Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Hed
Mar 31, 2004

Fun Shoe
I’ve been having a really rough time rolling out phishing resistant MFA in YubiKeys as FIDO2 for Entra ID.
About half the people in my test group can’t get prompted to present their FIDO2 key in the Microsoft iOS / iPadOS apps: they just get a “we need more information” screen or something that lets them select on the Microsoft dialog “Use security key” but doesn’t launch the system prompt.

Things that work great with FIDO2:
Windows logins
browser Entra logins (all platforms)
iOS and iPadOS Mail.app (System accounts)

Things that are hit and miss:
iOS and iPadOS Outlook or office apps

Things that don’t work at all:
macOS Mail.app

Not sure if I need to add Conditional Access policies or that would gently caress things up more. It’s like it really wants to use the Microsoft Authenticator Push with numbers if the user has ever set it up, and the policy tells it no, and it mostly can’t figure out what to do and hangs up.

Adbot
ADBOT LOVES YOU

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




MustardFacial posted:

Maybe just migrate to another VPN appliance at this point.

We already had a new one in testing, but Security said YOLO last week and pushed the new appliance on basically no notice. A couple of things are still broken, but it's been relatively smooth.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


https://fortiguard.fortinet.com/psirt/FG-IR-24-015

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Serious Hardware/Software Crap > The Infosec Thread: may allow a remote unauthenticated attacker to execute arbitrary code

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


I know they have their own problems but at least remote access tools like Prisma access or ZPA don’t leave crap like this exposed at the edge

flakeloaf
Feb 26, 2003

Still better than android clock

Very Public Network

BlankSystemDaemon
Mar 13, 2009



flakeloaf posted:

Very Public Network

Andohz
Aug 15, 2004

World's Strongest Smelly Hobo

flakeloaf posted:

Very Public Network

:nsavince:

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat

rafikki posted:

I know they have their own problems but at least remote access tools like Prisma access or ZPA don’t leave crap like this exposed at the edge

Isn't Prisma Access basically a cloud VPN anyways?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Super-NintendoUser posted:

Isn't Prisma Access basically a cloud VPN anyways?

Yeah, but you’re not exposing a client vpn gateway to the world. Of course, now you’re trusting Palo themselves not to get popped…

MustardFacial
Jun 20, 2011
George Russel's
Official Something Awful Account
Lifelong Tory Voter
I guess Ivanti is doing a full code review in light of the multiple 0-days, and are uncovering all of the bugs:

https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US

Anarchy Stocking
Jan 19, 2006

O wicked spirit born of a lost soul in limbo!

This has been my Friday.

Honey Im Homme
Sep 3, 2009

https://twitter.com/FP_Champagne/status/1755691837531078820?s=20

Incredible.

Thanks Ants
May 21, 2004

#essereFerrari


Ah yes car thieves will be deterred by making their tools illegal

Accipiter
Jan 24, 2004

SINATRA.
Fingers crossed they ban portable computers.

Hed
Mar 31, 2004

Fun Shoe
I WISH I could get my flipper to do something useful like be an opener for my garage door or car doors

flakeloaf
Feb 26, 2003

Still better than android clock

Can't stop a sea can full of cars but we have big plans for a device the size of a wallet, and those plans involve making it illegal to have a thing it was already illegal to have in circumstances that make it seem like you're using it to steal cars

Defenestrategy
Oct 24, 2010

Hed posted:

I WISH I could get my flipper to do something useful like be an opener for my garage door or car doors

Same. Where are these people who figured out how to make the flipper do anything more comolicated then bad keyboard and cloning keycards?

Jiro
Jan 13, 2004

MustardFacial posted:

I guess Ivanti is doing a full code review in light of the multiple 0-days, and are uncovering all of the bugs:

https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US

"Really really really really late QA" and then on to beta! :v:

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Defenestrategy posted:

Same. Where are these people who figured out how to make the flipper do anything more comolicated then bad keyboard and cloning keycards?

Yeah that's kind of the issue - this ban is toothless. They ban the tools, but you can easily replicate those tools.

Its typical politician thought process.

some kinda jackal
Feb 25, 2003

 
 
Looks like my Flipper Zero will gather more dust than it already is.

e: Just make it illegal to be subject to radio frequencies duh. You have no idea the amount of sensitive data that is flowing through my body right this second.

some kinda jackal fucked around with this message at 13:06 on Feb 12, 2024

Kazinsal
Dec 13, 2011


And here I was thinking of grabbing one to replace the extremely janky remote for my apartment building's underground parkade.

Still might.

SlowBloke
Aug 14, 2017

CommieGIR posted:

Yeah that's kind of the issue - this ban is toothless. They ban the tools, but you can easily replicate those tools.

Its typical politician thought process.

I bet they will still be sold on Amazon anyway, with a weird description like all those weird "Oil filters" on aliex or ebay.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

SlowBloke posted:

I bet they will still be sold on Amazon anyway, with a weird description like all those weird "Oil filters" on aliex or ebay.

"Unique remote and pet ID scanner!"

Mustache Ride
Sep 11, 2001



https://www.youtube.com/watch?v=p4OGQQPMiXQ

some kinda jackal
Feb 25, 2003

 
 
Buying a drinking bird toy to just mash the "stop breach" button 24/7

Just in case

Achmed Jones
Oct 16, 2004



SlowBloke posted:

I bet they will still be sold on Amazon anyway, with a weird description like all those weird "Oil filters" on aliex or ebay.

i searched for oil filters and just got oil filters, what do you mean?

SlowBloke
Aug 14, 2017

Achmed Jones posted:

i searched for oil filters and just got oil filters, what do you mean?

suppressors

Coxswain Balls
Jun 4, 2001

Achmed Jones posted:

i searched for oil filters and just got oil filters, what do you mean?



It seems like every year a couple dumbasses get busted for ordering them off AliExpress.

https://www.brandonsun.com/local/2023/07/26/absolute-discharge-in-silencer-case

Achmed Jones
Oct 16, 2004



lol nice :tipshat: thanks!

Internet Old One
Dec 6, 2021

Coke Adds Life
Apologize for the weirdness of this post but this is the best place I could think to ask this question in the new lovely internet.

So I’m getting back into information security after decades on the sidelines.
I’m looking to start building out some hacking tools and I even did a PoC of some of these ideas oh way back when before covid.

My question is when you have common scripting languages in windows, do eval() type functions typically get flagged by heuristic detection in endpoint security?

Pretty much every good idea I have revolves around eval but I can’t be the first to see the utility and I the times I’ve had to use such functions in normal well written programs I can probably count on one hand so it might look suspicious.

evil_bunnY
Apr 2, 2003

Coxswain Balls posted:



It seems like every year a couple dumbasses get busted for ordering them off AliExpress.

https://www.brandonsun.com/local/2023/07/26/absolute-discharge-in-silencer-case

You can register those, apparently, so everyone getting in federal trouble over them is doing it over the $200 stamp which, lol.

Coxswain Balls
Jun 4, 2001

evil_bunnY posted:

You can register those, apparently, so everyone getting in federal trouble over them is doing it over the $200 stamp which, lol.

We're talking specifically about Canada, since that's where the Flipper Zero ban is taking place. Suppressors are prohibited items here.

Diva Cupcake
Aug 15, 2005

Internet Old One posted:

Apologize for the weirdness of this post but this is the best place I could think to ask this question in the new lovely internet.

So I’m getting back into information security after decades on the sidelines.
I’m looking to start building out some hacking tools and I even did a PoC of some of these ideas oh way back when before covid.

My question is when you have common scripting languages in windows, do eval() type functions typically get flagged by heuristic detection in endpoint security?

Pretty much every good idea I have revolves around eval but I can’t be the first to see the utility and I the times I’ve had to use such functions in normal well written programs I can probably count on one hand so it might look suspicious.
The heuristic is obviously contextual but yes, Defender for Endpoint, Crowdstrike, et al are aware of the ability to abuse input into the function.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Coxswain Balls posted:

We're talking specifically about Canada, since that's where the Flipper Zero ban is taking place. Suppressors are prohibited items here.

Achmed Jones
Oct 16, 2004



evil_bunnY posted:

You can register those, apparently, so everyone getting in federal trouble over them is doing it over the $200 stamp which, lol.

ha, i can chime in here. it's not about the $200, it's about the "I'm not gonna put my name on a GOVERNMENT LIST! then they'll come to GET MY GUNS and MURDER MY FAMILY RUBY RIDGE WACO AND SO ON"

which is to say - it's even _dumber_ than if it were about $200. it's just childish NO I DONT WANNA

spankmeister
Jun 15, 2008






I just looked it up and the NFA is from 1934. Back in the 30's $200 was LOT of money, it was designed to be prohibitively expensive. The number was never indexed against inflation. Nowadays most gun people spend heaps on their hobby and $200 is nbd.

BonHair
Apr 28, 2007

Achmed Jones posted:

ha, i can chime in here. it's not about the $200, it's about the "I'm not gonna put my name on a GOVERNMENT LIST! then they'll come to GET MY GUNS and MURDER MY FAMILY RUBY RIDGE WACO AND SO ON"

which is to say - it's even _dumber_ than if it were about $200. it's just childish NO I DONT WANNA

I don't actually know how deep the freedom to own murder weapons runs, but I can also imagine a few people who get denied in their request to get a suppressor on account of they're not allowed guns at all, so they bought all their guns privately without receipts.

Edit: other fun Amazon products are novelty bottle openers that just so happen to fit into seatbelt buckles. Which, aside from the dumb impulse to drive without a seatbelt is fantastic because of the beer association.
Also reviews of fish antibiotics that were definitely used on people.

BonHair fucked around with this message at 19:41 on Feb 13, 2024

Hed
Mar 31, 2004

Fun Shoe

Achmed Jones posted:

ha, i can chime in here. it's not about the $200, it's about the "I'm not gonna put my name on a GOVERNMENT LIST! then they'll come to GET MY GUNS and MURDER MY FAMILY RUBY RIDGE WACO AND SO ON"

which is to say - it's even _dumber_ than if it were about $200. it's just childish NO I DONT WANNA

They do have to be fingerprinted and are subject to a waiting list, which has been "behind" for curiously long periods of time before. There's a host of other restrictions too, like letting the chief law enforcement officer know. I can see why vulnerable folks would prefer not to rouse cop attention. It's not like it's pay the $200 and go.

Adbot
ADBOT LOVES YOU

Pigbuster
Sep 12, 2010

Fun Shoe
Authy is ending support for their desktop app next month, March 19. Is there a good alternative that similarly uses the same account across both mobile and desktop? I don't want to drag my phone out every time I have to log in to a place.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply