Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

ate all the Oreos posted:

does NPM still let you delete packages you own completely from the service? i remember a while ago someone had a tantrum and deleted a package that was depended on by like, every other package and broke most of everything because NPM just lets you do that poo poo

you can't omit the part of the idiocy where the package was "left-pad", which adds spaces to the beginning of a string to pad it out to a certain length

Adbot
ADBOT LOVES YOU

necrotic
Aug 2, 2005
I owe my brother big time for this!

ate all the Oreos posted:

does NPM still let you delete packages you own completely from the service? i remember a while ago someone had a tantrum and deleted a package that was depended on by like, every other package and broke most of everything because NPM just lets you do that poo poo

With restrictions http://blog.npmjs.org/post/141905368000/changes-to-npms-unpublish-policy

Although some admin sidestepped the rules at one point I think thus making them pointless.

fins
May 31, 2011

Floss Finder

quote:

At least one password was significantly inappropriate — to the extent that one wouldn't want that to be linked to them online and could be publicly blamed in that case (i.e. not just a swearword). Don't use offensive passwords — those could (and in this case were) leaked to the public in cleartext.

I really want to know what that one was!

flakeloaf
Feb 26, 2003

Still better than android clock

fins posted:

I really want to know what that one was!

what's a nubian

Doom Mathematic
Sep 2, 2008

Cocoa Crispies posted:

you can't omit the part of the idiocy where the package was "left-pad", which adds spaces to the beginning of a string to pad it out to a certain length

Excuse me. Which adds characters to the beginning of a string to pad it out to a certain length, incorrectly.

JavaScript code:
leftPad("butts", 10, "fart").length // 25

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I'm looking at Symantec CSP for some industrial control stuff and it seems nice in that it brings selinux-like restrictions to windows-applications but it does it through Symantec kernel drivers and it seems like if you're a determined attacker you're just going to go after that privileged surface instead. I'm already doing the patching/emet/applocker/endpoint firewall route and I'm really on the fence if I am gaining anything with this or if there is another way to accomplish it that is less risky. I can always yell at the software vendor to stop running everything at system and start using the OS integrity levels but that is going to take year.'

I dunno, just spitballing.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

flakeloaf posted:

what's a nubian

not much what's a nubian with you?

buttcrackmenace
Nov 14, 2007

see its right there in the manual where it says
Grimey Drawer

fishmech posted:

actually a bunch of the conservative christians are leaving it ever since they decided to outright allow gays, and founding lovely splinter groups like camp life or whatever

is that their actual name

if so the irony is delicious

buttcrackmenace fucked around with this message at 16:33 on Jun 22, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

does NPM still let you delete packages you own completely from the service? i remember a while ago someone had a tantrum and deleted a package that was depended on by like, every other package and broke most of everything because NPM just lets you do that poo poo
https://twitter.com/maybekatz/status/872552185459908608

the npm community's reaction is mostly "oh, that's good, it shows that people are learning!" a few people believe that a repo full of garbage is at best worrying, and at worst would make it harder to find useful modules. that person above got mad at me when i said that their 'eh, works for me' reaction was defeatist and apathetic, because they apparently work for npm. also i learned that npm has employees, somehow.

Shame Boy
Mar 2, 2010

anthonypants posted:

https://twitter.com/maybekatz/status/872552185459908608

the npm community's reaction is mostly "oh, that's good, it shows that people are learning!" a few people believe that a repo full of garbage is at best worrying, and at worst would make it harder to find useful modules. that person above got mad at me when i said that their 'eh, works for me' reaction was defeatist and apathetic, because they apparently work for npm. also i learned that npm has employees, somehow.

also npm shows up on "unicorn" lists because it's worth over a billion dollars

somehow

Notorious b.s.d.
Jan 25, 2003

by Reene

BangersInMyKnickers posted:

I'm looking at Symantec CSP for some industrial control stuff and it seems nice in that it brings selinux-like restrictions to windows-applications but it does it through Symantec kernel drivers and it seems like if you're a determined attacker you're just going to go after that privileged surface instead. I'm already doing the patching/emet/applocker/endpoint firewall route and I'm really on the fence if I am gaining anything with this or if there is another way to accomplish it that is less risky. I can always yell at the software vendor to stop running everything at system and start using the OS integrity levels but that is going to take year.'

I dunno, just spitballing.

how is it better than the windows-native mac framework provided by microsoft

https://msdn.microsoft.com/en-us/library/windows/desktop/bb648648%28v=vs.85%29.aspx

Notorious b.s.d.
Jan 25, 2003

by Reene

anthonypants posted:

https://twitter.com/maybekatz/status/872552185459908608

the npm community's reaction is mostly "oh, that's good, it shows that people are learning!" a few people believe that a repo full of garbage is at best worrying, and at worst would make it harder to find useful modules. that person above got mad at me when i said that their 'eh, works for me' reaction was defeatist and apathetic, because they apparently work for npm. also i learned that npm has employees, somehow.

guys, we did it. we located the worst haircut.

also this is officially the grimdark cyberpunk future. billion dollar companies employ people who choose to resemble shadowrun campaign art, and computer software is distributed casually by idiots

cinci zoo sniper
Mar 15, 2013




Notorious b.s.d. posted:

guys, we did it. we located the worst haircut.

also this is officially the grimdark cyberpunk future

have you not gone outside in half a decade or something

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

cinci zoo sniper posted:

have you not gone outside in half a decade or something

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
also i like the haircut, it's cute

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
imo the haircut is good

necrotic
Aug 2, 2005
I owe my brother big time for this!
yeah youre broken if you think its the worst haircut ever.

flakeloaf
Feb 26, 2003

Still better than android clock

hi I'm from 1998 and the chelsea cut is the hot new thing

Pile Of Garbage
May 28, 2007



i really like the current style of live music, with emphasis. i'm so so tired but hearing music makes me so happy:

https://www.youtube.com/watch?v=9Y6H-YjsE9Q

concentrate on apparent requirement for voice and sounds, they sound really good atm...

e: i get really drunk but love some special ppl, awareness of the good style makes me feel much better!

https://www.youtube.com/watch?v=X_e55X-0W7M

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
https://grsecurity.net/an_ancient_kernel_hole_is_not_closed.php

spender :allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

has marcan issued his rebuttal?

i miss spender being on twitter

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Notorious b.s.d. posted:

how is it better than the windows-native mac framework provided by microsoft

https://msdn.microsoft.com/en-us/library/windows/desktop/bb648648%28v=vs.85%29.aspx

The application doesn't use that (yet, high on my request list), everything runs as high. I won't even be considering CSP if it did.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

quote:

Hacking Sony’s SIEA for fun and unreleased games

I began working on a game for the PlayStation at some point in 2016. A key part of releasing a game on an SIEA console is the global product proposal (“GPP”) approval process. Depending on the studio, they’ll submit details of their upcoming games months to years before they are released, and ensure SIEA has no objection to the game’s content. This happens on a web portal all publishers have access to.

It was when I went to download my own global product proposal when I began noticing severe security issues with the ColdFusion-powered site. The issues found could have led to the release of hundreds in-development games and unannounced concepts (and thousands of documents in total) to me and anyone else who tried. All issues found — described below — were responsibly disclosed to Sony’s vulnerability reporting program and fixed in a reasonable amount of time. All third-party data was erased after testing. No bounties (or t-shirts) were given by Sony.

It is hard to understate the critical nature of this site. These documents contain detailed information about upcoming releases, including concept art, detailed story lines, and release dates. I was able to successfully pull the GPP for NBA 2k18, among others, which was quite detailed about its features and release dates.

It’s clear nobody has audited the codebase for security issues. Further, the act of getting access to it is not difficult — SIEA liberally accepts companies to publish on their platforms. The site is luckily IP whitelisted, but this does little against a determined attacker.

Downloading GPP documents (Issue A)

The interface allows you to view your own global product proposals and download their associated files. When I looked at the URL used to download the file, I became curious: /FileServer/IPAMaterials/IPA_MATERIALS_IS00006260_1.zip. You may be able to guess what happens next — I decremented the ID in the last part of the URL to IPA_MATERIALS_IS00006259_1.zip, and ended up with someone else’s global product proposal.
As mentioned above, global product proposals, especially of unreleased games, are extremely sensitive, and they were left lying in the web server’s almost fully public filesystem, stored with sequential file names.

Unfortunately, this started a series of insufficient fixes on Sony’s part. After reporting this issue in 2016, Sony silently attempted to fix it and did not notify me. I came back to this in 2017, wondering if it had been fixed, and found that they had added a five digit unique ID to every download URL. Not only was this unique ID not long enough, it did not appear to even be random — they all seemed to be in the 5x,xxx range. Amusingly, they also ended up disclosing the ColdFusion source code of the page when you left off the filename and went to /FileServer/IPAMaterials.

At this point (in April of 2017), I emailed them and informed them that the new fix was not sufficient. I also gave them a 90-day disclosure deadline. They committed to a fix by the end of May, and added a 512-bit unique ID by then.
However, in early June, I discovered that there was a “skeleton key” ID — one that works for every file — after attempting to view a product that didn’t exist. This is explained in more detail below. I reported this to them on June 7th, and it was (finally) fixed shortly after.
Viewing metadata (Issue B)

Above, I mentioned that you are able to view your own global product proposals. The page that lists and shows these proposals fetches the details of a submission with a POST request to ipa_track_submission_details.cfm. The ID of the submission requested is not checked against the current user, allowing anyone to view the metadata of any product proposal.

The identifier for a product proposal, a v_unique_id, is sequentially incremented. This makes guessing and bulk retrieval trivially possible.

The returned data is actually raw HTML, injected into the page after it’s retrieved via an XMLHttpRequest. After this was fixed, there was a weird quirk: querying an ID the user doesn’t have access to would return the expected HTML, but without any data where there normally would be.

However, on these pages without any data, there was still a link to download the proposal — and it returned the same unique ID for every invalid proposal. This unique ID turned out to work for every file. I am guessing that it is the encoded version of 0 (i.e. null), and if the unique ID matches 0 it is allowed to download any file, for testing/internal use.

Viewing a company’s GPPs (Issue C)

Finally, on the page that allows you to view proposals, the client makes a request to ipa_submissions_frontend.cfc in order to find out what GPPs exist for a given company. Unfortunately, the client controls the company identifier used here, again without any validation.
Again, the company ID is sequential and easily guessable. The returned data allows you to enumerate the names and statuses of all the company’s titles — less detailed than the above, but certainly concerning.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

quote:

It is hard to understate the critical nature of this site

AARP LARPer
Feb 19, 2005

THE DARK SIDE OF SCIENCE BREEDS A WEAPON OF WAR

Buglord

Subjunctive posted:

It is hard to understate the [...] nature of this s[h]ite

sleepwalkers
Dec 7, 2008



poz my ancient hole

Shame Boy
Mar 2, 2010

Notorious b.s.d. posted:

guys, we did it. we located the worst haircut.

also this is officially the grimdark cyberpunk future. billion dollar companies employ people who choose to resemble shadowrun campaign art, and computer software is distributed casually by idiots

that haircut is fine, DAD

however that twitter profile at least made me aware of this site:

http://my.pronoun.is/butt/butt/butt%27s/butts/buttself

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

note how windows is explicitly called out and excluded :eng101:
windows abi specifies that dynamic stack allocations larger than a page should touch every page, so that the allocation won't skip the guard page

Malcolm XML
Aug 8, 2009

I always knew it would end like this.

hackbunny posted:

note how windows is explicitly called out and excluded :eng101:
windows abi specifies that dynamic stack allocations larger than a page should touch every page, so that the allocation won't skip the guard page

Bbbbut my.performance -- the actual reason Linux and crew give

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
anyone use any of those "we scan your paper mail and send it to you via email" services?

it seems like the perfect recipe for identity theft but I'm not living in the states and no longer have someone who can reliably check my mail for me

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Ur Getting Fatter posted:

anyone use any of those "we scan your paper mail and send it to you via email" services?

it seems like the perfect recipe for identity theft but I'm not living in the states and no longer have someone who can reliably check my mail for me
I used to, when I did consulting and was out of town a lot. These days, I don't even know that it's necessary since nearly everything important is paperless (except personal property tax :argh: virginia)

Is identity theft even "in person" these days? It seems like it's all stealing electronic records and forging paperwork and done from other countries to hamper investigations. I don't think any paperwork I get has my SSN on it anyway.

Bhodi fucked around with this message at 15:50 on Jun 23, 2017

effika
Jun 19, 2005
Birds do not want you to know any more than you already do.

Ur Getting Fatter posted:

anyone use any of those "we scan your paper mail and send it to you via email" services?

it seems like the perfect recipe for identity theft but I'm not living in the states and no longer have someone who can reliably check my mail for me

I use MyUSPS and got an email the other day that the postal service will start letting you see scans of the address side of everything coming to you in the mail for free.

Not quite as bad as having the content scanned, but at least you'll know if it's worth checking the mail that day.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

effika posted:

I use MyUSPS and got an email the other day that the postal service will start letting you see scans of the address side of everything coming to you in the mail for free.

Not quite as bad as having the content scanned, but at least you'll know if it's worth checking the mail that day.
is that like for a po box? because that owns

fritz
Jul 26, 2003

Notorious b.s.d. posted:

guys, we did it. we located the worst haircut.

also this is officially the grimdark cyberpunk future. billion dollar companies employ people who choose to resemble shadowrun campaign art, and computer software is distributed casually by idiots

i remember being young and seeing all the olds moaning about haircuts on kids these days and hoping i wouldnt do the same thing if i made it that long

effika
Jun 19, 2005
Birds do not want you to know any more than you already do.

anthonypants posted:

is that like for a po box? because that owns

All postal addresses- they are rolling it out this year. It's using the same equipment they use right now to scan & encode the address, they've just added stuff to make it automatically show up for you if you've linked your account to that address.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

effika posted:

I use MyUSPS and got an email the other day that the postal service will start letting you see scans of the address side of everything coming to you in the mail for free.

Not quite as bad as having the content scanned, but at least you'll know if it's worth checking the mail that day.

that owns but I think that only give you a heads up about the sender?

i need someone to actually open my mail which i suppose is the tricky part

flakeloaf
Feb 26, 2003

Still better than android clock

Ur Getting Fatter posted:

that owns but I think that only give you a heads up about the sender?

i need someone to actually open my mail which i suppose is the tricky part

grats on finding a branch of the us government not willing to do deep packet inspection

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

flakeloaf posted:

grats on finding a branch of the us government not willing to do deep packet inspection

but in this case i want the government to inspect my packets






if you know what i mean

edit: but seriously yeah, I understand that not having my mail snooped on is a good thing.

Adbot
ADBOT LOVES YOU

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



some danish developer noticed that his daycare had a form where you could look up anyone by their ss# & it had no ratelimiting, so you could pretty much enumerate the entire search space & get all valid #s + name + address (only 36,500,000 possibles).

he disclosed it to the vendor, and then went directly to the media & now the vendor is pressing charges for hacking

article in danish
http://nyheder.tv2.dk/krimi/2017-06-21-fandt-fejl-i-it-system-da-son-skulle-i-institution-nu-er-han-sigtet-for-hacking

  • Locked thread