Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Tankakern
Jul 25, 2007

why

Adbot
ADBOT LOVES YOU

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

for acknowledging a shaggar post in the security thread

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Stop shaggaring...

https://twitter.com/KateLibc/status/973609996071067649?s=19

spankmeister
Jun 15, 2008






Good luck Cari!

Pile Of Garbage
May 28, 2007



break a leg!!!

Tankakern
Jul 25, 2007

glhf!

Pile Of Garbage
May 28, 2007



nvm

Shaggar
Apr 26, 2006

cheese-cube posted:

the new Graph API looks p sw8, been meaning to find time to gently caress with that for a while now. apparently that's where microsoft are going to push all o365+services and seccom reporting to. also looks like a faster method of querying some of the more expensive exchange cmdlets (Get-MailboxStatistics, Get-MailboxFolderStatistics, etc.)

sorry im making GBS threads up the sec gently caress thread with msft stuff i'll stop now


:getout:

I used it for a recent project and there were some things missing that I had to get from some the older apis.

Raere
Dec 13, 2007

So are there any straightforward syslog collectors? What if I want to have all my devices send their syslogs to a central location but I don't want to configure Zabbix or w/e.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

there was a time people just used syslogd for that

Pile Of Garbage
May 28, 2007



yeah logs are still available via syslog from azure, just the auth is a bit more involved.

Pile Of Garbage
May 28, 2007



wd cari for surviving the talk, excellently presented imo.

Shame Boy
Mar 2, 2010

Raere posted:

So are there any straightforward syslog collectors? What if I want to have all my devices send their syslogs to a central location but I don't want to configure Zabbix or w/e.

rsyslogd is super duper extensible if you can use a recent version of it and don't mind their weird dumb config syntax

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

ate all the Oreos posted:

just got an email about suspicious activity with one of my microsoft accounts I don't really use, went to go change the password and enable 2fa because why not. tried to set it up using their wizard thing, select android and it's like "ok install the microsoft app and log in with it" and refuses to let me proceed until i log in with it. no thanks, so i go back and select "other" as my phone type and get this:



what fantastic advice :allears:

"durr I said I don't want the official app that does the job, now it's telling me to do something less secure"

No poo poo Sherlock, it now thinks you're using some blackberry esque abomination since you won't use the real Android app

Pile Of Garbage
May 28, 2007



that's a good fishmech, two pages late and no one cares

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

cheese-cube posted:

that's a good fishmech, two pages late and no one cares

Fishmech on ignore really improves your forums experience. I highly recommend it.

Pile Of Garbage
May 28, 2007



no i actually like a lot of fIshmech's posts, like in the transport thread. that post i had to quote because it was so bad

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

cheese-cube posted:

wd cari for surviving the talk, excellently presented imo.

thanks! i stumbled at one point only because silly me wrote too many notes and lost track of my place

FlapYoJacks
Feb 12, 2009

cheese-cube posted:

that's a good fishmech, two pages late and no one cares

He's right though.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that’s entirely secondary to the point

Wiggly Wayne DDS
Sep 11, 2010



Lain Iwakura posted:

thanks! i stumbled at one point only because silly me wrote too many notes and lost track of my place
it's fine no one could tell given the quality of the livestream

bicycle
Oct 23, 2013

Lain Iwakura posted:

thanks! i stumbled at one point only because silly me wrote too many notes and lost track of my place

this was my favorite part because you were like

"so what was i talking about, oh yea, it was-"*audio cuts out*


aside from stream quality this talk was great, i hope it gets put up as a separate video so i can show the log guys at work. theyre already impressed by that 1/3 reduction in event log bandwidth so ty for that.

30 TO 50 FERAL HOG
Mar 2, 2005



im a big fan of how ntfs and windows can have file paths of like 2.5 trillion characters but explorer is still limited to 255

Pile Of Garbage
May 28, 2007



NEED MORE MILK posted:

im a big fan of how ntfs and windows can have file paths of like 2.5 trillion characters but explorer is still limited to 255

not to over use this but :getout:

Shame Boy
Mar 2, 2010

fishmech posted:

"durr I said I don't want the official app that does the job, now it's telling me to do something less secure"

No poo poo Sherlock, it now thinks you're using some blackberry esque abomination since you won't use the real Android app

then it could have just left off step 1 and it would have been fine

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.

Truga posted:

https://amdflaws.com/


lol this is gonna be a fun ride. also, lol here we go again with lovely marketing websites for bugs.

quote:

CTS-Labs, a security company based in Israel, announced Tuesday that its researchers had found 13 critical security vulnerabilities that would let attackers access data stored on AMD's Ryzen and EPYC processors, as well as install malware on them. Ryzen chips power desktop and laptop computers, while EPYC processors are found in servers.

The researchers gave AMD less than 24 hours to look at the vulnerabilities and respond before publishing the report. Standard vulnerability disclosure calls for at least 90 days' notice so that companies have time to address flaws properly. For comparison, Google's researchers gave Intel six months to fix issues related to Spectre and Meltdown.
hmmmm

Wiggly Wayne DDS
Sep 11, 2010



hang on people are vouching for them

https://twitter.com/dguido/status/973648728925048834
https://twitter.com/gadievron/status/973655430441373696

completely independent parties that weren't given money or exposure for this

patch tuesday has a few minor gems:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0886

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0883

enjoying the 2 month opt-in period and how it'll make out of date rdp servers even more obvious

hobbesmaster
Jan 28, 2008

Wiggly Wayne DDS posted:

hang on people are vouching for them

https://twitter.com/dguido/status/973648728925048834
https://twitter.com/gadievron/status/973655430441373696

completely independent parties that weren't given money or exposure for this

patch tuesday has a few minor gems:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0886

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0883

enjoying the 2 month opt-in period and how it'll make out of date rdp servers even more obvious

quote:

To ensure public safety, all technical details that could be used to reproduce the vulnerabilities have been
redacted from this document. CTS has privately shared this information with AMD, select security
companies that can develop mitigations, and the U.S. regulators. What follows is a description of the
security problems we discovered and the risks they pose for users and organizations.

sure sounds like bullshit

evil_bunnY
Apr 2, 2003

NEED MORE MILK posted:

im a big fan of how ntfs and windows can have file paths of like 2.5 trillion characters but explorer is still limited to 255
it’s not just explorer, a whole bunch of utilities must use dumbass limited API because they’re just as limited. I can clearly remember inheriting a gently caress-you filestructure from somewhere, then at some point giving up on sanitizing it and just mounting the system share to rm -rf it from a Linux box.

Kazinsal
Dec 13, 2011

hobbesmaster posted:

sure sounds like bullshit

Kazinsal posted:

I do not believe the blockchain security researcher in those tweets is involved in any capacity in a 24-hour-disclosure-period massive CPU security bug fest that is in any way real

30 TO 50 FERAL HOG
Mar 2, 2005



cheese-cube posted:

not to over use this but :getout:

Wiggly Wayne DDS
Sep 11, 2010



i've yet to see proof he's a security researcher

Kazinsal
Dec 13, 2011

Wiggly Wayne DDS posted:

i've yet to see proof he's a security researcher

there is no security in blockchain so at best he's an enterprise-grade snake oil salesman

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

which US regulators? why wouldn’t they say?

FMguru
Sep 10, 2003

peed on;
sexually

Wiggly Wayne DDS posted:

i've yet to see proof he's a security researcher
techincally speaking, someone walking down a quiet street at night and trying the doors of every parked car he passes is doing "security research"

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
lol

Condiv
May 7, 2008

Sorry to undo the effort of paying a domestic abuser $10 to own this poster, but I am going to lose my dang mind if I keep seeing multiple posters who appear to be Baloogan.

With love,
a mod


limux weighs in:

geonetix
Mar 6, 2011


the man has shown a very nuanced view of “security people” in every single email in the past year or so

maybe somebody stole his cookies

Potato Salad
Oct 23, 2014

nobody cares


Where may I find the Sec Fuckup thread?

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



the entire page has been sec fuckups

what more do you want

  • Locked thread