Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Partycat
Oct 25, 2004

Would it be worse to put the Snowden app on your phone , knowing it would open you up to FSB backdoors - if it also locked out CIA backdoors ?

Adbot
ADBOT LOVES YOU

apseudonym
Feb 25, 2011

Partycat posted:

Would it be worse to put the Snowden app on your phone , knowing it would open you up to FSB backdoors - if it also locked out CIA backdoors ?

But it doesn't lock out anything...

Main Paineframe
Oct 27, 2010

Partycat posted:

Would it be worse to put the Snowden app on your phone , knowing it would open you up to FSB backdoors - if it also locked out CIA backdoors ?

the Snowden app doesn't lock out anything

it just logs data from the camera, mic, light sensor, accelerometer, and when certain conditions or triggers are met it sends the data to you and/or the FSB

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
when you convert the bytecode from the apk to human-readable, it exploits the interpreter and executes code on your desktop

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
weirdly, it's just a colour swapped version of GCHQ's cyber security advent calendar christmas tree

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Lain Iwakura posted:

when you convert the bytecode from the apk to human-readable, it exploits the interpreter and executes code on your desktop

At least then it would be interesting.

Bulgogi Hoagie
Jun 1, 2012

We
https://twitter.com/andysayler/status/944607187489509379

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
did anyone post this fortigate one https://securite.intrinsec.com/2017/12/22/cve-2017-7344-fortinet-forticlient-windows-privilege-escalation-at-logon/

Raere
Dec 13, 2007


ah, the 2017 version of 'press cancel at the login screen in windows 95 to log in anyway'

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
nice writeup about getting rce in win 10 by exploiting the jscript interpreter used to run proxy auto config scripts

https://googleprojectzero.blogspot.co.uk/2017/12/apacolypse-now-exploiting-windows-10-in_18.html

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
oh hey uber sucks https://medium.com/bread-and-circuses/how-i-got-paid-0-from-the-uber-security-bug-bounty-aa9646aa103f

Trabisnikof
Dec 24, 2005


and looks like hackerone too

Daman
Oct 28, 2011

to be fair, his first submissions are garbage begbounty style poo poo and probably set the tone for how the engineer would read his future reports

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Daman posted:

to be fair, his first submissions are garbage begbounty style poo poo and probably set the tone for how the engineer would read his future reports

"We already knew about this, and we also don't plan to fix it any time soon" is an incredibly bullshit reason to not pay out a bounty.

Truga
May 4, 2014
Lipstick Apathy
to be fair, if uber doesn't want to pay for low hanging bug bounties, maybe they should patch their issues

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
having non-expiring auth tokens and client-side logout seems really bad to me but what do i know

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe

Daman posted:

to be fair, his first submissions are garbage begbounty style poo poo and probably set the tone for how the engineer would read his future reports

also come the gently caress on, an engineer reads his final report in the wrong tone and decides that the correct course of action is to lock the report, fix the issue, not pay, and shadowban him????

Bulgogi Hoagie
Jun 1, 2012

We

Truga posted:

to be fair, if uber doesn't want to pay for low hanging bug bounties, maybe they should patch their issues

or at least document them

apseudonym
Feb 25, 2011

I'm not going to defend Uber but the first one is pretty dumb (and dumb on Uber making not having pinning a security bug).

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/whispersystems/status/944951877610831872

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug

:3:

Hed
Mar 31, 2004

Fun Shoe
lol. merry Christmas, ya filthy animals

DELETE CASCADE
Oct 25, 2017

i haven't washed my penis since i jerked it to a phtotograph of george w. bush in 2003

Hed posted:

lol. merry Christmas, ya filthy animals

give me some Hed

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
replace ‘Santa’ with ‘the UAE government’

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Don't be like Gori:

https://www.bleepingcomputer.com/news/security/man-threatened-company-with-cyber-attack-to-fire-employee-and-hire-him-instead/

quote:

North Carolina judge sentenced a Washington man this week to 37 months in prison for threatening a company with attacks unless they fire one of their employees and hire him instead.

According to court documents obtained by Bleeping Computer, on April 18, 2016, Todd Michael Gori sent an email to TSI Healthcare, a healthcare software vendor based in Chapel Hill, North Carolina.

Gori, a 28-year-old resident of Wenatchee, Washington, threatened the company with cyber attacks by him and unnamed friends if the company did not fire one of its employees and hire him instead.

Gori's email extortion
"I am giving you, TSI healthcare two choices," Gori wrote in the email. "You either lay-off [identity redacted] and replace her with me, an operator 100x better that she is oppressing. Or I will take out your entire company along with my comrades via a cyber attack."

According to the same letter, Gori was fueled by a personal vendetta after the same employee denied his job application several times in the past.

"Again you have two choices. Get ride of her and hire me. Or slowly be chipped away at until you are gone. She is a horrible operator that can only manage 2 screens with an over inflated travel budget. I fly at least 10x as many places as this loon on 1/5th of the budget," the email reads.

"I have petitioned for a job with you guys with her as a reference as I am a felon with computer skills and need assistance getting work as technically I have 'no work history'. She declines everytime and burries me even further."

Gori then bragged about having pen-tested TSI's website and having found weak security measures.

"'Im giving you guys 72 hours to respond until the attack goes full scale. There is nothing that can be done to stop the attacks. I have ran multiple penetration tests on your entire network and your company fails miserably.

"Again let me be clear. The only way I will work with TSI and stop the attack is to fire [identifying information redacted] and hire me and ensure I am compensated enough ..."

Gori allegedly threatened to shoot TSI employees
Gori did not detail the type of cyber-attack he was preparing. TSI turned to the FBI after receiving the email threat.

Authorities tracked down and arrested Gori in August 2017. According to the original indictment, the FBI charged Gori on more severe charges after they found out he also threatened to buy a gun and shoot TSI employees. Gori signed a plea agreement soon after his arrest, and prosecutors dropped this latter charge.

Besides the 37-month prison stint, Gori also received three years of supervised release.

"I'm a convicted felon and you'll never stop my attacks despite knowing my name and who I am because I desire a job with your company. I am a leet operator."

Workaday Wizard
Oct 23, 2009

by Pragmatica

quote:

replace her with me, an operator 100x better that she is oppressing

of course its a 4chan incel retard

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"
i dunno, the current employee can only manage 2 screens like a god drat chump

DrPossum
May 15, 2004

i am not a surgeon
Pull Request: Remove my password from lists so hackers won't be able to hack me

https://github.com/danielmiessler/SecLists/pull/155

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/cameo/status/945542159653937152

Main Paineframe
Oct 27, 2010

CommieGIR posted:

Don't be like Gori:

https://www.bleepingcomputer.com/news/security/man-threatened-company-with-cyber-attack-to-fire-employee-and-hire-him-instead/


"I'm a convicted felon and you'll never stop my attacks despite knowing my name and who I am because I desire a job with your company. I am a leet operator."

given his liking for posting insane rants on the internet under his real name, he's probably not getting hired any other way

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

CommieGIR posted:

Don't be like Gori:

https://www.bleepingcomputer.com/news/security/man-threatened-company-with-cyber-attack-to-fire-employee-and-hire-him-instead/


"I'm a convicted felon and you'll never stop my attacks despite knowing my name and who I am because I desire a job with your company. I am a leet operator."

I'm so close don't stop

Doom Mathematic
Sep 2, 2008

Isn't there like a lockable box you can get where people can drop packages? You give the delivery person the combination as a special instruction or something.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
like delivery drivers who won't even use the doorbell would ever care about that

vOv
Feb 8, 2014

ymgve posted:

like delivery drivers who won't even use the doorbell would ever care about that

i had a package marked as 'not at home' even though i live in an apartment complex with an intercom

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
amazon now has lockers in a lot of cities where they can leave your poo poo and you have three days to pick it up

DrPossum
May 15, 2004

i am not a surgeon

Cold on a Cob posted:

amazon now has lockers in a lot of cities where they can leave your poo poo and you have three days to pick it up

these are useful and lots of aparement complexes have their own version too

DJ Commie
Feb 29, 2004

Stupid drivers always breaking car, Gronk fix car...

Doom Mathematic posted:

Isn't there like a lockable box you can get where people can drop packages? You give the delivery person the combination as a special instruction or something.

like the post office has always had?

vOv
Feb 8, 2014

DJ Commie posted:

like the post office has always had?

only USPS can deliver to a PO box though

spankmeister
Jun 15, 2008






This whole concept of leaving packages out on people's porch is alien to me. Deliveries are made to a resident of the house, their neighbors or taken to the post office or w/e

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

spankmeister posted:

This whole concept of leaving packages out on people's porch is alien to me. Deliveries are made to a resident of the house, their neighbors or taken to the post office or w/e

"I don't have time to wait around for a package!" "How dare you hand my mail to someone else!" "You can't expect me to miss work to drive all the way to the post office!"

  • Locked thread