Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
here is a security fuckup for the new thread:

at my last job, they used solarwinds and most of the stuff piped logs to some server that it monitored. their "ids" solution was a script that checked logs for false ssh entries, and on the 100th hit, it would send a ticket to the noc. the noc was responsible for pulling that ip address, going back into solarwinds to make sure that they were really an active threat, and not some guy who only made two or three invalid attempts in the past hour, and then fed that ip address into another script that null routed that ip to some of the routers. this script was very old and did not affect the routers for the somewhat newer pci/compliance environment.

oh, and solarwinds was helpful in pulling the ptr for ip addresses that had one, and if you had a domain name that didn't have an a record, it couldn't get added to the null route table

anthonypants fucked around with this message at 19:34 on Apr 8, 2016

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

lol 100 hits, i've seen bots get bored and give up before that
the pci environment had different reporting and in there it was usually around three at a time but from like 50 different ips. that report was actually a solarwinds-generated pdf and was even worse to comb through

also i should be more clear that it wasn't 100 hits from the same ip, it was every 100 hits. no one had a problem with this

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

wait what, it would just flag every 100th failed login?
yes

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

goddamnedtwisto posted:

tbh a big part of why government it (in the uk at least) is so hosed up is that sort of bias. it goes like this:

"hey this system hasn't been updated in 10 years, can we have budget to fix it?"

"SEE TYPICAL PUBLIC SECTOR INEFFICIENCY! THE PRIVATE SECTOR IS FAR MORE EFFICIENT!"

*pays 200 million quid to logica/serco/cmg/lockheed/bae for poorly-specced and over-promising new system

*new system fails miserably, everyone goes back to old system

"hey this system hasn't been updated in 15 years"

etc
lowest bidder contract enforcement sure helps a ton

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

McGlockenshire posted:

Followup on yesterday's wordpress article with both new and old information: https://www.wordfence.com/blog/2016/04/panama-papers-wordpress-email-connection/


That changelog link is
code:
https://portal.mossfon.com/CHANGELOG.txt
and I'm not visiting it.
it's not in google's cache but someone else made a screenshot

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
the http://rebootmymodem.net/ url is prompting me for a google login so i guess i'm not going to see if it works on my sb6120, but it probably does

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

i'll buy this tag for the next 10 ppl who quote this post (might take me a couple of days to do so, ive just moved house and have no internet yet)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

there's no good way to get the bbcode for someone's existing title text, is there?
code:
I'd rather that you didn't, frankly.
[img]http://fi.somethingawful.com/whatever.png[/img]
and then check the center title checkbox

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

Yeah, I mean for others' more intricate ones. say, Captain Foo.

take http://fi.somethingawful.com/safs/titles/b9/ce/00054492.0001.png, upload it, the title text would be
code:
when the going gets Weird
the weird get Hard

[img]http://fi.somethingawful.com/safs/titles/cb/ee/00160693.0004.png[/img]

hail satan:ins:
and add the baud dudes one and click the center text checkbox


e: kalmstram's is way more intricate so here's his
code:
[b][size="x-large"][color=red]I support burning people alive in Odessa.[/color]

[color=fuchsia]Bandera & Shukhevych are my heroes![/color]:worship:[/size][/b]

anthonypants fucked around with this message at 19:47 on Apr 9, 2016

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Sharktopus posted:

I like baud bitches thats my fuckin problem
:same:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

lol you're jelly af

anyway, the following ppl should have baud dudes tags now. if not then let me know.

√ anthonypants
√ Wiggly Wayne DDS
√ PCjr sidecar
√ Subjunctive
√ uninterrupted
√ spankmeister
√ apseudonym
√ Parallel Paraplegic
√ kalstrams
√ Trabisnikof

yes i'm using sqrt as a tick lifehack. if your av looks wonky hit up an admin,
av check... ✓

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ChickenOfTomorrow posted:

see I was making a joke by asking if the quanta router was subject to the arris vuln because while usually that would be unlikely, the quanta router is just so bad that it probably is



anyway. Remember that debian xscreensaver kerfuffle? matthew garret does.
idk who that guy is but he sure is good at run-on sentences, and woo uh oops

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
rip to your avatar text

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

kalstrams posted:

:ssh: it was not too good if you knew russian
well i don't know what language it's in now so i don't know if it got worse or better

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
noice

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

jony ive aces posted:

remember security fuckups
you're probably thinking of the old thread

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

If a government agency is storing user creds in reversible form for one of their applications, what is the best way to get them to fix it? I've emailed the responsible organization w/ details and suggestions. Should I do anything else?
write a letter to a senator or something

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Midjack posted:

this is really the only thing that will make a usgov entity admit they have a problem
ok but he said he wanted someone to fix it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

granny natting, not double dmz natting like you should be
loving asus routers!!!!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

computer over, virus equal very yes
my mouth was a broken jpeg, i had no choice

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
finally, the long national nightmare of quicktime on windows is over http://blog.trendmicro.com/urgent-call-action-uninstall-quicktime-windows-today/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
apparently if you generated enough bit.ly urls you could get access to someone's onedrive until microsoft removed the feature http://www.wired.com/2016/04/researchers-cracked-microsoft-googles-shortened-urls-spy-people/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.
all the ones in my area are marked "broken/dead/stolen/gone"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/webster/status/720758545688477696

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Sharktopus posted:

wish I could find whatever the gently caress you're talking about

anthonypants posted:

apparently if you generated enough bit.ly urls you could get access to someone's onedrive until microsoft removed the feature http://www.wired.com/2016/04/researchers-cracked-microsoft-googles-shortened-urls-spy-people/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

i'm the sec fuckup. i published my sa password to github :rip:

(yes. this is still me)
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

i can say that this is not the case
where else did you use your sa password

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
did people itt really believe osi's password was kjs500? because that's an ancient radium password for everything

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ChickenOfTomorrow posted:

buncha people in here don't know forums history

at the risk of falling afoul of poe's law

see, kids, a long while ago there was an admin and forums coder named radium. radium was not very good at his job. he used 'kjs500' as his password in many places. one of those places was SA. we learned this via a forums 'hack'.


why kjs500? well for one, kjs were his initials


i could've sworn there was a saclopedia article about it but maybe it got deleted, and now we have to go to ed for ancient forums drama

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Captain Foo posted:

good thread title change

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

flakeloaf posted:

that's what our product needs, multiple barriers to sensible usage

what's wrong with keep rear end again?
keep rear end is bad because it's open sores, which means every feature you want (integration, sync, migration, mobile client) is a third-party addon

Parallel Paraplegic, there's a free tier of secret server that you can host in-house, and their browser integration is real good. iirc you can only have 100 users and 1000 passwords/secrets, but it's probably a good starting point to see if you want to implement that instead of sharing a 1password vault

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

lol if u allow lets encrypt certs to be trusted on ur networks.
why would you cj with the certificate store that you get from microsoft? that sounds like a recipe for disaster

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Maximum Leader posted:

i can't believe microsoft didnt gently caress with the active directory name yet. is it their only product with an unfucked name at this point?
fyi they still call it "windows"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
at my last job if you said you were a customer and wanted to do anything like ask for a csr or make dns changes you had a better than 50% chance of the change getting made without verifying you were who you said you were. later on they decided the sales team would update all the customers' contact information. but salesforce.com was never updated because it turned out to be too difficult so the policy changed to if the customer pays less than $50/month then you should just make the change anyway.

i'm like 99% positive you could email them and say "hey we need you to run this script on our server after hours" and they would, no questions asked

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

I especially liked the unexpected sexism at this part
i especially liked the not-joke-getting at this part

Cocoa Crispies posted:

why are all you people replying to shaggar
this one too

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Acer Pilot posted:

What was that other password manager? The less terrible free one? Keep rear end?
1password is good

Shaggar posted:

yeah that would be good but in the meantime I don't want lets encrypt certs marked as trusted. maybe there can be a new signing type that marks the certificate as encrypting but not trusted or untrusted. browsers that don't support the extension would treat it as untrusted or invalid and browsers that do support it would show it as encrypted/not-trusted.
the only way to do what you're whining about is to gently caress with the cert store your operating system imported from microsoft automatically, and i think you should do it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

lets encrypt is the worst of them because they provide automated mechanisms for malware to get certs and their policy specifically states that they're ok with signing malware certs.

I haven't checked the policies of the other free cert providers yet. I know startcom is one but who are others?
what shaggar really wants let's encrypt to offer is a gold starburst jpg that people can put on their website that says SECURE and today's date. maybe a picture of a lock or a check mark

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

CommunistPancake posted:

i feel like if you're already paying :10bux: for a domain you're not going to give up when you see that it's another :10bux: for a cert
no he's saying that $10 for a ssl cert in addition to a $10 domain is far too steep a price for anyone who wants to scam or spread malware

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

suffix posted:

SA has the lock so this checks out
remember when sa had ssl on the login page but still transmitted your username/password in cleartext

  • Locked thread