Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope
you pay 10k damages for pirating the game. the game developers go to jail for several years

Adbot
ADBOT LOVES YOU

homercles
Feb 14, 2010

Wheany posted:

you pay 10k damages for pirating the game. the game developers go to jail for several years
jailtreon.gov

Pay money to nominate someone to be jailed, they have to outbid you to stay free.

Stay free America! Capitalism, now rise for the national anthem!

Shaggar
Apr 26, 2006

why would it even be an option not to have authentication on something like that?

Mr.Radar
Nov 5, 2005

You guys aren't going to believe this, but that guy is our games teacher.
https://github.com/maxchehab/CSS-Keylogging

Shame Boy
Mar 2, 2010


it got posted here already and it's real cute

idk why this is presented as a chrome plugin though that's weird

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


ate all the Oreos posted:

it got posted here already and it's real cute

idk why this is presented as a chrome plugin though that's weird

its so it can be a self contained demo, doing it on the other browsers requires an external server

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

why would it even be an option not to have authentication on something like that?
because the market demands it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
meanwhile in the grey thread there's an idiot defending the password stealer drm

flakeloaf
Feb 26, 2003

Still better than android clock

anthonypants posted:

meanwhile in the grey thread there's an idiot

apseudonym
Feb 25, 2011

anthonypants posted:

meanwhile in the grey thread there's an idiot defending the password stealer drm

Reads like less defending and more "yeah but other things could be bad!" Which is even more annoying.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/captbaritone/status/966051583132758016

akadajet
Sep 14, 2003


doesn't reddit allow you to use custom css for subforums?

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

kebernutes

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).


Kerbalnetes Space Program

Edit: gently caress! Wrong muskie money pit.

cinci zoo sniper
Mar 15, 2013




akadajet posted:

doesn't reddit allow you to use custom css for subforums?

yes it does

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

akadajet posted:

doesn't reddit allow you to use custom css for subforums?

if only they had mentioned that in the tweet you quoted

Chalks
Sep 30, 2009

Seems difficult to make the attack viable on somewhere like reddit unless you're able to somehow serve a specific style sheet to a specific user before they've logged in. I assume it doesn't permit externally hosted styles and you have to upload a static CSS file to the reddit servers.

cinci zoo sniper
Mar 15, 2013




Chalks posted:

Seems difficult to make the attack viable on somewhere like reddit unless you're able to somehow serve a specific style sheet to a specific user before they've logged in. I assume it doesn't permit externally hosted styles and you have to upload a static CSS file to the reddit servers.

yeah they prohibit any non-local content in css afaik

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Chalks posted:

Seems difficult to make the attack viable on somewhere like reddit unless you're able to somehow serve a specific style sheet to a specific user before they've logged in. I assume it doesn't permit externally hosted styles and you have to upload a static CSS file to the reddit servers.

If you log out of your account each time you're finished, you would be likely to visit the subreddit with the danger CSS, and log in on that forum.


cinci zoo sniper posted:

yeah they prohibit any non-local content in css afaik

This would be the hard part, I think.

Chalks
Sep 30, 2009

Avenging_Mikon posted:

If you log out of your account each time you're finished, you would be likely to visit the subreddit with the danger CSS, and log in on that forum.

I guess you'd use the same technique on the username field as well, then try to match it all up using the requesting IP address. Hope that typing speed+latency doesn't mean that some of the requests get skipped or arrive out of order.

I assume reddit limit the CSS resources to their own site to exercise some control over filesizes - or are there other known css exploits like this that they were trying to mitigate?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
I...don't...know.

LOOKOVERTHERE!

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



got my first CVE ID assigned today

i have now graduated from lurker/white-noise shitposter to someone who can at least in theory contribute meaningfully to this thread

NFX
Jun 2, 2008

Fun Shoe
huh, they usually only assign CVEs to bugs

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Chalks posted:

I guess you'd use the same technique on the username field as well, then try to match it all up using the requesting IP address. Hope that typing speed+latency doesn't mean that some of the requests get skipped or arrive out of order.

I assume reddit limit the CSS resources to their own site to exercise some control over filesizes - or are there other known css exploits like this that they were trying to mitigate?

probably just the usual problems with letting users bring their own css that refers to external resources

leeching
styles turning to goatse
Image decoder vulnerabilities

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

NFX posted:

huh, they usually only assign CVEs to bugs
:iceburn:

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Chalks posted:

I guess you'd use the same technique on the username field as well, then try to match it all up using the requesting IP address. Hope that typing speed+latency doesn't mean that some of the requests get skipped or arrive out of order.

I assume reddit limit the CSS resources to their own site to exercise some control over filesizes - or are there other known css exploits like this that they were trying to mitigate?

i think they want to prevent people from using css styles to track users

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i would hope they just don't load custom css on any page where you enter your password

but it's reddit so i don't want to give them the benefit of the doubt

Nalin
Sep 29, 2007

Hair Elf

anthonypants posted:

i would hope they just don't load custom css on any page where you enter your password

but it's reddit so i don't want to give them the benefit of the doubt

If you visit a subreddit directly, they have username/password fields right in the sidebar.

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



NFX posted:

huh, they usually only assign CVEs to bugs

I walked into that one

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

anthonypants posted:

i would hope they just don't load custom css on any page where you enter your password

but it's reddit so i don't want to give them the benefit of the doubt

some subreddits use the first character of the login form csrf token to assign a random banner image every page load via css

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

NFX posted:

huh, they usually only assign CVEs to bugs

Thanks Dad :3:

Pile Of Garbage
May 28, 2007



work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:

Mo_Steel
Mar 7, 2008

Let's Clock Into The Sunset Together

Fun Shoe

cheese-cube posted:

work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:

jokes on you: all PCs are workgrouped the AD server is just a honeypot :downs:

Max Facetime
Apr 18, 2009

Chalks posted:

a random company accusing you of breaking a law doesn't automatically remove your legal rights.

of course not; even criminals still have access to lawyers and the courts

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

cheese-cube posted:

work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:

I don't know about that first one but the second is the default config for AD

evil_bunnY
Apr 2, 2003

cheese-cube posted:

work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:
if you look at the permissions in the last tab you can prob figure out who it was

akadajet
Sep 14, 2003

cheese-cube posted:

work secfuck: just discovered that some idiot hell fucker has configured ACEs at the root of the AD domain which allows auth users (aka almost everyone) to write properties on all computer objects and join computers to the domain :downsgun:

you're writing in janitor moonspeak, but that sounds bad.

Shame Boy
Mar 2, 2010

akadajet posted:

you're writing in janitor moonspeak, but that sounds bad.

some guy configured the main thingy to let all the other thingies into the thingy clubhouse without asking first and also to write all over each other

akadajet
Sep 14, 2003

lol if you don't immediately take your work laptop off of the domain when they give it to you

Adbot
ADBOT LOVES YOU

Truga
May 4, 2014
Lipstick Apathy

akadajet posted:

lol if you don't immediately take your work laptop off of the domain when they give it to you

yeah, it's an extremely good way of getting fired

  • Locked thread