Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Celexi
Nov 25, 2006

Slava Ukraini!
The employees get searched, the guests not

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



there's at least one goon in every occupation imaginable

Varkk
Apr 17, 2004

Squinky v2.0 posted:

if I was a nation state and I haven’t already owned mar a lago I’m definitely gonna do it like, next week

Probably the best defence Mar a Lago has is all the different states competing with each other to own it.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
The fees to join at some premium bullshit level are almost certainly cheaper than running an actual operation.

pseudorandom name
May 6, 2007

Varkk posted:

Probably the best defence Mar a Lago has is all the different states competing with each other to own it.

at this point mar a lago is probably hosting a private message board where the state actors coordinate their activities

pseudorandom name
May 6, 2007

occasionally the moderators have to ban an american

Midjack
Dec 24, 2007



Chalks posted:

you would have thought that an agent tasked with analysing a usb device of a foreign agent would be doing something more sophisticated than just plugging it into windows 10 and seeing what happened.

win10? they’re probably still on 7 if not xp.

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
hack in progress

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Varkk posted:

Probably the best defence Mar a Lago has is all the different states competing with each other to own it.

ah three stooges syndrome

Kassad
Nov 12, 2005

It's about time.

neutral milf hotel posted:

hack in progress



The Dark Web strikes again.

Proteus Jones
Feb 28, 2013



Kassad posted:

The Dark Dork Web strikes again.

pseudorandom
Jun 16, 2010



Yam Slacker

neutral milf hotel posted:

hack in progress




Probably clicked the big, shiny, green DOWNLOAD button, but not the correct big, shiny, green DOWNLOAD button.

Shame Boy
Mar 2, 2010

got yet another new variation of the "i've cracked your account!!!" email, this time the entire text of the email is embedded attachment images, except for the bitcoin address which is inserted clumsily between two of the images

i know this because apparently my email client is configured to automatically show attachment images of junk mail :whitewater:

also instead of the email being from me it's from some compromised server at "great feels dot com" which made me giggle

e: also also: "I guarantee you that I will not disturb you again after payment, as you are not my single victim. This is a hacker code of honor." :patriot:

e2: some weird headers on this thing, what's that about

code:
Content-Y-plufclong: bigskoopt
Content-Z-spibzoosp: wewsoong
Content-Transfer-Encoding: base64
Content-Type: IMAGE/PNG; name="hl_109.png"
Content-X-smoorbrof: chavnuz
Content-ID: <hl_109.png>
i don't know if i wanna be chavnuz or smoorbrof

Shame Boy fucked around with this message at 16:51 on Apr 10, 2019

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Shame Boy posted:

i know this because apparently my email client is configured to automatically show attachment images of junk mail :whitewater:

A shamefully exploitable client.

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

pseudorandom name posted:

at this point mar a lago is probably hosting a private message board where the state actors coordinate their activities

probably all trump properties are pwned :nsa:

https://www.propublica.org/article/any-half-decent-hacker-could-break-into-mar-a-lago

Agile Vector
May 21, 2007

scrum bored



Shame Boy posted:

got yet another new variation of the "i've cracked your account!!!" email, this time the entire text of the email is embedded attachment images, except for the bitcoin address which is inserted clumsily between two of the images

i know this because apparently my email client is configured to automatically show attachment images of junk mail :whitewater:

also instead of the email being from me it's from some compromised server at "great feels dot com" which made me giggle

e: also also: "I guarantee you that I will not disturb you again after payment, as you are not my single victim. This is a hacker code of honor." :patriot:

e2: some weird headers on this thing, what's that about

code:
Content-Y-plufclong: bigskoopt
Content-Z-spibzoosp: wewsoong
Content-Transfer-Encoding: base64
Content-Type: IMAGE/PNG; name="hl_109.png"
Content-X-smoorbrof: chavnuz
Content-ID: <hl_109.png>
i don't know if i wanna be chavnuz or smoorbrof

y pluf clong?

Shaggar
Apr 26, 2006

Shame Boy posted:

got yet another new variation of the "i've cracked your account!!!" email, this time the entire text of the email is embedded attachment images, except for the bitcoin address which is inserted clumsily between two of the images

i know this because apparently my email client is configured to automatically show attachment images of junk mail :whitewater:

also instead of the email being from me it's from some compromised server at "great feels dot com" which made me giggle

e: also also: "I guarantee you that I will not disturb you again after payment, as you are not my single victim. This is a hacker code of honor." :patriot:

e2: some weird headers on this thing, what's that about

code:
Content-Y-plufclong: bigskoopt
Content-Z-spibzoosp: wewsoong
Content-Transfer-Encoding: base64
Content-Type: IMAGE/PNG; name="hl_109.png"
Content-X-smoorbrof: chavnuz
Content-ID: <hl_109.png>
i don't know if i wanna be chavnuz or smoorbrof

are bitcoin addresses formatted in a standard way that could be detected and used to dumpster a message?

Shifty Pony
Dec 28, 2004

Up ta somethin'


Shaggar posted:

are bitcoin addresses formatted in a standard way that could be detected and used to dumpster a message?

there are standardized formats which I guess you could detect and use as part of the spam-filter. they are also so long that putting them in images to avoid that sort of filtering is bad for a spammer because typing them in is going to be prone to errors.

Shame Boy
Mar 2, 2010

they're all the same length and have a check digit of some kind i forgot built in, if you want to run every non-whitespace-having string of that length through a check for the digit you could probably make it work

it could be defeated pretty easy via HTML or just embedding a QR code or something but i doubt anyone cares enough to do that yet

Shame Boy
Mar 2, 2010

Shifty Pony posted:

there are standardized formats which I guess you could detect and use as part of the spam-filter. they are also so long that putting them in images to avoid that sort of filtering is bad for a spammer because typing them in is going to be prone to errors.

one of the two ways this latest email bodged in the address between the two text-images was as a picture of a QR code since that's how like every single bitcoin app works normally

however they also put the raw text address too so it's not like they were doing this to hide it or something

Shame Boy
Mar 2, 2010

in other news i just discovered that you can access any file on this particular cheap portable wireless scanner's SD card without having to log in. this would be bad but not a big deal for a home unit, if it didn't also constantly broadcast an AP that you can't turn off (even if you connect it to your own AP, it keeps running the other one in tandem for... some reason) that I'm guessing most people don't bother to change the password of, especially after connecting it to their home network.

it even makes downloading the files quick and easy because directory indexing is turned on, though confusingly it sends the "this is a download" flag to the browser so you have to save the directory index to disk first :thumbsup:

Wiggly Wayne DDS
Sep 11, 2010



well this is a new one

https://twitter.com/SmightLP/status/1116375888680161280

Shaggar
Apr 26, 2006

your backup email address can be different from your login email address for the cases where the login email address is a Microsoft one (Hotmail/outlook). i.e. whatever@outlook.com as the login and bonerlord6969@yahoo.com for the backup email. for the scenario where they don't match the hiding of the backup address prevents disclosing address info and acts as an additional check.

they just didn't bother to change it for the case where it the login email and backup email match.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



that's stupid

Shaggar
Apr 26, 2006
why?

Last Chance
Dec 31, 2004

if the email and the "backup email" are the same, then put the check in and move on automatically or it looks stupid, sloppy, and potentially confusing for the user.

TeenageArchipelago
Jul 23, 2013


so, I keep meaning to post this here, but if you use tracfone's website to buy more time it stores your credit card number in your form autofill in firefox. I assume it does it everywhere, but it at least does it in firefox. it's neat.

Celexi
Nov 25, 2006

Slava Ukraini!

TeenageArchipelago posted:

so, I keep meaning to post this here, but if you use tracfone's website to buy more time it stores your credit card number in your form autofill in firefox. I assume it does it everywhere, but it at least does it in firefox. it's neat.

Saves it as regular text and not a cc entry?

Shaggar
Apr 26, 2006

Last Chance posted:

if the email and the "backup email" are the same, then put the check in and move on automatically or it looks stupid, sloppy, and potentially confusing for the user.

what if the user wants to use their phone instead of the backup email?

TeenageArchipelago
Jul 23, 2013


Celexi posted:

Saves it as regular text and not a cc entry?

I just bought some more data to check, it saves it in your middle name. it also saves your CCV in your form history, so that's neat

Celexi
Nov 25, 2006

Slava Ukraini!
Cool

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


report it to mozilla
pretty sure they maintain a blacklist to prevent that

Last Chance
Dec 31, 2004

Shaggar posted:

what if the user wants to use their phone instead of the backup email?

then sure whatever present that option, but don't throw out a useless obfuscated confirm email thing if it's the same email address you just typed in.

geonetix
Mar 6, 2011


well someone is having fun with matrix.org

https://github.com/matrix-org/matrix.org/issues

Stabby McDamage
Dec 11, 2005

Doctor Rope

geonetix posted:

well someone is having fun with matrix.org

https://github.com/matrix-org/matrix.org/issues

These are hilarious.

You can see their write-up here -- they quietly mention in one small paragraph near the bottom "oh the guy posted a bunch of github issues telling us how we screwed up".

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
good to know that github takes its physical security seriously

https://twitter.com/cmaxw/status/1116439901141004288

Wiggly Wayne DDS
Sep 11, 2010



a podcaster with an inflated ego and no understanding of how the rest of the world operates? :monocle:

don't you know who i am

evil_bunnY
Apr 2, 2003

Wiggly Wayne DDS posted:

no understanding of how the rest of the world operates? :monocle:
Like seriously, what did you think was gonna happen, guy?

Diva Cupcake
Aug 15, 2005

for someone with supposedly 35k followers he gets almost zero engagement on his tweets, like 1-2 likes/retweets.

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
remember TheCthulhu/@CthulhuSec? guy who made a name for himself hosting various data dumps (fraternal order of police, turkish police, linkedin hack)

turns out he was the "dread pirate roberts" on silk road 2
also he was into child porn and planned on selling it

https://motherboard.vice.com/en_us/article/9kx59a/silk-road-2-founder-dread-pirate-roberts-2-caught-jailed-for-5-years

the surprising part to me is that he got arrested pretty early on and most of the things he is known for are things he did while on police bail

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply