Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Schadenboner
Aug 15, 2011

by Shine
The Russian 40k recaster I like is based in Russia. :ohdear:

Adbot
ADBOT LOVES YOU

Cybernetic Vermin
Apr 18, 2005

computer toucher posted:

the service providers should just hold their own, and let Russia gently caress itself with a broomstick over this.

i am sure they will indeed decide to be principled with no particular upside instead of protecting their bottom line

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD
yeah; the various app stores kept all sorts of VPN and messaging apps outside of the Chinese stores, what makes Russia any different

cinci zoo sniper
Mar 15, 2013




~Coxy posted:

yeah; the various app stores kept all sorts of VPN and messaging apps outside of the Chinese stores, what makes Russia any different

cause you can get in russia otherwise, it’s nowhere near as walled off as china


anyways, russian government continues onslaught and a few minutes ago the blocked ip count did exceed the number of users in russia

Shifty Pony
Dec 28, 2004

Up ta somethin'


Also important:

China e-commerce consumer spending: ~$1 Trillion

Russia e-commerce consumer spending: ~$25 billion

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
why does russia even care? it’s not like their investigations into “political interference” or “terrorism” are encumbered by any sort of due-process restrictions

Schadenboner
Aug 15, 2011

by Shine

rjmccall posted:

why does russia even care? it’s not like their investigations into “political interference” or “terrorism” are encumbered by any sort of due-process restrictions

That's what I never got. I mean, it seems like a lot of :effort: and :homebrew: for what's going to just end up being :commissar: and (based on the Russians in my family) it's not like anyone in :ussr: views any evidence the state presents as anything other than :jerkbag:.

:shrug:

Truga
May 4, 2014
Lipstick Apathy
it kinds helps if you know who the ringleaders of all your factions are when doing :commissar:, and it's a whole lot harder to find out if you can't simply real their email

Schadenboner
Aug 15, 2011

by Shine

Truga posted:

it kinds helps if you know who the ringleaders of all your factions are when doing :commissar:, and it's a whole lot harder to find out if you can't simply real their email

You just count the BMsW and Mercedes and exclude the people you banya with?

Chalks
Sep 30, 2009

There's always a suspicion that governments have access to messages but just pretend that they don't so that people keep using them thinking that they're safe. I guess Russia nuking half of the internet to try to stop people using telegram is proof that at least the Russians genuinely do not have access to those messages.

Pretty good PR for telegram, tbf.

Salt Fish
Sep 11, 2003

Cybernetic Crumb
I mean they didn't "nuke" it and they definitely didn't "carpet bomb' it. They dropped the traffic using inspection devices or changed BGP routes to null route it, point is they would still have access to the traffic if they wanted it.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
in vaguely related news apparently Google app engine is disabling "support" for meek-style domain fronting and Signal are moving to some other cdn instead

Crime on a Dime
Nov 28, 2006

Salt Fish posted:

I mean they didn't "nuke" it and they definitely didn't "carpet bomb' it. They dropped the traffic using inspection devices or changed BGP routes to null route it, point is they would still have access to the traffic if they wanted it.

publisher talking about a charged issue on internet uses hyperbole in a world first

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
lmao yikes Russia. Calm down over there lads.

Potato Salad
Oct 23, 2014

nobody cares


https://blogs.vmware.com/vsphere/2018/04/introducing-vsphere-6-7-security.html

"In the interest of helping out the NSA, we've enabled FIPS 140.2 mode by default"

computer toucher
Jan 8, 2012

Chalks posted:

There's always a suspicion that governments have access to messages but just pretend that they don't so that people keep using them thinking that they're safe. I guess Russia nuking half of the internet to try to stop people using telegram is proof that at least the Russians genuinely do not have access to those messages.

Pretty good PR for telegram, tbf.

right... or they’re just really dedicated to make you think they don’t.

Shame Boy
Mar 2, 2010

Chalks posted:

There's always a suspicion that governments have access to messages but just pretend that they don't so that people keep using them thinking that they're safe. I guess Russia nuking half of the internet to try to stop people using telegram is proof that at least the Russians genuinely do not have access to those messages.

Pretty good PR for telegram, tbf.

telegram being The Official Chat Program of ISIS is literally how most of my friends found out about it and at least partially why they decided to use it

Shame Boy
Mar 2, 2010

Potato Salad posted:

https://blogs.vmware.com/vsphere/2018/04/introducing-vsphere-6-7-security.html

"In the interest of helping out the NSA, we've enabled FIPS 140.2 mode by default"

the actual quote is pretty lol

quote:

What a typical vSphere customer should know is that all crypto operations in vSphere are being done using the highest standards because we have turned on all FIPS 140-2 cryptographic operations BY DEFAULT.

yep, the highest standards 2001 has to offer :allears:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I doubt it has much effective difference beyond encryption vmotion traffic by default. It was passing in the clear for a long time.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

ate all the Oreos posted:

the actual quote is pretty lol


yep, the highest standards 2001 has to offer :allears:

I'm inclined to say this is less.NSA trickery and more that everyone wants that sweet, sweet FedRAMP money. The 20 mile long supertanker known as the United States Federal Government doesn't write standards more than once every 25 years you know!

crazysim
May 23, 2004
I AM SOOOOO GAY
50,000 Minecraft users infected with hard drive formatting malware


quote:

Sometimes, doing your own thing means building hard drive-formatting malware, embedding it in player skins, and uploading them to the official Minecraft site.

article/blog post doesn't go into much detail on how it even tries to execute and reddit's not exactly sure why skins are "executed". i'm not sure either. maybe an exploit in png library in minecraft?

crazysim fucked around with this message at 23:58 on Apr 17, 2018

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

crazysim posted:

50,000 Minecraft users infected with hard drive formatting malware



article/blog post doesn't go into much detail on how it even tries to execute and reddit's not exactly sure why skins are "executed". i'm not sure either. maybe an exploit in png library in minecraft?

good thing the geniuses of reddit are on the case

quote:

[–]AdmissibleLender
[score hidden] 3 hours ago

Probably not.

Malware embedded in media needs to be specifically crafted a certain way. Converting it generally nukes that.

However, converting media formats just to get rid of malware is very computationally expensive to do, depending on the number of users. Additionally, converting tends to be a lossy process. Users would get irritated if their skins looked like even more mushy crap than minecraft already is

Main Paineframe
Oct 27, 2010

crazysim posted:

50,000 Minecraft users infected with hard drive formatting malware



article/blog post doesn't go into much detail on how it even tries to execute and reddit's not exactly sure why skins are "executed". i'm not sure either. maybe an exploit in png library in minecraft?

a bit more detail at the original source here
https://blog.avast.com/minecraft-players-exposed-to-malicious-code-in-modified-skins

it's just a powershell script embedded in the pngs

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Main Paineframe posted:

a bit more detail at the original source here
https://blog.avast.com/minecraft-players-exposed-to-malicious-code-in-modified-skins

it's just a powershell script embedded in the pngs

I don't get how the PS gets executed

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Main Paineframe posted:

a bit more detail at the original source here
https://blog.avast.com/minecraft-players-exposed-to-malicious-code-in-modified-skins

it's just a powershell script embedded in the pngs
looks like vbscript to me

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
pour one out for the russian furries

Zil
Jun 4, 2011

Satanically Summoned Citrus


Janitor Prime posted:

I don't get how the PS gets executed

Minecraft is not coded all that well.

Craig K
Nov 10, 2016

puck
https://gizmodo.com/dojs-amber-alert-website-is-redirecting-visitors-to-har-1825336250

quote:

A website run by the US Justice Department and used to gather information about missing and abducted children is redirecting visitors to porn web pages with names such as “schoolgirl porn” and “ungrateful huge boobs Indian wife being a slut,” Gizmodo has discovered.

A redirect bug on the AmberAlert.gov allows anyone to create backlinks on the DOJ-run site—functionality apparently too good to pass up for some porn bots. The Amber Alert site is being manipulated by at least a half dozen porn pages (and an untold number of others) likely in an effort to boost their Google rankings.

puttin the 69 and gently caress in page 69 of the secfuck thread

crazysim
May 23, 2004
I AM SOOOOO GAY

Janitor Prime posted:

I don't get how the PS gets executed

that's the part i'm really baffled on.

crazysim
May 23, 2004
I AM SOOOOO GAY

Cocoa Crispies posted:

good thing the geniuses of reddit are on the case

crazysim fucked around with this message at 01:36 on Apr 18, 2018

ozymandOS
Jun 9, 2004

so it's just an open redirect? IIRC Google runs one too, and they definitely don't consider open redirects to be a security flaw: https://sites.google.com/site/bughunteruniversity/best-reports/openredirectsthatmatter

though lol that it apparently auto-forwards you after a few seconds

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
looks like some other .gov sites did the same

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


yeah, that happens to pretty much every unsecured redirect

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
code:
> pngcheck -vv -f 37996a0a5ed45f7ea2c2a42f86976947825a2673e9419b59ba6e23d5f6f0
File: 37996a0a5ed45f7ea2c2a42f86976947825a2673e9419b59ba6e23d5f6f0 (5652 bytes)
  chunk IHDR at offset 0x0000c, length 13
    64 x 64 image, 32-bit RGB+alpha, non-interlaced
  chunk IDAT at offset 0x00025, length 2
    zlib: deflated, 32K window, superfast compression
    row filters (0 none, 1 sub, 2 up, 3 avg, 4 paeth):
      (0 out of 64)
  chunk IDAT at offset 0x00033, length 3284
    row filters (0 none, 1 sub, 2 up, 3 avg, 4 paeth):
      1 2 4 2 4 4 4 1 1 4 4 4 2 4 1 2 1 2 4 2 1 4 4 4 4
      4 4 4 4 4 4 4 1 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 4 2
      4 4 1 2 4 1 4 4 4 4 4 4 4 4 (64 out of 64)
  chunk IEND at offset 0x00d13, length 0
  additional data after IEND chunk
  invalid chunk name "cho " (63 68 6f 20)
  chunk cho  at offset 0x00d1f, length 218775653:  EOF while reading data
ERRORS DETECTED in 37996a0a5ed45f7ea2c2a42f86976947825a2673e9419b59ba6e23d5f6f0
echo You Are Nailed, Buy A New Computer This Is Piece Of poo poo.

Cocoa Crispies fucked around with this message at 02:38 on Apr 18, 2018

Cybernetic Vermin
Apr 18, 2005

Janitor Prime posted:

I don't get how the PS gets executed

presumably that code is just the payload, the actual exploit being some buffer overrun or such which it used to call into it

no real details published near as i can tell though, so without a fair bit of digging who knows v:shobon:v

Truga
May 4, 2014
Lipstick Apathy

left-hand side is services affected by telegram blockage
right-hand side is services that didn't

Celexi
Nov 25, 2006

Slava Ukraini!

Truga posted:


left-hand side is services affected by telegram blockage
right-hand side is services that didn't

Looks like they did well in blocking telegram

cinci zoo sniper
Mar 15, 2013




Truga posted:


left-hand side is services affected by telegram blockage
right-hand side is services that didn't

add to the confirmed casualty side the kremlin museum ticket e-sales system and :laffo: the roskomnadzor internet censorship system that got overloaded by the blacklist size and has lost its blocked traffic stats aggregation servers since they were also hosted in the cloud

cinci zoo sniper
Mar 15, 2013




the system itself is traffic monitoring hardware provided by roskomnadzor to isps - the latter did get urgent morning letter from the watchdog to reboot and update their systems

Adbot
ADBOT LOVES YOU

Celexi
Nov 25, 2006

Slava Ukraini!
can't they just rent whatever system china uses in exchange for more oil

  • Locked thread