Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Midjack
Dec 24, 2007



cinci zoo sniper posted:

The developers of open source video transcoder app Handbrake have issued a security warning to Mac users after a mirror download server hosting the software was hacked.

The alert was issued on Saturday after it was discovered that the original HandBrake-1.0.7.dmg installer file on mirror server download.handbrake.fr had been replaced by a malicious file.

The affected server has been shut down for investigation, but developers are warning that users who downloaded the software from the server between 14:30 UTC May 2 and 11:00 UTC May 6 have a 50/50 chance of their system being infected by a trojan. "If you see a process called 'Activity_agent' in the OS X Activity Monitor application, you are infected," read the alert.

same thing happened to transmission, a popular bittorrent client for macs, a few years ago

Adbot
ADBOT LOVES YOU

Trabisnikof
Dec 24, 2005

Midjack posted:

same thing happened to transmission, a popular bittorrent client for macs, a few years ago

Also happened to Xcode https://en.wikipedia.org/wiki/XcodeGhost

minivanmegafun
Jul 27, 2004

Midjack posted:

same thing happened to transmission, a popular bittorrent client for macs, a few years ago

iirc both handbrake and transmission were started by the same dev (hence the car puns); I don't know if they're still maintained by the same teams.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Midjack posted:

same thing happened to transmission, a popular bittorrent client for macs, a few years ago

was only a year ago.

Midjack
Dec 24, 2007



Chris Knight posted:

was only a year ago.

how time flies

Wiggly Wayne DDS
Sep 11, 2010



there's a difference between changing the official download and planting altered versions on geographic-specific fan mirrors

raminasi
Jan 25, 2005

a last drink with no ice
when was the last time an actual honest-to-god virus existed anywhere in the wild?

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

raminasi posted:

when was the last time an actual honest-to-god virus existed anywhere in the wild?

Are you looking for something matching some arbitrarily narrow definition you've got in your head or did you miss the virus being talked about literally a post before yours?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
symantec are trying to avoid having the smackdown laid on them by going over everyones head and crying directly to google execs

https://twitter.com/konklone/status/861392893747101696

hope this simply results in an even more punitive outcome for trying to subvert the official process

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Rufus Ping posted:

symantec are trying to avoid having the smackdown laid on them by going over everyones head and crying directly to google execs

https://twitter.com/konklone/status/861392893747101696

To be fair, there's a non-zero chance that it works, which is better than their current situation of "turbofucked".

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

To be fair, there's a non-zero chance that it works, which is better than their current situation of "turbofucked".
pretty much

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

pr0zac posted:

Are you looking for something matching some arbitrarily narrow definition you've got in your head or did you miss the virus being talked about literally a post before yours?

a virus is a program that animates an ambulance driving on the bottom of your screen in text mode.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
type cookie you idiot

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



anthonypants posted:

here is how it works: you try to log in to steam, the steam app on your phone gets a push notification (which you can choose to display on your lock screen or not) and that notification has a code that you type into the steam application on your desktop or on the webpage.

here is how I remember it working when I had to get a new phone because the old one stopped displaying anything:

try to log into steam on the new phone. steam says it needs the 2fa response from the app. hmm welp that's not happening because see above. there's no way to register a new phone in the client or site because the only infrastructure that matters to valve is the the part that accepts credit cards. disable 2fa because gently caress your broken garbage valve I only tolerate you because you've got a nice little monopoly going and I'm not going to bother with even shittier competitors

that might be kinda wrong because it was a year+ ago but I know I posted about it in a previous secfuck thread or maybe the fuckup thread in CoC

Wiggly Wayne DDS
Sep 11, 2010



so you didn't make a backup of your recovery code and the 2fa system didn't have an easy way to make it useless?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
He disabled the 2fa without his phone. Sounds like it already was useless.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



IDK if Steam even has backup keys - it's been a while since I set it up

I did still have a machine logged in the whole time which is how I disabled it IIRC. still probably not a great implementation

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Munkeymon posted:

IDK if Steam even has backup keys - it's been a while since I set it up

I did still have a machine logged in the whole time which is how I disabled it IIRC. still probably not a great implementation

Yeah, I assume a lot of Steam accounts are getting stolen via keylogging, and if they can run a keylogger on your main PC, they can probably also script some poo poo to disable 2FA after you've logged in.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

raminasi posted:

when was the last time an actual honest-to-god virus existed anywhere in the wild?

pr0zac posted:

Are you looking for something matching some arbitrarily narrow definition you've got in your head or did you miss the virus being talked about literally a post before yours?

went back and reread this and realized it comes off as a lot ruder than i intended, I am actually legit interested how you're defining virus in your head

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
self-replicating program that inserts itself into other files?

Shame Boy
Mar 2, 2010

infernal machines posted:

self-replicating program that inserts itself into other files?

what about that wordpress zero-day from like a week ago

e: I mean it was specifically a vuln but it was being used to infect stuff and presumably spread :shrug:

Shaggar
Apr 26, 2006
any exploits in wordpress or javascript are working as expected. when I think virus I think code that gets onto a user's machine without their interaction and replicates to other machines without user interaction.

spankmeister
Jun 15, 2008






viruses infect other binaries on the same system and spread that way. worms spread by using vulnerabilities and copying themselves to the newly infected host

An rce vuln like with worpress can be used by worms to spread but is not a worm in and of itself

Shaggar
Apr 26, 2006
yeah that's a better differentiator. either way, imo, they require no human interaction to spread.

Shame Boy
Mar 2, 2010

spankmeister posted:

viruses infect other binaries on the same system and spread that way. worms spread by using vulnerabilities and copying themselves to the newly infected host

An rce vuln like with worpress can be used by worms to spread but is not a worm in and of itself

I thought "zero day" implied that it was being actively exploited in the wild but I guess it could just mean "someone talked about it before it was patched"

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

I thought "zero day" implied that it was being actively exploited in the wild but I guess it could just mean "someone talked about it before it was patched"

:psyduck:

Shame Boy
Mar 2, 2010


what I thought that was the case for a lot of zero-days, that they first become known because someone sees them being used in the wild :shrug:

Wiggly Wayne DDS
Sep 11, 2010



no wonder everyone's so mad at project zero for causing all these vulnerabilities

spankmeister
Jun 15, 2008






ate all the Oreos posted:

I thought "zero day" implied that it was being actively exploited in the wild but I guess it could just mean "someone talked about it before it was patched"

no it just means that there is no patch.

FAT32 SHAMER
Aug 16, 2012



I'm thankful for posters willing to ask questions that i'm afraid to ask ITT

Wiggly Wayne DDS
Sep 11, 2010



always worth asking questions

nice read but 90% bloat: Bypassing OTR Signature Verification to Steal iCloud Keychain Secrets

Doom Mathematic
Sep 2, 2008

spankmeister posted:

no it just means that there is no patch.

I suppose Zero Day Exploit sounds cooler than "currently unpatched".

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



my internet of things smart home is powered by zero day energy

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Wiggly Wayne DDS posted:

no wonder everyone's so mad at project zero for causing all these vulnerabilities

DumbWhiteGuy
Jul 4, 2007

You need haters. Fellas if you got 20 haters, you need 40 of them motherfuckers. If there's any haters in here that don't have nobody to hate on, feel free to hate on me

Doom Mathematic posted:

I suppose Zero Day Exploit sounds cooler than "currently unpatched".

Zero Day(s since patch released)

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/internetofshit/status/840244403037970432

can't wait for this to blow up

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The S in IoT stands for Semen

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:haw:

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


looks like this is the thing that tavis and natasha at project zero found:

https://twitter.com/msftsecresponse/status/861734360193552385

that's a pretty good response time

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Number19 posted:

looks like this is the thing that tavis and natasha at project zero found:

https://twitter.com/msftsecresponse/status/861734360193552385

that's a pretty good response time
and the writeup https://twitter.com/taviso/status/861747942314487809

  • Locked thread