Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
duTrieux.
Oct 9, 2003

Jimmy Carter posted:

9/11 mayor getting made chief of cyber.

one of these days i'm going to give enough of a poo poo to edit in giulianiilini and a cloud service logo

Only registered members can see post attachments!

Adbot
ADBOT LOVES YOU

Crime on a Dime
Nov 28, 2006

duTrieux. posted:

one of these days i'm going to give enough of a poo poo to edit in giulianiilini and a cloud service logo



Oldster

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.

https://twitter.com/kenvogel/status/842790114635997184

FDE your poo poo peeps

30 TO 50 FERAL HOG
Mar 2, 2005



sharepoint 2016 ladies and gents

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
was updating the wildcard cert on our servers and came across one of them which didn't work because the account used for impersonation had a bad password. and the account belongs to one of our developers. and the password it has is "Companyname6!". and i tested with runas just now and his password is "Companyname7!".

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

BiohazrD posted:

sharepoint 2016 ladies and gents



how do you usually bootstrap a new account? have them stand at the IT gal's desk?

flakeloaf
Feb 26, 2003

Still better than android clock

encrypted email to the account requester's isso, have him stand at that guy's desk, force password change on first login

Shaggar
Apr 26, 2006

AggressivelyStupid posted:

On a scale of 1 to 10 how bad is storing SSNs in plaintext? I'm asking for a friend.

E: along with pretty much every other piece of PII

don't store SSN

Shaggar
Apr 26, 2006

Subjunctive posted:

how do you usually bootstrap a new account? have them stand at the IT gal's desk?

use windows auth so they don't have to think about another password

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
yeah. SSO your way out of that

Shaggar
Apr 26, 2006
sharepoint can do saml and ws-federation as well if the stars have aligned correctly and you make the right prayers to the right ancient gods

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shaggar posted:

use windows auth so they don't have to think about another password

well obviously if you have an existing account they can use. that's not always the case (and how do you bootstrap the windows auth password?)

Shaggar
Apr 26, 2006
generated passwords in a ticketing system that are relayed by mouth from their supervisor during which they create their new pw.

for external users yeah I don't really see another way to do it. a time expiring password creation link would probably be better since its likely the authentication store (like AD) doesn't have a concept of one off password expiry (afaik)

Shaggar
Apr 26, 2006
alternatively, have them login with their company's 365

duTrieux.
Oct 9, 2003


this is pretty fuckin' bad

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
loving lol at that secret service agent leaving her backpack in her car in her driveway while she was inside the house.

duTrieux.
Oct 9, 2003

Ur Getting Fatter posted:

loving lol at that secret service agent leaving her backpack in her car in her driveway while she was inside the house.

for real, tho

Pryor on Fire
May 14, 2013

they don't know all alien abduction experiences can be explained by people thinking saving private ryan was a documentary

Hmm someone was just able to break out of a VM and compromise the host in VMWare, I think that will cause some rethinking of things

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
yo dawg I heard you like virtualization

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

eeeh that's arguable imo but this:

https://twitter.com/faultywarrior/status/842569756360302593

is not. omg don't use encrypted filesystems as archives, it's a bad bad idea. it's bad crypto! disk encryption is, frankly, a hack: the cipher modes are poorly studied compared to stuff like cbc, and the encryption isn't authenticated (or at least I've never seen an authenticating implementation). never do this

duTrieux.
Oct 9, 2003

Pryor on Fire posted:

Hmm someone was just able to break out of a VM and compromise the host in VMWare, I think that will cause some rethinking of things

why pay for the whole exploit when you only need the edge

https://twitter.com/thezdi/status/842788469923442689

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

hackbunny posted:

eeeh that's arguable imo but this:

https://twitter.com/faultywarrior/status/842569756360302593

is not. omg don't use encrypted filesystems as archives, it's a bad bad idea. it's bad crypto! disk encryption is, frankly, a hack: the cipher modes are poorly studied compared to stuff like cbc, and the encryption isn't authenticated (or at least I've never seen an authenticating implementation). never do this
they caught silk road kingpin ross ulbricht at a public library while his disk was encrypted and he was caught with a bunch of unencrypted mycrimes.txt documents

for desktops there's this
https://www.youtube.com/watch?v=-G8sEYCOv-o

Workaday Wizard
Oct 23, 2009

by Pragmatica
even simpler than that: just read "%TEMP%\~secretzzzz.txt.autosave"

spankmeister
Jun 15, 2008






Pryor on Fire posted:

Hmm someone was just able to break out of a VM and compromise the host in VMWare, I think that will cause some rethinking of things

Well, VM escapes aren't exactly new. It's really cool how they chained all the exploits though.

Raere
Dec 13, 2007

shaggar was wrong

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

duTrieux. posted:

why pay for the whole exploit when you only need the edge

https://twitter.com/thezdi/status/842788469923442689

good thing they weren't using webkit

WrenP-Complete
Jul 27, 2012

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

spankmeister posted:

Well, VM escapes aren't exactly new. It's really cool how they chained all the exploits though.

yeah, it's like that SpaceX rocket landing video

flakeloaf
Feb 26, 2003

Still better than android clock

Ur Getting Fatter posted:

loving lol at that secret service agent leaving her backpack in her car in her driveway while she was inside the house.

:tinfoil: now let's wonder about all the things that could conveniently be "found" on said laptop

nah let's not that's dumb

Phoenixan
Jan 16, 2010

Just Keep Cool-idge
can't wait to see the president's coke habit confirmed

WrenP-Complete
Jul 27, 2012

Coke and not alphabetamines?

E: I meant amphetamines but love that autosuggestion error so I'll keep it.

WrenP-Complete fucked around with this message at 00:14 on Mar 18, 2017

cinci zoo sniper
Mar 15, 2013




WrenP-Complete posted:

Coke and not alphabetamines?

E: I meant amphetamines but love that autosuggestion error so I'll keep it.

alphabetamines would suggest literacy though

power botton
Nov 2, 2011

cinci zoo sniper posted:

alphabetamines would suggest literacy though

lol

WrenP-Complete
Jul 27, 2012

cinci zoo sniper posted:

alphabetamines would suggest literacy though

Truth.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cinci zoo sniper posted:

alphabetamines would suggest literacy though

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



cinci zoo sniper posted:

alphabetamines would suggest literacy though

lmbo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
these are mainly vizio tvs:
https://www.shodan.io/search?query=ERROR%7C101%7CUnknown+Message+Type%7CEND&page=1

Midjack
Dec 24, 2007



cinci zoo sniper posted:

alphabetamines would suggest literacy though

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

anthonypants posted:

they caught silk road kingpin ross ulbricht at a public library while his disk was encrypted and he was caught with a bunch of unencrypted mycrimes.txt documents

no, his mycrimes.txt were encrypted with FDE. that's why they nabbed him at the library. they wanted a place where both (a) he had the computer on, encryption password activated, screen unlocked, and (b) where they could sneak up behind him, cause a distraction, and snag the machine from him while it was in the unlocked state

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

Lutha Mahtin posted:

no, his mycrimes.txt were encrypted with FDE. that's why they nabbed him at the library. they wanted a place where both (a) he had the computer on, encryption password activated, screen unlocked, and (b) where they could sneak up behind him, cause a distraction, and snag the machine from him while it was in the unlocked state

my favorite random little detail in this story is that he didn't bring his laptop charger with him so the FBI agents had to scramble to find an ac adapter compatible with that type of laptop

  • Locked thread