Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Lain Iwakura posted:

as i tweeted, how is that not going to end up in tears?

you can set permissions in postgres such that a guest user can't do much

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

you can set permissions in postgres such that a guest user can't do much
i hope it's a read-only clone of the database but do they have json/xml export functionality yet, or is someone else going to have to do that now

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy

anthonypants posted:

what if you could run sql commands directly against crt.sh, to do custom queries or w/e

well, https://groups.google.com/forum/#!msg/crtsh/sUmV0mBz8bQ/K-6Vymd_AAAJ

never used that cert.sh site before, just noticed cloudflare made certs for my domains with them even though I only use them for dns

JewKiller 3000
Nov 28, 2006

by Lowtax

anthonypants posted:

i hope it's a read-only clone of the database but do they have json/xml export functionality yet, or is someone else going to have to do that now

for json you can use the row_to_json() function

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Perplx posted:

never used that cert.sh site before, just noticed cloudflare made certs for my domains with them even though I only use them for dns

they do it so turning on https for your poo poo takes seconds instead of minutes

also why would you use buttflare but only for dns

necrotic
Aug 2, 2005
I owe my brother big time for this!

Lain Iwakura posted:

as i tweeted, how is that not going to end up in tears?

they said they spun up new resources, so id assume they are read-only replica(s) with that account having read-only access on top of that.

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Cocoa Crispies posted:

also why would you use buttflare but only for dns

it's got a better interface than my registrar does and i don't care enough about my spare time projects to do anything else

buttcrackmenace
Nov 14, 2007

see its right there in the manual where it says
Grimey Drawer

Cocoa Crispies posted:

they do it so turning on https for your poo poo takes seconds instead of minutes

also why would you use buttflare but only for dns

:yayclod: to butt plugin is a thing of glory

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord
https://www.bleepingcomputer.com/news/security/malware-uses-router-leds-to-steal-data-from-secure-networks/

Bleeping Compter posted:

Specially-designed malware installed on a router or a switch can take control over the device’s LEDs and use them to transmit data in a binary format to a nearby attacker, who can capture it using simple video recording equipment.

This attack scenario is the creation of a talented team of researchers from the Cyber Security Research Center at the Ben-Gurion University of the Negev in Israel, who previously researched other types of data exfiltration scenarios relying on hard drive LEDs, coil whine, headphones, and others.



https://www.youtube.com/watch?v=mSNt4h7EDKo

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
tod durch blinkenlights

Raere
Dec 13, 2007

exfil via the sound of opening and closing the cd tray

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

I like this time of year. About a month and a half from DEFCON all the lovely Stunt Hacks come out as they get acceptance letter from DEFCON.

Shifty Pony
Dec 28, 2004

Up ta somethin'


They need to think larger on the thermal. If you were able to sufficiently infiltrate a server farm you could exfiltrate data by pointing a long range FLIR camera at the cooling system exhaust.

Agile Vector
May 21, 2007

scrum bored



Shifty Pony posted:

They need to think larger on the thermal. If you were able to sufficiently infiltrate a server farm you could exfiltrate data by pointing a long range FLIR camera at the cooling system exhaust.

brb registering stayontarget.com

invision
Mar 2, 2009

I DIDN'T GET ENOUGH RAPE LAST TIME, MAY I HAVE SOME MORE?
root:$1$$oQoSkI0acntd1ifGxMHvp0:0:0:root:/:/bin/sh

That's supposed to be... md5 with no salt, right???

md5crypt maybe?

invision fucked around with this message at 04:49 on Jun 8, 2017

Raere
Dec 13, 2007

invision posted:

root:$1$$oQoSkI0acntd1ifGxMHvp0:0:0:root:/:/bin/sh

That's supposed to be... md5 with no salt, right???

md5crypt maybe?

I only count 22 characters in the hash, md5 is 32

spankmeister
Jun 15, 2008






Raere posted:

I only count 22 characters in the hash, md5 is 32

That's only if it's a hex string, this is a different encoding.

$1$ is crypt so md5 and the salt is supposed to be between the second and third $ but it's not there so yeah, unsalted md5

Shame Boy
Mar 2, 2010

spankmeister posted:

That's only if it's a hex string, this is a different encoding.

speaking of encodings just yesterday i found a suspicious base64 encoded password field in this database i was trying to wrap my head around and was like "hmmm" and converted it to hex and yep google pulled it right up, straight unsalted MD5 :allears:

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Raere
Dec 13, 2007


woman up, as opposed to man up

NyetscapeNavigator
Sep 22, 2003

security down

Shame Boy
Mar 2, 2010

you're watchin' woman up, the worst show on television

Shame Boy
Mar 2, 2010

anyone ever hear of ReliaQuest? i got a somewhat suspicious recruiter email from them with half the mail merge tokens still showing claiming they need a dev for their security product but "no previous security experience required!" (exclamation point theirs) which seems... uhh... yeah...

there was also random bits about "creating new capabilities and platforms that don’t exist today in our industry" which always ends well as this thread has seen

e: just saw this winner on their homepage

flakeloaf
Feb 26, 2003

Still better than android clock

that guy is four seconds from declaring "gently caress it o'clock" and making the giant mess on the screen someone else's problem

Phone
Jul 30, 2005

親子丼をほしい。
https://twitter.com/SwiftOnSecurity/status/873052608851697664

lmao

flakeloaf
Feb 26, 2003

Still better than android clock

the real secfuck is such a person having access to classified systems in the first place

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

It took me a moment to see that he was wearing a jacket, it honestly looked like he was wearing a bib.

FAT32 SHAMER
Aug 16, 2012



flakeloaf posted:

the real secfuck is such a person having access to classified systems in the first place

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Clearly we can only trust our intelligence decisions to skynet

Shame Boy
Mar 2, 2010

flakeloaf posted:

the real secfuck is such a person having access to classified systems in the first place

but she was in the military, which comes with an automatic societal assumption of trustworthiness and Real American Hero status :911:

Maximum Leader
Dec 5, 2014
that name should be enough of a red flag

spit on my clit
Jul 19, 2015

by Cyrano4747
guess who just got two letters from Gamestop notifying me that they had a security breach from august 10th 2016 to february 9th 2017 and that I put CC info into their system during that time. thiiiiiiiiiis guuuuuuuuy.

spit on my clit fucked around with this message at 18:40 on Jun 9, 2017

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

spit on my clit posted:

guess who just got two letters from Gamestop notifying me that they had a security breach from august 10th to february 9th and that I put CC info into their system during that time. thiiiiiiiiiis guuuuuuuuy.

august 10th to february 9th of what? 2008?

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
Stay Alert: 6 Ways To Tell If The Email You Got From Scarlett Johansson Asking For Your Credit Card Info So She Can Buy Sex Gear For Your Love Carnival Is A Phishing Scam Or Not

flakeloaf
Feb 26, 2003

Still better than android clock

next thing you'll be telling me these hot lesbians don't actually want my penis

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
what do you mean that google didn't send me an e-mail telling me i was a good user of their services?

cinci zoo sniper
Mar 15, 2013




guys i just became the millionth visitor of amazon

haveblue
Aug 15, 2005



Toilet Rascal
still waiting for that check from bill gates

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

all promised funds from Bill Gates will be issued in Shoe Carnival gift certificates

Adbot
ADBOT LOVES YOU

spit on my clit
Jul 19, 2015

by Cyrano4747

ThePeavstenator posted:

august 10th to february 9th of what? 2008?

2016-2017.

  • Locked thread