Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
spankmeister
Jun 15, 2008






Rip zonealarm

Adbot
ADBOT LOVES YOU

Cybernetic Vermin
Apr 18, 2005

mostly rip thinking that the identity of the base image of a process is a useful/refined security distinction

pseudorandom name
May 6, 2007

speaking of jre, ghidra got an update today

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Midjack posted:

motherfuckers act like they forgot about jre

eqing for rotor

rotor
Jun 11, 2001

classic case of pineapple derangement syndrome

Midjack posted:

motherfuckers act like they forgot about jre

rotor
Jun 11, 2001

classic case of pineapple derangement syndrome

Sniep posted:

eqing for rotor

thanks but i forgot i was logged in here so BAM

Soricidus
Oct 21, 2010
freedom-hating statist shill

pseudorandom name posted:

speaking of jre, ghidra got an update today

"turned on font antialiasing by default for linux"
yup this is authentic government code

DrPossum
May 15, 2004

i am not a surgeon

Midjack posted:

motherfuckers act like they forgot about jre

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Midjack posted:

motherfuckers act like they forgot about jre

drat lol

also this actually happened at work! turns out some poo poo old application depends on it and its critical for hr so some poor fucker has to figure out how to keep it working! not me though!

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

Midjack posted:

motherfuckers act like they forgot about jre

graph please

Phone
Jul 30, 2005

親子丼をほしい。

Midjack posted:

motherfuckers act like they forgot about jre

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Midjack posted:

motherfuckers act like they forgot about jre

FlapYoJacks
Feb 12, 2009

Midjack posted:

motherfuckers act like they forgot about jre

Tatsujin
Apr 26, 2004

:golgo:
EVERYONE EXCEPT THE HOT WOMEN
:golgo:
now now we can just hang onto it until this thread gets closed yet again

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



lotta yall dont understand thread semver

minor point updates for title changes, version bumps for new threads

please dont use yospos threads in production until you have internalized this

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



also, mods pls

Midjack posted:

Security Fuckup Megathread - v17.1 - motherfuckers act like they forgot about jre

also also, little snitch owns bones

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

yoloer420 posted:

The question was about process aware firewalls that work. They do work, I'm not aware of any enterprise level solutions (for anything) that work though. The tech exists however.

it's called "the windows firewall"

ewiley
Jul 9, 2003

More trash for the trash fire

Krankenstyle posted:

lotta yall dont understand thread semver

minor point updates for title changes, version bumps for new threads

please dont use yospos threads in production until you have internalized this

I'm going to need to see your versioning documentation in the IG, this seems to be a non-security impacting change so you can probably use a wildcard.

ewiley
Jul 9, 2003

More trash for the trash fire

BangersInMyKnickers posted:

it's called "the windows firewall"

Windows firewall is good in the same way Defender is good. Microsoft actually implemented a relatively simple, good thing that you can manage centrally but then forgot that you might care about central logging.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ewiley posted:

Windows firewall is good in the same way Defender is good. Microsoft actually implemented a relatively simple, good thing that you can manage centrally but then forgot that you might care about central logging.

They do need a native mechanism to forward that in to an event log but if you aren't already deploying a log forwarding agent to scape application log files then you've already messed up so its kinda a moot issue

Shame Boy
Mar 2, 2010

Krankenstyle posted:

lotta yall dont understand thread semver

minor point updates for title changes, version bumps for new threads

please dont use yospos threads in production until you have internalized this

actually i think you'll find the way semver works is nobody ever changes major versions because we need to "get a marketing win out of a new major version", minor versions are meaningless and patch versions are random

and then someone changes it to be based on the current year and then never updates it again so your version is forever 2017.x.x

MononcQc
May 29, 2007

half the libs are pre 1.0.0 and the versions mean nothing too

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Defender is getting stronger with ATP, ATA, and Sandbox testing builtin.

Honestly, if you have Azure AD, even just for your off prem stuff, you should totally take advantage of ATP and their Event Forewarding Analysis stuff.

We've been testing its use as a way to isolate infected machines, and even though it modifies the firewall to block all outbound internet traffic if it detects an infection, it keeps pushing the ATP and even forewarding for analysis

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Midjack posted:

motherfuckers act like they forgot about jre

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Shame Boy posted:

actually i think you'll find the way semver works is nobody ever changes major versions because we need to "get a marketing win out of a new major version", minor versions are meaningless and patch versions are random

and then someone changes it to be based on the current year and then never updates it again so your version is forever 2017.x.x

lol at using patch versions just increment the minor version number and look in the code if you want to see what check ins are covered in that

The Fool
Oct 16, 2003


CommieGIR posted:

Defender is getting stronger with ATP, ATA, and Sandbox testing builtin.

Honestly, if you have Azure AD, even just for your off prem stuff, you should totally take advantage of ATP and their Event Forewarding Analysis stuff.

We've been testing its use as a way to isolate infected machines, and even though it modifies the firewall to block all outbound internet traffic if it detects an infection, it keeps pushing the ATP and even forewarding for analysis

There's like 4 different ATP products

El Mero Mero
Oct 13, 2001

Someone post some anime so we can force the devs to update

cinci zoo sniper
Mar 15, 2013




smoka, i heed thee

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
pro thread title

cinci zoo sniper
Mar 15, 2013




Now fix the versioning

Wiggly Wayne DDS
Sep 11, 2010



cinci zoo sniper posted:

Now fix the versioning

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



cinci zoo sniper posted:

Now fix the versioning

lmao

:negative:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

lel

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



good hustle

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

The Fool posted:

There's like 4 different ATP products

And I'm specifically talking about one of them.



How it relates to the ATP product chain as a whole:

CommieGIR fucked around with this message at 22:04 on Mar 27, 2019

Soricidus
Oct 21, 2010
freedom-hating statist shill

ftfy

ErIog
Jul 11, 2001

:nsacloud:

ate poo poo on live tv posted:

Yea, this is where I'm at. Idempotent is a fun word, and ansible/network changes AREN'T.

I can spin up (from scratch) an almost unlimited number of switches or routers that will be configured identically with dynamically assigned ip addresses, and hostnames, and ACLs etc etc. But tell me that you want to change our production vlan from 100 to 101 and I'll be at a loss to figure out how to do that cleanly and remove the old vlan :/

Thirding this. All configuration is a transition from some state to another state, and the concept of idempotence with regard to configuration just seems like either pretending the starting state doesn't exist or implicitly assuming a known clean starting state. I like Ansible for configuration automation, but the idempotent paradigm is stupid and I don't use it. I thought I was stupid or that I must have been using Ansible wrong. I may still be stupid, but it seems pretty clear to me after a few years of using it that Ansible itself misunderstands the nature of their own project.

ate shit on live tv
Feb 15, 2004

by Azathoth
For Juniper devices Ansible works really well because you just delete the entire config, then apply the complete new one. Juniper commit engine is smart and as long as the section that you deleted and put back didn't change, the router won't recommit and cause router reconvergence, or firewalls to drop sessions etc.

For Cisco/Arista, welp...

Rahu
Feb 14, 2009


let me just check my figures real quick here
Grimey Drawer
Cisco had a rce vulnerability on one of their routers which was reported to them along with a curl command that would trigger the problem.

They released an update that solves this problem by blocking user agents containing 'curl'

:thumbsup:

https://twitter.com/RedTeamPT/status/1110843396657238016

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Rahu posted:

Cisco had a rce vulnerability on one of their routers which was reported to them along with a curl command that would trigger the problem.

They released an update that solves this problem by blocking user agents containing 'curl'

:thumbsup:

https://twitter.com/RedTeamPT/status/1110843396657238016

:eyepoop:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply