Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




e: wrongthread

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

devmd01 posted:

Just wrote a group policy and built out a plan to migrate all of our server local admin access to be completely managed by group policy, with access only granted through a serveradmin_%servername% security group for service accounts and support staff.

it will purge local admins every time policy runs and only assign the server name group dynamically. I have the security manager's buy-in, and I'll sell it to my team tomorrow with a POC demo.

from there, I'll build out RBAC for all of the support staff's admin accounts, because right now it's all over the place and we need to be able to assign team-level access to every server a team supports.

after that, implementing LAPS for servers as well.

drat that's some nice cjing.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

cinci zoo sniper posted:

so whats up with aws secret region and aws top secret airgapped region or whatever

aws can run a computer cheaper than most anyone else and even with a huge markup to pay for dealing with government bullshit and cage codes and poo poo it's price competitive for us government stuff

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
also fedramp is big and using govcloud checkboxes a lot of things

ate shit on live tv
Feb 15, 2004

by Azathoth

quote:


NoScript detected a potential Cross-Site Scripting attack

from https://forums.somethingawful.com to https://syndication.twitter.com.

Suspicious data:

(POST) l={"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932723792908050432"],"item_details":{"932723792908050432":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932640826844426240"],"item_details":{"932640826844426240":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932723792908050432"],"item_details":{"932723792908050432":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932723792908050432"],"item_details":{"932723792908050432":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932723792908050432"],"item_details":{"932723792908050432":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932293049027264517"],"item_details":{"932293049027264517":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932642318502584320"],"item_details":{"932642318502584320":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932641559245443072"],"item_details":{"932641559245443072":{"item_type":0}},"associations":{"4":{"association_id":"932642318502584320","association_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279611,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"conversation","component":"tweet","action":"results"}};{"widget_origin":"https://forums.somethingawful.com/newreply.php?action=newreply&postid=478595975","widget_frame":false,"message":null,"item_ids":["932723792908050432"],"item_details":{"932723792908050432":{"item_type":0}},"_category_":"tfw_client_event","triggered_on":1511239279612,"dnt":true,"client_version":"f1483d66:1511158958856","format_version":1,"event_namespace":{"client":"tfw","page":"tweet","section":"subject","component":"tweet","action":"results"}}

Security fuckup?

Pile Of Garbage
May 28, 2007



Bhodi posted:

also fedramp is big and using govcloud checkboxes a lot of things

reading the fedramp reports in o365 seccom is interesting as they have some pretty indepth deets on the architecture of GFS and azure. also lots of ticked boxes

spit on my clit
Jul 19, 2015

by Cyrano4747

umatrix is much better than noscript, i've found

Phone
Jul 30, 2005

親子丼をほしい。

Farmer Crack-rear end posted:

so do you guys have phone anxiety or what

:nsa:

Condiv
May 7, 2008

Sorry to undo the effort of paying a domestic abuser $10 to own this poster, but I am going to lose my dang mind if I keep seeing multiple posters who appear to be Baloogan.

With love,
a mod


so, am i about to have the joys of daily firmware updates of my cpu? or can i count on my vendor just not bothering and my cpu having a ton of open backdoors for hackers to abuse?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Condiv posted:

so, am i about to have the joys of daily firmware updates of my cpu? or can i count on my vendor just not bothering and my cpu having a ton of open backdoors for hackers to abuse?

depends on the vendor

i suspect that apple, microsoft surfaces, and chrome os boxes will get updates, and intel will make something for windows users available but it's a flip of the coin if they'll get msft to push it

flakeloaf
Feb 26, 2003

Still better than android clock

spit on my clit posted:

umatrix is much better than noscript, i've found

noscript is great for hijacking new browser windows to tell you about itself, which is like, irony or something

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

depends on the vendor

i suspect that apple, microsoft surfaces, and chrome os boxes will get updates, and intel will make something for windows users available but it's a flip of the coin if they'll get msft to push it
didn't they push the last updates? and linux will continue to get intel-firmware packages so i don't think delivery is an issue

Workaday Wizard
Oct 23, 2009

by Pragmatica

Cocoa Crispies posted:

or the drunkenly speed changing nokia ringer from "Crank"

so *thats* where that annoying ringtone came from

Rufus Ping posted:

classic Mr Hands

lomarf

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

lol no script

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

anthonypants posted:

didn't they push the last updates? and linux will continue to get intel-firmware packages so i don't think delivery is an issue

yes, microsoft routinely pushes intel and amd microcode updates through windows update on supported systems, don't see why they wouldn't push this at the appointed time.

of course some of the affected cpus are ones explicitly not supported for say someone insisting on running windows 7 on the latest hardware, but thats that user's own fault for doing that

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

anthonypants posted:

didn't they push the last updates? and linux will continue to get intel-firmware packages so i don't think delivery is an issue

idk windows is trash and i don't use it

cinci zoo sniper
Mar 15, 2013




Cocoa Crispies posted:

aws can run a computer cheaper than most anyone else and even with a huge markup to pay for dealing with government bullshit and cage codes and poo poo it's price competitive for us government stuff

oic

cheese-cube posted:

reading the fedramp reports in o365 seccom is interesting as they have some pretty indepth deets on the architecture of GFS and azure. also lots of ticked boxes

gps not the positioning system, right?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

cinci zoo sniper posted:

oic


gps not the positioning system, right?

gfs

Diva Cupcake
Aug 15, 2005

uber is a trashorg #7864
https://twitter.com/TheStalwart/status/933092923259760640
e: lol

quote:

Uber now says it had a legal obligation to report the hack to regulators and to drivers whose license numbers were taken. Instead, the company paid hackers $100,000 to delete the data and keep the breach quiet. Uber said it believes the information was never used but declined to disclose the identities of the attackers.

Diva Cupcake fucked around with this message at 23:14 on Nov 21, 2017

Carbon dioxide
Oct 9, 2012

Cool, so they 1. pay ransoms to hackers and 2. keep the hackers' identities secret. This is useful to know.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

ahahahhahaha

Main Paineframe
Oct 27, 2010
lmao

quote:

Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company.

pseudorandom name
May 6, 2007

secure loving fuckup:

https://twitter.com/SarahJamieLewis/status/933152571052605440
https://twitter.com/SarahJamieLewis/status/933152933524283392
https://twitter.com/SarahJamieLewis/status/933153209652146176
https://twitter.com/SarahJamieLewis/status/933153699970650113
https://twitter.com/SarahJamieLewis/status/933154709837266946
https://twitter.com/SarahJamieLewis/status/933155844471918592

https://twitter.com/SarahJamieLewis/status/933160463109468160

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Your not a real startup bro until you've committed at least a dozen aws secrets to GitHub.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

sarah is cool irl fyi

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i thought this was going to be "men started emailing blowjobs to women, harassing them" but it's not that so i'm not sure i understand what they're saying

hobbesmaster
Jan 28, 2008

mrmcd posted:

Your not a real startup bro until you've committed at least a dozen aws secrets to GitHub.

i do this constantly with toy or demo applications, gah

Proteus Jones
Feb 28, 2013



anthonypants posted:

i thought this was going to be "men started emailing blowjobs to women, harassing them" but it's not that so i'm not sure i understand what they're saying

Signature based identification of someone based on their custom blowjob, I think?

I don't know, I started getting confused around the idea of a blowjob device and sending people blowjob choreography. I'm not sure that was a market need going unfulfilled.

Main Paineframe
Oct 27, 2010

anthonypants posted:

i thought this was going to be "men started emailing blowjobs to women, harassing them" but it's not that so i'm not sure i understand what they're saying

for some reason pseudorandom left out the tweet that actually gets to the point:

https://twitter.com/SarahJamieLewis/status/933156388745895936

BattleMaster
Aug 14, 2000

I was expecting mangled dicks from malformed blowjob data

edit: hey look at that

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BattleMaster posted:

I was expecting mangled dicks from malformed blowjob data

edit: hey look at that

thread title

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
one thing i don't get is that if the email data was just the base64-encoded json data from your create-a-blowjob, why would that site need to keep a copy of your create-a-blowjob after it was emailed out, or did their xss allow them to generate a feed from all subsequent create-a-blowjobs

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
this is why in holding out for quantum blowjobs

Condiv
May 7, 2008

Sorry to undo the effort of paying a domestic abuser $10 to own this poster, but I am going to lose my dang mind if I keep seeing multiple posters who appear to be Baloogan.

With love,
a mod


this wouldn't have been a problem if they'd used the block chain

or rather, the blow chain

pseudorandom name
May 6, 2007

Main Paineframe posted:

for some reason pseudorandom left out the tweet that actually gets to the point:

https://twitter.com/SarahJamieLewis/status/933156388745895936

I was trying to edit it down to something a little more manageable and it turns out its hard to keep track of which tweets you've copied and pasted

haveblue
Aug 15, 2005



Toilet Rascal

anthonypants posted:

one thing i don't get is that if the email data was just the base64-encoded json data from your create-a-blowjob, why would that site need to keep a copy of your create-a-blowjob after it was emailed out, or did their xss allow them to generate a feed from all subsequent create-a-blowjobs

guessing how it works is that the interpreter for the base64 lives on their web service and the link invokes it with the base64 as an argument. then the client displays the unpacked blowjob profile in a web app where it's exploitable. no online storage needed, it lives only in the email but has to pass through the server and js frontend before being uploaded to the blowjob bot

haveblue fucked around with this message at 04:43 on Nov 22, 2017

hitze
Aug 28, 2007
Give me a dollar. No, the twenty. This is gonna blow your mind...

Security Fuckup Megathread - v14.1 - the client displays the unpacked blowjob profile

Main Paineframe
Oct 27, 2010

anthonypants posted:

one thing i don't get is that if the email data was just the base64-encoded json data from your create-a-blowjob, why would that site need to keep a copy of your create-a-blowjob after it was emailed out, or did their xss allow them to generate a feed from all subsequent create-a-blowjobs

judging from the way she describes it, I think the blowjob machine is controlled from the browser via the website. the base64 is just a parameter in the link that the site parses into instructions for the machine, which it then forwards to the machine probably via a plugin or something. naturally, no validation is done on those directions, so there's nothing to stop an attacker from base64-encoding dick_destroyer.js and sending it out as a blowjob link

if I'm reading those tweets right, it gets worse. because if the parsing encounters an illegal character, it just stops and dumps the rest of the decoded content into the page. so you could easily exploit that to insert an iframe into the page, and then load arbitrary scripts into that iframe. this could potentially be used to hijack however the site connects to the blowjob machine, and directly control it without needing to go through the site's code at all

that's my read on it

Zil
Jun 4, 2011

Satanically Summoned Citrus


Main Paineframe posted:

judging from the way she describes it, I think the blowjob machine is controlled from the browser via the website. the base64 is just a parameter in the link that the site parses into instructions for the machine, which it then forwards to the machine probably via a plugin or something. naturally, no validation is done on those directions, so there's nothing to stop an attacker from base64-encoding dick_destroyer.js and sending it out as a blowjob link

if I'm reading those tweets right, it gets worse. because if the parsing encounters an illegal character, it just stops and dumps the rest of the decoded content into the page. so you could easily exploit that to insert an iframe into the page, and then load arbitrary scripts into that iframe. this could potentially be used to hijack however the site connects to the blowjob machine, and directly control it without needing to go through the site's code at all

that's my read on it

dick_destroyer.js

Mods? Name change please?

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Main Paineframe posted:

judging from the way she describes it, I think the blowjob machine is controlled from the browser via the website. the base64 is just a parameter in the link that the site parses into instructions for the machine, which it then forwards to the machine probably via a plugin or something. naturally, no validation is done on those directions, so there's nothing to stop an attacker from base64-encoding dick_destroyer.js and sending it out as a blowjob link

if I'm reading those tweets right, it gets worse. because if the parsing encounters an illegal character, it just stops and dumps the rest of the decoded content into the page. so you could easily exploit that to insert an iframe into the page, and then load arbitrary scripts into that iframe. this could potentially be used to hijack however the site connects to the blowjob machine, and directly control it without needing to go through the site's code at all

that's my read on it
right and according to them they downloaded a bunch of blowjobs to put in a chart, which are also the ones on which they plan to do "blowjob fingerprinting". so those blowjobs either exist in storage on that server, or they were actively intercepting all blowjob traffic over some period of time. i feel like there's something missing from their story.

  • Locked thread