Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Midjack
Dec 24, 2007



don't touch the poop you imbeciles

Adbot
ADBOT LOVES YOU

fisting by many
Dec 25, 2009



rafikki posted:

don't link this right now, thanks!

i'm not very familiar with sql but please tell me what happened is someone read the funny bug report and promptly went to log in as ; DROP TABLE

Somebody fucked around with this message at 02:23 on Mar 21, 2017

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

fisting by many posted:

i'm not very familiar with sql but please tell me what happened is someone read the funny bug report and promptly went to log in as ; DROP TABLE

yep

Soldier of Fortran
May 2, 2009

rafikki posted:

don't link this right now, thanks!

arse is claiming that they send credit card credentials over plaintext:

quote:

As several commenters have pointed out, the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.

https://arstechnica.com/security/2017/03/firefox-gets-complaint-for-labeling-unencrypted-login-page-insecure/#p3
:classiclol:

Somebody fucked around with this message at 02:24 on Mar 21, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Don't loving touch the poop.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Munkeymon posted:

aww the bug report is private
:ssh: https://archive.fo/53Cbd

graph
Nov 22, 2006

aaag peanuts
don't link to that site from here, thank you!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Midjack posted:

don't touch the poop you imbeciles

OSI bean dip posted:

Don't loving touch the poop.
according to the above arse link there's a reddit thread and that's where the poop-touching is happening

Acer Pilot
Feb 17, 2007
put the 'the' in therapist

:dukedog:

Rip probably thread.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

according to the above arse link there's a reddit thread and that's where the poop-touching is happening

Reddit can deal with the consequences if any then.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Hilariously the DB was apparently dropped.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

Reddit can deal with the consequences if any then.
yes, some redditor is probably going to jail over some poo poo they learned off xkcd

OSI bean dip posted:

Hilariously the DB was apparently dropped.
graph removed a screenshot which seemed to indicate this

EndlessRagdoll
May 20, 2016

OSI bean dip posted:

Reddit can deal with the consequences if any then.

they definitely touched the poop

spit on my clit
Jul 19, 2015

by Cyrano4747
But I love poop!

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

anthonypants posted:

yes, some redditor is probably going to jail over some poo poo they learned off xkcd

lmao

Midjack
Dec 24, 2007



anthonypants posted:

according to the above arse link there's a reddit thread and that's where the poop-touching is happening

probably still a good idea not to directly link to the action from here

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Midjack posted:

probably still a good idea not to directly link to the action from here
just trying to let everyone know that the posters from the something awful forums are not complicit

a witch
Jan 12, 2017

RIP that guy. I feel like statement mappers and ORMs are so pervasive nowadays that making a site vulnerable to sql injection is more difficult than not. maybe that's a very sheltered perspective though.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

a witch posted:

RIP that guy. I feel like statement mappers and ORMs are so pervasive nowadays that making a site vulnerable to sql injection is more difficult than not. maybe that's a very sheltered perspective though.

Lol if you think that site didn't have hardcoded and unsanitized SQL calls interspersed with HTML outputs.

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

a witch posted:

RIP that guy. I feel like statement mappers and ORMs are so pervasive nowadays that making a site vulnerable to sql injection is more difficult than not. maybe that's a very sheltered perspective though.

i had to explain to somebody with 6+ years experience recently that just because you're using neo4j instead of mysql, it doesn't mean you can go back to string building queries

cypher injection sounds a lot cooler than sql injection tho

flakeloaf
Feb 26, 2003

Still better than android clock

OSI bean dip posted:

Hilariously the DB was apparently dropped.

i want to say it was out of benevolence but knowing more than zero humans means i should know better

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

flakeloaf posted:

i want to say it was out of benevolence but knowing more than zero humans means i should know better

eh, i'm pretty sure the guy who did it thought he was doing a favor

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it's definitely one way to keep it off of haveibeenpwned

Computer Serf
May 14, 2005
Buglord

Dex posted:

cypher injection

ate shit on live tv
Feb 15, 2004

by Azathoth

OSI bean dip posted:

Hilariously the DB was apparently dropped.

Good.

Pile Of Garbage
May 28, 2007



yo, anyone here used skyformation (http://www.skyformation.com/) before? we're looking at it maybe for pulling in events from azure ad and o365 seccom to then pass onto mcafee siem (:barf:). just wondering if anyone has any horror stories or can recommend anything better

quelfromage
Mar 31, 2013

BangersInMyKnickers posted:

XTS and CBC diffuser modes at least made some attempt to improve this situation so it isn't as bad as it was a few years ago but still not great. validation has too much overhead, gotta run fast and dirty

vOv
Feb 8, 2014

where would you even store signatures or checksums? iirc both storing them next to the data and storing them all off at the end somewhere both have problems

spankmeister
Jun 15, 2008






vOv posted:

where would you even store signatures or checksums? iirc both storing them next to the data and storing them all off at the end somewhere both have problems

IIRC disk encryption solutions don't sign every block. They only protect confidentiality, and depending on the mode, integrity.

spankmeister fucked around with this message at 09:47 on Mar 21, 2017

Westie
May 30, 2013



Baboon Simulator
so my ex is currently making an shirt+trousers outfit that uses a pair of arduinos to power decorative lights and such

something depressing was said

quote:

how long do you think it'll be until clothes need virus protection and firewalls?

the internet of things is reaching clothing

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
continuing lols
https://twitter.com/taviso/status/844013365991104513

cinci zoo sniper
Mar 15, 2013





"150 mb/line of code" 🤔

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
is LastPass dead now? did taviso kill it?

power botton
Nov 2, 2011

anyone who knows who taviso is already stopped using last pass ages ago, but this is not normal behavior

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
bunch of people in his replies asking about 1password, i'm just glad he changed his mind about password managers
https://twitter.com/taviso/status/765953546713825280
https://twitter.com/taviso/status/769378052254015488

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.




quote:

RESOLVED WONTFIX

yisss that's what I needed

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
so at this point should i just never use a password manager again? lol

cinci zoo sniper
Mar 15, 2013




Cold on a Cob posted:

so at this point should i just never use a password manager again? lol
sounds more like "dont use password managers' browser plugins, and potentially their inhouse synchronisation solutions"

ate shit on live tv
Feb 15, 2004

by Azathoth
Just don't use auto-fill?

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

ate poo poo on live tv posted:

Just don't use lastpass?

  • Locked thread