Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
bicycle
Oct 23, 2013

flosofl posted:

From the Grey Thread.


British tabloids completely doxxed MalwareTech. Like name, age and where he lives.

Man, gently caress the press.

this is loving gross and makes me mad - malwaretech repeatedly asked to be anonymous and although right now this malware looks to be hacked together and vaguely skiddish it could just have easily have been a serious gang with nothing against causing this guy damage

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

funny Star Wars parody posted:

Oh hey i work tangentially on things similar to that

let me tell u about USB debugging and what all you can do

Please, do. I'm kind of interested in what can be done in car context that's surprising coming from the phone world.

FAT32 SHAMER
Aug 16, 2012



Volmarias posted:

Please, do. I'm kind of interested in what can be done in car context that's surprising coming from the phone world.

You can control Navigation, HVAC, audio sources, and access a bunch of logs remotely. I havent dug very deep but with a CAN/Cocoa box simulator you can get at a lot more depending on the make and model

Doom Mathematic
Sep 2, 2008

flosofl posted:

From the Grey Thread.


British tabloids completely doxxed MalwareTech. Like name, age and where he lives.

Man, gently caress the press.

For the tabloid press this is completely standard behaviour. There's nothing they won't stoop to.

Proteus Jones
Feb 28, 2013



bicycle posted:

this is loving gross and makes me mad

TBH, I'm almost as outraged that Flipboard is still a thing.

Midjack
Dec 24, 2007



Doom Mathematic posted:

For the tabloid press this is completely standard behaviour. There's nothing they won't stoop to.

it's not like they're worse than any other brand of journalist. the days of trustworthy reporters are long behind us

Diva Cupcake
Aug 15, 2005

more sophos lol

https://twitter.com/SophosSupport/status/864211021359194112

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol

Shaggar
Apr 26, 2006

this is cause they're using samba. I found another bug in that same component that was supposed to be patched this week.

Daman
Oct 28, 2011

bicycle posted:

this is loving gross and makes me mad - malwaretech repeatedly asked to be anonymous and although right now this malware looks to be hacked together and vaguely skiddish it could just have easily have been a serious gang with nothing against causing this guy damage

if he didn't know his handle was doxxable he's an idiot practicing bad opsec. if some poo poo journalist can do it, anyone can.

good thing he was made aware of it? so he can gently caress with malware gangs on an alias that won't get him assassinated. or take the full Brian Krebs route

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

this is cause they're using samba. I found another bug in that same component that was supposed to be patched this week.

what old broken or otherwise misconfigured samba implimentation doesn't support smb2

FAT32 SHAMER
Aug 16, 2012



Daman posted:

if he didn't know his handle was doxxable he's an idiot practicing bad opsec. if some poo poo journalist can do it, anyone can.

good thing he was made aware of it? so he can gently caress with malware gangs on an alias that won't get him assassinated. or take the full Brian Krebs route

I'm curious, how do you get around registering a site and getting whois'd?

Bulgogi Hoagie
Jun 1, 2012

We

funny Star Wars parody posted:

I'm curious, how do you get around registering a site and getting whois'd?

you ask a third party legal fiction personality to do so on your behalf

so pay a company to do it for you and transfer ownership

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

funny Star Wars parody posted:

I'm curious, how do you get around registering a site and getting whois'd?
what registrar these days won't let you register a site anonymously

FAT32 SHAMER
Aug 16, 2012



anthonypants posted:

what registrar these days won't let you register a site anonymously

I've never registered a site, only used whois :shobon:

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

every registrar i've used lets you hide your info from whois, though it usually costs a bit extra. 'course, you can always fill out fake info, because nobody verifies it.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
The guy got lucky. He didn't know what registering the domain would do in the end. He could have made poo poo worse.

Proteus Jones
Feb 28, 2013



OSI bean dip posted:

The guy got lucky. He didn't know what registering the domain would do in the end. He could have made poo poo worse.

Apparently it's SOP where he works? Seems reckless to me.

I think if he sandboxed it and saw that it killed itself every time it reached out to <bogus domain> and got a response from the sandbox, he might have ended up at the same action, but confident it was the right action.

30 TO 50 FERAL HOG
Mar 2, 2005




i think this is UTM only, you should be running XG if you have the capability

Shame Boy
Mar 2, 2010

anthonypants posted:

what registrar these days won't let you register a site anonymously

gandi

though they let you hide everything but your name, and you can give them a fake name :shrug:

Midjack
Dec 24, 2007



anthonypants posted:

what registrar these days won't let you register a site anonymously

there are a few tlds that some registrars decline to allow anonymous registration for

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
does anyone know of a good security appliance i could use as a vpn/firewall

i have a colocated server and wanna put vsphere and some other stuff on private IPs (currently it's just software firewalled), going with hardware since i currently pay for 2U and i'm only using 1

keep in mind this is hobbyist budget, so i'm not looking to spend a whole lot, probably less than $300 at most

secondhand/refurb is fine as long as there's a warranty of some sort

i just wish i could get the massive discount my company gets on cisco products, i'd get myself a nice ASA :sigh:

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


You could play around with pfsense. Buy a prebuilt one or roll your own on a spare server or even some cheap micro pc laying around.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
well obviously if you can get a refurb asa from work do it but putting pfsense on an old box is pretty hobbyist-level

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

rafikki posted:

You could play around with pfsense. Buy a prebuilt one or roll your own on a spare server or even some cheap micro pc laying around.

i love pfsense but the prebuilt stuff is pretty expensive, and i don't want to roll my own because i suck at it

i need at least 3xGbE (DRAC, management NIC, and vmnet NIC)

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

well obviously if you can get a refurb asa from work do it but putting pfsense on an old box is pretty hobbyist-level

like i said, i wish i could

since we're internal we pay 10% of MSRP on cisco gear

but doing that for my own use would leave me out of work lmao, so there's no way

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

i love pfsense but the prebuilt stuff is pretty expensive, and i don't want to roll my own because i suck at it
so your options are spend a bunch of money or learn how to plug a pcie card into a motherboard and click the Next button a bunch, hmmmmmm

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

so your options are spend a bunch of money or learn how to plug a pcie card into a motherboard and click the Next button a bunch, hmmmmmm

i've built PCs but never a firewall/router, is $300 overkill or?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

i've built PCs but never a firewall/router, is $300 overkill or?
do you have a computer from ~5 years ago lying around and does it have enough pcie lanes for a network card

Proteus Jones
Feb 28, 2013



RISCy Business posted:

i need at least 3xGbE (DRAC, management NIC, and vmnet NIC)

For less than $300?

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

do you have a computer from ~5 years ago lying around and does it have enough pcie lanes for a network card

unfortunately i don't

flosofl posted:

For less than $300?

hence looking for used/refurb stuff, i thought maybe it'd be doable in that price range

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
a buddy of mine is selling an edgerouter-x, i suppose i could pick that up and get a rackmount kit?

Shame Boy
Mar 2, 2010

if you really want a separate machine there's a lot of old-ish servers on ebay (or even newegg sometimes) that go for like $100-$200 that have two gig-e ports built right in, generally they were leased out to a company for a few years and are still in good working order, just not bleeding edge

keep in mind they're loud as gently caress though

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

ate all the Oreos posted:

if you really want a separate machine there's a lot of old-ish servers on ebay (or even newegg sometimes) that go for like $100-$200 that have two gig-e ports built right in, generally they were leased out to a company for a few years and are still in good working order, just not bleeding edge

keep in mind they're loud as gently caress though

eh, it's a colocated box so noise isn't a concern at all, just needs to fit in 1U

Wiggly Wayne DDS
Sep 11, 2010



flosofl posted:

Apparently it's SOP where he works? Seems reckless to me.

I think if he sandboxed it and saw that it killed itself every time it reached out to <bogus domain> and got a response from the sandbox, he might have ended up at the same action, but confident it was the right action.
the domain was bought and sinkholed before any analysis happened beyond 'hey this malware contacts x at startup'

it was an absurdly reckless move that everyone's applauding and copying in the hopes of similar pr

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

RISCy Business posted:

eh, it's a colocated box so noise isn't a concern at all, just needs to fit in 1U
if it needs to be 1u then you probably should've mentioned that

Wiggly Wayne DDS posted:

the domain was bought and sinkholed before any analysis happened beyond 'hey this malware contacts x at startup'

it was an absurdly reckless move that everyone's applauding and copying in the hopes of similar pr
his initial reaction was "shucks i'm just glad that worked i had no idea what it would do" and now it's "well in my lab i simulated what putting the site back up would do, and then i sprung into action!!!!!!!"

Proteus Jones
Feb 28, 2013



RISCy Business posted:

hence looking for used/refurb stuff, i thought maybe it'd be doable in that price range

Fortigate 60D's on ebay. They typically go for $150 or so. It's "half-width" but you can buy full width mounting plates for them.

Make sure they include the power adapter or you'll have to snag one of those as well.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

anthonypants posted:

if it needs to be 1u then you probably should've mentioned that

"going with hardware since i currently pay for 2U and i'm only using 1"

:smith:

hifi
Jul 25, 2012

mikrotik. latvia strong

Adbot
ADBOT LOVES YOU

Phone
Jul 30, 2005

親子丼をほしい。

Wiggly Wayne DDS posted:

the domain was bought and sinkholed before any analysis happened beyond 'hey this malware contacts x at startup'

it was an absurdly reckless move that everyone's applauding and copying in the hopes of similar pr

just wait until next time when the next wave of ransomware triggers in the opposite direction

  • Locked thread