Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

abigserve posted:

this seems hideously unprofessional

tbf what you do in your own time is cool but it's a bit weird having dildo auctions one degree of separation away from a work conference unless I've been going to the wrong conferences

it's called being horny on main

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



Shame Boy posted:

nah they're talking about the second item, not the knot gag. the second item is in fact an ovipositor, complete with egg mold for making your own gelatin eggs


i mean i'm no stranger to shoving weird things up my rear end so i'm not exactly in a position to judge but it seems like an... odd choice for a charity raffle taking place at a professional industry conference

It's a bit of a stretch to call DEFCON a "professional" industry conference, but yeah. Still a bit much.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Proteus Jones posted:

It's a bit of a stretch to call DEFCON a "professional" industry conference, but yeah. Still a bit much.

yeah

I’m a bit surprised that DEF CON furs is organized enough to have a budget and tax classification but it’s far from the first or last organization I’d expect to see at DEF CON

less weird and off putting than the “stripper con” types

cinci zoo sniper
Mar 15, 2013




Cocoa Crispies posted:

yeah

I’m a bit surprised that DEF CON furs is organized enough to have a budget and tax classification but it’s far from the first or last organization I’d expect to see at DEF CON

less weird and off putting than the “stripper con” types

the what now :staredog:

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

hackbunny posted:

dumpbin (part of visual c++) can do the static part. the nx/dep part is easy, just dump the executable sections:

for the safeseh table, there's a different command line switch:

code:

    Safe Exception Handler Table

          Address
          --------
          0041B6F0
          0041BCB7
note that only x86 executables can have a safeseh table, other architectures already have mandatory exception handler tables. also note that I shortened the massive output again, because the load configuration data also includes the control flow guard tables, which can get pretty long

Okay, so maybe you can help validate some theories I have as to what's going on

One of my vendors started seeing their code get terminated for SEHOP faults. It got run through their dev shop who determined that because they are compiling with SafeSEH, SEHOP is redundant and they've modified their code to do a SEHOP optout. After reading through the MS documentation on SafeSEH and SEHOP, it seems that they are correct*, with a couple caveats. I dumped the process in question to get all its supporting dll's and ran them through Get-PESecurity and confirmed that everything was being compiled with SafeSEH (and DEP) so that's good, but now the question I keep coming back to is how the hell did this thing manage to those SEHOP errors if it was SafeSEH compiled in the first place.

My working theory is some kind of memory leak was resulting in exception handler addresses being overwritten by garbage and since SEHOP does regular walking of the exception handler chain looking for breaks, it caught it before an actual exception was throwing forcing the code to execute that path. This assumes that they are putting exception handler code in addresses flagged as writable which seems like a no-no to me, shouldn't that be immutable code?

With SEHOP disabled, I think one of two things are going to happen:

1. Assume they configured the SafeSEH tables correctly, the corruption happens and just stays there until an exception is thrown and it goes down the exception chain to the break where something doesn't match the SafeSEH table and hopefully the program crashes at that point?
2. They populated the SafeSEH table with every/most allocated addresses in the heap to cheat and SafeSEH is only going to catch random crap being overwritten in exception handler addresses and not stop a determined attacker.

This is the first time I've dealt with a SEHOP error that wasn't either an immediate crash at startup because the code was compiled with a broken exception handler chain or an actual attack attempt that was correctly terminated by the control and I'm a little out of my depth and trying to give myself a crash course on this stuff.

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
"look, being a furry isn't a weird sex thing, it's just a fun subculture ha ha!" doesn't seem to square with raffling off sex toys but go off kings

Shame Boy
Mar 2, 2010

Proteus Jones posted:

It's a bit of a stretch to call DEFCON a "professional" industry conference, but yeah. Still a bit much.

i mean don't most people who go do so because work paid for it? i think it sorta counts just based on that :shrug:

to be fair they are managing it fairly well - to see the things you have to hit a "show NSFW prizes" button on their raffle web page - but it definitely feels like a case of the ol' "nerds don't understand why other people might have a problem with sexuality being everywhere all the time"

Proteus Jones
Feb 28, 2013



Shame Boy posted:

i mean don't most people who go do so because work paid for it? i think it sorta counts just based on that :shrug:

to be fair they are managing it fairly well - to see the things you have to hit a "show NSFW prizes" button on their raffle web page - but it definitely feels like a case of the ol' "nerds don't understand why other people might have a problem with sexuality being everywhere all the time"

The cost of DEFCON is not out of reach for most people. I paid my own way for years. Then when I worked at $BIG_BANK, they sent me to Black Hat every year and I just stayed the extra days to go to DEFCON and expensed it.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

flyover dipshits that think Vegas is an adult playground instead of an over stimulating capitalist hell

Proteus Jones posted:

The cost of DEFCON is not out of reach for most people. I paid my own way for years. Then when I worked at $BIG_BANK, they sent me to Black Hat every year and I just stayed the extra days to go to DEFCON and expensed it.

get work to pay for ccc events imo, they’re more fun than black hat

BattleMaster
Aug 14, 2000

Shame Boy posted:

nah they're talking about the second item, not the knot gag. the second item is in fact an ovipositor, complete with egg mold for making your own gelatin eggs


i mean i'm no stranger to shoving weird things up my rear end so i'm not exactly in a position to judge but it seems like an... odd choice for a charity raffle taking place at a professional industry conference

furries know what they like, I guess

Vapor Moon
Feb 24, 2010

Neato!
The Human Font

fisting by many posted:

deleted, must have been a typo or something, I think this is the update

https://twitter.com/hacks4pancakes/status/1088599594366320640

The deleted tweet mentioned that some of these devices can be found on Shodan.

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Cocoa Crispies posted:

flyover dipshits that think Vegas is an adult playground instead of an over stimulating capitalist hell

yeah as a flyover dipshit vegas sucks. the place is dirty as hell and the populace is disgusting. that said, my first work trip was there for CES and I ended up dropping a grand at the strip club near my hotel.

I was so hungover the next day that at CES someone thought I had spilled beer all over myself. (it was just my pores)

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

the question is above my pay grade for now, sorry. I'm not even entirely sure how SEHOP and SafeSEH work, but I'll look into them and see if I can make sense of the issue or at least tell you if your theories are viable

in the meantime see if you can get crash dumps for the faults. are the devs familiar with windbg? because running the !address extension on a good dump should answer all their questions

Carbon dioxide
Oct 9, 2012

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
looool I'm going on vacation and the hotel concierge offered to take care of the ski rentals and lift tickets for me, saying I'd get a link to an online payment gateway. When I took them up on it, this is what they sent, and told me to email back:

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
I should note that this is part of Marriott. You know, the company that just had a massive data breach.

Midjack
Dec 24, 2007



that's why they're telling you to fax it, duh.

Carbon dioxide
Oct 9, 2012

January 11, 2015?

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

https://twitter.com/BSidesLV/status/1088901048985518080?s=19

For those of you planning to attend

Shame Boy
Mar 2, 2010

oh hey my company's sales department got (unsuccessfully) spear phished, neat. i guess that means we're a Real Actual Company now :allears:

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/x0rz/status/1089101900069384192

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Im sure this is a dumb question and maybe not specific to this thread but i dont know where else to ask it. Does anyone have any resources/courses for reverse malware and digital forensics? Looking to brush up a bit

spankmeister
Jun 15, 2008






ZeusCannon posted:

Im sure this is a dumb question and maybe not specific to this thread but i dont know where else to ask it. Does anyone have any resources/courses for reverse malware and digital forensics? Looking to brush up a bit

The SANS series of courses are pretty decent and sort of the industry standard.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Yeah i was looking into those but unlikely to have the wherewithal to pay for something like that so figured id ask if there was anything else that would be suitable to give basics.

spankmeister
Jun 15, 2008






ZeusCannon posted:

Yeah i was looking into those but unlikely to have the wherewithal to pay for something like that so figured id ask if there was anything else that would be suitable to give basics.

Oh I see. Well in that case you're probably better off with self-study, by buying a couple of books and starting to reverse-engineer malware samples.

Basically if you can't get an employer to pay for them, I wouldn't do it. They're not valuable enough to pay for them yourself imo.

Here are two good books about reverse engineering
https://nostarch.com/malware
https://nostarch.com/idapro2.htm

Hexyflexy
Sep 2, 2011

asymptotically approaching one

ZeusCannon posted:

Yeah i was looking into those but unlikely to have the wherewithal to pay for something like that so figured id ask if there was anything else that would be suitable to give basics.

If you can't steal it, you probably aren't going to be very good at it.

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Haha true enough

Wiggly Wayne DDS
Sep 11, 2010



2019: session management is still a dark art

Shame Boy
Mar 2, 2010

while waiting in the parking lot of my wife's office today i noticed that there was an open, unprotected wifi network...

...called "WiFi_ODBII" :allears:

post hole digger
Mar 21, 2011

https://twitter.com/hshaban/status/1090050364148207627

apple has had some impossibly bad and silly bugs in the last year but this one might take the cake

edit: drat the admin login thing was 2017 time has no meaning anymore

Midjack
Dec 24, 2007



Shame Boy posted:

while waiting in the parking lot of my wife's office today i noticed that there was an open, unprotected wifi network...

...called "WiFi_ODBII" :allears:

ol dirty bastard lives!

Schadenboner
Aug 15, 2011

by Shine

Midjack posted:

ol dirty bastard lives!

This is probably a transpositional error, they probably meant to name it “OBD II” meaning “On Board Diagnostic II” which is the standard used to communicate engine data. It seems likely that the wireless network is from an “OBD dongle” and connecting to it would not provide access to broader information networks (e.g. the Internet)?

H
T
H
!

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Shame Boy posted:

while waiting in the parking lot of my wife's office today i noticed that there was an open, unprotected wifi network...

...called "WiFi_ODBII" :allears:

dump the VIN to find the owner

Gallatin
Sep 20, 2004

CRIP EATIN BREAD posted:

dump the VIN to find the owner

wifi range and a vin decoder would narrow down to almost the specific car

Diva Cupcake
Aug 15, 2005

https://twitter.com/waxpancake/status/1090042151910526976

Crusader
Apr 11, 2002

rip that qa team

Shaggar
Apr 26, 2006

how is that even possible?

Shaggar
Apr 26, 2006
oh. I know what it is. gently caress face idiot jonny ives decided he wanted you to see the live video of who was calling you so to make that work it creates the session setup required for the call even if you don't accept.

e: whatever code handles the event for adding a new party to the call is probably below the phone ui so theres no checking to see if the user accepted the call. it assumes that because theres an active call the user picked it up even though the UI automatically picked up in order to display the incoming video.

Shaggar fucked around with this message at 03:46 on Jan 29, 2019

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

I wonder if people who normally don't get a lot of facetime calls are suddenly getting a lot of them right now.

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shaggar posted:

oh. I know what it is. gently caress face idiot jonny ives decided he wanted you to see the live video of who was calling you so to make that work it creates the session setup required for the call even if you don't accept.

e: whatever code handles the event for adding a new party to the call is probably below the phone ui so theres no checking to see if the user accepted the call. it assumes that because theres an active call the user picked it up even though the UI automatically picked up in order to display the incoming video.

You mean Google Duo?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply