Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
mod saas
May 4, 2004

Grimey Drawer

Jeesis posted:

advice for someone trying to get into the security field?

going out on a limb here but maybe don't poo poo over people's advice and then ask for more

Adbot
ADBOT LOVES YOU

mod saas
May 4, 2004

Grimey Drawer

sarehu posted:

Don't hang out online with people that get butthurt over your posting who somehow also are too cool to use the shift key.

This is a good post. I like it because it demonstrates three variants of tribalism in only a single sentence: the Boomer xenophobia about avoiding the shift key, Gen-X angst over people who think they're cool, and the Millennial attitude that an echo chamber is objectively better than differences in belief. Forums poster sarehu, thank you for this gift.

mod saas
May 4, 2004

Grimey Drawer

EVIR Gibson posted:

So here's a random tool I always use when scoping out a target; Bing.

Stop laughing.

But really, Bing has a feature no other search engine out there has including Google. It gives the user the ability to search for domains by IP.

Why is this useful? It gives possible ways to get into the target domain via another vulnerable domain.

So the sequence of events that have to happen is

1) The target site is fully patched
2) The target site is on a shared-host with a site (it could be a firewall rule giving the sites the same IP remember), let's call it the side-target, that is not fully patched (Wordpress, Drupal are super good targets)
3) The side-target installation has a path traversal issue or the ability to run remote commands via the site
4) If there is no virtualization or weak very sandboxing.
5) Compromising the side-target can allow for access to the host all the sites are served on including your target


Bing lets you get a bit of Shodan functionality for free.

Type the following to Bing search for where SA is hosted at.

code:
ip:104.25.246.12
Now admire how many gambling site and dentists sites are hosted on the same IP as Senor Lowtax

Rufus Ping posted:

That's cloudflare you idiot

whether a poorly executed joke or not this is the best post combo ever

mod saas
May 4, 2004

Grimey Drawer
it's my understanding that Facebook finds it worthwhile to allow people in authoritarian regimes to use their services - they even have a tor-facing server so you can connect via hidden service. it's my understanding things like whatsapp are already used/in a position to be used by people in that same situation. it's worth the social/ethical capital for them to support keeping those communication lines open even if it doesn't support their main business

mod saas
May 4, 2004

Grimey Drawer

DeaconBlues posted:

So are you saying that the kudos (or 'cool factor') they receive for providing such a service (if it is trustworthy) is worth the possibility of putting the government and/or legal system's noses out of joint?

Like how Apple gained respect (from a lot of quarters, maybe not everyone but I'd say a majority) due to standing up for privacy.

I'm going off half-remembered posts from fb people in yospos but I think it boiled down to "we have the ability, and therefore responsibility, to lose targeted ads to prevent targeted bullets for a segment of people"

mod saas
May 4, 2004

Grimey Drawer

OSI bean dip posted:

I'd be careful about challenging pr0zac on this one here because he actually knows a thing or two more about WhatsApp than most here.

no dude you don't understand the man wants us to think it's encrypted so it can ??? that it wouldn't already do over non-encrypted channels

or

the man knows that people who want secret conversations are totally going to click those targeted ads about the conversations they have, this is obviously an untapped market

mod saas
May 4, 2004

Grimey Drawer

pr0zac posted:

Do you understand how iOS device tokens work? Do you need me to explain why the answers to those last two questions make avoiding metadata collection on whatsapp trivial for anyone whos concerned about that?

I'd unironically like to know more about both of these

mod saas
May 4, 2004

Grimey Drawer

Mustache Ride posted:

No no no, you're not getting it at all. I agree that av is crap. That's why we don't pay for it. You should at least use something you get with a Microsoft license than nothing at all to stop the limited crap it does catch.

The people who pay for it are the idiots.

guys guys i'm with you 100% except for the point you're actually making so can we please just agree i'm right and move on

mod saas
May 4, 2004

Grimey Drawer

Paul MaudDib posted:

and a bunch of white noise posters.

don't whitewash my noise

mod saas
May 4, 2004

Grimey Drawer

baka kaba posted:

what makes people happy to use third-party KeePass apps (and plugins I guess)?

some men just want to watch the world not burn, mostly

mod saas
May 4, 2004

Grimey Drawer

TimWinter posted:

I think 'Wear A Helment' is likely counterproductive. You should wear a helmet when riding on busy roads, but god if that one phrase hasn't raised a generation of bicyclists who know nothing about safety.

mod saas
May 4, 2004

Grimey Drawer

FeloniousDrunk posted:

Respectfully, read the text. The page itself doesn't generate the password; it generates the code that goes into a bookmark which then generates the password. The point of it all is, it runs in the client browser without external dependencies or communication.

But yes, the randomness can be improved.

hey bro i read some site and pro-tip ssl is free now

mod saas
May 4, 2004

Grimey Drawer
the media will report it as a gas leak, but we'll know the real cause of the explosion was putting security and antisecurity in such close proximity




realtalk good on you for taking the hits and deciding to learn more instead of hugboxing

mod saas
May 4, 2004

Grimey Drawer

Sickening posted:

20 mb hard drive is all your are ever going to need.

You're right. There is absolutely no possibility the allowed password length will increase over time.

Adbot
ADBOT LOVES YOU

mod saas
May 4, 2004

Grimey Drawer

Sickening posted:

Don't sperg out over even the lamest of jokes. :itwaspoo:

sorry that your venn diagram of jokes overlaps with both "things that aren't funny" and "things that aren't jokes"

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply