Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

minivanmegafun posted:

why the gently caress does mackeeper run a blog. do they actually have competent people working on their garbage?

I remember that guy posting a couple of years ago about how he found a bunch of MongoDB instances that were setup without authentication, and then suddenly he started working for MacKeeper but all he posts about is still just unsecured DBs he's found.

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

minivanmegafun posted:

why the gently caress does mackeeper run a blog. do they actually have competent people working on their garbage?

"start a blog" is like one of the golden rules of SEO charlatans

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
oh wait that's right, he found out about THEIR unsecured MongoDB so they hired him and I guess his job is now to make them appear that they have a 'security' team? all I know is that mackeeper is the thing that's always on my friends' macs when they got a 'virus' from trying to download adobe.photoshop.cc.2016.n0sC0pEcReW.torrent

Daman
Oct 28, 2011

OSI bean dip posted:

then again nothing generally works out of the box at $0 anyway

feel free to PM me if you have specific questions you don't want to share in here

yeah, I've got to get them set up with an ELK stack until their permanent engineers can grab a better splunk license. WEF is a great tip, I think that'll be really useful for when they need to do IR again. Hopefully I can use one DB for WEF and point multiple things at it (google timesketch, kibana, etc)

osquery is cool, but none of the security dudes at this co can program for poo poo so I was swerving it. bro-osquery like you linked looks like the automation/collection layer I was missing for osquery which is awesome! I'll check out how much pain is involved.

Pile Of Garbage
May 28, 2007



has anyone ever done research into URL shortening services like bitly? i've just noticed that raytheon is one of their customers (rtn.co) which has me interested.

e: who is going to bsides next month? not me because i suck

Pile Of Garbage fucked around with this message at 13:16 on Feb 27, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Daman posted:

yeah, I've got to get them set up with an ELK stack until their permanent engineers can grab a better splunk license. WEF is a great tip, I think that'll be really useful for when they need to do IR again. Hopefully I can use one DB for WEF and point multiple things at it (google timesketch, kibana, etc)

osquery is cool, but none of the security dudes at this co can program for poo poo so I was swerving it. bro-osquery like you linked looks like the automation/collection layer I was missing for osquery which is awesome! I'll check out how much pain is involved.

your security dudes need to learn how to code; especially learn how to write sql. they don't need to be experts (i certainly as hell am not) but they just need to be able to whip up scripts

also

https://twitter.com/thepacketrat/status/836217505416884224

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
also also

https://twitter.com/mikispag/status/836218370605318144

Shame Boy
Mar 2, 2010

OSI bean dip posted:

your security dudes need to learn how to code; especially learn how to write sql. they don't need to be experts (i certainly as hell am not) but they just need to be able to whip up scripts

or more importantly read code so they can tell what is a really terrible script to run

Sapozhnik
Jan 2, 2005

Nap Ghost
LWN had a quote about how some company mandated that everybody's password start with / because people kept pasting them into the company's IRC by accident

(TRWTF is using IRC of course)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Sapozhnik posted:

LWN had a quote about how some company mandated that everybody's password start with / because people kept pasting them into the company's IRC by accident

(TRWTF is using IRC of course)

Just make sure it doesn't have two slashes at the start.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
all my passwords start with "/amsg "

Truga
May 4, 2014
Lipstick Apathy
my irc client is super smart and if I type in a file path like /etc/something it will count as a normal line rather than a command.

i've never managed to type my password into irc before, probably because i'm super paranoid when i have passwords in the clipboard and also saw people who pasted passwords into the channel and laughed at them and it'd be very embarrassing to happen to me

that's my irc secfuck story

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
hunter2

Truga
May 4, 2014
Lipstick Apathy
please stop spamming asterisks tia

Hollow Talk
Feb 2, 2014

:confused:

Crime on a Dime
Nov 28, 2006
groundbreaking lols in the secfuck thread, lads..

Hollow Talk
Feb 2, 2014

Crime on a Dime posted:

groundbreaking lols in the secfuck thread, lads..

Translating that quote's content to HTTP session data leaked via Cloudbleed is left as an exercise to the reader.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sapozhnik posted:

LWN had a quote about how some company mandated that everybody's password start with / because people kept pasting them into the company's IRC by accident

(TRWTF is using IRC of course)

hahahahaha

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

why does anyone still use LastPass KeePass and Dropbox are literally all you need and it's actual secure

Wiggly Wayne DDS
Sep 11, 2010



http://seclists.org/fulldisclosure/2017/Feb/68

quote:

Summary
=======
Name: Remote Code Execution as Root via ESET Endpoint Antivirus 6
CVE: CVE-2016-9892
Discoverers: Jason Geffner and Jan Bee
Vendor: ESET
Product: ESET Endpoint Antivirus 6 for macOS
Risk: Critical
Discovery Date: 2016-11-03
Publication Data: 2017-02-27
Fixed Version: 6.4.168.0
....
Vulnerability
=============
The esets_daemon service, which runs as root, is statically linked with an
outdated version of the POCO XML parser library (https://pocoproject.org/) --
version 1.4.6p1 from 2013-03-06. This version of POCO is based on Expat
(http://expat.sourceforge.net/) version 2.0.1 from 2007-06-05, which has a
publicly known XML parsing vulnerability (CVE-2016-0718) that allows for
arbitrary code execution via malformed XML content.

When ESET Endpoint Antivirus tries to activate its license, esets_daemon sends a
request to https://edf.eset.com/edf. The esets_daemon service does not validate
the web server's certificate, so a man-in-the-middle can intercept the request
and respond using a self-signed HTTPS certificate. The esets_daemon service
parses the response as an XML document, thereby allowing the attacker to supply
malformed content and exploit CVE-2016-0718 to achieve arbitrary code execution
as root.
...
Timeline
========
2016-11-03 - Vulnerability discovered
2016-11-03 - Vulnerability reported to ESET Security Team
2016-11-10 - Phone call between Google and ESET to discuss vulnerability
2016-02-08 - ESET provided Google with updated build
2016-02-21 - Google confirmed vulnerability remediated
2016-02-21 - ESET publicly released version 6.4.168.0
2016-02-27 - Public disclosure

cinci zoo sniper
Mar 15, 2013




kek

flakeloaf
Feb 26, 2003

Still better than android clock

my passwords all start with +++

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
+++ATH0 just in case

AggressivelyStupid
Jan 9, 2012

My Linux Rig posted:

why does anyone still use LastPass, KeePass and SpiderOak are literally all you need and it's actual secure

cinci zoo sniper
Mar 15, 2013





spideroak lol

cinci zoo sniper
Mar 15, 2013




what next, tresorit?

AggressivelyStupid
Jan 9, 2012

I rolled my own cloud storage

cinci zoo sniper
Mar 15, 2013




AggressivelyStupid posted:

I rolled my own cloud storage
aptly named ownCloud, then

apseudonym
Feb 25, 2011


Lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/ who could have seen this coming

https://www.youtube.com/watch?v=EcxNHgYUz6s

Salt Fish
Sep 11, 2003

Cybernetic Crumb
Cloud enabled shoes that phone home to alert you if they become untied while you're walking.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender



thx mongo

Asshole Masonanie
Oct 27, 2009

by vyelkin

AggressivelyStupid posted:

I rolled my own cloud storage

username/post combo ftw

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://www.youtube.com/watch?v=xL-UfLci6_A&t=50s

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

i'm the qwe

Shame Boy
Mar 2, 2010


i got a deal on spideroak so I get unlimited storage space and it works well enough :shrug:

burning swine
May 26, 2004



E: wrong thread lol

burning swine fucked around with this message at 22:44 on Feb 27, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

sarehu posted:

Yeah, make your passwords short, and different for each website. The length doesn't help -- if somebody's hacked the website, they'll probably get everything else in the database too, and a targeted crack isn't going to matter much.

:psyduck:

Salt Fish
Sep 11, 2003

Cybernetic Crumb


I just finished reading this article and it was really entertaining and well written and I recommend reading it too!

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010


shorter, smaller passwords are less conspicuous and harder for hackers to see

hunter2

  • Locked thread