Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jre
Sep 2, 2011

To the cloud ?



Bangersinmyknickers" posted:

jre is such poo poo

Hey gently caress you :argh:

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



computer toucher posted:

what the hell are you talking about?

Person who has never left the US gives hot take on Scandinavia

jre
Sep 2, 2011

To the cloud ?



cheese-cube posted:

i'll buy this tag for the next 10 ppl who quote this post (might take me a couple of days to do so, ive just moved house and have no internet yet)

jre
Sep 2, 2011

To the cloud ?



FopeDush posted:

oh hey 72 new posts in the secfuck thread something big must have gone down

Yeah, yer maw

tag check

jre
Sep 2, 2011

To the cloud ?



Subjunctive posted:

I think there's a problem with the last 4 on that list, I'll have to mail support or something :effort:

Just post in QCS about the tags not showing up in opera 8

jre
Sep 2, 2011

To the cloud ?



Shaggar posted:

Microsoft ftw.

Shagger was right :stare:

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

i'm the sec fuckup. i published my sa password to github :rip:

(yes. this is still me)

Thats exactly what I would say if I'd taken over your account :tinfoil:

Was it p4ssword

jre
Sep 2, 2011

To the cloud ?



CommunistPancake posted:

a good word filter

:omarcomin:

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

i'm sold


i wonder what they're using. must be some horrid snort-based solution

Mod security was amazing for those kind of false positives

jre
Sep 2, 2011

To the cloud ?



Paul MaudDib posted:

Why? It's just YOSPOS having some drunken weekend anal leakage. You've got OSI Bean Dip, the Internet Antivirus Expert who once interned at Symantec or something, who just keeps asking someone to explain antivirus to him and who thinks the NSA is going after grandma's cat pictures (the explanation he gave in the thread he linked for why antivirus sucked, after I got past all the "under construction" paragraphs), and a bunch of white noise posters.

It would almost be funny if they weren't giving such bad advice. Sure, anyone who posts in this forum can probably avoid clicking any obvious malware links or opening a suspicious attachment. But that's not good advice for a business or for your aunt who loves those FWD: FWD: FWD: emails.


So angry. One of these idiots actually started stalking my posts to yell at me in other forums. Saturday night on Something Awful Dot Com, y'all :lol:
:allears:

Security Fuckup Megathread - v12.1.3 - drunken weekend anal leakage

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

imagemagick allowed me to make huge.jpg back in 2001 :unsmith:

you monster

jre
Sep 2, 2011

To the cloud ?




Well that escalated rapidly :eyepop:


EDIT:

gently caress its like half the grey forums :stare:

jre
Sep 2, 2011

To the cloud ?



I am glad that the infosec community are continuing to be approachable and non judgmental

jre
Sep 2, 2011

To the cloud ?




Worse than a gray

jre
Sep 2, 2011

To the cloud ?



CRIP EATIN BREAD posted:

std::string should have zero allocations because memory is expensive. Instead, it should use other solutions such as mongodb. That way, Chrome can easily handle massive amount of data and big data ready for 2015. Added bonus is that std::string is now async, which means massive IO, which is impossible with memory allocations because even mmap is bound by virtual space. C++17 is indeed actually working on embedding mongodb and node.js into STL because those should be industry standard and solve 100% of business problems that C++ is aimed at solving at. Already github pull request is made. All you need is 2 thumb ups and will get merged in. Just imagine, std::string is everywhere: network stack, user applications, kernel drivers... And now they all use mongodb. And they will be Actor model massively concurrent paradigm. This is new science Wolfram is talking about. Just accept the PR already.

Markov generated or mental illness ? Or both ?

jre
Sep 2, 2011

To the cloud ?



Rooney McNibnug posted:

Name and shame.

Plus net ?

jre
Sep 2, 2011

To the cloud ?



Dex posted:

*shoves grey into cryptolocker*

jre
Sep 2, 2011

To the cloud ?




:vince:

jre
Sep 2, 2011

To the cloud ?



Midjack posted:

if it's a legitimate rc.script the server has ways to just try to shut that whole thing down

Jesus this thread lately :stare:

jre
Sep 2, 2011

To the cloud ?



Chris Knight posted:

ya it's been real good

CRIP EATIN BREAD posted:

code:
Broadcast message from [email]conservative@shittysouthernstate.com[/email]
	(/dev/pp/1) at 11:28 ...

The system is going down in 24 hours are you sure you have read everything you need to know about this decision?

This took me way too long to get as well

jre
Sep 2, 2011

To the cloud ?



ymgve posted:

so what would happen if this dude reported someone for child porn and when the police searched the suspect's house they didn't find anything?

it's not like the content of the computer sent to geek squad could be used as evidence because holy poo poo broken chain of custody

Garry Glitter first got discovered as being a paedo because he sent his computer to PC world for repair and they found child porn on it.

http://news.bbc.co.uk/1/hi/uk/517604.stm

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

No fighting in the war room

jre
Sep 2, 2011

To the cloud ?



Powercrazy posted:

Perhaps there is something more to food then "calories?"

Oh gently caress you'll summon a fishmech semantic argument :suicide:

jre
Sep 2, 2011

To the cloud ?



qntm posted:

haha what workplace is going to approve that

Mine ? :shrug:

jre
Sep 2, 2011

To the cloud ?



ratbert90 posted:

The gently caress? What packages are you needing specifically that a new version would work better than a older version + security updates?

the version of git that comes with centos is so old it that some golang dependancy downloads break because it can't handle redirects properly

jre
Sep 2, 2011

To the cloud ?



you should still use centos though

jre
Sep 2, 2011

To the cloud ?



pr0zac posted:

go is ok even tho the standard lib fokls are really rigid about what they put in meaning a lot of basic stuff doesn't exist because its "easy to implement yourself!"

the dependancy management :smithicide:

jre
Sep 2, 2011

To the cloud ?



vOv posted:

I've never used go in seriousness, what's wrong with its dependency management

Dependancies are fulfilled by cloning the master branch from github. Good luck trying to get reproducible builds without having to keep copies of every library you use

jre
Sep 2, 2011

To the cloud ?




:stare:

jre
Sep 2, 2011

To the cloud ?




Holy lol :qq:

jre
Sep 2, 2011

To the cloud ?



bicycle posted:

UK universities are far worse. Source: I went to a UK uni and know next to nothing.

Is that not more likely because you're a bit thick rather than all universities in the UK being bad ?

jre
Sep 2, 2011

To the cloud ?



bicycle posted:

little of column A, little of column B

the curriculum definitely needs improving, but it's always the case that the individuals who work their rear end off and care about the subject enough before attending uni will do better.

there's also a weird thing where many people go to university and expect a job to be handed to them as soon as they're done - they don't often care about what subject they choose because they just need to pass some tests to get an easy job


bicycle posted:

Two years later I'm interviewing uni grads who don't understand what a snort rule is or what grep does :shrug:

Why do you expect computing science grads to know a specific piece of software, and why are asking that in a interview ?

A good computing science degree course shouldn't be about teaching you how to program in java/c# or use specific software

jre
Sep 2, 2011

To the cloud ?



bicycle posted:

to clarify I'm talking about the Network/Computer Security specific degrees rather than computer science which is generally miles ahead in my experience

gently caress, that's a fairly important detail I missed.

jre
Sep 2, 2011

To the cloud ?



Wiggly Wayne DDS posted:

you missed the best part: first time a poc was sent to them it crashed their mail servers as they were actively scanning incoming attachments

:drat: son

jre
Sep 2, 2011

To the cloud ?



Who was the yosposter who had a massive meltdown and bought all the red text in that thread ?

jre
Sep 2, 2011

To the cloud ?



SELinux is too complex. I have 100+ servers to manage. Do you think I have the time to set the policy, domain, type and level for a directory tree. Now I have to upgrade 25 servers tonight with a 2 hour maintenance window... If I only had 4 or 6 servers I could do stuff with SELinux.... Honestly, it's too complex for the time + number of systems I manage. It's like having a fleet of cars and I have to fine tune the fuel injection port on each cylinder, change the amperage going into the radio and polish all the windows by hand. Too complex to be useful.

jre
Sep 2, 2011

To the cloud ?



That is a loving awesome honey pot for incompetent admins

quote:

You manage 100+ servers and you're not using something like Ansible/Chef/Puppet? I agree SELinux is a huge pain in the arse (and I'm here searching something related) but come on, only you can make your job easier!

quote:

Lots of us have been managing 100's and 100's of Linux system long before Chef/Puppet/etc... and honestly they are no easier to use for an experienced Linux system admin than a couple bash scripts. Plus I don't have to deal with the overhead putting up an entire Ruby stack just to copy a couple freggin public keys.

Besides, what is the point of keeping SELinux enabled if your going to "gem install" a package dependency that does a direct git clone from an unsigned github repository. It's not like you are configuring these systems with security as the primary concern at that point.

My experience, and it just my opinion btw, is that the vast majority of developers who use one of the mentioned tools are generally Apple developers who don't actually know how to do Linux things on Linux systems because they don't actually regularly use the systems they build their software to run on.

jre
Sep 2, 2011

To the cloud ?



geonetix posted:

How would you call somebody in an organisation that does code review and educates their colleagues?
Dr No

jre
Sep 2, 2011

To the cloud ?



Shaggar posted:

so did they have public dns returning 192.168.1.1 or is the dns entry intercepted by the router and sent to the current router ip cause if its the later that's not that big of a deal.


anthonypants posted:

the first one

:stare:


daft punk railroad posted:

i need tp-link for my security hole

fuckin smooth

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



Your girlfriend is from Canada you say ?

  • Locked thread