Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Instant Grat posted:

is it a big faux pas to use lastpass or am i just "suboptimal" for sticking w/ that

security fuckup megathread: a big faux pass

Adbot
ADBOT LOVES YOU

mod saas
May 4, 2004

Grimey Drawer
re:keep rear end, is there an acceptable version for macos?

spankmeister
Jun 15, 2008







15 years ago maybe

angry_keebler
Jul 16, 2006

In His presence the mountains quake and the hills melt away; the earth trembles and its people are destroyed. Who can stand before His fierce anger?

surebet posted:

imagining for a moment that they wouldn't get wrecked, if the requested payment was over paypal, i'm sure the conversion rate would be significantly higher. maybe they should try with amazon giftcards or something

the problem is amazon will work with investigators to see what account had gc code xxxx applied and to what address any purchases made by that account have been sent

the best bet would be to just steal somebody's identity to make a paypal account and cash out to bitcoin or w/e, then the poor schlub with the bank account would have to explain why a paypal in his name was being used for cool crimes

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

mod saas posted:

re:keep rear end, is there an acceptable version for macos?

macpass

duTrieux.
Oct 9, 2003

mod saas posted:

re:keep rear end, is there an acceptable version for macos?

...you aren't running windows in a vm?

Shame Boy
Mar 2, 2010


seconded, it actually looks good! :unsmith:

Shame Boy
Mar 2, 2010

my favorite media player is whatever's on the computer played at a reasonable volume

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

ErIog posted:

1password not having Linux support is killing me right now and I think I'm going to just bite the bullet and switch back to Keepass like I was using 9 years ago.

1password works fine under wine

Shifty Pony
Dec 28, 2004

Up ta somethin'


angry_keebler posted:

the problem is amazon will work with investigators to see what account had gc code xxxx applied and to what address any purchases made by that account have been sent

the best bet would be to just steal somebody's identity to make a paypal account and cash out to bitcoin or w/e, then the poor schlub with the bank account would have to explain why a paypal in his name was being used for cool crimes

nah you get people to reship or money mule into bitcoin or western union via spam or Craigslist job listings. you don't need to steal account credentials when people will gladly do the dirty work for you if you promise them money for little effort.

but these ransomware programs are being sold to script kiddies who are unwilling or unable to pull that much coordination off.

Jewel
May 2, 2009

Oh, I didn't see this posted here even though it's 8hrs old, maybe I just missed it though.

https://twitter.com/TalBeerySec/status/863741929401585664

Shame Boy
Mar 2, 2010

am i correct in reading that as some loving OS/2 to NT compatibility thing

windows :allears:

spankmeister
Jun 15, 2008






Neat

pseudorandom name
May 6, 2007

ate all the Oreos posted:

am i correct in reading that as some loving OS/2 to NT compatibility thing

windows :allears:

It may just be parts of the protocol are still encoded using OS/2 data types & values while not actually being OS/2 compatible, but, yeah, probably.

mod saas
May 4, 2004

Grimey Drawer

duTrieux. posted:

...you aren't running windows in a vm?

dude i'm just excited to get someone's second hand mac i don't know the rules yet

i wanted to integrate with my existing win10/anroid setup

fins
May 31, 2011

Floss Finder
finally.. 2017: the year of linux on the desktop

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ate all the Oreos posted:

am i correct in reading that as some loving OS/2 to NT compatibility thing

windows :allears:

There are a lot of references to OS/2 in NT due to its development history. It doesn't necessarily mean it is a backwards compatibility situation here.

I don't even think SMB or RPC existed in OS/2 itself.

FCKGW
May 21, 2006

I finally moved away from Lastpass to Dashlane and it seems pretty good. I tried 1password but keep running into a bunch of little annoyances, especially on PC.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

OSI bean dip posted:

There are a lot of references to OS/2 in NT due to its development history. It doesn't necessarily mean it is a backwards compatibility situation here.

I don't even think SMB or RPC existed in OS/2 itself.

SMB was developed at IBM initially, and was in OS/2 from version 2.0 onwards. that would mean it was in os/2 about 6 months sooner than it showed up in the first Windows for Workgroups.

Proteus Jones
Feb 28, 2013



Midjack
Dec 24, 2007




lol

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.

fins posted:

finally.. 2017: the year of linux on the desktop

https://twitter.com/hackerfantastic/status/863359375787925505

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/maldr0id/status/863838938477338625 lol https://archive.fo/izWrH

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

lol

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
I appreciate namecheap being the a part of the vanguard of preventing global worm apocalyptics.

jre
Sep 2, 2011

To the cloud ?




Lmao

Truga
May 4, 2014
Lipstick Apathy

fishmech posted:

what? the last couple versions from aol and the latest version (5.666) from the Dutch people who bought it out when AOL gave up all run fine.

are you trying to run some dodgy version from 2002 or something

unironically thanks for this, I didn't know there was a new version released in 2014. i gave up on winamp before that.

Wiggly Wayne DDS
Sep 11, 2010



https://oded.ninja/2017/05/14/amt-n-ken-hack/

quote:

The bug was fairly simple. Instead of this:
code:
int main () {
  string realpass = "secret";
  string userpass = "user-secret";
  int equal = strncmp(realpass.c_str(),userpass.c_str(),realpass.size());
  if (equal == 0) {
     printf ("'%s' equals to '%s'", realpass.c_str(), userpass.c_str());
  }
  return equal * equal; // make sure it's positive
}
The code was compiled like this:
code:
int main () {
  string realpass = "secret";
  string userpass = "user-secret";
  int equal = strncmp(realpass.c_str(), userpass.c_str(), userpass.size());
  if (equal == 0) {
     printf ("'%s' equals to '%s'", realpass.c_str(), userpass.c_str());
  }
  return equal * equal; // make sure it's positive
}

Jewel
May 2, 2009

i didn't see this part lmao

https://twitter.com/internetofshit/status/864079949287878656

Truga
May 4, 2014
Lipstick Apathy
well, we know what the attack vector was now

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

mod saas posted:

re:keep rear end, is there an acceptable version for macos?

I use MacPass which doesn't completely blow buuuuuut I dunno how good the PRNG and the generated passwords are

vodkat
Jun 30, 2012



cannot legally be sold as vodka
More wannacry lols

https://twitter.com/tarah/status/863848105023643648

https://twitter.com/hackerfantastic/status/863833239475171329

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Would be much better if this guy didn't jump to "it must be a nation state attack to opaquely modify the compilers everyone uses to replace this one specific string" from the get go.

Shame Boy
Mar 2, 2010


oh well if rainbow dash avatar tried to hack it and couldn't it must be a lost cause

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

oh well if rainbow dash avatar tried to hack it and couldn't it must be a lost cause

which pony is on your avatar btw

fins
May 31, 2011

Floss Finder
http://illmatics.com/carhacking.html

papers and tools from the jeep cherokee hack. interesting read.

quote:


The ‘rmTrack’ method contains a command injection vulnerably that will allow an attacker that can call the D-Bus method to run arbitrary shell commands by specifying a file name containing a shell meta- character. (There are others methods with similar vulnerabilities as well). Our suspicions were correct, as command injection is quite typical when dealing with user input from supposed trusted sources.
However, the command injection is not necessary because the ‘NavTrailService’ service actually provides an ‘execute’ method which is designed to execute arbitrary shell commands! Hey, it’s a feature, not a bug!

Shame Boy
Mar 2, 2010

cinci zoo sniper posted:

which pony is on your avatar btw

it's a horrifying dead-eyed version of applejack called spookyjack:

https://www.youtube.com/watch?v=CaKS4zK7Hu4

i haven't seen any of the pony show because i'm not a child but i think this pony homunculus is wonderfully horrible :v:

Chalks
Sep 30, 2009

ate all the Oreos posted:

it's a horrifying dead-eyed version of applejack called spookyjack:

Every time I see it I think it's a tropical fish.

Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror

spankmeister posted:

15 years ago maybe

if there's a better one out there please by all means tell me what it is. esp if it works on macs cause winamp doesn't work on my work laptop :(

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

I thought it was some wide-eyed yellow bird

  • Locked thread