Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

NEED MORE MILK posted:

Just use your internal CA and AD to deploy an internal root w/ GPO

this might work if it was just us. but this needs to work with the computers in both the customer's organization and in our organization.

poo poo's hosed

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

spankmeister posted:

Windows only very recently took font rendering out of the kernel sooo.

therefore ios still having a font rendering bug is good, actually

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
one of my banks just sent me an unsolicited e-mail with the subject "your temporary password". i clicked on it thinking that someone was trying to reset my bank password, but nope, it's worse that that:



:stonk: do i even need to count the ways this is bad? (yes, they included the password in the text of the e-mail)

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Mr.Radar posted:

one of my banks just sent me an unsolicited e-mail with the subject "your temporary password". i clicked on it thinking that someone was trying to reset my bank password, but nope, it's worse that that:



:stonk: do i even need to count the ways this is bad? (yes, they included the password in the text of the e-mail)

Get a new bank.

Salt Fish
Sep 11, 2003

Cybernetic Crumb
Why does anyone bother with 2-factor when we've already created the perfect and most secure authentication scheme possible, social security?

spankmeister
Jun 15, 2008






Is this one of those "You can get code exec if you have code exec!" bugs?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

spankmeister posted:

Is this one of those "You can get code exec if you have code exec!" bugs?

If you mean that banking password email, they just emailed in plain text a password, which is bad. And they explicitly stated the schema for generating these passwords, which is worse. And it's generated from information which is not excessively difficult to get, which is terrible.

Now how difficult is it to get the user names?

spankmeister
Jun 15, 2008






No I'm sorry but I was talking about the apple screenshot thing

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

spankmeister posted:

No I'm sorry but I was talking about the apple screenshot thing

Oh. Yeah, for me the big issue is I never considered that the default screenshot tool would be available to a sandboxed program. So I'm like "fuuuuuuck, what else did I not think about?"

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.

Avenging_Mikon posted:

If you mean that banking password email, they just emailed in plain text a password, which is bad. And they explicitly stated the schema for generating these passwords, which is worse. And it's generated from information which is not excessively difficult to get, which is terrible.

Now how difficult is it to get the user names?

don't forget that you won't even be able to change your "password" until their new site launches in more than a week. better hope nobody logs in with your username before you do

edit: could someone tweet my screenshot to @associatedbank with a scolding message? i'd do it myself but my twitter profile contains my irl name which is obv problematic in this context

Mr.Radar fucked around with this message at 18:20 on Feb 15, 2018

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
Heads up, there's a problematic OpenType ligature that triggers a heap buffer overrun in CoreText's OpenType layout engine, crashing... well, pretty much any macOS or iOS application that shows text. I found a workaround for macOS but it's a little involved:
  • reboot in recovery mode and open a terminal (Utilities → Terminal)
  • run the following command to disable System Integrity Protection (SIP): csrutil disable
  • reboot again, in normal mode
  • from a terminal, run the following command to uninstall one of the fonts that triggers the crash: sudo mv /System/Library/Fonts/KohinoorTelugu.ttc /System/Library/Fonts/KohinoorTelugu.ttc.bak. You may have to re-enter your password for confirmation. It's a font for the Indian Telugu script so I imagine... almost none of you will be affected
  • reboot in recovery mode again, and open a terminal
  • run the following command to re-enable SIP: csrutil enable
  • reboot in normal mode for the last time
Pass it on

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
oh, look what happened again

at some point amazon is going to have to start forcing credentialed access to s3 storage buckets just to prevent idiots from stepping on their own dicks

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

hackbunny posted:

Heads up, there's a problematic OpenType ligature that triggers a heap buffer overrun in CoreText's OpenType layout engine, crashing... well, pretty much any macOS or iOS application that shows text. I found a workaround for macOS but it's a little involved:
  • reboot in recovery mode and open a terminal (Utilities → Terminal)
  • run the following command to disable System Integrity Protection (SIP): csrutil disable
  • reboot again, in normal mode
  • from a terminal, run the following command to uninstall one of the fonts that triggers the crash: sudo mv /System/Library/Fonts/KohinoorTelugu.ttc /System/Library/Fonts/KohinoorTelugu.ttc.bak. You may have to re-enter your password for confirmation. It's a font for the Indian Telugu script so I imagine... almost none of you will be affected
  • reboot in recovery mode again, and open a terminal
  • run the following command to re-enable SIP: csrutil enable
  • reboot in normal mode for the last time
Pass it on

Solution for phones: cry

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

ChubbyThePhat posted:

Solution for phones: cry

Backup often, stay in airplane mode as much as possible, wait patiently for patch ¯\_(ツ)_/¯

Depending on how hard you're hit, you may have to nuke the device to stop the crash-reboot-crash loop. This is where frequent backups come in

e: VVV I heard that too

hackbunny fucked around with this message at 19:44 on Feb 15, 2018

Daman
Oct 28, 2011
ios beta fixes it

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



hackbunny posted:

Heads up, there's a problematic OpenType ligature that triggers a heap buffer overrun in CoreText's OpenType layout engine, crashing... well, pretty much any macOS or iOS application that shows text. I found a workaround for macOS but it's a little involved:
  • reboot in recovery mode and open a terminal (Utilities → Terminal)
  • run the following command to disable System Integrity Protection (SIP): csrutil disable
  • reboot again, in normal mode
  • from a terminal, run the following command to uninstall one of the fonts that triggers the crash: sudo mv /System/Library/Fonts/KohinoorTelugu.ttc /System/Library/Fonts/KohinoorTelugu.ttc.bak. You may have to re-enter your password for confirmation. It's a font for the Indian Telugu script so I imagine... almost none of you will be affected
  • reboot in recovery mode again, and open a terminal
  • run the following command to re-enable SIP: csrutil enable
  • reboot in normal mode for the last time
Pass it on

ehh is turning off SIP such a good idea?

i mean if you get a file with the character in it, you can delete the file without opening it once youve recovered from your crash right? so far this doesnt give RCE or anything does it?

Cybernetic Vermin
Apr 18, 2005

Daman posted:

ios beta fixes it

yeah, by the timing the exploit was most likely derived from the fix delivered in the beta

lends some hope that apple has finally gotten around to properly fuzzing this, surely eminently fuzzable, bit of code

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Krankenstyle posted:

ehh is turning off SIP such a good idea?

i mean if you get a file with the character in it, you can delete the file without opening it once youve recovered from your crash right? so far this doesnt give RCE or anything does it?
you're only supposed to disable sip temporarily in order to rename the .ttc file. the post you're quoting instructs the reader to re-enable it afterward.

haveblue
Aug 15, 2005



Toilet Rascal

Krankenstyle posted:

ehh is turning off SIP such a good idea?

sip protects against abuse of root/sudo permission, turning it off doesn't turn off all the other layers of defense

also as above you are instructed to immediately turn it back on

e: "just delete the file after" may not work because the file may be examined by background services at any moment. this is why it can ruin an iphone, the string ends up somewhere that's automatically processed with no chance to avert it

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



and you cant delete the file in recovery mode??

i just dont see the point i guess

Shame Boy
Mar 2, 2010

Krankenstyle posted:

and you cant delete the file in recovery mode??

i just dont see the point i guess

osx works in weird ways

for example to keep the OS from eating this one USB device I needed direct access to I had to install a fake kext that claims to require the device and then do nothing with it (literally a config file in a folder with nothing else in it). the only way to do this without disabling all the security stuff is if you have a kext signing certificate, which costs money and you can only get by submitting a very good reason as to why you need it to apple. as far as i can tell you can't just install your own CA cert either. guess i just get to disable signature checking forever now, thanks guys!

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
my favourite is "this kext literally prevents the machine from booting", you want to remove it? gently caress you, disable all your security first.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Krankenstyle posted:

ehh is turning off SIP such a good idea?

It's not a good idea and that's why you reenable it in the next to last step

wolrah
May 8, 2006
what?

Shaggar posted:

sure, but has windows ever had a font vulnerability that bricked your computer? bsod and restart definitely, but not rendering your device unbootable afaik.
One of the common "softmod" techniques for the original Xbox was an exploit for a vulnerability in its (Windows 2000 derived) TrueType implementations. Early versions of the exploit could effectively brick the system by causing it to get in to an infinite loop of crashing on boot if the RTC's capacitor ran dry. If you backed up your hard drive lock code you could just restore the original font pretty easily, but if you did not do that you were effectively bricked without a modchip.

Not exactly Windows but not entirely not-Windows, and definitely more bricked than just requiring a reload of firmware. I believe the same issue did exist in related versions of desktop Windows, so if web page delivered fonts had been a thing at the time it could have been exploited in a "drive-by" fashion. An attacker wanting to "brick" systems as a result could replace a system font with one triggering the glitch similar to the Xbox exploit and the system would be rendered about equally useless to the average user as an iPhone requiring a DFU reload.

Wiggly Wayne DDS
Sep 11, 2010



a fun work in progress: https://www.nccgroup.trust/uk/about...ide-of-the-lab/

Notorious b.s.d.
Jan 25, 2003

by Reene

Wheany posted:

this might work if it was just us. but this needs to work with the computers in both the customer's organization and in our organization.

poo poo's hosed

public ssl certificate for a private hostname was the right answer

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



oh poo poo this owns


i really want to see what the output of this would be on our network as my guess is f 'you're hosed', but I think our security team are ignoring me after I reported our own hr system as a phishing risk so I guess I'll never know

Shaggar
Apr 26, 2006

wolrah posted:

One of the common "softmod" techniques for the original Xbox was an exploit for a vulnerability in its (Windows 2000 derived) TrueType implementations. Early versions of the exploit could effectively brick the system by causing it to get in to an infinite loop of crashing on boot if the RTC's capacitor ran dry. If you backed up your hard drive lock code you could just restore the original font pretty easily, but if you did not do that you were effectively bricked without a modchip.

Not exactly Windows but not entirely not-Windows, and definitely more bricked than just requiring a reload of firmware. I believe the same issue did exist in related versions of desktop Windows, so if web page delivered fonts had been a thing at the time it could have been exploited in a "drive-by" fashion. An attacker wanting to "brick" systems as a result could replace a system font with one triggering the glitch similar to the Xbox exploit and the system would be rendered about equally useless to the average user as an iPhone requiring a DFU reload.

cool. I remember doing xbox softmods w/ some MechWarrior save exploit or something. it was easy as hell but it had a similar problem where if the clock poo poo the bed you were hosed if you hadn't already unlocked the drive.

vOv
Feb 8, 2014

i homebrewed my n3ds and you have to force downgrade it to like 2.something at one point, which is an OS version that came out before the n3ds existed, so there's a big 'if you close the lid during this step it'll brick' warning

you also used to be hosed if you didn't have wifi enabled (o3ds has a hardware switch, n3ds doesn't, 2.something doesn't have a wifi toggle and the next step in the process exploits wifi code) but then someone discovered that if you let the battery run out the wifi will be back on when it resets, so that's recoverable

vOv fucked around with this message at 01:56 on Feb 16, 2018

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shaggar posted:

cool. I remember doing xbox softmods w/ some MechWarrior save exploit or something. it was easy as hell but it had a similar problem where if the clock poo poo the bed you were hosed if you hadn't already unlocked the drive.

yeah iirc you used the corrupt mechassault save to get code execution, then replaced a dashboard font to get persistence

ate shit on live tv
Feb 15, 2004

by Azathoth
Homebrew hacks were/are cool as gently caress.

30 TO 50 FERAL HOG
Mar 2, 2005



Wheany posted:

this might work if it was just us. but this needs to work with the computers in both the customer's organization and in our organization.

poo poo's hosed

im extremely confused.

how is this server not accessible to the internet but people both inside and outside of your organization are using it

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Wheany posted:

certificate advice needed: we have a web page/app that is accessed by ip address. our customer uses one internal ip address, and we use another ip address through a vpn (we can only access it over vpn). the server is not visible to the internet.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
my talk profile is up (title is wrong but still)

https://www.bsidesvancouver.com/cariad-keigher/

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Notorious b.s.d. posted:

public ssl certificate for a private hostname was the right answer

man, this is gonna suck...

spankmeister
Jun 15, 2008






https://www.bishopfox.com/blog/2018/02/hello-world-introducing-the-bishop-fox-cybersecurity-style-guide/

A style guide for cyberspace, from a cursory skim it actually looks ok.

spankmeister
Jun 15, 2008






Lain Iwakura posted:

my talk profile is up (title is wrong but still)

https://www.bsidesvancouver.com/cariad-keigher/

lol @ "diversified natural resources company"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

it's good

quote:

AI
Artificial intelligence, often used as jargon to refer to a computer program.

crypto
Historically, this was short for cryptography. Now, it can also mean cryptocurrency. Spell out on first use to clarify your intended meaning.

cyber-
Industry professionals don’t use this prefix, but it’s helpful when informing the public, as in the title of this document. For many users, “cyber” on its own invokes cybersex, not hacking. https://willusingtheprefixcybermakemelooklikeanidiot.com/

Referer
Famously misspelled HTTP header.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

spankmeister posted:

lol @ "diversified natural resources company"

ellingson mineral corporation

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



can't believe they missed out setec

  • Locked thread