Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

im the well-named and properly self-documenting backdoor functions

e: there's even structs that start with "CCBkdr" what a thoughtful hack

better documented than my coworkers' code (thousand lines long sql scripts, commentless)

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



aug 15th- sep 12th means a lot of shoddy it support companies doing updates post-emotet 'fixed' a lot of machines

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Cocoa Crispies posted:

gg on shipping the debug symbols

they didn't ship the debug symbols, just the link to the debug symbols: a UUID and the original path to the PDB file. what's worrying is that they apparently compromised one of the developer machines, because it appears the malware was built there

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
on the other hand: that looks like the symbols for the installer itself, not the malware part, which is probably just a self-contained .obj dropped somewhere on the build machine and sneakily added to the linker's command line. from how it's described to work, it's trivial to make it self-contained: the payload is saved in a big static array, and the bootstrap function is registered as a TLS constructor by declaring a pointer to it in one of the specially named sections that the linker merges to form the array of TLS constructors

Wiggly Wayne DDS
Sep 11, 2010



in the wild memory leak in apache for non-default configs:

https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html

FlapYoJacks
Feb 12, 2009

Lol, Apache is such an unadulterated gigantic poo poo show.

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet




"Optionsbleed"

gently caress everything

Schadenboner
Aug 15, 2011

by Shine

mrmcd posted:

Not a lawyer, so just pure speculation: If you get arrested and had previously written "the code is 1-2-3-4" on your arm, and the cop saw that and unlocked the phone with all the evidence, I seriously doubt any court is going to consider that a violation of your rights. Facial unlock seems more or less like writing the pin code of your face in magic iPhone-only readable ink. I guess what I'm saying is if you're the kind of person who likes to commit crimes or doesn't trust police, don't use biometric unlock features. :shrug:

I don't mean that in a "well, if you have nothing to hide..." kinda way. Rather it's a choice to get more convenient/faster unlocking, in exchange for only defending against random thefts and snoops, and not advesaries targeting you specifically who may or may not enjoy a bit of the ultraviolence.

Literally no-one should trust cops. Hth, Bunk.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


lmbo

Jewel
May 2, 2009

lol if you ever use a tool that says it "cleans your registry to make things crash less" and "delete old files and settings to make your computer run faster"

Shame Boy
Mar 2, 2010

Pikavangelist posted:

"Optionsbleed"

gently caress everything

quote:

That clearly looked interesting - and dangerous. It suspiciously looked like a "bleed"-style bug, which has become a name for bugs where arbitrary pieces of memory are leaked to a potential attacker.

:mrwhite:

Pile Of Garbage
May 28, 2007




lmao i know what our SCCM guys will be doing tomorrow

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Wiggly Wayne DDS posted:

aug 15th- sep 12th means a lot of shoddy it support companies doing updates post-emotet 'fixed' a lot of machines

wait, what was emotet

Pile Of Garbage
May 28, 2007



imhotep imhotep imhotep

Wiggly Wayne DDS
Sep 11, 2010



fishmech posted:

wait, what was emotet
banking malware that changed tactics lately and decided to target organisations and load other malware as well, doesn't it have a wiki article? they've been dabbling in lateral movement as well

Wiggly Wayne DDS
Sep 11, 2010



i got fed up with the yosmas present i sent last year not being solved and made a thread for it https://forums.somethingawful.com/showthread.php?threadid=3834637

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug
everyone that thinks police won't try to hold you indefinitely for not giving up your password if they think it's protecting relevant evidence realize that's already happening in the USA right?

like the biggest current trial is a excop cp sharing dude so they purposely chose the least appealing person to build case law off of, but the end result for everyone else is going to be the same if they win

necrotic
Aug 2, 2005
I owe my brother big time for this!
huh this story is familiar

https://arstechnica.com/information-technology/2017/09/devs-unknowingly-use-malicious-modules-put-into-official-python-repository/

Pile Of Garbage
May 28, 2007



pr0zac posted:

everyone that thinks police won't try to hold you indefinitely for not giving up your password if they think it's protecting relevant evidence realize that's already happening in the USA right?

like the biggest current trial is a excop cp sharing dude so they purposely chose the least appealing person to build case law off of, but the end result for everyone else is going to be the same if they win

what if you have 2FA using an OTP app on a phone you leave at home in another country and don't have with you when you go through customs and you don't have secondary 2FA like SMS configured so you literally cannot give them your password?

Schadenboner
Aug 15, 2011

by Shine

cheese-cube posted:

what if you have 2FA using an OTP app on a phone you leave at home in another country and don't have with you when you go through customs and you don't have secondary 2FA like SMS configured so you literally cannot give them your password?

It's :shobon: as gently caress that you think this would, in any way, protect you or limit the length of your detention.

Pile Of Garbage
May 28, 2007



Schadenboner posted:

It's :shobon: as gently caress that you think this would, in any way, protect you or limit the length of your detention.

when did i even imply that it would you fuckin bonehead? i was just wondering how they'd respond in such a situation (prolly still infinite detention i guess)

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



or if you're really worried about customs digging through your phone, make a backup beforehand, wipe your phone, and hand it to them to look over.

Mr. Nice!
Oct 13, 2005

c-spam cannot afford



i mean if we're posting crackpot theories on how to hide from cbp. basically gently caress cbp.

cinci zoo sniper
Mar 15, 2013





yeah i posted it not even 2 pages ago i think

necrotic
Aug 2, 2005
I owe my brother big time for this!
ah totally missed that.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

the real option is a shadow os on phones/laptops.

There was a story about kevin mitnick (or someone) going to the border and getting hauled aside and told to log on to his laptop so they could check it. He had some other account setup and logged on with that showing that it was just a boring old windows account or something.

The real pro-tip: fly without anything and buy a chromebook/phone when you land and sell/return when you leave. But if you're that paranoid just don't travel at all.

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

cheese-cube posted:

what if you have 2FA using an OTP app on a phone you leave at home in another country and don't have with you when you go through customs and you don't have secondary 2FA like SMS configured so you literally cannot give them your password?

im not talking about customs, im talking about being arrested by the police in the usa, customs as a non American you already have zero rights

Wiggly Wayne DDS
Sep 11, 2010



https://www.piriform.com/news/blog/...t-windows-users

quote:

At this stage, we don’t want to speculate how the unauthorized code appeared in the CCleaner software, where the attack originated from, how long it was being prepared and who stood behind it. The investigation is still ongoing. We want to thank the Avast Threat Labs for their help and assistance with this analysis.
i'm also the

quote:

The code then read a reply from the same IP address, providing it with the functionality to download a second stage payload from the aforementioned IP address. The second stage payload is received as a custom base64-encoded string, further encrypted by the same xor-based encryption algorithm as all the strings in the first stage code. We have not detected an execution of the second stage payload and believe that its activation is highly unlikely.

Main Paineframe
Oct 27, 2010

pr0zac posted:

everyone that thinks police won't try to hold you indefinitely for not giving up your password if they think it's protecting relevant evidence realize that's already happening in the USA right?

like the biggest current trial is a excop cp sharing dude so they purposely chose the least appealing person to build case law off of, but the end result for everyone else is going to be the same if they win

there's a world of difference between "cop pulled you over and decided to rifle through your phone while he's there" and "police have good reason to believe your electronics are full of illegal poo poo and got a search warrant and court order for your electronics"

cinci zoo sniper
Mar 15, 2013





im the last 7 words in the i'm also the

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Mr. Nice! posted:

or if you're really worried about customs digging through your phone, make a backup beforehand, wipe your phone, and hand it to them to look over.

like that won't get you detained, interrogated and refused entry

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Optimus_Rhyme posted:

the real option is a shadow os on phones/laptops.

thegrugq works or is otherwise involved in a company making shadow os phones. for obvious reasons they don't advertise a lot, the photos on the site are completely unbranded devices, and they aren't mass marketed. iirc they don't even list prices

Shame Boy
Mar 2, 2010

Optimus_Rhyme posted:

the real option is a shadow os on phones/laptops.

There was a story about kevin mitnick (or someone) going to the border and getting hauled aside and told to log on to his laptop so they could check it. He had some other account setup and logged on with that showing that it was just a boring old windows account or something.

The real pro-tip: fly without anything and buy a chromebook/phone when you land and sell/return when you leave. But if you're that paranoid just don't travel at all.

i don't know if i would trust anything kevin mitnick says about himself ever

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

pr0zac posted:

im not talking about customs, im talking about being arrested by the police in the usa, customs as a non American you already have zero rights

I thought everyone had the same rights with customs (nil), and it was immigration that Americans had an advantage with

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

i don't know if i would trust anything kevin mitnick says about himself ever
i could be mistaken but it was my understanding that you could set up a kind of "panic button"-type logon for truecrypt/veracrypt, where you put in a password and it takes you to a fake desktop, which is functional but doesn't have all your supersecret hacker junk on it

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Subjunctive posted:

I thought everyone had the same rights with customs (nil), and it was immigration that Americans had an advantage with

if you can prove american citizenship, you can not be prevented from entering the country and you aren't supposed to be detained for more than a few hours
none of your possessions have the right of entry
and ofc the normal police can then detain you as soon as customs clears you

wolrah
May 8, 2006
what?

anthonypants posted:

i could be mistaken but it was my understanding that you could set up a kind of "panic button"-type logon for truecrypt/veracrypt, where you put in a password and it takes you to a fake desktop, which is functional but doesn't have all your supersecret hacker junk on it

https://veracrypt.codeplex.com/wikipage?title=Hidden%20Volume
https://veracrypt.codeplex.com/wikipage?title=VeraCrypt%20Hidden%20Operating%20System


The catch is that the decoy OS doesn't know the hidden one exists, it just thinks that's blank space. Inadvertently writing too much data to the disk can start to overwrite the hidden partition. Depending on how you set it up this can make things complicated if you want to keep your decoy OS plausibly used and up-to-date.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

CLAM DOWN posted:

https://nakedsecurity.sophos.com/2017/09/17/vevo-hacked-3-12-tb-of-data-leaked/

quote:

Vevo hacked, 3.12 TB of data leaked

...

A Vevo spokesperson said to Gizmodo on Friday:

(We) can confirm that Vevo experienced a data breach as a result of a phishing scam via LinkedIn. We have addressed the issue and are investigating the extent of exposure.

...





aaahaahahaahhaahahahahaha

jammyozzy
Dec 7, 2006

Is that a challenge?
Some nice security questions for my council's website...

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

b-b-b-b--but why is linkedin blocked

  • Locked thread