, and random aides, while surrounded by mar-a-largo guests having diner

join us in the opsec thread for more

Applebees
Jul 23, 2013

yospos
Has anyone heard of IBM Security Trusteer Rapport? Multiple Canadian banks are recommending it. They must have some sort of deal.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

this is literally one hour of RSA tomorrow. such quality



and part of the rest of the afternoon

Daman
Oct 28, 2011
carbon black is good software, I did bug bounty stuff for them. would recommend. not so sure about your privacy as an end user, but you should assume networking knows what you jack to

Shame Boy
Mar 2, 2010

Optimus_Rhyme posted:

this is literally one hour of RSA tomorrow. such quality



and part of the rest of the afternoon


please tell me the one about "talk to your teen about cyber" is going to be recorded so i can see it because lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Applebees posted:

Has anyone heard of IBM Security Trusteer Rapport? Multiple Canadian banks are recommending it. They must have some sort of deal.
our finance/hr team uses it and the only other thing i know about it is like every month they need to reinstall the client for updates

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
the client is a piece of poo poo. Its protective features include stopping you pressing printscreen for some reason

cinci zoo sniper
Mar 15, 2013




Rufus Ping posted:

the client is a piece of poo poo. Its protective features include stopping you pressing printscreen for some reason
that's so you don't exfiltrate screenshots

Wiggly Wayne DDS
Sep 11, 2010



Applebees posted:

Has anyone heard of IBM Security Trusteer Rapport? Multiple Canadian banks are recommending it. They must have some sort of deal.
banks are recommending it over here as well - looked like a piece of poo poo last time it came up in the thread

ErIog
Jul 11, 2001

:nsacloud:
I know this post is ancient history now, but I have been waiting months for an appropriate time to make this joke. and this probably isn't it


bg, bg, bg, can't you see, sometimes your routes just hypnotize me

spankmeister
Jun 15, 2008






Notorious BGP

stoopidmunkey
May 21, 2005

yep

Applebees posted:

Has anyone heard of IBM Security Trusteer Rapport? Multiple Canadian banks are recommending it. They must have some sort of deal.

Finance uses it at work for talking to our bank. The program sucks and the brightcloud protections in it time out causing connection issues. We had to turn off the web filtering to get it to work for the nice ladies that cut my check.

Shaggar
Apr 26, 2006

stoopidmunkey posted:

We had to turn off <INSERT_SECURITY_MECHANISM_HERE> to get it to work for the nice ladies that cut my check.

burning swine
May 26, 2004



LeftistMuslimObama posted:

do any of you know much about Carbon Black? it's apparently an application whitelisting program for windows that they're rolling out here at work. i'm just curious how many ways it inadvertently links other user activity to the admins or vendor, as it sounds like the vendor has to actually help our local admins add things to the whitelist from the internal memo.

man I had this idea years ago. Wrote a service that acted as a whitelist for other windows services. Listened for service start events and killed any service that attempted to start but wasn't allowed by the whitelist


my goal was to stop IT from pushing software onto my work machine via the domain / group policy, lol

it didn't end well

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

stoopidmunkey posted:

Finance uses it at work for talking to our bank. The program sucks and the brightcloud protections in it time out causing connection issues. We had to turn off the web filtering to get it to work for the nice ladies that cut my check.

it's been pushed for years up here by a few of the banks. i'm constantly having to pull it from systems because it breaks https sessions in new and exciting ways. breaks in the sense of connections just plain ol fail at random if it's running. it also occasionally manages to peg an entire cpu core, doing something

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ErIog posted:

I know this post is ancient history now, but I have been waiting months for an appropriate time to make this joke. and this probably isn't it


bg, bg, bg, can't you see, sometimes your routes just hypnotize me


spankmeister posted:

Notorious BGP

these are both good

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

spankmeister posted:

Notorious BGP

Crazy Achmed
Mar 13, 2001

Optimus_Rhyme posted:

this is literally one hour of RSA tomorrow. such quality



and part of the rest of the afternoon


I'm the cyber-law

Pile Of Garbage
May 28, 2007



spankmeister posted:

Notorious BGP

ozymandOS
Jun 9, 2004

spankmeister posted:

Notorious BGP

Kazinsal
Dec 13, 2011


spankmeister posted:

Notorious BGP

mods pls do the needful

Truga
May 4, 2014
Lipstick Apathy
https://www.vusec.net/projects/anc/

:rip: aslr

power botton
Nov 2, 2011

we almost bought thycotic and thank god we didn't cause lmao @ that name.

spankmeister
Jun 15, 2008







https://www.youtube.com/watch?v=fKLmZNnMT0A

Proteus Jones
Feb 28, 2013




Welp.

quote:

AnC, on the other hand, exploits a fundamental mechanism that is in place for efficient code execution that is present in all modern processors. Hence, it is not straightforward to “fix” AnC. Furthermore, AnC runs from JavaScript and does not need to make assumptions on core placement, significantly increasing its impact over Jump over ASLR.

Daman
Oct 28, 2011
has anyone looked into their native library yet? exactly what address is it that they're finding via JS? from their videos that looks like a stack or library address, stack makes more sense because the data changes, but I'm not sure. if it is a stack location there's way less cause for concern than if they leaked an executable's aslr slide. if it turns out they can only leak addresses for locations they can rapidly change the contents of, that's disappointing

Wiggly Wayne DDS
Sep 11, 2010



google's private 2014 report into apt28 is out, notably made a month before fireeye publicised the group: https://www.documentcloud.org/documents/3461560-Google-Aquarium-Clean.html

Shaggar
Apr 26, 2006

javascript is the absolute worst thing

pseudorandom name
May 6, 2007

Shaggar posted:

javascript is the absolute worst thing

You can do the exact same thing, easier, with Java.

Shaggar
Apr 26, 2006
java has mechanisms for establishing trust and most people don't have jvms even installed on their machines. javascript requires that you run untrusted code everywhere and is installed on every computer.

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Shaggar posted:

javascript is the absolute worst thing

much like
















































you're posting

Shaggar
Apr 26, 2006
basically if you ever supported firefox or chrome for their expansion of the use of javascript it is entirely 100% your fault that the state of web security is so bad.

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



Wiggly Wayne DDS posted:

google's private 2014 report into apt28 is out, notably made a month before fireeye publicised the group: https://www.documentcloud.org/documents/3461560-Google-Aquarium-Clean.html
this is a must read for how well it's put together compared to any other public report analysing the attackers on a technical level

  • Locked thread