Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

i always love responses to breaches that are "we must increase arbitrary password complexity requirements"

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

if you invite 3 of your friends
and then they invite 3
and then so on and so on
we will solve the cyber

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Volmarias posted:

So, having not actually read the source material, and not wanting to read the possibly hyperbolic wikileaks writeup, is there anything in the recent CIA leak which is particularly unexpected? It seems like "no" since normally I'd be reading all about it here with :rip: smilies etc if there was.

i mean in just skimming earlier, there's a thinly-spread description of a remote iOS 0-day/jailbreak vector that may still work.

jammyozzy
Dec 7, 2006
<img src="https://fi.somethingawful.com/customtitles/title-jammyozzy.gif"><br>Is that a challenge?
Are SSL Lab screenshots still cool? I got linked to a customer portal today that immediately threw a cert error and, well:



(The cert expired 2 1/2 years ago)

:catstare:

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
i mean if you can broadly paint "the CIA hacked people and hoarded exploits" as a given, then sure? i mean it's no ShadowBrokers where there's usable exploits in the dump, but there's write-ups on hacking office phones (but don't tell any other countries for some reason?), evidence of holding onto an OS X/iOS mach kernel ASLR defeat for a few years, hacking a very specific model of samsung tv to be used as a listening device...

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anatoliy pltkrvkay posted:

i always love responses to breaches that are "we must increase arbitrary password complexity requirements"
as a computer janitor i'm thrilled that a giant payment processor is going to start taking away local admin from workstations

Suspicious
Apr 30, 2005
You know he's the villain, because he's got shifty eyes.
when i was a computer janitoring childe i quickly found out that arbitrary password complexity requirements coupled with frequent required password changes only led to passwords written on post-it notes stickied on monitors

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

maslow's hierarchy of cyber

i think the top of that pyramid is av

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

ultramiraculous posted:

hacking a very specific model of samsung tv to be used as a listening device...

i haven't seen that part of the dump yet, but samsung tvs share an in house linux distro, unless the specific exploit has been patched, pretty much every smart tv using that stack will be vulnerable, and that can span several model years and series

flakeloaf
Feb 26, 2003

Still better than android clock

Suspicious posted:

when i was a computer janitoring childe i quickly found out that arbitrary password complexity requirements coupled with frequent required password changes only led to passwords.doc in the root directory of everyone's network drives

Computer Serf
May 14, 2005
Buglord
⊂(ºд◉)つ < ( "Dear God Why ‽ )

Pile Of Garbage
May 28, 2007



jammyozzy posted:

Are SSL Lab screenshots still cool? I got linked to a customer portal today that immediately threw a cert error and, well:



(The cert expired 2 1/2 years ago)

:catstare:

only if you name and shame. the lack of TLS 1.2 support is pretty funny, must be an ancient and or incredibly poorly configured server

spankmeister
Jun 15, 2008






I have this rhel5 box kicking around that has openssl 098e or something and apache 2.2.

it only supports TLS 1.0 now (because I turned off SSLv2 and 3 for obvious reasons) and I turned off all of the Diffie Hellman cipher suites because the apache version uses hardcoded 1024 bit parameters. So it only supports RSA key exchange.

It gets a B on ssllabs, but at least it's secure? Sort of?

a7m2
Jul 9, 2012


fins posted:

https://wikileaks.org/ciav7p1/cms/page_17760284.html
They will be distraught that this leaked

https://wikileaks.org/ciav7p1/cms/page_14588483.html

Also realised that some user's names that are redacted could be recovered from the copyright strings on this page:
https://wikileaks.org/ciav7p1/cms/page_15728683.html

pre:
( ゚д゚)、                            vomits saliva

yoloer420
May 19, 2006
I'm the pirated windows keys

Nice one CIA

Edit: seriously, Google any of those keys.

yoloer420 fucked around with this message at 12:23 on Mar 8, 2017

Jewel
May 2, 2009



:buddy:

Westie
May 30, 2013



Baboon Simulator

i'm triggered

minivanmegafun
Jul 27, 2004

infernal machines posted:

i haven't seen that part of the dump yet, but samsung tvs share an in house linux distro, unless the specific exploit has been patched, pretty much every smart tv using that stack will be vulnerable, and that can span several model years and series

Samsung dumped a bunch of cash on the Enlightenment team for some reason, so you can be assured they're making whatever bad decisions they can when it comes to Linux.

Shame Boy
Mar 2, 2010

Bognar posted:

there's a section in there where people are arguing that linux is safe because any attempts to backdoor it would be immediately spotted because ~open source~

my favorite counterargument to this was that there was a bug a while back where someone was doing like "if(uid = root)" instead of "if(uid == root)" that was only caught by luck

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Westie posted:

i'm triggered

Same.

This awful, awful site...

Pile Of Garbage
May 28, 2007



firefox v52.0 has a new captive-portal detection feature which works by sending a HTTP GET to http://detectportal.firefox.com/success.txt. however it seems to do it extremely aggressively (from looking at my session logs sometimes once every minute). i'm sure there's a secfuck in here somewhere. also it's dumb that it's requesting a literal file instead of just looking for a HTTP 200 (maybe? i'm probably dumb, could depend on how the captive portal works).

minivanmegafun
Jul 27, 2004

I'm sure there are plenty of captive portals that return a 200 with a body containing a <meta refresh> tag

Cybernetic Vermin
Apr 18, 2005

also the file is 7 bytes, so might as well check that stuff makes it through unmolested

Thanks Ants
May 21, 2004

#essereFerrari


apple does the same thing, fyi http://captive.apple.com/hotspot-detect.html

i dont know how often it checks, each time connectivity changes at a guess?

b0red
Apr 3, 2013


This has to be by someone's nephew during a summer internship.

cinci zoo sniper
Mar 15, 2013




izi security

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

anatoliy pltkrvkay posted:

i always love responses to breaches that are "we must increase arbitrary password complexity requirements"

That's about making sure your users with the Worst Passwords have to change.

Truga
May 4, 2014
Lipstick Apathy

Wiggly Wayne DDS
Sep 11, 2010



cheese-cube posted:

firefox v52.0 has a new captive-portal detection feature which works by sending a HTTP GET to http://detectportal.firefox.com/success.txt. however it seems to do it extremely aggressively (from looking at my session logs sometimes once every minute). i'm sure there's a secfuck in here somewhere. also it's dumb that it's requesting a literal file instead of just looking for a HTTP 200 (maybe? i'm probably dumb, could depend on how the captive portal works).

Thanks Ants posted:

apple does the same thing, fyi http://captive.apple.com/hotspot-detect.html

i dont know how often it checks, each time connectivity changes at a guess?
ya abusing captive portals is in the cia's docs where they outline that the https cert for captive.apple.com is a big pain in the rear end and they'd never be able to source it

hopefully firefox isn't just plain http as cheese-cube says

Truga
May 4, 2014
Lipstick Apathy
well https returns bad domain with cloudflare cn, so unless they're doing some http header magic, it's probably bad

Shaggar
Apr 26, 2006

the maine ez pass site is surprisingly good. theres a little gauge that shows your current discount rate and instead of a generated image, its svg. its by far the best government site ive ever used, though i don't want to think about how they're storing my creds cause that's probably bad.

Wiggly Wayne DDS
Sep 11, 2010



ioactive just pushed on a report on confide - that crappy messenger that white house officials decided to randomly use: http://www.ioactive.com/pdfs/IOActive-Security-Advisory-Confide-Messaging-Ap.pdf

Pile Of Garbage
May 28, 2007



Wiggly Wayne DDS posted:

ya abusing captive portals is in the cia's docs where they outline that the https cert for captive.apple.com is a big pain in the rear end and they'd never be able to source it

hopefully firefox isn't just plain http as cheese-cube says

Truga posted:

well https returns bad domain with cloudflare cn, so unless they're doing some http header magic, it's probably bad

yeah they definitely appear to be doing it in the clear, i can see the requests for straight plain HTTP on tcp/80. and as Truga said the endpoint is listening on tcp/443 but has a bad cert so unlikely they're using HTTPS

e: my dumb idiotfucker tweet about the thing:

https://twitter.com/GarbageDotNet/status/839476937441476608

Pile Of Garbage fucked around with this message at 16:58 on Mar 8, 2017

apseudonym
Feb 25, 2011

Wiggly Wayne DDS posted:

ya abusing captive portals is in the cia's docs where they outline that the https cert for captive.apple.com is a big pain in the rear end and they'd never be able to source it

hopefully firefox isn't just plain http as cheese-cube says

Captive portals are garbage so you have to test http if you plan to send anything plaintext, since they may let HTTPS through unmolested but then gently caress up HTTP. Pretty much everyone does this but usually only when you move networks or if something looks particularly off.

Captive portals are a fuckup.

Pile Of Garbage
May 28, 2007



apseudonym posted:

Captive portals are garbage so you have to test http if you plan to send anything plaintext, since they may let HTTPS through unmolested but then gently caress up HTTP. Pretty much everyone does this but usually only when you move networks or if something looks particularly off.

Captive portals are a fuckup.

i've actually been dealing with some cisco anyconnect VPN fuckery recently and yeah captive portals are turbo retarded. things become immensely more complicated if you're directing users to use a VPN that implements split-tunnel or even split-DNS.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cheese-cube posted:

only if you name and shame. the lack of TLS 1.2 support is pretty funny, must be an ancient and or incredibly poorly configured server

or any recent oracle middleware stack which is still stuck on openssl .9.8.x

Carbon dioxide
Oct 9, 2012

fins posted:

https://wikileaks.org/ciav7p1/cms/page_17760284.html
They will be distraught that this leaked

https://wikileaks.org/ciav7p1/cms/page_14588483.html

Also realised that some user's names that are redacted could be recovered from the copyright strings on this page:
https://wikileaks.org/ciav7p1/cms/page_15728683.html

More goodies. http://jacksbrain.com/2017/03/personal-favorites-vault7-cia-leak/

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.


Security fuckup megathread - WhereIKeepMyNukes.pdf

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender



PNGA file for your pleasure

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/pdbogen/status/839554926313254912

  • Locked thread