Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Raere posted:

i think 56k is still used for oob in some places as like a tertiary way to connect to a crashed remote server that you cant easily get to

yeah, the place i used to work at had three us robotics modems (and who knew they were still going?) at each of the thousand or so telephone exchanges they had kit in - one for testing lines at the exchange, one for out-of-band console management, and one as an absolute last resort for emergency calls over voip (i.e. if the exchange suffered a total loss of connectivity, calls from customers to 112/999 could still be routed back to the core using a pots line from another provider)

the last one is being phased out for a cell modem but the first two are going to be there pretty much forever (or at least as long as pots is a thing which probably isn't that long)

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


We use several thousand modems for out of band access as well.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

https://bugs.chromium.org/p/project-zero/issues/detail?id=1527&desc=2

In which Tavis, hallowed be his name, reveals that a keylogger you voluntarily install in your browser might not have the best security practices.

flakeloaf
Feb 26, 2003

Still better than android clock

quote:

The Grammarly chrome extension (approx ~22M users) exposes it's auth tokens

exposes it is auth tokens, huh?

i hear there's a browser extension for that

quote:

That grauth token matches the grauth cookie used on grammarly.com, and I verified that is enough to login to a grammarly.com account. Therefore any website can access all your docs.

lomarf, chome

chomarf

MononcQc
May 29, 2007

I don't recall seeing this one in here https://github.com/dxa4481/cssInjection

quote:

CSS attribute selectors developers to select elements based on substring matches of the value of attribute tags.

[...]

An unfortunate by-product of this is, sensitive information can sometimes be stored in html attribute values. Most often, CSRF tokens are stored this way: in value attributes on hidden forms.

This allows us to match CSS selectors to the attributes on the form in question, and based on whether the form matches the starting string, load an extrenal resource such as a background image, which signals to the attacker the first charecter.

Using this method, they can walk down the string, and exfiltrate the entire secret value.

[...]

To do this without iFrames, I've used a method similiar to one I've discussed before: I'll create a popup and then alter the location of the popup after a set timer.

Using this method, I can still load the victim's CSS, but I no longer depend on the victim being frameable. Because the initial pop-up is triggered via user event, I am not blocked by the browser.

akadajet
Sep 14, 2003

mrmcd posted:

https://bugs.chromium.org/p/project-zero/issues/detail?id=1527&desc=2

In which Tavis, hallowed be his name, reveals that a keylogger you voluntarily install in your browser might not have the best security practices.

yeah, but it prevents me from making embarrassing typos

Shame Boy
Mar 2, 2010

MononcQc posted:

I don't recall seeing this one in here https://github.com/dxa4481/cssInjection

that's super clever

Jewel
May 2, 2009

ah the hawaii guy found work again

https://twitter.com/accuweather/status/960874208715853824

flakeloaf
Feb 26, 2003

Still better than android clock

attention passengers this is your pilot speaking, everything is perfectly fine and there's nothing to worry about

well uh yes this organization has complete confidence in its coaching staff, we like our front office and we have no plans for personnel changes at this time

there is definitely no tsunami coming to kill all of you today

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
https://www.youtube.com/watch?v=lTzByQTeyJQ

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

flakeloaf posted:

exposes it is auth tokens, huh?

i hear there's a browser extension for that

:xd:

taqueso
Mar 8, 2004


:911:
:wookie: :thermidor: :wookie:
:dehumanize:

:pirate::hf::tinfoil:

BattleMaster posted:

true enough, for some reason they still make 8051s and 68HC11s

My company still sells products that run on 8051s, too. No need to redesign them if we can still buy the processors.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

MononcQc posted:

I don't recall seeing this one in here https://github.com/dxa4481/cssInjection

Slick

EMILY BLUNTS
Jan 1, 2005

8051 will outlive the cockroaches that outlive humanity

30 TO 50 FERAL HOG
Mar 2, 2005



mrmcd posted:

https://bugs.chromium.org/p/project-zero/issues/detail?id=1527&desc=2

In which Tavis, hallowed be his name, reveals that a keylogger you voluntarily install in your browser might not have the best security practices.

lomarf

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
looks like big T.O. gave them high marks for response time though

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
only tangentially an infosec fuckup https://twitter.com/fail0verflow/status/960894909304786945

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

love those guys

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

love those guys
:yossame:

motoh
Oct 16, 2012

The clack of a light autocannon going off is just how you know everything's alright.
https://twitter.com/warrenellis/status/960888792570875904

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
owned, strong unique password havers

Pryor on Fire
May 14, 2013

they don't know all alien abduction experiences can be explained by people thinking saving private ryan was a documentary

I never knew someone out there would really get me, would really understand, until I met her, the one, the amazing person who also chose slayer69

30 TO 50 FERAL HOG
Mar 2, 2005




omg yea

Phone
Jul 30, 2005

親子丼をほしい。
hunter2 is all single moms with 2 kids :thunk:

akadajet
Sep 14, 2003


https://twitter.com/EpicLPer/status/960895465763065856

yeah, linux does that

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost
but the screenname isn't shaggar....

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

EMILY BLUNTS posted:

8051 will outlive the cockroaches that outlive humanity

I think I have 8051s in my Bosch ECUs

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

fishmech posted:

Winmodems run fine on Linux and os x and bsd. For that matter most computers could do it fully in software at this point, it's trivial, so long as supplied with a Winmodem like set of interface parts.


Also idk why the hell you assume "it's 15 bucks it must be bad". People host dang bbses on those things with excellent uptime

and, when I tried it in 2004, BeOS

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

BattleMaster posted:

true enough, for some reason they still make 8051s and 68HC11s

and greenarrays still makes FORTH chips, for less understandable reasons

Cybernetic Vermin
Apr 18, 2005

atomicthumbs posted:

and greenarrays still makes FORTH chips, for less understandable reasons

near as i can tell they have been around for less than 10 years, so while perhaps a weird design they probably should not be lumped in with legacy chips being around because they are used in old designs

Bulgakov
Mar 8, 2009


рукописи не горят

i'll be impressed when honest rad-hardened 8051 chips can be had on alibababa for cents

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

hahahahahahahaha

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/961318014355296256

this laptop prevents phishing e-mails i guess

Trabisnikof
Dec 24, 2005


it should just ship without a nic

Shame Boy
Mar 2, 2010

im a "visual hacking attempt"

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

im a "visual hacking attempt"

anime is banned from yospos

flakeloaf
Feb 26, 2003

Still better than android clock

what language was that press release google translated from

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

flakeloaf posted:

what language was that press release google translated from

MBA

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Who is the marketing genius that wrote that turd.

Adbot
ADBOT LOVES YOU

You Am I
May 20, 2001

Me @ your poasting


I bet the weblink goes to a phishing site

  • Locked thread