Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


What's Upguard?

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos

Cup Runneth Over posted:

What's Upguard?

Not bad, how about you?

Mr Chips
Jun 27, 2007
Whose arse do I have to blow smoke up to get rid of this baby?

Cup Runneth Over posted:

What's Upguard?

UpGuard is the first cyber resilience platform designed to reduce risk of outages and breaches by managing configurations, IT processes, and vendor risk.

Double Punctuation
Dec 30, 2009

Ships were made for sinking;
Whiskey made for drinking;
If we were made of cellophane
We'd all get stinking drunk much faster!
So a money hole then?

Klyith
Aug 3, 2007

GBS Pledge Week

Thanks Ants posted:

For some reason I'm shocked that @fart does Serious Work

oh, I was wondering why http://www.smashmouth.com got a zero on their CSTAR score

Furism
Feb 21, 2006

Live long and headbang
A friend wanted to give Signal a try. So we did. Now he has a mobile plan with no data. But Signal (which now replaces my Text app in Android) insists on trying to send the messages to him over Signal and not SMS. I can't find any way to tell Signal "this person doesn't use Signal anymore, please send it over SMS, yes I know it's poo poo and not encrypted anymore."

What am I missing? This doesn't seem like much of a loophole nobody ran into before.

Tamba
Apr 5, 2010

When the send icon is blue, it will try to send the messge over Signal.

Long press that and you can chose between Signal messages and SMS.

e: or tell your friend to use this:
https://whispersystems.org/textsecure/unregister/

Tamba fucked around with this message at 13:04 on Aug 21, 2017

Furism
Feb 21, 2006

Live long and headbang

Tamba posted:

Long press that and you can chose between Signal messages and SMS.

Oh for gently caress's sake.

Thanks!

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Unfortunately that doesn't stick and every sender has to remember to do it every time they send a message, so he should consider just unregistering if he doesn't have proper data

Furism
Feb 21, 2006

Live long and headbang

Rufus Ping posted:

Unfortunately that doesn't stick and every sender has to remember to do it every time they send a message, so he should consider just unregistering if he doesn't have proper data

Absolutely, I'll have him do that, but that's a good workaround (and overall trick, I never considered trying to hold the button to check for an alternative way of sending).

PBS
Sep 21, 2015
*snip*

PBS fucked around with this message at 17:10 on Sep 4, 2017

Boris Galerkin
Dec 17, 2011

I don't understand why I can't harass people online. Seriously, somebody please explain why I shouldn't be allowed to stalk others on social media!
I just bought the new IKEA smart light system as a impulse buy to play with before figuring out if I want to keep it or not. Never had another iot device before. This one comes with a hub that I plug into my network.

Link: http://m.ikea.com/us/en/catalog/products/art/90353361/

How do I plug it in without getting my network pwned? For what it's worth my home network is a edge router lite -> hub -> wifi . There is an unused port on my router still. Is my understanding correct that plugging the ikea hub into that second unused port will isolate it from my wifi/pc network?

Thanks Ants
May 21, 2004

#essereFerrari


Create a second VLAN for all the IoT stuff so that you can apply much harsher ACLs. You may have to put some IP-helpers in place so that your phone on your normal Wi-Fi network can get to the restricted IoT network though.

For what it's worth, an assessment of the Ikea product was quite encouraging https://www.iot-tests.org/2017/04/ikea-tradfri-a-smart-light-in-the-darkness-of-iot-security/

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Boris Galerkin posted:

I just bought the new IKEA smart light system as a impulse buy to play with before figuring out if I want to keep it or not. Never had another iot device before. This one comes with a hub that I plug into my network.

Link: http://m.ikea.com/us/en/catalog/products/art/90353361/

How do I plug it in without getting my network pwned? For what it's worth my home network is a edge router lite -> hub -> wifi . There is an unused port on my router still. Is my understanding correct that plugging the ikea hub into that second unused port will isolate it from my wifi/pc network?

If it's actually a router and not a switch, you would configure that unused port on its own network with an ACL preventing access to your other subnet. There's more around IoT security of course, but that segments it from your other devices. Note that that makes it trickier to control those lights from devices on your "trusted" network.

wolrah
May 8, 2006
what?
An ERL is a three-port router and yes, using the extra ethernet port will isolate the hub from the network.

Even if it was a switch, many routers with built-in switches actually have basic managed switch chipsets which can be accessed by the user, if not on the official firmware then almost certainly with OpenWRT or similar if available.

As noted the Ikea hub at least at this point seems to be well implemented, though we'll see if that changes as they add features.

Rectus
Apr 27, 2008

Also, you can unplug the gateway at anytime, and the lights will still work with the remote pucks. I bought one, but realized I didn't have much use of the gateway (apart from a timer when traveling), so I just keep it unplugged.

orange sky
May 7, 2007

What's the best introductory book to hacking/pentesting/vulnerability exploiting?

I am a consultant that works mostly on enterprise environments with Microsoft stuff, but I'm bored of this and want to switch to a more security based role.

Stuff I know:

- Computer architectures. Did Assembly in school and a shitload of programming languages, including object oriented;
- General tools. I've tried out Mimikatz, for example, to get a feel for what it can do;
- Basic terminology for malware - delivery, payload, exploit, C2;
- Network protocols, I studied everything including BGP but could probably use a refresh;

What I don't know:

- I don't yet work with github that much. It seems like a shitload of trouble looking for projects where I might have any know-how and be able to help. But I know that having a good github profile will get you jobs. Any tips on where to start out here would be very good;
- Everything about hacking history, main hacking targets & weak spots, etc;
- What to do next. This seems like a very, very big area;

Any help would be appreciated.

Diva Cupcake
Aug 15, 2005

I would say the Georgia Weidman book is pretty boss as far as introductory penetration testing skills and methodologies go. It lines up pretty well as a study guide for OSCP as well.

Hacker Playbook 2 is also good.

Furism
Feb 21, 2006

Live long and headbang

Check your PMs.

ufarn
May 30, 2009
"The Web Application Hacker's Handbook" seems to be the bible of websec, and everyone and their dog bring it up. It'd probably at least be a good book to have on your shelf.

LochNessMonster
Feb 3, 2005

I need about three fitty


Furism posted:

Check your PMs.

I'm looking to move in the same direction. Could you PM me the same info?

orange sky
May 7, 2007

Thank you all for your help guys! Got a lot to go through already :)

Talas
Aug 27, 2005

I would also like some recommendations on the side of IS Risk Management and Auditing. I already have a CISM, but I would like to do more way more reading about this topics.

Thanks in advance.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
Yeah, a good part of commercial infosec is auditing and regulatory compliance, which is a field that you might not run into otherwise doing IT/dev. Check out PCI standards, and get familiar with the requirements of HIPAA, FERPA, etc.

Oh whoops you just mentioned this ... thought I'd just make note of it while I'm about. I learned about PCI from just reading the standards documents online, they're very helpfully written.

Vvv Oh yeah, http://csrc.nist.gov/publications/PubsSPs.html and specifically 800-30: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

dougdrums fucked around with this message at 20:22 on Aug 31, 2017

Furism
Feb 21, 2006

Live long and headbang

Talas posted:

I would also like some recommendations on the side of IS Risk Management and Auditing. I already have a CISM, but I would like to do more way more reading about this topics.

Thanks in advance.

It's probably not deep enough for you, but one of the 12 domains of the CISSP covers Risk Management so you might want to read that bit?

It's too bad guys, something like 1 month ago there was an InfoSec ebook bundle on Humble Bundle :/

CLAM DOWN
Feb 13, 2007




Reading cissp material is enough to make me want to off myself out of boredom. Why am I doing this.

Furism
Feb 21, 2006

Live long and headbang

CLAM DOWN posted:

Reading cissp material is enough to make me want to off myself out of boredom. Why am I doing this.

I have to admit I can't do much more than 1 hour at a time. But it's great high-level reference material I think. Really worried about being able to spit it back out for the exam though.

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
Yeah it's all incredibly dull. If I were to do this as my career forever I think I'd go into LE instead. I'm sure LE have their share of boring poo poo, but it still seems like a much more useful and interesting gig.

CLAM DOWN
Feb 13, 2007




Furism posted:

I have to admit I can't do much more than 1 hour at a time. But it's great high-level reference material I think. Really worried about being able to spit it back out for the exam though.

The most boring part to me is that most of it is review as I've been working in various parts of infosec for a while, but I just know that the exam is going to require me to spit out specific tidbits and the very thought of that makes me want to puke then eat my own puke

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
EveryMicrosoftExamEver.jpg

some kinda jackal
Feb 25, 2003

 
 

CLAM DOWN posted:

Reading cissp material is enough to make me want to off myself out of boredom. Why am I doing this.

Oof, this post brought back unpleasant memories.

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Martytoof posted:

Oof, this post brought back unpleasant memories.

Get the app that customize the tests for your weak subjects. Just remember that on the test they will mix answers from out subjects that sound acceptable if you second guess yourself .

That was the one thing that will trip you up seriously.

Solaron
Sep 6, 2007

Whatever the reason you're on Mars, I'm glad you're there, and I wish I was with you.

Talas posted:

I would also like some recommendations on the side of IS Risk Management and Auditing. I already have a CISM, but I would like to do more way more reading about this topics.

Thanks in advance.

I got my CISSP earlier this year which has turned into a new job in IT RIsk and Controls - and while my security background and the CISSP have both been valuable, I definitely don't feel super comfortable compared to my previous job in Ops. I had someone recommend a book to me - Information Assurance Handbook by Dr. Corey Schou and Steve Hernandez - but I would welcome other recommendations. I would especially love anything audio (podcasts, audiobooks, etc) because I have a pretty good hike back and forth to my car now and need to fill up that time with something.

Wicaeed
Feb 8, 2005
Is it common practice for a third party we use to host an external support website (these guys are pretty large too) to ask for the following?

quote:

We do not fulfill CSR requests and it should not be necessary in order to retrieve the certificate information from the provider.
 
For SSL renewals, please attach the following:
 
New SSL certificate
Respective Private KEY
Bundle (Intermediate and Root certificates)
* If a PASSWORD is required to open the .ZIP file, please make sure you enclose it in a .txt document.
 
Please do not email the files. Please attach the files to the case in one of the following formats only: .txt or .pem format.

Doesn't sending the private keys to someone that didn't generate them defeat one of the basic points of a loving private key? :confused:

EVIL Gibson
Mar 23, 2001

Internet of Things is just someone else's computer that people can't help attaching cameras and door locks to!
:vapes:
Switchblade Switcharoo

Wicaeed posted:

Is it common practice for a third party we use to host an external support website (these guys are pretty large too) to ask for the following?


Doesn't sending the private keys to someone that didn't generate them defeat one of the basic points of a loving private key? :confused:

It is pretty loving strange they are asking for the exact thing they need to fully pretend to be your company.

What is exactly happening? It says they are not filling out a CSR ; renewal?

Ask them why they need the private key since that will allow them to create their own certs that identify as you. Are they looking for ways to identify you are saying who you are? Easy way is to sign something using the private key and they'll be able to identify using the public keys they already have. Or go through, I dunno, the loving CSR process which is built for this exact situation?

EVIL Gibson fucked around with this message at 19:06 on Sep 1, 2017

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Wicaeed posted:

Is it common practice for a third party we use to host an external support website (these guys are pretty large too) to ask for the following?


Doesn't sending the private keys to someone that didn't generate them defeat one of the basic points of a loving private key? :confused:

What are you trying to do here? Renew a cert? I would say you are extremely correct to be suspect of this request. I can't imagine a world in which they would need your private key for any reason other than to pretend to be your company.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Presumably the cert they want is one for support.acmecorp.com or whatever

Bit stupid they can't just handle the issuance/renewal themselves once you've set up the CNAME at your end though

Thanks Ants
May 21, 2004

#essereFerrari


I don't see a good reason to request that the customer provides a cert any more when certbot is a thing.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Allowing a custom one to be uploaded (for e.g. EV) would kinda make sense but yes I agree

Adbot
ADBOT LOVES YOU

Pablo Bluth
Sep 7, 2007

I've made a huge mistake.
I listen out of curiosity rather than any relevance to anything I do, but I've take to listening to the weekly Risky Business podcast on my way to work and find most of it pretty interesting.

https://risky.biz/

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply