Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
0day posting in a new thread that gives me an excuse to write off the thousands of unread posts in the old one

Adbot
ADBOT LOVES YOU

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
caro is alive :eyepop:

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
better charset support? lol if u don't remember dos programs being all [√]

relevant to thread: p sure norton for dos did that

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
remember security fuckups

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

anthonypants posted:

you're probably thinking of the old thread
yeah i have 5 posts itt and they're all white noise

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
yeah i hate ipv6 because i liked the insignificant level of deniability provided by nat :( if oses are configured to rotate thats p cool tho

Kazinsal posted:

btw what's the rule on gang-tagging yourself if you're going to be doing a title change anyways? kosher/not kosher
do it, i usually rotate gangtags with each av change

i only got around to paying :10bux: after lf was deleted but still al aqsa posters brigade 4 lyf

maybe don't follow my advice tho, i'm a p bad poster

Shaggar posted:

If a government agency is storing user creds in reversible form for one of their applications, what is the best way to get them to fix it? I've emailed the responsible organization w/ details and suggestions. Should I do anything else?
was going to say public disclosure but glad i was beaten to it

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Cocoa Crispies posted:

granny natting, not double dmz natting like you should be

anthonypants posted:

loving asus routers!!!!
:vince:

my parents used to have an adsl1 modem connected to a wifi router, then when they got adsl2+ dad bought a combined modem/router but with no wifi because he was adamant that the neighbours must've been hacking the wifi and using up all the :australia:download quota:australia: (this was when i still lived there and i even said "nah i'm p sure that's just me doing all the downloading" because i loving love consuming digital content but w/e we had everything cabled so i didn't care). then about two years ago mum got a tablet so needed wifi so i just told dad to dig up the old wifi router from before and i went to set it up to work like an access point. dad always bought the cheapest possible d-link poses so there was literally no way in either device's configurations to avoid the worst possible double natting but w/e it was just for tablet browsing so who cares

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

ratbert90 posted:

Cause baby, now we've got bad block.

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

goddamnedtwisto posted:

to be honest though, the fact that the vast majority of internet users these days are behind nat is probably the most effective defence against those sort of worms - early 2000s was of course the peak of the dsl "modem" years
does that mean xp will continue to be protected by its lack of ipv6 support

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
the coolest ones by definition get full public disclosure without any warning (even to the vendor)

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
tbh it can be even cooler if you just exploit it without it ever getting disclosed

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
ehh that's a usability issue not a secfuck

wikipedia lets (or used to idk) people register without an email address. they have a warning that without one password losers are boned but don't actually stop it

which is handy if signing up a burner account for vandalism

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

hackbunny posted:

I use emoji in my code, like this:

- (NSString *) stringAsWarning
{
return [NSString stringWithFormat:@"⚠️ %@", self];
}

- (NSString *) stringAsError
{
return [NSString stringWithFormat:@"⛔️ %@", self];
}

they're a godsend
- (NSString *) stringAsMyPosting
{
return [NSString stringWithFormat:@"💩 %@", self];
}

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

ewiley posted:

e: sorry didn't mean to insult everyone
starwars420@juno.com

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
lol

if it's not on the company's domain that could be a good idea...

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Shaggar posted:

put them on your one drive and share them only with a specific user. anyone with the url will still have to log in and only the user you authorized will be able to access it.
unless you get owned by bit.ly or whatever


e: like i assume that won't happen if you use onedrive properly but the wired article doesn't really make it clear so idk. tech journalism is trash

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
this is probably old but i just saw it come up on twitter today: trip report from the hacking team own: https://ghostbin.com/paste/6kho7

i especially liked

quote:

The worst thing that could happen would be that my backdoor or post-exploit tools would make the system unstable, and force an employee to investigate. So I spent a week testing my exploit, backdoor, and post-exploit tools in the networks of other vulnerable businesses before entering Hacking Team network.

quote:

NoSQL, or rather NoAuthentication, has been a great gift to the hacker community



edit: well yeah this was the other one that jumped out at me
code:
HACKINGTEAM  c.pozzi        P4ssword      <---- look! the sysadmin!
but i thought that got leaked already? idk

jony ive aces fucked around with this message at 04:44 on Apr 18, 2016

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Powerful Two-Hander posted:

shall i compare thee to an md5?

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
from my experience in the very early 00s (i was only in high school at the time but my dad lectured there so yeah...) my university appeared to (?) give public ips for everything (only a /16 tho) but was already firewalled to gently caress

idk i don't really understand networking

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

vOv posted:

e: lol SA filters S J W into robocop
sjw :hellyeah:

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

spankmeister posted:

anroid sjw lol
he's more of a cyborg really

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
notavirus.scr wants to install updates, give it admin rights?

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
my mum hasn't used her laptop in a while and is worried she'll get 0wned in the time it takes it to install updates also wants me to go have a look at it because she's worried she'll click yes on an "update" that isn't

i told her she can handle it and will probably be fine. lol

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

OSI bean dip posted:

this is the case everywhere. some security professionals publish their passwords on github <---- look! the op!

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
isn't that how op's service works as well

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
what if you push a commit to a private repo and then some time later set it to public, obviously you can still search but would it show up in a feed?

i accidentally did that with a student project a while back. someone else was in charge of our net stuff so idk but it's possible he did it in a bad way that had enough in our sourcecode to 0wn our free student azure (lol) account. this was just after we'd finished our final presentation (it wasn't really a coding-focused subject but then at the end the lecturer asked to see our code anyway and we were like sure just make it public i guess) so it didn't matter what happened, but a few weeks later i was dicking around in our app and it had mysteriously stopped working. so i guess either we got owned or we were just really lovely programmers who make stuff that breaks easily

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

flakeloaf posted:

what's wrong with keep rear end again?
it's a security product that still lacks https on its site even after lets encrypt

at least the site their binaries are hosted on does https (tho that's only a recent addition) but your downloads will probably still be injected full of malware because that site is sourceforge

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

OSI bean dip posted:

this is horrible because shaggar cannot see the forest from the trees here okay?
more like

OSI bean dip posted:

this is horrible because shaggar

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
ilu shaggar :glomp:

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
i'm glad i brought up lets encrypt

but yeah in case anyone was wondering keep rear end is a p deece password manager if you can get past the insecure method of actually obtaining it. tho keep in mind what other posters said about "every nerd has their favourite password manager who gives a poo poo" and how keep rear end being open sores means things can be a big mess of plugins

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
maybe the mess of third party things for stuff like mobile apps is trapping some people into sticking with the 1.x file format or something

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Thermopyle posted:

even with the web auto fill plugin and the keepass mobile app thingy, lastpass is just so much easier to use for me (or maybe i'm just too used to the LP way).
what kind of web forms are you regularly autofilling that need an actual plugin rather than just doing username tab password enter with the keepass autofill hotkey?

i guess keepass autofill is theoretically prone to secfucks if you happen to hit the hotkey combo at the wrong time though. without a web plugin it only uses the window title to determine which password to type which could be taken advantage of. and until recently my bank had their full page title as just "Login Page" lol



OSI bean dip posted:

the greys are overly paranoid about whatsapp :allears:
b-but what if people reverse engineer and find that it's perfectly safe, only for them to later get a national security letter and push an update :tinfoil: :tinfoil: :tinfoil:

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
good point

i do have it removed from some individual passwords but not from the default one, gonna fix that now

(i guess having a mix of different per-site ones and a global default could potentially become an issue as well but yolo)



e: my favourite is sites that somehow make tab not work

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Trabisnikof posted:

Switching from Drupal to Wordpress, I'm looking forward to future secfuckups
a few days ago i clicked "all mail" on my gmail and discovered that i'm still subscribed to the drupal security updates list but have them filtered somewhere i normally never click on

turns out even in 2016 they still have emails about this or that module tagged "critical - xss" at least once a month, with rce and csrf being fairly common too

php devs v:shobon:v

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

OSI bean dip posted:

goons in the games forum disable anti-virus to let their mods work :allears:

i am not sure what is worse: the fact that disabling anti-virus is the advice or the fact that anti-virus is being poo poo (as expected) here. both are equally dumb
the x series of games have scripting functions that you can use to cheat among other things, but if you do it marks your save as cheating so you won't get achievements etc. it also tries to detect if you've hacked the game files to cheat as well

one time i was playing a clean game and noticed that my save game had been flagged. i googled it and found others had the same problem while running avast which i was dumb enough to use at the time and the advice (from other players) was to disable it while playing. it's stupid that the programs conflicted like that, but at least disabling av to specifically play an unmodded game is relatively less dumb than "pls turn off av to execute this file from some rando on the internet"

also a few third party mods that were found to be useful but not cheats were cryptographically signed by the game's devs so that people could use those ones without getting flagged. so for people who really did want to cheat, some genius came up with the idea of making any mod work if you just added a fake signature, by replicating whatever standard windows signing dll the game used but making it always return true. the file was distributed with a big warning to only drop it in the game directory and not system32 but it's still p lomarf that gamers were doing that

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Dessert Rose posted:

I read it with the kink meaning and it makes perfect sense that way
same and then other people acted like there were other definitions of "cbt" and i was disappointed

LordSaturn posted:

more like steve ballmurder

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Malloc Voidstar posted:

The SWIFT malware sample was uploaded to Virustotal possibly by the author himself, to find out if static antiviruses detect it or not.
kind of makes sense i guess

like, i get why hacking team were all DO NOT UPLOAD TO VIRUSTOTAL IT WILL JEOPARDISE EVERYTHING because they do share files with researchers, but still

would be p lomarf if they end up arresting someone based on virustotal's ip address logs though

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
virustotal say they share files with av vendors and whoever but on what basis does anyone choose a file for closer inspection? people probably upload "true negatives" all the time. maybe if a file gets a lot of comments or downvotes they pass it around for everyone to have a look at but if it's 0day that's not the case

i mean i guess in theory someone could have like a "meta-heuristic" that flags executables found to have certain internet/filesystem/crypto/etc related functions for manual analysis but lol

Cocoa Crispies posted:

I can't say I wouldn't have done the same

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord

Powerful Two-Hander posted:

word to your moms, i came to drop cyberbombs
https://www.youtube.com/watch?v=P3npKQHo48E

Adbot
ADBOT LOVES YOU

jony ive aces
Jun 14, 2012

designer of the lomarf car


Buglord
inside everyone is a spooky skeleton trying to get out

  • Locked thread