Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Lockpick village would be hard to replicate online. That place is so fun.

Adbot
ADBOT LOVES YOU

wolrah
May 8, 2006
what?

EVIL Gibson posted:

The flipping charge list is accusing him of helping develop the malware to be better and getting paid for it with the people that were using it for profit.

Doing that is not research.

Reread the second sentence of mine that you quoted. I completely agree that as far as this guy in particular it looks like they have some legitimate charges, but the post I was replying to was speaking in absolutes as if there aren't all sorts of ways for purely legitimate security researchers to end up considered criminals if they embarrass the wrong person/company.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

wolrah posted:

Reread the second sentence of mine that you quoted. I completely agree that as far as this guy in particular it looks like they have some legitimate charges, but the post I was replying to was speaking in absolutes as if there aren't all sorts of ways for purely legitimate security researchers to end up considered criminals if they embarrass the wrong person/company.

And I am agreeing with you and have seen people tell stories how close they were for being curious and looking into something a company would considered criminal (like looking at your engine stats through Bluetooth and how people found out about Volvo's emission cheatery).

I was saying the moment you are purposely working to make something that will negatively affect others in any way you are no longer a researcher and actually an attacker now.

Kerning Chameleon
Apr 8, 2015

by Cyrano4747
I think we all need a good laugh right now:

Petition to open source Flash and Shockwave spec

quote:

Adobe is going to stop distributing and updating Flash player and the Shockwave player. That's ok.

However Flash along with its sister project Shockwave is an important piece of Internet history and killing Flash and Shockwave means future generations can't access the past. Games, experiments and websites would be forgotten.

Open sourcing Flash and the Shockwave spec would be a good solution to keep Flash and Shockwave projects alive safely for archive reasons. Don't know how, but that's the beauty of open source: you never know what will come up after you go open source! There might be a way to convert swf/fla/drc/dir to HTML5/canvas/webgl/webassembly, or some might write a standalone player for it. Another possibility would be to have a separate browser. We're not saying Flash and Shockwave player should be preserved as is.

We understand that there can be licensed components you might not be able to release. Simply leave them out with a note explaining what was removed. We will either bypass them, or replace them with open source alternatives.

Star this repository to sign the petition. Pull requests are also welcome. Add cool Flash and Shockwave links here and reasons to open source Flash and Shockwave.

This petition will be delivered to Adobe.

(found posted unironically on the Pale Moon forums, as if you needed any more excuses to avoid the Firefox knock-off like the plague)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Kerning Chameleon posted:

quote:

Open sourcing Flash and the Shockwave spec would be a good solution to keep Flash and Shockwave projects alive safely for archive reasons. Don't know how, but that's the beauty of open source:
Brilliant.

maskenfreiheit
Dec 30, 2004
i mean it probably would be nice if all the newgrounds stuff doesn't just disappear

(still waiting on pico 2 btw!)

Kerning Chameleon
Apr 8, 2015

by Cyrano4747

maskenfreiheit posted:

i mean it probably would be nice if all the newgrounds stuff doesn't just disappear

(still waiting on pico 2 btw!)

Hot take: It would be nice if all the Newgrounds stuff did disappear.

Also, Newgrounds itself.

Thanks Ants
May 21, 2004

#essereFerrari



Look they just provide the ideas.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I'm an Ideas Guy. And my ideas are terrible.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Incomplete open source implementations of Flash have been around for a long time. I worked a bit on one in the early 2000s, and there have been many since (Gordon and Shumway the most recent serious ones).

Being able to run Flash content in JS and avoid the native code attack surface would have been great (and plausibly faster), but it's a big job even with Adobe's cooperation.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
It definitely would be nice if the source code was provided under a non commercial license of some kind solely for archivists.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

They could likely never do that, they don't have sufficient rights to big pieces of it (like the H.264 stuff).

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Subjunctive posted:

They could likely never do that, they don't have sufficient rights to big pieces of it (like the H.264 stuff).

We also don't need a Mozilla-esque like setup for Flash.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Lain Iwakura posted:

We also don't need a Mozilla-esque like setup for Flash.

They could get someone to take it on, probably. Mozilla already hosts some of one of their script engines.

vOv
Feb 8, 2014

Kerning Chameleon posted:

I think we all need a good laugh right now:

Petition to open source Flash and Shockwave spec


(found posted unironically on the Pale Moon forums, as if you needed any more excuses to avoid the Firefox knock-off like the plague)

This is unironically good though. Digital cultural archiving is a big thing and it'd be lovely if it all got lost.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Adobe has published an incomplete spec for years, but the licensing terms on it make it useless.

The Fool
Oct 16, 2003


vOv posted:

This is unironically good though. Digital cultural archiving is a big thing and it'd be lovely if it all got lost.

Because virtual machines and archived installers don't exist.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Just keep a computer that still has Flash in a museum somewhere.

Not connected to the Internet, obviously. Give it SWF files through a thumb drive and keep backups.

Volguus
Mar 3, 2009

vOv posted:

This is unironically good though. Digital cultural archiving is a big thing and it'd be lovely if it all got lost.

This is one piece of software that i would not feel sorry if it got lost into ether.

maskenfreiheit
Dec 30, 2004

Subjunctive posted:

They could get someone to take it on, probably. Mozilla already hosts some of one of their script engines.

if mozilla takes on chrome after claiming they don't have enough resources to support thunderbind i'm lobbing piss filled water balloons on their precious deck from the chrome team balcony

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

There are resources to support tbird, it's just not a good use of them.

BelDin
Jan 29, 2001

vOv posted:

This is unironically good though. Digital cultural archiving is a big thing and it'd be lovely if it all got lost.

Yeah, how will future generations be able to play Dance Dance Karnov without it?

maskenfreiheit
Dec 30, 2004

Subjunctive posted:

There are resources to support tbird, it's just not a good use of them.

WRONG.

LAME.

FAKE NEWS

Volguus posted:

This is one piece of software that i would not feel sorry if it got lost into ether.

there's a big difference between open sourcing with an emphasis on playing existing media and active development. i don't think anyone advocates continued development just keeping it working so we can play existing media (and maybe export to a less lovely format)

vOv
Feb 8, 2014

maskenfreiheit posted:

there's a big difference between open sourcing with an emphasis on playing existing media and active development. i don't think anyone advocates continued development just keeping it working so we can play existing media (and maybe export to a less lovely format)

Yeah this. I'd be perfectly happy if nobody ever made anything new in flash.

The Fool posted:

Because virtual machines and archived installers don't exist.

IIRC the Linux version isn't as good so if you do want to go this route then you'd also have to store Windows ISOs and deal with whatever antipiracy they have (and be OK with people having to break the law to experience old Internet culture).

Absurd Alhazred
Mar 27, 2010

by Athanatos
Yeah, it would be sad if nobody ever got to experience Strong Bad Emails, discovering Easter eggs themselves, ever again. :smith:

maskenfreiheit
Dec 30, 2004

Absurd Alhazred posted:

Yeah, it would be sad if nobody ever got to experience Strong Bad Emails, discovering Easter eggs themselves, ever again. :smith:

HOW CAN FLASH BE BAD IF HOMESTAR IS GOOD. RIDDLE ME THAT LINUX HUFFERS

Absurd Alhazred
Mar 27, 2010

by Athanatos

maskenfreiheit posted:

HOW CAN FLASH BE BAD IF HOMESTAR IS GOOD. RIDDLE ME THAT LINUX HUFFERS

Don't let your compy be eaten by Linux, folks!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

maskenfreiheit posted:

HOW CAN FLASH BE BAD IF HOMESTAR IS GOOD. RIDDLE ME THAT LINUX HUFFERS
They have a cartoon about that, too.

https://www.youtube.com/watch?v=L0nuQ5o2DYU&hd=1

RFC2324
Jun 7, 2012

http 418

fsack would be a great username

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



RFC2324 posted:

fsack would be a great username

Nope, nope, nope, the Land of Ten Thousand Nopes.

Diva Cupcake
Aug 15, 2005

So this appears to be v bad.

CLAM DOWN
Feb 13, 2007




Diva Cupcake posted:

So this appears to be v bad.



What does?

e: oh weird, there's an image there but it's 404ing for me for whatever reason, can you rehost on imgur?

The Fool
Oct 16, 2003


CLAM DOWN posted:

What does?

e: oh weird, there's an image there but it's 404ing for me for whatever reason, can you rehost on imgur?

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8620

quote:

A remote code execution vulnerability exists when Windows Search handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit the vulnerability, the attacker could send specially crafted messages to the Windows Search service. An attacker with access to a target computer could exploit this vulnerability to elevate privileges and take control of the computer. Additionally, in an enterprise scenario, a remote unauthenticated attacker could remotely trigger the vulnerability through an SMB connection and then take control of a target computer.
The security update addresses the vulnerability by correcting how Windows Search handles objects in memory.

CLAM DOWN
Feb 13, 2007




loving :lol: that sounds amazing, I want more details

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

Yeah, but how often does a program handle objects in memory?

mewse
May 2, 2006

Thermopyle posted:

Yeah, but how often does a program handle objects in memory?

Only a few high end CAD packages I think

Diva Cupcake
Aug 15, 2005

It's a no-priv RCE with a POC already in existence per the NIST calc. Good thing is that wsearch shouldn't be enabled by default on most servers.

https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?calculator&version=3&vector=(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)

Daman
Oct 28, 2011

Diva Cupcake posted:

It's a post-auth guest-privs-minimum RCE with a POC already in existence per the NIST calc. Good thing is that wsearch shouldn't be enabled by default on most servers.

https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?calculator&version=3&vector=(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)

fixed

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

...said 1% of all system administrators.

Adbot
ADBOT LOVES YOU

maskenfreiheit
Dec 30, 2004
so i'm working on my oscp and the general workflow seems to be:

get into the windows box

scan for one of a myriad of smb vulns

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply