Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Workaday Wizard
Oct 23, 2009

by Pragmatica

Wiggly Wayne DDS posted:

there's a set of locks that are really easy for beginners, i think they call them master locks?

lol

Adbot
ADBOT LOVES YOU

Salt Fish
Sep 11, 2003

Cybernetic Crumb
One time I spent like 5 hours reading about padlocks and watching youtube videos about them, and I found the best one but it was a hundred dollars or something. I was going to buy it but I was like, wait I don't need a padlocks for anything.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Mr.Radar posted:

lol, im sure this will work well: A Case for Safe Eval. tl;dr: im too lazy to write a proper dsl so i'll just use this magic regex to "sanitize" the input to the js eval() function instead.
jesus christ

Midjack
Dec 24, 2007



bob dobbs is dead posted:

get an easier progressive lock. but not a transparent one. you can get a pin lock with two tumblers if you're willing to pay

you can make your own progressive set if you can carefully disassemble an off the shelf cylinder.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
On that note is there a set of picks people recommend when practicing?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ErIog posted:

I had to do this last year to chase down something stupid a previous sysadmin did in order to prove something wasn't malicious during an audit.

Here's a Medium post which explains some of the things that get left around when psexec is used:
https://medium.com/@mbromileyDFIR/digging-into-sysinternals-psexec-64c783bace2b

I remember it being kind of a pain, though, because there's not really a smoking gun. You have to dig for info you can then correlate to logs/files on the system.

Yeah, I ended up getting a user ID that issued the job and it was some disk cleanup script that they decided to start running. I'm going to dump Sysmon on every single server in the environment so this isn't an issue again. It's a bit poo poo that this thing doesn't dump a log file somewhere of what commands came through it. Sure you could clean that up after yourself, but no logging by default seems ill-advised.

BangersInMyKnickers fucked around with this message at 14:46 on Jun 4, 2018

canis minor
May 4, 2011

anthonypants posted:

jesus christ

This reminds me of a charity website where the amount you were pledging was calculated as eval(document.getElementById('amount').value+" * "+document.getElementById('value').value)

:allears:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that sort of thing is very common

PIZZA.BAT
Nov 12, 2016


:cheers:


has this been posted itt yet?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
you'll be surprised to learn this was not an android, but instead, https://twitter.com/laforgia_/status/1003619629355413504

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I cannot believe this Corporate Zero Privacy Phone has Zero Privacy

PIZZA.BAT
Nov 12, 2016


:cheers:


BangersInMyKnickers posted:

I cannot believe this Corporate Zero Privacy Phone has Zero Privacy

i think the takeaway is that said zero privacy phone is utilizing apis that were supposed to have been closed years ago

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

no, the APIs for native apps are different from the platform APIs

PIZZA.BAT
Nov 12, 2016


:cheers:


Subjunctive posted:

no, the APIs for native apps are different from the platform APIs

not sure what your point is, here

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Rex-Goliath posted:

not sure what your point is, here

the APIs that were supposed to be closed off in 2014 are different from the APIs in question here. afaik there was never any impetus to close off the wire APIs the BlackBerry app uses, because it would also have disabled the iOS and Android apps

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost

ZeusCannon posted:

On that note is there a set of picks people recommend when practicing?

every recommendation from toool is good
https://toool.us/

(tremendous twelve tookit)

Daman
Oct 28, 2011
literally a non story, the facebook app you give your credentials to can access whatever it wants. surprise?

if you log into the Facebook dot com you can also see it pull information about you and your friends LIVE and render it ON YOUR SCREEN for some kind of timeline... 😱😱😱

PIZZA.BAT
Nov 12, 2016


:cheers:


Daman posted:

literally a non story, the facebook app you give your credentials to can access whatever it wants. surprise?

if you log into the Facebook dot com you can also see it pull information about you and your friends LIVE and render it ON YOUR SCREEN for some kind of timeline... 😱😱😱

i think they should have mentioned that they had 295k direct-contacts if that were the case

PIZZA.BAT
Nov 12, 2016


:cheers:


i mean correct me if i'm wrong but i thought the whole 'friend of a friend' stuff was supposed to have been closed off a while ago, right?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

this isn’t the platform APIs used by Cambridge. this is (roughly) the set of APIs used by the Facebook apps themselves

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
why does that give you friend-of-a-friend info though?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

public profile information found through friend-visible links, if I had to guess

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
sure but it shouldn't immediately slurp those 526k contacts down, should it?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

well, FB provides address book integration on different OSes. I’m pretty sure the in-house variants for iOS and Android only did the friends list, but if Blackberry hosed up then they could have been pulling transitively either on purpose or by accident. their testing was bad enough that “an extra 500K contacts in the list” could plausibly have escaped their notice

I wanted to kill that app the whole time I was there because it was such a lovely experience, but the contracts had long clocks on them

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
what's stopping someone from reverse engineering those apis to pull contact data. you'd probably say "monitoring" but they were able to grab 500k more contacts than they should so thats clearly a lie

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

nothing, if they have the user’s credentials. same as with any API, any game, etc. you can’t authenticate the identity of client software, just the user credentials. all the rest is client-side data, lost before the fight began

EssOEss
Oct 23, 2006
128-bit approved
Speaking of different APIs is missing the forest for the trees. The point is that Facebook gave the public the impression they were disabling sharing of your deep details for 3rd parties - yet here we see just that happening.

Sure, there may be reasons for it from Facebook perspective and they might never have explicitly said they would turn off this path but it seems rather disingenuous of them to treat access to personal info differently for "platform" and "other" 3rd party companies.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

this is collection of publicly available information, rather than “deep details”, as far as I’ve read, but I admit that I haven’t read very far

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

sometimes i feel like i'm paranoid about my data privacy but then something like this comes along that i'd never even considered

Bulgogi Hoagie
Jun 1, 2012

We

anthonypants posted:

you'll be surprised to learn this was not an android, but instead, https://twitter.com/laforgia_/status/1003619629355413504

wow, the blackberry finally has a niche

Bulgogi Hoagie
Jun 1, 2012

We
on the topic of phone forensics, guess what owns insanely hard

https://twitter.com/lorenzoFB/status/1003749479441412096

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

on the topic of phone forensics, guess what owns insanely hard

https://twitter.com/lorenzoFB/status/1003749479441412096
ahh that must be why i got a "you need to unlock your phone to use accessories" popup when i plugged my phone in at work this morning

Bulgogi Hoagie
Jun 1, 2012

We

anthonypants posted:

ahh that must be why i got a "you need to unlock your phone to use accessories" popup when i plugged my phone in at work this morning

that's the seven day limit that's already been implemented kicking in, but apparently they're taking a step further in the next update

spankmeister
Jun 15, 2008






Bulgogi Hoagie posted:

on the topic of phone forensics, guess what owns insanely hard

https://twitter.com/lorenzoFB/status/1003749479441412096

rip feds

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Bulgogi Hoagie posted:

that's the seven day limit that's already been implemented kicking in, but apparently they're taking a step further in the next update
i've had the 11.4.1 beta since thursday

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

that’s excellent

The_Franz
Aug 8, 2003

Bulgogi Hoagie posted:

on the topic of phone forensics, guess what owns insanely hard

https://twitter.com/lorenzoFB/status/1003749479441412096

:discourse:

spankmeister
Jun 15, 2008






You know I have to wonder if there's not some kind of bypass for that because they have some kind of jailbreak to run their code and they're already bypassing the pin counters anyway.

Phone
Jul 30, 2005

親子丼をほしい。
iirc the way the current ios pin enumeration works is by interrupting the 10x and you're out policy by killing the power to reset the counter. this is separate from law enforcement agencies having magic boxes that they plug your phone into and it basically does an entire dump of the phone including stuff that isn't accessible in user space.

1 hour USB timer throws a wrench in both, i think

Adbot
ADBOT LOVES YOU

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
like someobdy in that twitter thread, i also wonder how this affects wiping / factory resetting a phone

is the phone now a brick if you forget the passcode and dont have the "wipe phone after 10 attempts" thing turned on?

  • Locked thread