Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

i was googling for something and misspelled it and wound up here:

http://www.digitalstorefronts.com/intercart.htm

quote:

How to add InterCart™ to your existing web site
Here's an example of how to add InterCart™ to your web page. Copy and paste the following HTML code into your web page.

<FORM METHOD=POST ACTION="HTTP://www.digitalstorefronts.com/store/shop.asp">
<INPUT TYPE=HIDDEN NAME=CartID VALUE="CART">
<INPUT TYPE=HIDDEN NAME=ItemNum VALUE="A-0050">
<INPUT TYPE=HIDDEN NAME=ItemPrice VALUE="9.99">
<INPUT TYPE=HIDDEN NAME=ItemWt VALUE="3.2">
<INPUT TYPE=HIDDEN NAME=ItemDec VALUE="This is a widget description">
<INPUT TYPE=SUBMIT VALUE="Add To Cart">
</FORM>

i assume this page has been up since the mid-90's if it's still passing price in (all-caps) form fields :allears:

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



Phone posted:

is this an "oh day"?

It's more of an "oh poo poo"

MononcQc
May 29, 2007

Volmarias posted:

:haw: Well I tried to use the original document, but word told me that it was too old so it converted it to a new one, I'm not sure I'm not good at computers

:doink: Neither am I, that sounds plausible. Case dismissed!

Seriously though, I love that there's always some new way for Microsoft's font handling to screw people over.

The linked twitter post picture seems to mention document signatures:

https://twitter.com/frooq/status/884497768131297284

So they probably had a printed copy back-dated 2006 with a signature on it.

flakeloaf
Feb 26, 2003

Still better than android clock

well roboto is completely unreadable on my screen so i chanaged it to calibri

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


I'm curious who happened to have that bit of trivia on file.

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

ate all the Oreos posted:

#1 as in the first actual IT person at the whole company ever

this. They're running the business currently off of the router included with FiOS, and there's unlimited rosé in the refrigerator at work (but the Fiji water is off-limits, that's for clients only).

Shaggar
Apr 26, 2006
is it her job to know what to pick or is she IT by way of "oh, you know what a computer is, you deal w/ this."

I like Sophos utms for small biz stuff. their pretty easy to use and manage and have a boatload of features.

Chalks
Sep 30, 2009

rafikki posted:

I'm curious who happened to have that bit of trivia on file.

I imagine a forensic document examination company has a whole load of tricks like that to try to verify the validity of a document. To be honest it's probably the sort of mistake that document forgers make all the time.

surebet
Jan 10, 2013

avatar
specialist


mrmcd posted:

Microsoft should change the default font on Word every year just to gently caress with really dumb forgers.

too obvious; figure out what the 100 most statistically likely pairs of consecutive characters are and encode original document creation date w/ other metadata through very subtle fractional em spacing fuckery

no one except for the most attentive designer is going to notice, and their not going to be using word anyway

wolrah
May 8, 2006
what?

surebet posted:

How the Calibri font could take down Pakistan’s prime minister
Microsoft’s default font is at the centre of an ongoing corruption investigation



I don't know why this "not available until 2007" thing keeps going around, it's demonstrably false.

It became the default in Office 2007 (released January 2007), but it was available semi-publicly in Windows Longhorn betas as early as August 2004. Microsoft themselves made it available to the world in 2005 and there are a number of articles from 2005 and 2006 discussing it.

It's obviously still not incredibly likely that someone used a beta version of an OS or Office suite, or manually installed a font pack, for use on official government correspondence but it's definitely not impossible either.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
times new roman was introduced in 1932 but that didn't make the Killian documents less fake

post hole digger
Mar 21, 2011

Calibri more like Sans Sharif

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this font poo poo while hilarious is best suited for the opsec thread

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lain Iwakura posted:

this font poo poo while hilarious is best suited for the opsec thread
are you telling them to go gently caress themselves

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Jimmy Carter posted:

my girlfriend just started as IT person #1 at an office of like 60 and they are apparently freaking out that they don't 'have a firewall' yet

what should she tell them to buy other than 'whatever is being advertising at the airport'

call a few local vendors, get some quotes for remediation, make it somebody else's problem asap

then after she's been there a year and has a better understanding of sec and the business unfuck whatever the msp set up

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Lain Iwakura posted:

this font poo poo while hilarious is best suited for the opsec thread

That was gassed :/

Cybernetic Vermin
Apr 18, 2005

my bitter bi rival posted:

Calibri more like Sans Sharif

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

my bitter bi rival posted:

Calibri more like Sans Sharif

:popeye:

ThePeavstenator
Dec 18, 2012

:burger::burger::burger::burger::burger:

Establish the Buns

:burger::burger::burger::burger::burger:

my bitter bi rival posted:

Calibri more like Sans Sharif

I shot the Sharif, but I did not shoot the Calibri.

FlapYoJacks
Feb 12, 2009

ThePeavstenator posted:

I shot the Sharif, but I did not shoot the Calibri.

They say it was a Capital offense!

Shame Boy
Mar 2, 2010

Avenging_Mikon posted:

That was gassed :/

did anyone ever get a reason why? i want to poo poo talk about lovely US politics but D&D seems to be full of awful people and "ironic" unironic racists trump supporters and has been trying to be ~fair and balanced~ lately. i'd make a new thread myself but if i don't know why the old one failed it'd just get gassed again i assume?

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
the developers of the pvs studio static analyzer ran it on about 3% of the tizen codebase and discovered over 900 coding errors (note: not static analysis warnings, actual, needed to be fixed, programming errors). extrapolating, they estimate that if this was a representative sample of the tizen codebase they would have found over 27k errors if they had analyzed all of tizen.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ate all the Oreos posted:

did anyone ever get a reason why? i want to poo poo talk about lovely US politics but D&D seems to be full of awful people and "ironic" unironic racists trump supporters and has been trying to be ~fair and balanced~ lately. i'd make a new thread myself but if i don't know why the old one failed it'd just get gassed again i assume?

it was closed by the OP, not gassed

FAT32 SHAMER
Aug 16, 2012



ate all the Oreos posted:

did anyone ever get a reason why? i want to poo poo talk about lovely US politics but D&D seems to be full of awful people and "ironic" unironic racists trump supporters and has been trying to be ~fair and balanced~ lately. i'd make a new thread myself but if i don't know why the old one failed it'd just get gassed again i assume?

threads that are closed in yospos get autogassed

cinci zoo sniper
Mar 15, 2013




old was closed, new one opened and also died i think? not sure, but i've pm'd graph about this a few mins back, ill make one if he says it's ok

BattleMaster
Aug 14, 2000

my bitter bi rival posted:

Calibri more like Sans Sharif

:stwoon:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cinci zoo sniper posted:

old was closed, new one opened and also died i think? not sure, but i've pm'd graph about this a few mins back, ill make one if he says it's ok
iirc graph shut down the second thread. both threads were closed. there is no opsec thread.

flakeloaf
Feb 26, 2003

Still better than android clock

my bitter bi rival posted:

Calibri more like Sans Sharif

Shame Boy
Mar 2, 2010

anthonypants posted:

iirc graph shut down the second thread. both threads were closed. there is no opsec thread.

yeah as other posters mentioned the first one was closed by the OP but the second one just kinda ended suddenly with no explanation that i've seen :iiam:

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

Mr.Radar posted:

the developers of the pvs studio static analyzer ran it on about 3% of the tizen codebase and discovered over 900 coding errors (note: not static analysis warnings, actual, needed to be fixed, programming errors). extrapolating, they estimate that if this was a representative sample of the tizen codebase they would have found over 27k errors if they had analyzed all of tizen.

isn't tizen the project where everything is a void pointer and a hosed up variant type with a bunch of casting everywhere because everyone working on it is literally insane?

if so i imagine a static analyzer would just explode if it touched that code

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Deep Dish Fuckfest posted:

isn't tizen the project where everything is a void pointer and a hosed up variant type with a bunch of casting everywhere because everyone working on it is literally insane?

if so i imagine a static analyzer would just explode if it touched that code

yeah that's just their native UI toolkit - I'm sure there's plenty of just :magical: poo poo in there

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Deep Dish Fuckfest posted:

isn't tizen the project where everything is a void pointer and a hosed up variant type with a bunch of casting everywhere because everyone working on it is literally insane?

if so i imagine a static analyzer would just explode if it touched that code
yeah reportedly it's pretty bad
https://motherboard.vice.com/en_us/article/xy9p7n/samsung-tizen-operating-system-bugs-vulnerabilities
there's also this post about enlightenment which tizen uses https://what.thedailywtf.com/topic/15001/enlightened

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

enlightenment and rasterman have been bad-kind-of-crazy for 20 years now

FAT32 SHAMER
Aug 16, 2012




lol enlightenment literally has "hell if i know" in the documentation

Wiggly Wayne DDS
Sep 11, 2010



:nsa:
https://groups.google.com/forum/m/#!topic/mozilla.dev.security.policy/71AXGTgcX9c

quote:

Hello,

I recently did an investigation where I tried to simply download private
keys from web servers with common filenames. I collected these
filenames simply from common tutorials on the web (server.key,
privatekey.key, myserver.key, key.pem and [hostname].key with and
without www).
In several cases I was able to download private keys belonging to
currently valid certificates.

I wrote about this today for the German news site Golem.de (with an
english translation available): https://www.golem.de/news/https-private-keys-on-web-servers-1707-128862.html

In the course of this I also learned quite a bit about the revocation
process. According to the baseline requirements a CA shall revoke keys
within 24 hours in case of a key compromise.

Some notes about my experiences:
* All certificates I reported are revoked now.

* In several cases the deadline wasn't hit and CAs took longer. Some
took over 4 days. In one case (Gandi) I learned that it's a branded
CA from Comodo. Comodo immediately revoked the cert after they
learned about it, but this raises interesting questions about the
responsibilities of branded CAs.

* The reporting process is wildly different. Some CAs provide email
addresses, others online forms, Symantec has forms with captchas. In
the April CA communications [1] mozilla announced that it wants to
compile a list of contact methods and has asked CAs for them. I would
encourage streamlining that process. I also think revocation should
be automatable (at least on the side of the reporter) and wonder
whether things like forms with captchas should be outruled.
Particularly interesting is Let's Encrypt that provides an API via
ACME to revoke if you posess the private key. IMHO that's ideal.

* Comodo re-issued certs with the same key. I wonder if there should be
a rule that once a key compromise event is known to the CA it must
make sure this key is blacklisted. (Or maybe one of the existing
rules already apply, I don't know.)


I had opened a private bug in mozillas bugtracker which contains some
more info and lists of the specific certificates. It's up to mozilla
when they'll open it, but from my side I think this can go public.


[1] https://wiki.mozilla.org/CA/Communications#April_2017_Responses
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=1378074
--
Hanno Böck

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
"Comodo re-issued certs with the same key"

ooooof course they did

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
oh comodo :allears:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it's called security through obscurity, nobody would ever think to check for the private key in a webserver-readable directory

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

it's like the old htpasswd attack all grown up

Adbot
ADBOT LOVES YOU

surebet
Jan 10, 2013

avatar
specialist


ate all the Oreos posted:

did anyone ever get a reason why? i want to poo poo talk about lovely US politics but D&D seems to be full of awful people and "ironic" unironic racists trump supporters and has been trying to be ~fair and balanced~ lately. i'd make a new thread myself but if i don't know why the old one failed it'd just get gassed again i assume?

i'd be mega down for a new thread that follows the model of the first one, with alternating opsec fuckups & us polchat

i need a place to stare in disbelief at current events and while i do read a few pages of trumpchat in d&d, lol at the idea of keeping up with that thread

my bitter bi rival posted:

Calibri more like Sans Sharif

ThePeavstenator posted:

I shot the Sharif, but I did not shoot the Calibri.

ratbert90 posted:

They say it was a Capital offense!

jfc nice!

  • Locked thread