Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Truga
May 4, 2014
Lipstick Apathy
https://wycd.net/posts/2017-02-21-ibm-whole-cluster-privilege-escalation-disclosure.html

quote:

This is a disclosure of a privilege escalation vulnerability I found in the IBM Data Science Experience product, which was patched on Feb 15th, 2017. It was a misconfiguration vulnerability with very severe consequences. In short, they left all the Docker TLS keys in the container

...

What was at stake:
* Root access across whole compute cluster
* R/W to 100s of TBs of customer data

Conditions required:
* Web browser
* Free trial account



ayyyy lmao

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010


i actually like and use docker all the time and i'm pretty sure it's still a net negative on the world because it seems like nobody in the loving world but me knows how not to gently caress it up in laughably terrible ways

Truga
May 4, 2014
Lipstick Apathy
i'm currently in the process of deploying openshift through our infrastructure and butts and it's going to own and be the best thing ever, but yes, i agree

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

another quote from the ibm thing

quote:

Customers should have received a security bulletin for this. I was told that a security bulletin would not be posted for this incident or cloud security incidents in general, but if I were a paying customer, I would absolutely want to hear it from the company itself and not some stupid tech blog.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


were his previous reports any good? lots of reporters are super noisy, and never produce anything of value

mod saas
May 4, 2004

Grimey Drawer
Security Fuckup Megathread - v13.3 - not some stupid tech blog

Pile Of Garbage
May 28, 2007



ate all the Oreos posted:

i actually like and use docker all the time and i'm pretty sure it's still a net negative on the world because it seems like nobody in the loving world but me knows how not to gently caress it up in laughably terrible ways

i know what docker is but i've never actually used it. however whenever i hear colleagues mention it i quietly lol because of exactly that. it seems like one of those things which is easy to get into but easy to fuckup.

cinci zoo sniper
Mar 15, 2013




so, i was brosing startups...

http://www.authbase.net/

Pile Of Garbage
May 28, 2007



cinci zoo sniper posted:

so, i was brosing startups...

http://www.authbase.net/

quote:

SECURITY IS NOT AN OPTION!

except for HTTPS i guess which their website doesnt support...

e: copyright date in the footer is 2016, site is prolly long ded

Shame Boy
Mar 2, 2010

Subjunctive posted:

were his previous reports any good? lots of reporters are super noisy, and never produce anything of value

one of the reasons I haven't really looked into bug bounties at all is because the way i imagine them working is you have 2000 indian guys running metasploit or w/e and auto-generating reports on literally everything their tools spit out and then probably 100 actually competent people finding the neat bugs who are much better at it than me and it just seems like i'd be lost in the sea of piss that is the first group since i don't think i'm cool hacker guy enough to be in the second group :sigh:

Shame Boy
Mar 2, 2010

cinci zoo sniper posted:

so, i was brosing startups...

http://www.authbase.net/

code:
< A u t h e n t i c a t . i o / n > - Make IT Secure!
THAT IS NOT HOW TAGS WORK :argh:

Shame Boy
Mar 2, 2010

also im the 2016 copyright

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Subjunctive posted:

were his previous reports any good? lots of reporters are super noisy, and never produce anything of value

his website has a rant about it, basically he's angry that their bug bounty doesn't cover ie

Truga
May 4, 2014
Lipstick Apathy
the main problem of docker is the ease of access i bet. you click or paste a few things and are developing the app in a production like environment! another few clicks and it's running on production in a ha cluster! it's like magic

you're supposed to have a sysadmin and/or devops guys handling all the configuration poo poo, but lol if a manager will hire a dude he doesn't explicitly need to push his project into production, when he could raise his own salary by pushing out more project faster, cheaper

if a secfuck happens, the dev will be the one getting hosed anyway

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

ate all the Oreos posted:

2000 indian guys running metasploit or w/e and auto-generating reports on literally everything their tools spit out and then probably 100 actually competent people

lol the ratios aren't even that good signal/noise and the bad reporters aren't skilled enough to use metasploit, also india isn't actually the worst country reporter wise

quote:

i'd be lost in the sea of piss that is the first group since i don't think i'm cool hacker guy enough to be in the second group :sigh:

maybe you're not good enough to be in the second group (then again neither am I), but theres a lot of stuff you can do to not be in the first group either, for instance: don't be an rear end in a top hat and give reasonable risk assessments instead of insisting your IE8 only reflected XSS in a unauthenticated marketing microsite is a severe vulnerability

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

rjmccall posted:

his website has a rant about it, basically he's angry that their bug bounty doesn't cover ie

i for one am shocked that microsoft isn't actively patching their officially deprecated browser

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech posted:

i for one am shocked that microsoft isn't actively patching their officially deprecated browser

internet explorer 11 is still supported

https://www.microsoft.com/en-ca/WindowsForBusiness/End-of-IE-support

quote:

Internet Explorer 11 is the last version of Internet Explorer, and will continue to receive security updates, compatibility fixes, and technical support on Windows 7, Windows 8.1, and Windows 10.

https://support.microsoft.com/en-us/help/17454/lifecycle-support-policy-faq-internet-explorer

quote:

Internet Explorer 11 is the last major version of Internet Explorer. Internet Explorer 11 will continue receiving security updates and technical support for the support lifecycle of the version of Windows on which it is installed.

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

mod saas posted:

Security Fuckup Megathread - v13.3 - not some stupid tech blog

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
not only is it still supported, it's the only browser in the windows 10 long-term servicing branch, indicating that there are no long-term plans or goals for microsoft edge. and, like the guy's blog says, a ton of microsoft garbage like skype are essentially running ie 11

Sapozhnik
Jan 2, 2005

Nap Ghost
i don't know much about docker but i'm still convinced it's bad

let's have a complex god process that runs as root managing everything and it also has some sort of http interface, what could possibly go wrong

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

anthonypants posted:

not only is it still supported, it's the only browser in the windows 10 long-term servicing branch, indicating that there are no long-term plans or goals for microsoft edge

this is one of those posts where i genuinely can't decide if it's sarcasm or not

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lutha Mahtin posted:

this is one of those posts where i genuinely can't decide if it's sarcasm or not
they named the third xbox the xbox one

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

anthonypants posted:

they named the third xbox the xbox one

does it still have the wrong ram

Cybernetic Vermin
Apr 18, 2005

rjmccall posted:

his website has a rant about it, basically he's angry that their bug bounty doesn't cover ie

lol, the anarcho-capitalistic endgame of security research is here

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sapozhnik posted:

i don't know much about docker but i'm still convinced it's bad

let's have a complex god process that runs as root managing everything and it also has some sort of http interface, what could possibly go wrong

Yeah you should be using rkt instead

Wiggly Wayne DDS
Sep 11, 2010



PCjr sidecar posted:

does it still have the wrong ram
the wrong ram?!

cinci zoo sniper
Mar 15, 2013




Wiggly Wayne DDS posted:

the wrong ram?!

xbone has ddr3, ps4 - gddr5

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

PCjr sidecar posted:

does it still have the wrong ram
project scorpio will have six teraflops of power

Sapozhnik
Jan 2, 2005

Nap Ghost

anthonypants posted:

project scorpio will have six teraflops of power

https://www.youtube.com/watch?v=9QEsjd1WZuY

Wiggly Wayne DDS
Sep 11, 2010



cinci zoo sniper posted:

xbone has ddr3, ps4 - gddr5
32mb of esram disagrees

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

my favorite episode :allears:

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
lomarf

https://twitter.com/ressym/status/834458698563145728

jre
Sep 2, 2011

To the cloud ?




I was staring at that for ages going, what's wrong with a minimum of 8 chars, mix of caps , small and numbers?


:psyduck: wtf ?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Eripsa posted:

You aren't "hammering" me, you are showing off. In academic talks, there's always the guy who asks the question that goes "I don't know anything about what you're talking about, and I don't care. But here's what I do, and I'm really great at it. Really really great! What do you have to say to that?" You are that guy. You are explaining in detail how poor our existing security systems are, and how easy they are to compromise. Boy, you sure are right about that! Great comment. Here's your gold sticker.

Would it be nice to have better security? You betcha! Should security experts have a bigger say in the design and development of technological infrastructure? Well, from an engineering design perspective sure, but the security experts also install backdoors for the NSA. So I don't think the security experts can be the last line of defense either.

You've made a convincing case that big security challenges exist in identity management. I never denied it, so your effort wasn't really necessary and contributed basically nothing but your bravado and testosterone and racism to the thread. Is that all?

:qq:

pseudorandom name
May 6, 2007

Wiggly Wayne DDS posted:

32mb of esram disagrees
G-buffers

Wiggly Wayne DDS
Sep 11, 2010



if the security experts are the ones installing nsa backdoors, then who are the ones detecting them?

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

It doesn't matter to me if you're "rich", you're as white as many other posters in this thread and unlike many people who are not white, you've had the ability to get a degree that enabled you to teach at two post-secondary institutions. Like many other white males such as yourself, you've also attempted to go into business in a white male-dominated field--we're talking about your failed cryptocurrency nonsense.

Now as a white male, you're trying to impose a social order that again will make white males such as yourself have a privileged position. How can someone who makes minimum wage who is just as likely to not be a white male like yourself be able to afford an 8x8 grid of "EMV chips" (again something you have failed to explain) when they cost an exorbitant amount of money that they're unlikely to be able to put aside?

quote:

Sorry for bursting your tender white male bubble, Eripsa, but no matter what you say you're as white as they come. I'm Irish and by that definition I am not technically "white" but guess what? I am and so are you. Where you were raised, what level of education your parents have, or where you were born are completely irrelevant to me. You have the privilege of being white and just like most people with attitudes like yours, you don't understand it.

You're white.


I enjoyed the posts where you told the hispanic guy that he wasn't dark enough to be an ethnic minority, that was good. I'm surprised you didn't quote these brutal owns yourself.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
quit derailing the wizardsec thread with canuckistani insanity and the ravings of the mentally ill

Wiggly Wayne DDS
Sep 11, 2010



Cocoa Crispies posted:

quit derailing the wizardsec thread with canuckistani insanity and the ravings of the mentally ill
we've been trying to get osi to stop posting for years to no effect

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



Wiggly Wayne DDS posted:

we've been trying to get osi to stop posting for years to no effect

  • Locked thread