Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


ate all the Oreos posted:

today my friend managed to catch in code review one of our shittier devs' "solution" to running tasks remotely.

anyone wanna guess what it was doing?

it was literally just netcat piped to sh of course!

this was going to be installed on a customer's corporate network :stonk:

i'm a neophyte when it comes to remote execution or IPC or whatever, what IS the 'correct' thing to do when you have a task to farm out

Adbot
ADBOT LOVES YOU

power botton
Nov 2, 2011

Ciaphas posted:

i'm a neophyte when it comes to remote execution or IPC or whatever, what IS the 'correct' thing to do when you have a task to farm out

cron job/scheduled task then delete it after the job runs

Haquer
Nov 15, 2009

That windswept look...
i once used netcat for a quick and dirty eve online in game chat monitoring script and even though it didn't go past my local network I felt dirty as gently caress

Shame Boy
Mar 2, 2010

Ciaphas posted:

i'm a neophyte when it comes to remote execution or IPC or whatever, what IS the 'correct' thing to do when you have a task to farm out

in this case we needed one specific task to run on demand when called from our server (it retrieved some data and packaged it up and sent it to us, we can't access the place the data's coming from directly so it's really just being a proxy / reformatter thing), there's infinity better ways to do it but at least using SSH instead of accepting arbitrary user input on a raw TCP socket and piping it directly to the shell would be a, uh, start

e: to be completely fair it was connecting out to our server rather than opening a port and listening so it would have at least required, what, one extra step to gently caress poo poo up real bad?

DJ Commie
Feb 29, 2004

Stupid drivers always breaking car, Gronk fix car...

Deep Dish Fuckfest posted:

the term is "unix philosophy"

its not a crash, its a stall man

Haquer
Nov 15, 2009

That windswept look...
:raise:

Storysmith
Dec 31, 2006

ate all the Oreos posted:

in this case we needed one specific task to run on demand when called from our server (it retrieved some data and packaged it up and sent it to us, we can't access the place the data's coming from directly so it's really just being a proxy / reformatter thing), there's infinity better ways to do it but at least using SSH instead of accepting arbitrary user input on a raw TCP socket and piping it directly to the shell would be a, uh, start

e: to be completely fair it was connecting out to our server rather than opening a port and listening so it would have at least required, what, one extra step to gently caress poo poo up real bad?

if only distributed worker queues that connect to a central server to get work were a solved problem they could literally just include a library for. they could resque themselves from this fuckup using some other developer's work, but that would just make the coder into some kind of sidekiq
activemq

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


funnily enough that activemq thing is totally new to me and may be just the ticket for a side project i've wanted to do for a while at work

so thanks for that :v:

Shame Boy
Mar 2, 2010

Storysmith posted:

if only distributed worker queues that connect to a central server to get work were a solved problem they could literally just include a library for. they could resque themselves from this fuckup using some other developer's work, but that would just make the coder into some kind of sidekiq
activemq

at the same time another team has built a distributed worker queue into a project that it's totally not appropriate for and it's fuckin' poo poo up

my company is kinda dum

Wiggly Wayne DDS
Sep 11, 2010



some fun quirks between win32 and nt apis https://googleprojectzero.blogspot.co.uk/2017/08/windows-exploitation-tricks-arbitrary.html

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
we got our pentest results back and it turns out that when you have asas on an ancient firmware revision you're probably exposed to ancient cves

reportedly they had tried to update the firmware on these asas at one point, but couldn't because there wasn't enough memory on them or something. we have a bad networking guy who's been tasked with moving the vpn endpoint from these asas to different ones but it's been months and he's made literally zero progress until this week, because my boss is freaking out about this critical vulnerability on our network that we've had for the past year and a half.


update: my boss had not read the cisco advisory and didn't understand why i wanted to shut down vpn services sooner rather than wait for all the other crap to get migrated off first

anthonypants fucked around with this message at 21:04 on Aug 8, 2017

ohgodwhat
Aug 6, 2005

My company is trying to build a fault/partition tolerant distributed, auditable database on top of a message broker without using any of the useful and relevant features the message broker provides because nobody involved has ever read any documentation.

necrotic
Aug 2, 2005
I owe my brother big time for this!
Good username post combo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
upguard found a bunch of data from some energy infrastructure company a month ago https://www.upguard.com/breaches/data-leak-pqe

spankmeister
Jun 15, 2008






What's upguard?

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
not much how about you

power botton
Nov 2, 2011

isnt that fart's company

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
yes

https://piss.io/2016-cybersecurity-report-for-pizza-only-8d8a76020b5d

spankmeister
Jun 15, 2008






Kuvo posted:

not much how about you

That was the joke thank you for getting it (not being sarcastic)

spankmeister
Jun 15, 2008






It's very confusing to read something by fart that is serious

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

It's very confusing to read something by fart that is serious
it helps that the domain is piss dot io

Hed
Mar 31, 2004

Fun Shoe

anthonypants posted:

we got our pentest results back and it turns out that when you have asas on an ancient firmware revision you're probably exposed to ancient cves

reportedly they had tried to update the firmware on these asas at one point, but couldn't because there wasn't enough memory on them or something. we have a bad networking guy who's been tasked with moving the vpn endpoint from these asas to different ones but it's been months and he's made literally zero progress until this week, because my boss is freaking out about this critical vulnerability on our network that we've had for the past year and a half.


update: my boss had not read the cisco advisory and didn't understand why i wanted to shut down vpn services sooner rather than wait for all the other crap to get migrated off first

it's been like 15 years since my experience but if you have smartnet on the ASA (which I assume you do because new firmware) and they release a firmware that's too big won't they send you an updated one with enough RAM?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Hed posted:

it's been like 15 years since my experience but if you have smartnet on the ASA (which I assume you do because new firmware) and they release a firmware that's too big won't they send you an updated one with enough RAM?
idk about smartnet but they won't even send us replacements for the devices affected by the C2000 bug

Partycat
Oct 25, 2004

No they wont, and you can't renew it indefinitely. They pretty clearly announce the last date to attach a service contract, which at that point will be hardware only.

If your primary business growth appliance acquisition vector is eBay or one of those lovely refurb vendors then god help you. Smartnet won't save you when an 8 year old raccoon attack vector wrecks your MSP from the inside out

Agile Vector
May 21, 2007

scrum bored



gonna go out on a limb and call it Fartnet

Storysmith
Dec 31, 2006

https://twitter.com/ken5m1th/status/895110528221290496

time to make the 0days

Schadenboner
Aug 15, 2011

by Shine

Dunkin Donuts is trash, patronized only by same.

Phrosphor
Feb 25, 2007

Urbanisation

Why does this earth need a dunkin' donuts app?

quote:

Fresh from the oven we bring the new app Dunkin 'Coffee. So that you enjoy coupons and promotions in your Dunkin 'favorites. Where is the nearest? Enter the shopping section and we'll show the closest.

A round and very sweet option!

Gobbeldygook
May 13, 2009
Hates Native American people and tries to justify their genocides.

Put this racist on ignore immediately!
restaurant rewards accounts/apps are a very soft target. lots of people have their starbucks, steak 'n shake, etc account linked to their bank account/credit card.

Phrosphor posted:

Why does this earth need a dunkin' donuts app?
rewards points + make orders so they are ready for pickup when you get there.

geonetix
Mar 6, 2011


nist has some very cynical people in their copywriting department

Jamsta
Dec 16, 2006

Oh you want some too? Fuck you!

edit: haddock

Jamsta fucked around with this message at 11:25 on Aug 9, 2017

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Schadenboner posted:

Dunkin Donuts is trash, patronized only by same.

i don't know if this is coffee bait but it's good, actually

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

CommunistPancake posted:

i don't know if this is coffee bait but it's good, actually

I am on a trip to Canada and drinking Tim Horton's coffee right now, and DD is a bad version of Tim Hortons. Then again Timmy's is about as good as you get for massive corporate chain coffee.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

geonetix posted:

nist has some very cynical people in their copywriting department



... Nice?

MononcQc
May 29, 2007

mrmcd posted:

I am on a trip to Canada and drinking Tim Horton's coffee right now, and DD is a bad version of Tim Hortons. Then again Timmy's is about as good as you get for massive corporate chain coffee.

The general rule is that Tim Horton's was good in the 90s. By the early 2000s, they decided to stop having fresh donuts and whatnot (instead shipping frozen stuff from Ontario). Somewhere in the last few years, they also changed their coffee providers and most people ended up complaining about the change. From the regulars I know, Tim Horton's is pretty bad across the line now, and McDonald's coffee is probably a safer bet.

fisting by many
Dec 25, 2009



mrmcd posted:

I am on a trip to Canada and drinking Tim Horton's coffee right now, and DD is a bad version of Tim Hortons. Then again Timmy's is about as good as you get for massive corporate chain coffee.

this and the dunkin donuts reminded me that for a while last year tim's was pushing a dual credit card/gift card (maybe they still are :shrug:)

it was a tim horton's branded visa but it had buttons on the card to switch between gift card mode and credit card mode (and a led to indicate which mode the card was active) and of course you could have the credit card automatically recharge the gift card for convenience

i swear this is a real thing that actually got made

maybe it was just in toronto, the only canadian city where people would be dumb enough to get one

e: also to make things worse canada has had nearly universal tap-to-pay on credit and bank cards for a few years now so it's several additional levels of complication

fisting by many fucked around with this message at 14:50 on Aug 9, 2017

Shaggar
Apr 26, 2006
tim hortons is terrible and got laughed out of the us. dd is good, mcdonalds is good. starbucks is burnt dumpster beans

FAT32 SHAMER
Aug 16, 2012



Shaggar posted:

tim hortons is terrible and got laughed out of the us. dd is good, mcdonalds is good. starbucks is burnt dumpster beans

they're everywhere here in Detroit

OJ MIST 2 THE DICK
Sep 11, 2008

Anytime I need to see your face I just close my eyes
And I am taken to a place
Where your crystal minds and magenta feelings
Take up shelter in the base of my spine
Sweet like a chica cherry cola

-Cheap Trick

Nap Ghost

Gobbeldygook posted:

restaurant rewards accounts/apps are a very soft target. lots of people have their starbucks, steak 'n shake, etc account linked to their bank account/credit card.

someone once put a bunch of fraudulent charges on my dunkin card



but that's because someone broke into my card and stole the giftcard

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

fisting by many posted:

i swear this is a real thing that actually got made

maybe it was just in toronto, the only canadian city where people would be dumb enough to get one

it's a real thing available across canada? https://www.cibc.com/ca/doubledoublecard/index.html

it was so big they ran out of the first run of cards in a couple of weeks

  • Locked thread