Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BlankSystemDaemon
Mar 13, 2009




Combat Pretzel posted:

Using unbound as local full resolver would still get me to the proper edge servers of CDNs, right? This isn't something coordinated with the ISPs DNS resolvers?
It's a recursive resolver, meaning it still needs to have an authoritative nameserver to ask when it doesn't have an answer (ie doesn't have it cached).
You need 'nsd' (also by NLnet Labs) for that.

EDIT: Or are you talking about GeoIP or topological round-robin CDNs?

Adbot
ADBOT LOVES YOU

Impotence
Nov 8, 2010
Lipstick Apathy
edns-client-subnet doesn't matter if you are directly hitting their nameserver and they can get the full ip of the requestor

CyberPingu
Sep 15, 2013


If you're not striving to improve, you'll end up going backwards.



:chloe:

Butter Activities
May 4, 2018





Condensing out all the “lol I upvote this insult good sir” comments ruining this nugget of joy I found while trying to trouble shoot Kali Linux.

Butter Activities fucked around with this message at 16:48 on Nov 29, 2020

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Humble bundle has a bunch of No Starch Press's hacking books up:

https://www.humblebundle.com/books/...ress_bookbundle

Butter Activities
May 4, 2018

CommieGIR posted:

Humble bundle has a bunch of No Starch Press's hacking books up:

https://www.humblebundle.com/books/...ress_bookbundle

Oh gently caress yeah I almost dropped 20 dollars on just one book in that bundle yesterday.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

CommieGIR posted:

Humble bundle has a bunch of No Starch Press's hacking books up:

https://www.humblebundle.com/books/...ress_bookbundle

some top tier book covers in here

can't decide if i'm the alcoholic robot or the alien autopsy

Proteus Jones
Feb 28, 2013



The Practical Packet Capture book is worth almost the entire bundle.

I bought that for my team's little reference library one year. It disappeared during one of our building moves years ago.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Yea, I have a few of those books and they're pretty good.

some kinda jackal
Feb 25, 2003

 
 
I need to brush up on my crypto so I'm in for twenty-something dollaroos.

xtal
Jan 9, 2011

by Fluffdaddy
You could learn infosec at the same time by pirating them

Potato Salad
Oct 23, 2014

nobody cares


CommieGIR posted:

Humble bundle has a bunch of No Starch Press's hacking books up:

https://www.humblebundle.com/books/...ress_bookbundle

I bought a copy of practical packet analysis for every single member of my team 3 years ago

We are mysteriously quicker at zeroing in application problems

Extrinsic Value
Dec 2, 2020

by Pragmatica
Did someone say crypto?!?!

spankmeister
Jun 15, 2008






gently caress off seraph

BlankSystemDaemon
Mar 13, 2009




Ian Beer at Project Zero posted:

In this demo I remotely trigger an unauthenticated kernel memory corruption vulnerability which causes all iOS devices in radio-proximity to reboot, with no user interaction. Over the next 30'000 words I'll cover the entire process to go from this basic demo to successfully exploiting this vulnerability in order to run arbitrary code on any nearby iOS device and steal all the user data.
Hollywood ain't got poo poo on this.

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?

BlankSystemDaemon posted:

Hollywood ain't got poo poo on this.

Yeah, it almost reads like one of those Hollywood plots where you roll your eyes a bit and go, "That's not really how things work" even if it's theoretically plausible.

Diva Cupcake
Aug 15, 2005

Here's a fun read.

https://twitter.com/i41nbeer/status/1333885229086412801?s=20

astral
Apr 26, 2004


Or, if you want a direct link to the fun read:
https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html

Proteus Jones
Feb 28, 2013




It gets super in the weeds, but has a great breakdown of how AWDL works.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
https://twitter.com/thugcrowd/status/1334974030559006724?s=20

Sheep
Jul 24, 2003
Much as anyone may hate OANN, this isn't responsible disclosure and shouldn't be encouraged or directly linked, in my opinion.

RFC2324
Jun 7, 2012

http 418

Sheep posted:

Much as anyone may hate OANN, this isn't responsible disclosure and shouldn't be encouraged or directly linked, in my opinion.

I feel like ThugCrowd may not be the most responsible organization.

E: I do appreciate their all ascii art website tho

spankmeister
Jun 15, 2008






I used to be all about responsible disclosure, but I have since changed my opinion.

Some companies just don't deserve it.

CLAM DOWN
Feb 13, 2007




Sheep posted:

Much as anyone may hate OANN, this isn't responsible disclosure and shouldn't be encouraged or directly linked, in my opinion.

gently caress that, OANN deserves it.

trashy owl
Aug 23, 2017

CLAM DOWN posted:

gently caress that, OANN deserves it.

:emptyquote:

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sheep posted:

Much as anyone may hate OANN, this isn't responsible disclosure and shouldn't be encouraged or directly linked, in my opinion.

Not familiar with OANN but you sound like a huge square saying this. Your boss or whoever you're trying to suck up to isn't watching. Get over yourself

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!

Rufus Ping posted:

Not familiar with OANN but you sound like a huge square saying this. Your boss or whoever you're trying to suck up to isn't watching. Get over yourself

If you don't know what OANN is then he's right, responsible disclosure is important to keep in infosec. If people stop assuming researchers are acting in good faith, a legal crackdown could hurt good security everywhere.

On the other hand, this org specifically is reprehensibly morally bankrupt.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Rufus Ping posted:

Not familiar with OANN but you sound like a huge square saying this. Your boss or whoever you're trying to suck up to isn't watching. Get over yourself

It's the propaganda rag for people who think that Fox News is an extreme left organization. They're on the same level of respect as Stormfront would be if they were still around.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

klosterdev posted:

If you don't know what OANN is then he's right, responsible disclosure is important to keep in infosec. If people stop assuming researchers are acting in good faith, a legal crackdown could hurt good security everywhere.

On the other hand, this org specifically is reprehensibly morally bankrupt.

The way to avoid good faith researchers getting blowback is not to dress all hacking up as "research". It's the SWIM "research chemicals" gambit of the computing world.

Posting this guy's creds is good and would still be good if the site were less reprehensible. It sounds like they should have finished the job, in fact, and anonymously wrecked their poo poo beyond repair rather than simply giving them a kindly heads up to rotate their passwords.

It's okay to have the courage of one's convictions and defend hacking on its own terms rather than handwringing over appearing sensible and grown-up.

spankmeister
Jun 15, 2008






Having dealt with a fair number of Responsible Disclosures and Coordinated Vulnerability Disclosures myself, I can tell you that sometimes it's really not worth the time and effort. Because it really takes a lot of time and effort to do RD. Some companies just don't respond, or they threaten to sue.

I totally understand why some researchers feel the only way to achieve your goal (get vulnerability fixed) is to embarrass a company publically.

Achmed Jones
Oct 16, 2004



There is no world in which brute-forcing a wordpress password (or whatever) is "research." This was just some skids owning some shitbirds, except instead of doing it themselves they're hoping somebody else will use the creds to finish the job. Good on those kids, I hope they don't get caught, but they aren't exactly tavis over here. Responsible disclosure shouldn't be part of this conversation because it's way beside the point

spankmeister
Jun 15, 2008






Brute forcing? The creds were in a pdf accessible to the entire internet.

Achmed Jones
Oct 16, 2004



hence the "or whatever". but that seems like even less research-like, if that's possible


e: holy poo poo is that pdf _just_ what they found? i thought they'd made the 'use these creds, here is how' pdf and were hosting it on OANN itself for funsies. that's even funnier

Achmed Jones fucked around with this message at 02:48 on Dec 5, 2020

Internet Explorer
Jun 1, 2005





I guess infosec really isn't punk rock after all.

trashy owl
Aug 23, 2017

Achmed Jones posted:

hence the "or whatever". but that seems like even less research-like, if that's possible


e: holy poo poo is that pdf _just_ what they found? i thought they'd made the 'use these creds, here is how' pdf and were hosting it on OANN itself for funsies. that's even funnier

If you thought it was anything other than "haha look at these morons, these absolute buffoons" I really don't know what to tell you.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Internet Explorer posted:

I guess infosec really isn't punk rock after all.

They arrested all the punk ones :(

Achmed Jones
Oct 16, 2004



I feel like somebody should quote the thing from slc punk, but I don't want to look it up myself

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
This is the dumbest thing. OANN sucks but the level of interest I have in celebrating leaked Wordpress credentials is nonexistent. They’re not owning anyone. They’re certainly not pwning anyone.

siggy2021
Mar 8, 2010
Chill out nobody claimed anyone "pwned" anyone. We can all have a good laugh at a reprehensible organization doing real dumb poo poo.

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

Don't you see? Its impossible that someone could have done this without a capitalist profit motive!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply