Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Chronojam
Feb 20, 2006

This is me on vacation in Amsterdam :)
Never be afraid of being yourself!


Did you check your PATH?

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos
Nothing Javaish there.

Dread Head
Aug 1, 2005

0-#01
Love spending friday night shutting down servers as that is the direction we have been given! Going to be a fun weekend!

Nukelear v.2
Jun 25, 2004
My optional title text
Are there any details on the vulnerability for 1.x? Especially around say any sort of equivalent properties to log4j2.formatmsgnolookups that could be set to mitigate the issue.
Yes it's been EOL for a mere 6 years, but we can't be bothered to upgrade.

Dread Head
Aug 1, 2005

0-#01

Nukelear v.2 posted:

Are there any details on the vulnerability for 1.x? Especially around say any sort of equivalent properties to log4j2.formatmsgnolookups that could be set to mitigate the issue.
Yes it's been EOL for a mere 6 years, but we can't be bothered to upgrade.

If you want to believe this: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126

Then it should not be impacted, probably the most official thing you will get. We only shutdown stuff with 2.x running.

KillHour
Oct 28, 2007


I'm just going to continue as usual and if I get hacked they can see what kind of hosed up porn I watch and demand I pay 0.05BTC to decrypt all the pictures I save from the funny pictures thread.

Nukelear v.2
Jun 25, 2004
My optional title text

Dread Head posted:

If you want to believe this: https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126

Then it should not be impacted, probably the most official thing you will get. We only shutdown stuff with 2.x running.

I want to believe. Appreciate it, I totally missed ceki's post on that page.

Fart Amplifier
Apr 12, 2003

The log4j vulnerability was known of for 5 years

https://twitter.com/th3_protoCOL/status/1469644923028656130?t=YQpiCqm6xn1Q4S3X0657kg

SlowBloke
Aug 14, 2017
Maybe I missed this thru the posting but if you decided to nerd out and have a unifi controller hosted on the cloud or exposed to the web in any way, upgrade to 6.5.54 immediately, any other build is vulnerable to this log4j vuln.

Dread Head
Aug 1, 2005

0-#01

lol

CLAM DOWN
Feb 13, 2007




Ugh Friday was so exhausting with this stupid log4j poo poo

some kinda jackal
Feb 25, 2003

 
 
I'm being called into comms bridges today, so much for a relaxing weekend after a lovely Friday.

chin up everything sucks
Jan 29, 2012

8am in the morning yesterday I pinged our infrastructure team about Log4J. They said that we were fine. 2 hours later they start really digging in and going "ok poo poo, we aren't fine."

11am a conference bridge starts, and I was included on it. 8pm last night the bridge finally ended.

My boss sent me a $50 doordash gift card for my hard work. Yay!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Yeah already had to deal with two clients who got popped and had cryptominers installed. Its gonna be a long weekend.

Dread Head
Aug 1, 2005

0-#01
Hello weekend crew dealing with log4j. Spending the weekend shutting things down and waiting to see how long vendors will take to provide patches!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Dread Head posted:

Hello weekend crew dealing with log4j. Spending the weekend shutting things down and waiting to see how long vendors will take to provide patches!

We asked the Exec team to sign off on shutting down non-critical apps. Got told no.

CLAM DOWN
Feb 13, 2007




The Something Awful Forums > Discussion > Serious Hardware/Software Crap > The Infosec Thread: hard for 10.0s

Saukkis
May 16, 2003

Unless I'm on the inside curve pointing straight at oncoming traffic the high beams stay on and I laugh at your puny protest flashes.
I am Most Important Man. Most Important Man in the World.

Should've come up with a name and a hashtag :(

repiv
Aug 13, 2009

I'd say the NSA probably had fun with that, but the NSAs own Ghidra tool was vulnerable lol

:nsamad:

Dread Head
Aug 1, 2005

0-#01

CommieGIR posted:

We asked the Exec team to sign off on shutting down non-critical apps. Got told no.

We have shut down any MC apps that will not result in danger to users (we managed a few that fall into this area) on top of non MC apps. The biggest shock is how many things still use 1.x version of those even though it was EOL back in 2015, many of those are bundled in middle ware from vendors (adobe etc) so not trivial to update those if you can't wait for a patch from said vendor...

Fart Amplifier
Apr 12, 2003

24 hours after all the SIS systems in the province are found to be trivially hackable



Maybe you can start by taking people offline you dorks

Mustache Ride
Sep 11, 2001



Got everything patched by 3:30am. Yay infrastructure as code and automation!

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Fart Amplifier posted:

Honest question, how do you know you're not running Java?



Television sets, parking meters, telephones, cars, birdcages, cheese graters, battleships, and pants. :ohdear:

Sir Bobert Fishbone
Jan 16, 2006

Beebort

Powered Descent posted:



Television sets, parking meters, telephones, cars, birdcages, cheese graters, battleships, and pants. :ohdear:

pygmies, budgies, kuala lumpur

WhiteHowler
Apr 3, 2001

I'M HUGE!

Dread Head posted:

Hello weekend crew dealing with log4j. Spending the weekend shutting things down and waiting to see how long vendors will take to provide patches!

16 hours on and still rolling!

I'll just say I have a new respect for a well-maintained intrusion detection/prevention suite. This morning ours started lighting up like a Christmas tree with blocked log4j attacks, and while we took pretty quick action on remediating once the vulnerability was widely reported, I have to wonder how much grief it saved us.

Tryzzub
Jan 1, 2007

Mudslide Experiment
https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592

^^ vendor response cheat sheet for this nonsense

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?

WhiteHowler posted:

16 hours on and still rolling!

I'll just say I have a new respect for a well-maintained intrusion detection/prevention suite. This morning ours started lighting up like a Christmas tree with blocked log4j attacks, and while we took pretty quick action on remediating once the vulnerability was widely reported, I have to wonder how much grief it saved us.

What suite do you use? Nothing speaks like working in a real world event.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

repiv posted:

I'd say the NSA probably had fun with that, but the NSAs own Ghidra tool was vulnerable lol

:nsamad:

The public version, at least!

Hughmoris
Apr 21, 2007
Let's go to the abyss!

Subjunctive posted:

The public version, at least!

That's interesting. In a hypothetical world, if they knew their tool was compromised before the majority heard of this vulnerability, they could have exploited the users that downloaded it?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Hughmoris posted:

That's interesting. In a hypothetical world, if they knew their tool was compromised before the majority heard of this vulnerability, they could have exploited the users that downloaded it?

I mean, I don’t know of evidence that they would, but the set of people who use Ghidra are probably pretty interesting to the NSA.

RFC2324
Jun 7, 2012

http 418

Subjunctive posted:

I mean, I don’t know of evidence that they would, but the set of people who use Ghidra are probably pretty interesting to the NSA.

Isn't the evidence the fact that they are the NSA?

some kinda jackal
Feb 25, 2003

 
 
Can I claim this weekend as CPEs

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Good graphic of Log4j vuln:

https://twitter.com/markus_neis/status/1470109712649756674?s=20

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
For the people asking about Android, no, it's not affected. Android has the ability to use Java jars and bytecode for development, but it's not the JVM and doesn't feature the mechanism used for this, AIUI

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Volmarias posted:

For the people asking about Android, no, it's not affected. Android has the ability to use Java jars and bytecode for development, but it's not the JVM and doesn't feature the mechanism used for this, AIUI

Yeah I actually scanned a couple android test devices out of curiosity, but people tend to forget: Its not REALLY java, its java-like.

unknown
Nov 16, 2002
Ain't got no stinking title yet!


https://twitter.com/p_malynin/status/1469866520939429889

Thanks Ants
May 21, 2004

#essereFerrari


:vince:

BaseballPCHiker
Jan 16, 2006

Someone on a conference call around my companies response to Log4J just said they werent ever told to patch their stuff so they never have and that as a result they arent vulnerable because they run Log4J version 1x.

This place is so loving backwards and behind the times. I need to remember to just take a deep breath, not let it get to me, and keep collecting the paychecks.

chin up everything sucks
Jan 29, 2012

BaseballPCHiker posted:

Someone on a conference call around my companies response to Log4J just said they werent ever told to patch their stuff so they never have and that as a result they arent vulnerable because they run Log4J version 1x.

This place is so loving backwards and behind the times. I need to remember to just take a deep breath, not let it get to me, and keep collecting the paychecks.

Point them to the 1.x CSV from 2 years ago that is just as bad.

Adbot
ADBOT LOVES YOU

BaseballPCHiker
Jan 16, 2006

Good loving lord. Now someone doesnt want to update because a change freeze was going to go into affect next week.

I should just start live tweeting this poo poo. I cant believe this company hasnt been just totally annihilated by ransomware or something yet.

BaseballPCHiker fucked around with this message at 18:14 on Dec 13, 2021

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply