Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
DoctorTristan
Mar 11, 2006

I would look up into your lifeless eyes and wave, like this. Can you and your associates arrange that for me, Mr. Morden?
if they're all poo poo might as well stick with the one you already have

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




DoctorTristan posted:

if they're all poo poo might as well stick with the one you already have

no

Raluek
Nov 3, 2006

WUT.

DoctorTristan posted:

if they're all poo poo might as well stick with the one you already have

you mean like the free* copy of norton that came installed on my bestbuy computer? :v:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Daman posted:

how can msmpeng not be sandboxed? like, what? they rolled it in as a standard component. they're even sandboxing dangerous kernel areas now.

did someone just forget all this weird AV poo poo

I bet it can but keep in mind this is ultimately a scanning engine MS acquired from GiantAV years ago. Sandboxing wasn't common then and it's quite a bit of work to shoehorn it in. I bet they're putting some serious resources in to it now that they've been popped a few times, MS understands security models and how to write code they chose not to do so until forced.

As it stands MSE is still the least-bad and gets patched in a timely manner without the devs fighting or denying you. This is a difficult and obscure bug the execute, he was turning up a ton of dirt before with basic poo poo like input fuzzing which demonstrates other products having zero real security review for their coding teams.

FlapYoJacks
Feb 12, 2009
My company doesn't want to start a security bug bounty program because it might make us look weak. :suicide:

cinci zoo sniper
Mar 15, 2013




ratbert90 posted:

My company doesn't want to start a security bug bounty program because it might make us look weak. :suicide:

show them us army bug bounty programs

Shaggar
Apr 26, 2006
I would like to see what someone like tavis would do to an EHR. they'd probably try to sue him into the dirt.

DumbWhiteGuy
Jul 4, 2007

You need haters. Fellas if you got 20 haters, you need 40 of them motherfuckers. If there's any haters in here that don't have nobody to hate on, feel free to hate on me

ratbert90 posted:

My company doesn't want to start a security bug bounty program because it might make us look weak. :suicide:

"we got hit with ransomware"

"walk it off"

FlapYoJacks
Feb 12, 2009

DumbWhiteGuy posted:

"we got hit with ransomware"

"walk it off"

It's for our embedded product. We don't have an established security bug bounty program, but his worry is that other companies in our industry might go: "See, THEY have bugs, so don't buy them. :smug:"

(Our competitors also do not have security bug bounty programs either.)

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Shaggar posted:

I would like to see what someone like tavis would do to an EHR. they'd probably try to sue him into the dirt.

epic hides all description of security bugs in a secret folder they only the person fixing has access to. they never disclose them to customers until they're patched. most of them are straight up code injection due to heavy use of the x and d @ operators in their code.

spankmeister
Jun 15, 2008






_somebody_ should own they poo poo and do a full disclosure maybe

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

redleader posted:

it's cool how there's this giant, freakishly insecure subsystem buried deep in every modern windows installation

that's why corporate it people like windows, they see a bit of themselves in it

power botton
Nov 2, 2011

Cocoa Crispies posted:

that's why corporate it people like windows, they see a bit of themselves in it

spankmeister
Jun 15, 2008






con\con is back in mft form

https://arstechnica.com/information-technology/2017/05/in-a-throwback-to-the-90s-ntfs-bug-lets-anyone-hang-or-crash-windows-7-8-1/

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news
so apparently ubuntu can get owned by that smb thing

https://twitter.com/hdmoore/status/867490406111604736

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

Shaggar posted:

I would like to see what someone like tavis would do to an EHR. they'd probably try to sue him into the dirt.

loving christ he'd probably end up accidentally killing thousands just by touching a dev server. somehow

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Cocoa Crispies posted:

that's why corporate it people like windows, they see a bit of themselves in it

Truga
May 4, 2014
Lipstick Apathy

Cocoa Crispies posted:

that's why corporate it people like windows, they see a bit of themselves in it

lol

wolrah
May 8, 2006
what?

Mr SuperAwesome posted:

so apparently ubuntu can get owned by that smb thing

The Samba bug affects over 7 years worth of Samba releases. 95% of everything serving SMB from a *nix-ish platform released in this decade is vulnerable if it hasn't been patched or had the affected feature (something about named pipes) turned off.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

wolrah posted:

The Samba bug affects over 7 years worth of Samba releases. 95% of everything serving SMB from a *nix-ish platform released in this decade is vulnerable if it hasn't been patched or had the affected feature (something about named pipes) turned off.

hahahahah HAHAHAHAHAH yes

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I am sure all those storage appliances that companies are dependent on will be issued prompt patches that will be installed by IT staff

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

wolrah posted:

The Samba bug affects over 7 years worth of Samba releases. 95% of everything serving SMB from a *nix-ish platform released in this decade is vulnerable if it hasn't been patched or had the affected feature (something about named pipes) turned off.

centos is unaffected because selinux saves the day

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

does selinux stop samba from executing as root somehow?

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

BangersInMyKnickers posted:

does selinux stop samba from executing as root somehow?

https://access.redhat.com/security/cve/CVE-2017-7494 posted:

Mitigation

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside of samba's module directories and therefore blocks the exploit

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I am asking this in all honestly: what is the architecture in selinux that prevents services running as root like samba from tampering with its own constraints and escaping? Is it some sort of integrity level mechanism?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BangersInMyKnickers posted:

I am sure all those storage appliances that companies are dependent on will be issued prompt patches that will be installed by IT staff

i literally just sent a notice to a client telling them to update their synology asap

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Synology's will autoupdate and restart with a 1 hour warning which is kinda nice but also you can't configure a maintenance interval last I checked so its probably getting turned off my the small business segment. I get an email notification at like 5am a few times a month

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
there isn't a true root under selinux, it's privileges all the way down. you can give a program or user specific privileges, but it doesn't include an omnipotent power to alter privileges

apseudonym
Feb 25, 2011

BangersInMyKnickers posted:

I am asking this in all honestly: what is the architecture in selinux that prevents services running as root like samba from tampering with its own constraints and escaping? Is it some sort of integrity level mechanism?

The service doesn't control it's selinux domain. Unless it has selinux permissions to transition to another domain it's stuck there till it owns the kernel or owns someone else it's allowed to talk to

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Cool, thanks.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

So is Microsoft dropping EMET because they're rolling all the features in to the base OS at some point or because they have some idiotic dream that all apps in a year will come through the Windows store and enforce opt-in for all the security features that EMET enforces? Because there's still going to be decades of legacy applications that could benefit from it

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

So is Microsoft dropping EMET because they're rolling all the features in to the base OS at some point or because they have some idiotic dream that all apps in a year will come through the Windows store and enforce opt-in for all the security features that EMET enforces? Because there's still going to be decades of legacy applications that could benefit from it

iirc lots of emet was already made native as part of defender in win10

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Shaggar posted:

iirc lots of emet was already made native as part of defender in win10

This was my understanding as well but I don't follow window sec news v closely

Wiggly Wayne DDS
Sep 11, 2010



they make it hard to follow any emet news in particular

Thanks Ants
May 21, 2004

#essereFerrari


BangersInMyKnickers posted:

Synology's will autoupdate and restart with a 1 hour warning which is kinda nice but also you can't configure a maintenance interval last I checked so its probably getting turned off my the small business segment. I get an email notification at like 5am a few times a month

you can set a time and day for automatic updates to be applied and for the box to reboot if required

i can poo poo-talk about synology a lot which mainly comes down to people using them for things they arent meant to do, but they are on the ball with their patches

Thanks Ants fucked around with this message at 20:19 on May 26, 2017

Shaggar
Apr 26, 2006

Wiggly Wayne DDS posted:

they make it hard to follow any emet news in particular

hmm, looks like its EOL https://technet.microsoft.com/en-us/security/jj653751

I was not aware

Wiggly Wayne DDS
Sep 11, 2010



yeah but even before EOL it was nigh impossible to get any news on their updates

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

iirc lots of emet was already made native as part of defender in win10

Got any documentation I'd like to know exactly what they are doing

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

The poo poo still works and even the server OS ships with too many system-wide mitigations as opt-in when they should be enforced or opt-out and I'm not really seeing MS addressing that possibly because they are poo poo gently caress idiots

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






BangersInMyKnickers posted:

The poo poo still works and even the server OS ships with too many system-wide mitigations as opt-in when they should be enforced or opt-out and I'm not really seeing MS addressing that possibly because they are poo poo gently caress idiots

don't sign

  • Locked thread