Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
maskenfreiheit
Dec 30, 2004

Jabor posted:

actual 4g coverage, or is someone there running a stingray?

my vpn tunnels all data including 4g so suck it FBI

Adbot
ADBOT LOVES YOU

FAT32 SHAMER
Aug 16, 2012



fishmech posted:

nearly 10 year old defcon joke

ok that explains a lot more

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

please stop touching computers

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

FAT32 SHAMER posted:

ok that explains a lot more

I think it was the post Graham did before he banned himself

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
how in the gently caress could anybody be this stupid

FAT32 SHAMER
Aug 16, 2012



I'm not really sure what's going on with that CVE other than it does bad stuff, but what's especially stupid about it?

Notorious b.s.d.
Jan 25, 2003

by Reene

FAT32 SHAMER posted:

I'm not really sure what's going on with that CVE other than it does bad stuff, but what's especially stupid about it?

dude interpolates a filename into a command string that is then passed to vbscript.exe, which is stupid enough to execute arbitrary code passed on the command line

this was
a.) stupid
b.) totally unnecessary
c.) did i mention really, really stupid?

FAT32 SHAMER
Aug 16, 2012



Notorious b.s.d. posted:

dude interpolates a filename into a command string that is then passed to vbscript.exe, which is stupid enough to execute arbitrary code passed on the command line

this was
a.) stupid
b.) totally unnecessary
c.) did i mention really, really stupid?

oh nice

that's bad

ate shit on live tv
Feb 15, 2004

by Azathoth

Rufus Ping posted:

Well i'm bored in vegas, got no plans till an early dinner meetup tonight and already got my defcon badge so i will answer questions till my mifi is nearly out of batteries


to be clear, jello, you insipid loving backwoods redneck moron, i banned business catte because i had people at work being tracked down to be asked questions about me by the yospos irc sewing circle and frankly i didn't need that much internet in my real life. i still don't, so i'll ban this account too when my batteries get low and you can go back to being constantly wrong for another year. you kids proved that you aren't capable of being even vaguely grownup about people being honest in here about who they are or what they do, so i can't leave the two connected


btw i'm not answering anything about work that is either obvious trolling or over the line with poo poo i shouldn't/can't talk about, or poo poo i just don't feel like answering, but other than that let er rip

I recognize this reference

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

FAT32 SHAMER posted:

I'm not really sure what's going on with that CVE other than it does bad stuff, but what's especially stupid about it?
there's a writeup in the second link and also it was quoted

Bonfire Lit
Jul 9, 2008

If you're one of the sinners who caused this please unfriend me now.

Notorious b.s.d. posted:

dude interpolates a filename into a command string that is then passed to vbscript.exe, which is stupid enough to execute arbitrary code passed on the command line
it's not; dude writes the arbitrary code into a temporary file, which vbscript.exe then runs

anyway "script interpreter runs code passed to it" isn't really stupid but rather something script interpreters are supposed to do. the stupid part is handing raw user data to something that expects to be given executable code

Bonfire Lit fucked around with this message at 08:55 on Jul 30, 2017

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
shadowhawk could you explain why the gently caress does a thumbnailer need to access the product version of an installer package, in the first place?

Cybernetic Vermin
Apr 18, 2005

Notorious b.s.d. posted:

dude interpolates a filename into a command string that is then passed to vbscript.exe, which is stupid enough to execute arbitrary code passed on the command line

this was
a.) stupid
b.) totally unnecessary
c.) did i mention really, really stupid?

vbscript.exe is entirely innocent here, it is, say it with me ~~~a bash script where arbitrary user data is syntactically escaped into a string by haaaaand~~~

Cybernetic Vermin
Apr 18, 2005

hackbunny posted:

shadowhawk could you explain why the gently caress does a thumbnailer need to access the product version of an installer package, in the first place?

code:
# Put a version label on the thumbnail:
if [ "$VERSION" ]
then
	convert -font -*-clean-medium-r-*-*-6-*-*-*-*-*-*-* \
	-background transparent -fill white label:"$VERSION" \
	-trim -bordercolor '#00001090' -border 2 \
	-fill '#00001048' \
	-draw $'color 0,0 point\ncolor 0,8 point' -flop \
	-draw $'color 0,0 point\ncolor 0,8 point' -flop \
	miff:- | composite -gravity southeast - $TEMPTHUMB $OUTPUTFILE
else
	cp $TEMPTHUMB $OUTPUTFILE
fi
not that this quite answers the question asked

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
a bash script
that uses wine
to run windows script host
to run a vbscript script
to run a sql query on an msi file
to embed a very minor metadata label in a thumbnail icon

Cybernetic Vermin posted:

vbscript.exe is entirely innocent here, it is, say it with me ~~~a bash script where arbitrary user data is syntactically escaped into a string by haaaaand~~~

windows script host shares part of the blame though, as

code:
		# Workaround wine bug #19799: cscript crashes if you call WScript.Arguments(0)
		# [url]http://bugs.winehq.org/show_bug.cgi?id=19799[/url]
if it wasn't for working around that bug, the filename could have been passed as an argument, automatically quoted by bash and wine

blame wine too but especially wsh for being a fragile pos that requires external and easily corrupted metadata for something as simple as retrieving the command line arguments

spankmeister
Jun 15, 2008






hackbunny posted:

a bash script
that uses wine
to run windows script host
to run a vbscript script
to run a sql query on an msi file
to embed a very minor metadata label in a thumbnail icon

:pwn:

ShadowHawk
Jun 25, 2000

CERTIFIED PRE OWNED TESLA OWNER

Notorious b.s.d. posted:

a.) why would you do this, you colossal idiot
b.) why would you fess up to it here, of all places
To be clear I didn't actually write the code in question, I just put a packaging wrapper on it and had it installed by default. The original packaged version didn't do anything with MSI files, that came with a later upgrade that I just rubber stamped into the latest package version.

The thumbnailer's point was to show the windows embedded executable icons for executable files rather than a generic featureless square icon. The author added some other magic to make it do fancy things with MSI files too, which is where this vulnerability came from.

If I remember right the original reason the program used wine's built in handler instead of the (now proven safer) external msiinfo package was because it was already a dependency of Wine and you pretty much only installed this package because it came alongside Wine.


That said the attack surface of this vulnerability is only slightly larger than Wine itself -- "download wine and malicious file on filesystem and then browse to its folder" vs "download malicious file on filesystem, browse to folder, and then open with wine".

ShadowHawk
Jun 25, 2000

CERTIFIED PRE OWNED TESLA OWNER
And yeah it's my fuckup but I was so used to thinking of the threat model of Wine being the actual malicious app itself and if a user launches such an app it's already over.

Now it turns out you can have an elaborate really long filename with script embedded into the name, and sometimes files can appear without user intent, so that makes it relatively worse.


The packages got updated within a day or two of the publication of the CVE though, so that's good.

spankmeister
Jun 15, 2008






bugs like this is one of the reasons why the default browser behavior of just downloading files is so bad

Shame Boy
Mar 2, 2010

spankmeister posted:

bugs like this is one of the reasons why the default browser behavior of just downloading files is so bad

don't worry, the automatic antivirus scan will stop anything bad! :downs:

pseudorandom name
May 6, 2007

Today at DEFCON: SMBloris

The first three bytes of a SMB connection are the NBSS header, the last 17 bits of which is a length field. 217 = 128 KB, so you can send a 3 bytes down a TCP connection to a Windows server and the kernel will allocate 128 KB of non-paged physical memory and wait 30 seconds before timing out. That's per TCP source port, for both IPv4 and IPv6, so 16 GB of non-paged physical memory per source machine. Memory is allocated in kernel mode with interrupts disabled, so when physical memory is exhausted, the Windows machine just hangs.

Wiggly Wayne DDS
Sep 11, 2010



yeah the best part is when they told microsoft who said it's not a security issue and wontfix

hobbesmaster
Jan 28, 2008

Microsoft: denied service is a feature!

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
e: misread, nevermind

Raere
Dec 13, 2007

Solution: Install more memory

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Notorious b.s.d. posted:

a.) why would you do this, you colossal idiot
b.) why would you fess up to it here, of all places

a posser who can't laugh at he own fuckups, a shameful posser

JewKiller 3000
Nov 28, 2006

by Lowtax

Rufus Ping posted:

Well i'm bored in vegas, got no plans till an early dinner meetup tonight and already got my defcon badge so i will answer questions till my mifi is nearly out of batteries


to be clear, jello, you insipid loving backwoods redneck moron, i banned business catte because i had people at work being tracked down to be asked questions about me by the yospos irc sewing circle and frankly i didn't need that much internet in my real life. i still don't, so i'll ban this account too when my batteries get low and you can go back to being constantly wrong for another year. you kids proved that you aren't capable of being even vaguely grownup about people being honest in here about who they are or what they do, so i can't leave the two connected


btw i'm not answering anything about work that is either obvious trolling or over the line with poo poo i shouldn't/can't talk about, or poo poo i just don't feel like answering, but other than that let er rip

go gently caress yourself with a shovel

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
def con was good but Vegas is bad

FCKGW
May 21, 2006

Cocoa Crispies posted:

def con was good but Vegas is bad

going to Vegas in two days

gonna peep dat atomic museum

Shame Boy
Mar 2, 2010

my favorite part of visiting vegas a while ago was the ticket clickers that swarm on you and try to give you ads for prostitutes, i hope they still have those

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


ate all the Oreos posted:

my favorite part of visiting vegas a while ago was the ticket clickers that swarm on you and try to give you ads for prostitutes, i hope they still have those

i wouldn't say they swarm but they still seem to exist

Cocoa Crispies posted:

def con was good but Vegas is bad

eh living here's not so bad when it's not summer

Shame Boy
Mar 2, 2010

Ciaphas posted:

i wouldn't say they swarm but they still seem to exist


eh living here's not so bad when it's not summer

they only swarmed if you took a ticket, all the other ones would see you and swarm you

my dad is an idiot and just wanted to take all the free things because he likes taking free worthless things so I saw this happen multiple times

Max Facetime
Apr 18, 2009


actually never mind, I agree there's no point trying to bait fishmech when he's right like usual

as fishmech correctly points out, for all their hundreds of years of history corporations have only ever existed literally, as legal fairytales adults read to each other to make themselves feel better

I guess you saw that one coming a mile away :frogbon:

Shame Boy
Mar 2, 2010

Max Facetime posted:

actually never mind, I agree there's no point trying to bait fishmech when he's right like usual

as fishmech correctly points out, for all their hundreds of years of history corporations have only ever existed literally, as legal fairytales adults read to each other to make themselves feel better

I guess you saw that one coming a mile away :frogbon:

that's not what stopping looks like friend

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

ate all the Oreos posted:

my favorite part of visiting vegas a while ago was the ticket clickers that swarm on you and try to give you ads for prostitutes, i hope they still have those

i have to ask what a "ticket clicker" is because it sort of sounds like victorian slang for a prostitute as it is

Wiggly Wayne DDS
Sep 11, 2010



well this certainly is a response to a security issue: https://beingwinsysadmin.blogspot.co.uk/2017/07/bug-windows-10-default-user-profile-is.html

Phrosphor
Feb 25, 2007

Urbanisation

Total VPN ban in China by 2018?

https://techcrunch.com/2017/07/10/china-vpn-ban/

spankmeister
Jun 15, 2008






Also Russia just passed a similar law.

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

Also Russia just passed a similar law.

yeah, also affecting sim card purchases, use of anonymisers. they are trying to curb people getting around the state firewall

Adbot
ADBOT LOVES YOU

Workaday Wizard
Oct 23, 2009

by Pragmatica
the only surprise is why didnt this happen earlier

  • Locked thread