Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
jre
Sep 2, 2011

To the cloud ?



welp php

Adbot
ADBOT LOVES YOU

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

is PEAR uh, the main package repository for PHP? :stare:

Shame Boy
Mar 2, 2010

Lutha Mahtin posted:

is PEAR uh, the main package repository for PHP? :stare:

it's the big one yes, though generally the package repository for php is "whatever your system package manager is"

necrotic
Aug 2, 2005
I owe my brother big time for this!
i think composer has all but replaced pear these days. i havent touched php in years and im not going to check now.

Shame Boy
Mar 2, 2010

necrotic posted:

i think composer has all but replaced pear these days. i havent touched php in years and im not going to check now.

doesn't composer do the gentoo thing of recompiling everything all the time? that's what it did the one time i had to use it...

Truga
May 4, 2014
Lipstick Apathy
it's not anymore, everyone wants the latest and greatest now.

i get real bad looks at work when i insist on using only distro packages for php, and trying to avoid composer at all costs, but it's got us safely past a couple of these idiocies entirely unaffected so i guess it's not the worst idea

Truga fucked around with this message at 01:08 on Jan 22, 2019

Shame Boy
Mar 2, 2010

Truga posted:

it's not anymore, everyone wants the latest and greatest now.

i get real bad looks at work when i insist on using only distro packages for php, and trying to avoid composer at all costs, but it's got us safely past a couple of these idiocies entirely unaffected so i guess it's not the worst idea

i've never encountered someone who uses loving php who wants the "latest and greatest" of anything

Truga
May 4, 2014
Lipstick Apathy
i have, and they're the worst. everyone wants php 7.4 or whatever's newest now and they all want to work with loving composer, which is basically npm for php and it's terrible

necrotic
Aug 2, 2005
I owe my brother big time for this!

Shame Boy posted:

doesn't composer do the gentoo thing of recompiling everything all the time? that's what it did the one time i had to use it...

didnt pear also do that for c extensions?

php is trash, no surprise the packaging systems are also trash.

Truga
May 4, 2014
Lipstick Apathy
pear is for php, pecl is for c extensions

i have no idea why pear was replaced by composer either, i guess it was too stable for php

necrotic
Aug 2, 2005
I owe my brother big time for this!

Truga posted:

pear is for php, pecl is for c extensions

oh right

Raere
Dec 13, 2007

looks like everything's going pear shaped

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Raere posted:

looks like everything's going pear shaped

Schadenboner
Aug 15, 2011

by Shine
I didn’t understand any of the sponsor interview from the most recent Risky Business. And not for the usual reason (:australia:). Like it was all about math and modeling selectric typewriters in a can of La Croix in Second Life?

:psyduck:

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Wiggly Wayne DDS posted:

a more thorough analysis: http://watt-logic.com/2018/06/13/smets2/

take note of gb-specific zigbee

i'm really not following this, especially as the main "problem" seems to be that they make it inconvenient to use the pointless ~free market~ electricity bit as much as you like? there appear to be fairly identical security issues between the two standards based on that article

also it seems like the new standard wasn't available until very recently while the old one was being installed from 2012? and surely there was some manner of smart meters in use in the uk since well before that too, as other countries had their programs start in the 90s and early 2000s

generally seems like a case of "the old version isn't as good" which is the way things usually tend to go

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Truga posted:

pear is for php, pecl is for c extensions

i have no idea why pear was replaced by composer either, i guess it was too stable for php

probably cause it doesnt download straight from github and run it blindly, well maybe with this breach it has been

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

it's the big one yes, though generally the package repository for php is…

…the comment section of snack overflow

spankmeister
Jun 15, 2008






Schadenboner posted:

I didn’t understand any of the sponsor interview from the most recent Risky Business. And not for the usual reason (:australia:). Like it was all about math and modeling selectric typewriters in a can of La Croix in Second Life?

:psyduck:

Funny because the trail of bits guy CTF one was one of the very few sponsor interviews that I listened to and actively enjoyed. I usually skip them after a couple of minutes.

This one was absolutely great. It's because I like to play CTF's and it's cool to hear from someone who designs these absolutely insane challenges.

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

Schadenboner
Aug 15, 2011

by Shine

spankmeister posted:

Funny because the trail of bits guy CTF one was one of the very few sponsor interviews that I listened to and actively enjoyed. I usually skip them after a couple of minutes.

This one was absolutely great. It's because I like to play CTF's and it's cool to hear from someone who designs these absolutely insane challenges.

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

He never said what flavor it was though. I’m going to be so loving mad if it turns out not to have been Pamplemousse.

cinci zoo sniper
Mar 15, 2013




huh, our nation-wide bank 2fa app system has github https://github.com/SK-EID/smart-id-documentation

spankmeister
Jun 15, 2008






cinci zoo sniper posted:

huh, our nation-wide bank 2fa app system has github https://github.com/SK-EID/smart-id-documentation

Estonia is pretty good at the cybers imo

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

Estonia is pretty good at the cybers imo

yeah i like that we figured out one system for baltics, since looking at websites and apps of authentically latvian banks is painful

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

“internet banking is only available between 0600 and 2200 please log in between these times”

4lokos basilisk
Jul 17, 2008


spankmeister posted:

Estonia is pretty good at the cybers imo

let's wait a couple of months with this statement, as e-voting for the current parliamentary elections started yesterday :)

evil_bunnY
Apr 2, 2003

BangersInMyKnickers posted:

It's a plenty good idea and why I'm trying to enable it, I'm just worried that it will poo poo itself when I have 20k clients all jabbering it at once. If they were less-poo poo this would have a secure out of box config with some kinda of cert validation of the server instead of blind-tls and some kind of rpc endpoint mapper to handle the socket limits that are loving obvious for any large-scale deployment. I have to assume that most products have something similar for optimization, though probably doing some kind of cloud lookup to the vendors servers by deferring the actual scan of the file until it get can a verdict back on the file from the cloud or it times out and fails back to a local scan.
lol it DDoSing itself in test would be enough to call it garbage and tell symantec to go gently caress itself. You don't want to tie more engineering resources into that shitheap.

Wiggly Wayne DDS posted:

well ya but your smartmeter data shouldn't go to your landlord
lmao you think they won't have a "strategic partnership"?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

evil_bunnY posted:

lol it DDoSing itself in test would be enough to call it garbage and tell symantec to go gently caress itself. You don't want to tie more engineering resources into that shitheap.

its literally my job right now to throw good engineering hours after bad product because that how we spend our money I guess. it at least gets me some good laughs even though all of them end in depressing sighs

Wiggly Wayne DDS
Sep 11, 2010



Package : apt
CVE ID : CVE-2019-3462

Max Justicz discovered a vulnerability in APT, the high level package manager.
The code handling HTTP redirects in the HTTP transport method doesn't properly
sanitize fields transmitted over the wire. This vulnerability could be used by
an attacker located as a man-in-the-middle between APT and a mirror to inject
malicous content in the HTTP connection. This content could then be recognized
as a valid package by APT and used later for code execution with root
privileges on the target machine.

Since the vulnerability is present in the package manager itself, it is
recommended to disable redirects in order to prevent exploitation during this
upgrade only, using:

apt -o Acquire::http::AllowRedirect=false update
apt -o Acquire::http::AllowRedirect=false upgrade

This is known to break some proxies when used against security.debian.org. If
that happens, people can switch their security APT source to use:

deb http://cdn-fastly.deb.debian.org/debian-security stable/updates main

For the stable distribution (stretch), this problem has been fixed in
version 1.4.9.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

spankmeister posted:

It's also nice that they used their sponsor spot to just tell a story about a cool CTF challenge, instead of actively trying to push some product.

trail of bits is a contractor doing fairly intensive research; what they're pushing is that it's cool to let them reap the difference between the fruits of your labor and your paycheck

(by all reports they're a nice place to work)

flakeloaf
Feb 26, 2003

Still better than android clock

Schadenboner posted:

He never said what flavor it was though. I’m going to be so loving mad if it turns out not to have been Pamplemousse.

he thought vaguely of it before the interview started, which is an explosion of flavour naming by la croix standards

Also, doesn't epo let you set up distributed av scans & reports? I seem to remember that from the course but ofc the book is uh, elsewhere

flakeloaf
Feb 26, 2003

Still better than android clock

https://twitter.com/jinnysims/status/1087763839469277184

jesus christ

spankmeister
Jun 15, 2008






Cocoa Crispies posted:

trail of bits is a contractor doing fairly intensive research; what they're pushing is that it's cool to let them reap the difference between the fruits of your labor and your paycheck

(by all reports they're a nice place to work)

Of course, it's pretty obvious that it's a recruiting bit but they do it in a very chill way.

Midjack
Dec 24, 2007




wrong ministry

theflyingexecutive
Apr 22, 2007

a dude I know has been FOIAing for the astroturfed FCC comments about net neutrality in 2017, and here are the first fruits of his labor: https://link.medium.com/mrLavhhIGT

flakeloaf
Feb 26, 2003

Still better than android clock

Midjack posted:

wrong ministry

soon i discovered
that this block chain was true

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

flakeloaf posted:

soon i discovered
that this block chain was true

terry a davis was the devil, and rms was an architect previous to his career as a prophet

Sereri
Sep 30, 2008

awwwrigami

Maybe someone should delete the ladder of her pool :v:

Brute Squad
Dec 20, 2006

Laughter is the sun that drives winter from the human race

https://twitter.com/gregotto/status/1087800274511634434

EMILY BLUNTS
Jan 1, 2005

seeing some hints of conspiracy theories around that but not sure what nefarious and diabolical plans would come of it

chemosh6969
Jul 3, 2004

code:
cat /dev/null > /etc/professionalism

I am in fact a massive asswagon.
Do not let me touch computer.
More on the DNS hijacking stuff that's been going on since last year

https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html

https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html

quote:

Cisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airline company. Based on our research, it's clear that this adversary spent time understanding the victims' network infrastructure in order to remain under the radar and act as inconspicuous as possible during their attacks.

Based on this actor's infrastructure and TTPs, we haven't been able to connect them with any other campaign or actor that's been observed recently. This particular campaign utilizes two fake, malicious websites containing job postings that are used to compromise targets via malicious Microsoft Office documents with embedded macros. The malware utilized by this actor, which we are calling "DNSpionage," supports HTTP and DNS communication with the attackers.

In a separate campaign, the attackers used the same IP to redirect the DNS of legitimate .gov and private company domains. During each DNS compromise, the actor carefully generated Let's Encrypt certificates for the redirected domains. These certificates provide X.509 certificates for TLS free of charge to the user. We don't know at this time if the DNS redirections were successful.

Adbot
ADBOT LOVES YOU

fisting by many
Dec 25, 2009




oh no, there's more and it's worse

https://twitter.com/jinnysims

https://news.gov.bc.ca/releases/2019CITZ0002-000062

of all the entities that would possibly be lured by "trustless" "immutable" ledgers, i can't for the life of me understand why that would be of interest to a government. it doesn't matter if loonies don't trust you, you're the law! :psyduck:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply