Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.

https://www.youtube.com/watch?v=DJklHwoYgBQ

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




man i remember when i first read about gait analysis & keyboard pauses & using them for identification. it was pretty mindblowing but of course it goes for every single thing we do.

you could likely identify people by the way they pick their nose if you have enough data about people picking their noses

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

man i remember when i first read about gait analysis & keyboard pauses & using them for identification. it was pretty mindblowing but of course it goes for every single thing we do.

you could likely identify people by the way they pick their nose if you have enough data about people picking their noses

something something zizek

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
you ever pick your toes in Poughkeepsie?

we'll know!

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Jeez, and here I thought internet of poo poo was a metaphor

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


Please Use KeepAss

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



BangersInMyKnickers posted:

Please Use KeepAss

surebet
Jan 10, 2013

avatar
specialist


Last Chance posted:

are you sure you don't have dissociative identity disorder and you actually own both email accounts?

man, i wish

flakeloaf
Feb 26, 2003

Still better than android clock

BangersInMyKnickers posted:

Please Use KeepAss

:eyepoop:

El Mero Mero
Oct 13, 2001

surebet posted:

security fuckup: the poop is trying to touch me edition

pretty sure i previously mentioned the lady that has a similar first name/same last name as me before that keeps using my x.yyyyyy@gmail.com address

what's the best practice here?

Just ignore it/archive it/trash it. If she keeps doing it create a filter to stop her stuff from showing up. You can't stop people from idiotically sending you their stuff, but please don't take advantage of that idiocy. :shrug:


A long time ago I picked up a very generic gmail address, something as common as help@gmail.com (and similar to that). Every time I check that address these days it's a dumpster fire of folks willingly dumping sensitive information to it and convincing every single idiot to stop sending things to it would take up too much time. Hell. I had a visa processing office in Iran cc'ing that address on every passport and visa they processed for months with full color scans of passports attached to every application.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
can you put an auto respond on saying "stop sending me poo poo you moron" ?

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

BangersInMyKnickers posted:

Please Use KeepAss

two-ply authentication

Thanks Ants
May 21, 2004

#essereFerrari


welp

https://www.theguardian.com/society/2017/may/12/hospitals-across-england-hit-by-large-scale-cyber-attack

haveblue
Aug 15, 2005



Toilet Rascal
2FA













two flush authentication

flakeloaf
Feb 26, 2003

Still better than android clock

Ur Getting Fatter posted:

two-ply authentication

aes poofish

flakeloaf
Feb 26, 2003

Still better than android clock


quote:

Hospitals across the country appear to have been simultaneously hit by a bug in their IT systems

ah yes that "malware appears out of nowhere through no fault of anyone" bug

big problem that one's been causing

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
in more secfuck news:

https://www.bleepingcomputer.com/news/security/telefonica-tells-employees-to-shut-down-computers-amid-massive-ransomware-outbreak/

quote:

A ransomware outbreak is wreaking havoc all over the world, but especially in Spain, where Telefonica — one of the country's biggest telecommunications companies — has fallen victim, and its IT staff is desperately telling employees to shut down computers and VPN connections in order to limit the ransomware's reach.

quote:

In Twitter conversations, Telefonica employees and collaborators told Bleeping Computer that the company had sent several internal memos, telling employees to also disconnect from the company's internal WiFi network. Additionally, the company blasted warnings throgh audio speakers inside their Madrid headquarters, warning employees to shut down their computers.

Wiggly Wayne DDS
Sep 11, 2010



it was reported as ransomware to at least one reporter before the announcement

re: hospital

https://twitter.com/GossiTheDog/status/863035626496684035

https://twitter.com/millscj01/status/863038449720414208

https://twitter.com/Felix_Nuno/status/863039071857364992

Truga
May 4, 2014
Lipstick Apathy
i'm glad people finally started attacking low hanging fruits, maybe they'll finally start taking this poo poo serisouly


hahaha who am i kidding nothing will change, iot mri in 3.. 2.. 1..

Thanks Ants
May 21, 2004

#essereFerrari


im imagining the network guys doing a full boris in goldeneye and pulling modems out to stop the hack

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
imo "full boris" should be a standard name for that kind of intrusion response plan

"just finished a call with the it chief. we're going full boris"

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
if you don't use the phrase "slug heads" at least once then it's a half boris, at best

haveblue
Aug 15, 2005



Toilet Rascal
breaking: chief of NHS IT authorizes deployment of spike, declares self "invincible"

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Deep Dish Fuckfest posted:

imo "full boris" should be a standard name for that kind of intrusion response plan

"just finished a call with the it chief. we're going full boris"


Meat Beat Agent posted:

if you don't use the phrase "slug heads" at least once then it's a half boris, at best

Thanks Ants
May 21, 2004

#essereFerrari


haveblue posted:

breaking: chief of NHS IT authorizes deployment of spike, declares self "invincible"

runs at wall, disappears

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



my source on the inside says 'our systems aren't affected because we run our own network on win 7 but all other machines are xp and with no AV because they didn't want to pay [av vendor] for extended support'

i mean av is poo poo and all but it probably would have picked up last years cryptolocker

also lol at 'cyberattack', thats like calling a hurricane you knew was coming as an act of 'weather war'

Wiggly Wayne DDS
Sep 11, 2010



well it isn't last year's cryptolocker it's WannaCry using ms17-010

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Wiggly Wayne DDS posted:

well it isn't last year's cryptolocker it's WannaCry using ms17-010

oh well i guess whoever decided not to update the av is off the hook.

They are mega owned though. There's no segregation of machines between 'poo poo running IE7 people use on their break' and 'machines used to do diagnostic images'

spankmeister
Jun 15, 2008






Nah AV wouldn't pick that up in the first few hours or days after release even if the ransomware is "old". The samples used would be unique.

Also lol this is what you get if you don't patch.

SeaborneClink
Aug 27, 2010

MAWP... MAWP!
https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn

If you'd like to follow along with people paying up.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Truga posted:

i'm glad people finally started attacking low hanging fruits, maybe they'll finally start taking this poo poo serisouly


hahaha who am i kidding nothing will change, iot mri in 3.. 2.. 1..

between poo poo like this and the latest executive order I fully expect security compliance standards like NERC-CIP to expand in scope to include things like all the municipal utilities that have been flying under the radar. The EO is surprisingly not poo poo except for the whole "cyber threat deterrence policy" bit which could have wildly unintentional consequences for security researchers and people doing disclosures

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
re nhs: just heard from a guy i know about how their office got clipped

"Thankfully it looks like only one of our machines was hit, and it was a low end dev server running Windows server 2003, which is probably why it got hit in the first place."

:madmax:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
is it just me or is an azure-hosted cloud website leaving iis stack trace error pages on a bad idea

Loving Africa Chaps
Dec 3, 2007


We had not left it yet, but when I would wake in the night, I would lie, listening, homesick for it already.


My hospital got completely taken out. Everything went down and managers were running around shouting at people to switch off computers at the socket. Lots of lulzy chat about cybers and Russia by people who struggle to unlock their phones who are in charge of the response.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

is it just me or is an azure-hosted cloud website leaving iis stack trace error pages on a bad idea

lol leaving stack traces on an error page is always a bad idea in production, doesn't matter where it's running

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

my goth gf posted:

lol leaving stack traces on an error page is always a bad idea in production, doesn't matter where it's running
what if that website is "secret server cloud dot com"

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

what if that website is "secret server cloud dot com"

i don't know what the gently caress that is but it's still bad

e: oh god i just looked and that sounds real fuckin dumb

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Loving Africa Chaps posted:

My hospital got completely taken out. Everything went down and managers were running around shouting at people to switch off computers at the socket. Lots of lulzy chat about cybers and Russia by people who struggle to unlock their phones who are in charge of the response.

a cryptolocker variant that blasted out WoL frames to every conceivable Mac address for maximum penetration would be slick as hell

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

my goth gf posted:

i don't know what the gently caress that is but it's still bad

e: oh god i just looked and that sounds real fuckin dumb
cool

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


BangersInMyKnickers posted:

maximum penetration

call me

  • Locked thread