Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

qat

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013





DIIGI!I!!

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



gershon & kingsley - peanuts.mp3

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


my battle.net authenticator went off from a chinese request, i rejected it ofc and changed my b.net password but it made me wonder something

maybe this is a dumb question but idk about security, anyway

barring physical access, could an attacker have taken control of my account or gathered information to do so later through my actions? (denying their request, logging in (and accepting mine), and changing my password, in that order and within five minutes of seeing the notice)

geonetix
Mar 6, 2011


make sure your secret question is something that cannot be guessed or reasonable circumvented ("I entered garbage as the answer"), that's the only way forward for an attacker

likely though your password was just leaked and someone is trying to hit it on all things, try haveibeenpwned

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


geonetix posted:

make sure your secret question is something that cannot be guessed or reasonable circumvented ("I entered garbage as the answer"), that's the only way forward for an attacker

likely though your password was just leaked and someone is trying to hit it on all things, try haveibeenpwned

haw, that revealed the cause straight off: wildstar loving me from the grave (i was lazy with it and reused my b.net password there 'cos they were both under separate 2FA anyway)

thanks for that, didn't know about haveibeenpwned

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


's what i get for playing loving mmos (and being lazy)

spankmeister
Jun 15, 2008






Speaking of MMO's: Here's a podcast in two parts about hacking online games. It's pretty good. They interview "Manfred" a guy who's apparently a big deal in the mmo hacking scene. You may remember the ultima online house deletion debacle, well this guy did it and he explains how. He also explains how he made a living for years by cloning items and gold in MMO's and selling them on eBay.


https://darknetdiaries.com/episode/7
https://darknetdiaries.com/episode/8

geonetix
Mar 6, 2011


Ciaphas posted:

haw, that revealed the cause straight off: wildstar loving me from the grave (i was lazy with it and reused my b.net password there 'cos they were both under separate 2FA anyway)

thanks for that, didn't know about haveibeenpwned

np buddy. just be aware that blizzards password forgotten procedure is still completely nuts, so be careful


also mmos and security are fun, wasn't a goon in an anti-cheat role with eve online at some point?

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


thank goodness for lastpass memorizing most good passwords for me nowadays (i know i know i should use keepass, blame work)

Wiggly Wayne DDS
Sep 11, 2010



good news

https://twitter.com/taviso/status/938509218805514240

Cybernetic Vermin
Apr 18, 2005


do you have a clearer grasp of the context than i do, the chain starts with looking in the a steam folder, is there more to suggest that this is a steam issue being chased down or are there other details?

Proteus Jones
Feb 28, 2013



Cybernetic Vermin posted:

do you have a clearer grasp of the context than i do, the chain starts with looking in the a steam folder, is there more to suggest that this is a steam issue being chased down or are there other details?

Steam?

I thought Battlenet was a Blizzard thing.

Wiggly Wayne DDS
Sep 11, 2010



it starts with steam then someone points at battle.net

it's all low handing fruit everyone's known forever and no one's bothered to fix

Cybernetic Vermin
Apr 18, 2005

Proteus Jones posted:

Steam?

I thought Battlenet was a Blizzard thing.

oh, didn't even read the link, clicked localbattle.net and firefox errored out of loading and i didn't dig deeper into it

Jewel
May 2, 2009

I still don't quite get it, it's hinting at RCE in battlenet but.. what is localbattle.net? Like, that's not a registered domain and I cant find anything in the battle.net client that hosts some kind of web interface access like some programs do. And googling that url only returns that taviso tweet.

Raere
Dec 13, 2007

Taviso works in mysterious ways

Cybernetic Vermin
Apr 18, 2005

while i do appreciate his sense of drama i don't appreciate the sense of the world crumbling around me that it induces

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
the steam thing is him complaining that valve is still using the app directory for config and games and poo poo because nobody used %appdata% in 2003 and therefore they don't do it in 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Jewel posted:

I still don't quite get it, it's hinting at RCE in battlenet but.. what is localbattle.net? Like, that's not a registered domain and I cant find anything in the battle.net client that hosts some kind of web interface access like some programs do. And googling that url only returns that taviso tweet.
it points to localhost. if you have the blizzard app open https://localbattle.net:22885 in a web browser

the certificate is almost certainly so they can do secure traffic relating to drm

anthonypants fucked around with this message at 20:27 on Dec 9, 2017

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

spankmeister posted:

Speaking of MMO's: Here's a podcast in two parts about hacking online games. It's pretty good. They interview "Manfred" a guy who's apparently a big deal in the mmo hacking scene. You may remember the ultima online house deletion debacle, well this guy did it and he explains how. He also explains how he made a living for years by cloning items and gold in MMO's and selling them on eBay.


https://darknetdiaries.com/episode/7
https://darknetdiaries.com/episode/8

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

apseudonym
Feb 25, 2011

anthonypants posted:

it points to localhost. if you have the blizzard app open https://localbattle.net:22885 in a web browser

the certificate is almost certainly so they can do secure traffic relating to drm

That cert should get revoked so hard. I'm sure Ryan will have fun https://twitter.com/sleevi_/status/939574006759424006

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
perhaps someone should put that cert into crt.sh

Workaday Wizard
Oct 23, 2009

by Pragmatica

Optimus_Rhyme posted:

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

youtube suck balllllllllllllls and not in the good way 🤬🤬🤬🤬🤬🤬

spankmeister
Jun 15, 2008






Optimus_Rhyme posted:

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

pretty sure blizzard DMCA'd it or something.

Dylan16807
May 12, 2010

Optimus_Rhyme posted:

I was gonna reply to a link to his awesome DEFCON talk but NOOOOOPE youtube took it down

https://www.youtube.com/watch?v=PfbMZJsb1cQ&hd=1

well a quick search found this link. seems to be the presentation. http://www120.zippyshare.com/v/qq5Tatj5/file.html


spankmeister posted:

pretty sure blizzard DMCA'd it or something.

arenanet because of some GW2 exploit? DMCA abuse sucks, this has nothing to do with copyright.

evil_bunnY
Apr 2, 2003

spankmeister posted:

pretty sure blizzard DMCA'd it or something.
the guild wars people, actually.

Dylan16807 posted:

arenanet because of some GW2 exploit? DMCA abuse sucks, this has nothing to do with copyright.
it’s mega dumb and abused constantly

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender

evil_bunnY posted:

it’s mega dumb and abused constantly
dsyp

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
https://twitter.com/mjg59/status/939661304997953536

e:

https://twitter.com/mjg59/status/939666525736206336

Mr.Radar fucked around with this message at 02:28 on Dec 10, 2017

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
guess who made it to ars

https://arstechnica.com/information-technology/2017/12/top-selling-handgun-safe-can-be-remotely-opened-in-seconds-no-pin-needed/

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:



why does a gun safe have bluetooth

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i dunno, ask Harik

Shame Boy
Mar 2, 2010

quote:

In an e-mail, Vaultek officials said the attack demonstrated in the video would be hard to execute.

"What you are not seeing is the prep time required to isolate the correct code and the time required to study the safe and it's transmissions, and the subsequent decoding time needed to generate the final code," company officials wrote. "This can take hours of work and also requires the ability to observe a correctly paired phone."

:allears:

spit on my clit
Jul 19, 2015

by Cyrano4747
https://twitter.com/kinugawamasato/status/939866903513767936

so glad i hopped over to uMatrix.

hobbesmaster
Jan 28, 2008

I’m sorely disappointed that vaultek safes don’t have giant impractical cog doors

Shame Boy
Mar 2, 2010

i think we've talked about this stupid wifi rock before but i just re-discovered it and still think it's ridiculous so here:



https://dojo.bullguard.com/

quote:

Dojo constantly studies your home network to enhance and protect at all times. Dojo never sleeps and is always adapting, planning and protecting your network.

...

The pebble is free to move about your home and glows when there is activity that needs to be addressed in the app, and is designed so it doesn't need to be yet another thing you line up next to your TV.

let the pebble freely move about your house, adapting and plotting

quote:

Dojo actually learns! It gets to know your devices and finds patterns in their total behavior. Using this intelligence, it then sets up a perimeter that protects your home and makes sure that you are in total control. Nothing gets in or out.
Dojo's sophisticated defense system utilizes pattern recognition to learn to detect threats. It does this without having to look at the data or knowing what's attacking. Dojo can simply block them. It listens to patterns, not your data, to keep your home safe and your data private.

they also love the phrase "enterprise-grade security" which is always great

as far as i can tell from the instructions you connect it to your network and then it logs into your router by itself and disables DHCP and then starts broadcasting its own, so your devices connect to it first and then it forwards everything through the router

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

ate all the Oreos posted:

they also love the phrase "enterprise-grade security" which is always great

as far as i can tell from the instructions you connect it to your network and then it logs into your router by itself and disables DHCP and then starts broadcasting its own, so your devices connect to it first and then it forwards everything through the router

you forgot the part of enterprise-grade security where there's only two groups that have access, one of them is read-only with a symbol-for-char substituted password and the elevated credentials are admin:admin.

Phone
Jul 30, 2005

親子丼をほしい。
enterprise grade security is just a fancy way of saying "a bunch of post its stuck to your monitor"

Varkk
Apr 17, 2004

Phone posted:

enterprise grade security is just a fancy way of saying "a bunch of post its stuck to your monitor"

I am pretty sure that is military spec
https://www.google.co.nz/amp/s/nakedsecurity.sophos.com/2012/11/21/prince-william-photos-password/amp/

Adbot
ADBOT LOVES YOU

DrPossum
May 15, 2004

i am not a surgeon

I like umatrix but god help you if you want to play an embedded video and aren't an internationally renowned whackamole competitor

  • Locked thread