Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




0day posting

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

i'll buy this tag for the next 10 ppl who quote this post (might take me a couple of days to do so, ive just moved house and have no internet yet)

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

e: kalmstram's is way more intricate so here's his
code:
[b][size="x-large"][color=red]I support burning people alive in Odessa.[/color]

[color=fuchsia]Bandera & Shukhevych are my heroes![/color]:worship:[/size][/b]
mine's actually a hateful redtext some really mad 5th column kremlinist lurking eastern european poltics thread rebought me 6 months after someone in imp zone unfucked it for me, i.e. cheese-cube doesn't really have to bother with preserving it as is :v:

e: i mean unless you think i deserve it :(

cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

lol you're jelly af

anyway, the following ppl should have baud dudes tags now. if not then let me know.

√ anthonypants
√ Wiggly Wayne DDS
√ PCjr sidecar
√ Subjunctive
√ uninterrupted
√ spankmeister
√ apseudonym
√ Parallel Paraplegic
√ kalstrams
√ Trabisnikof

yes i'm using sqrt as a tick lifehack. if your av looks wonky hit up an admin,
can confirm, spray painting my laptop rn :tipshat:

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

rip to your avatar text
:ssh: it was not too good if you knew russian

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

well i don't know what language it's in now so i don't know if it got worse or better
it is still in russian, forums.pos just borked up encoding

cinci zoo sniper
Mar 15, 2013




Illusive gently caress Man posted:

i forgot i never shared this






im very pleased with the quality and aesthetics of my password, and would recommend this service to others.
:eyepop:

cinci zoo sniper
Mar 15, 2013




https://threatpost.com/moxa-wont-patch-publicly-disclosed-flaws-until-august/117311/

quote:

A number of publicly disclosed vulnerabilities in Moxa networking gear won’t be patched until August, if at all, according to an alert published on Friday by the Industrial Control System Cyber Emergency Response Team (ICS-CERT).

Researcher Joakim Kennedy of Rapid7 disclosed in March some details affecting critical flaws in Moxa NPort 6110 Modbus/TCP to serial communication gateways, and 5100 and 6000 series serial-to-Ethernet converters.

Moxa said the NPort 6110 device has been discontinued and it will not provide patches. The 5100 and 6000 series will be patched new firmware expected to be made available in August, ICS-CERT said.

Kennedy said that the devices are not password-protected and many are reachable online. For example, users are not required to set passwords for the NPort 5100 series, and many do not and are reachable via telnet or a web interface. A Shodan search conducted by Rapid7 found 5,000 Moxa devices online, 46 percent of which are not password-protected.

ICS-CERT said the vendor has validated three of five vulnerabilities that have been disclosed: one flaw enables an attacker to retrieve account information; another allows an attacker to make remote firmware updates without the need for authentication; and the third is a cross-site request forgery bug. Noxa has not been able to verify a buffer overflow bug leading to remote code execution, nor a cross-site scripting flaw. All of the flaws are remotely exploitable and allow for the execution or malicious script or malware, and privilege escalation.

Kennedy’s March 17 disclosure also identified ports UDP/4800, TCP/4900, TCP/80, TCP/443, TCP/23, TCP/22, and UDP/161 as possible attack vectors. ICS-CERT says it’s not aware of public attacks.

In the meantime, the devices, which are used to connect remote administration tools to things such as medical devices, industrial applications, point-of-sale systems and more, will remain exposed for at least another four months.

ICS-CERT’s alert did recommend some temporary mitigations, such as password protecting NPort 5100 and 6000 series configuration files to prevent attackers from being able to upload binaries to devices. Vulnerable systems can also be removed from the Internet, while control system networks can be put behind a firewall or isolated from the business network, the alert said. Remote administration should also be conducted over a VPN.

“Securing legacy hardware is still very difficult, and this how not to do it,” Kennedy wrote in his disclosure. “Security is being compromised for convenience, and consumers are, in many cases, just using the default settings. The easier you make it for yourself to connect, the easier you make it for the attacker.”

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

that you know of
:ghost:

cinci zoo sniper
Mar 15, 2013




Varkk posted:

All the cool exploits should earn their name from the first high profile victim they take down. Just like some diseases.
im windows

cinci zoo sniper
Mar 15, 2013




:five:

cinci zoo sniper
Mar 15, 2013




Migishu posted:

ah yes, robertcop

cinci zoo sniper
Mar 15, 2013




:rip: corporation dad works in got hit by ransomware embedded in ms word attachments

cinci zoo sniper
Mar 15, 2013




:vince: you shall not pass, files

cinci zoo sniper
Mar 15, 2013




Snapchat A Titty posted:

yeah you love not getting weird emails that you can prank

youre really into not having a weird partial view of a random persons life

you get loving jazzed because all your emails are actually for you
yeah thats me too, i have snowflake special surname for latvia, and no one in my extended family shares name with me

cinci zoo sniper
Mar 15, 2013




http://www.engadget.com/2016/05/29/dropbox-infinite-kernel/

starting my timer

cinci zoo sniper
Mar 15, 2013




https://www.microsoft.com/en-us/sto...%29%28%29%28%29

cinci zoo sniper
Mar 15, 2013




CommunistPancake posted:

dropbox infinite is just mounting dropbox as a filesystem, right?

so just fuse on unix and dokan on windows?
they though about fuse but then they figured out that they dont want it, both for performance and otherwise, so here's what they've got https://blogs.dropbox.com/tech/2016/05/going-deeper-with-project-infinite/

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

File systems exist in the kernel, so if you are going to extend the file system itself, you need to interface with the kernel.
yes but why would you wont something that involved for your cloud2butt storage

cinci zoo sniper
Mar 15, 2013




hackbunny posted:

italian SSNs are calculated from your name, gender, date and place of birth, so they never had a chance of being used as "secret" codes
same, in latvia everyone born before 2017 has ddmmyy-code where code is ABCDE - A is 1 for 20th centruy, 2 for 21st century, BCD is related to area of birth, and E is checksum


everyone born in 2017 or after will have 11 digit code starting with 32, that doesnt start birth date

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

probably because the texturing on the cards is part of the "security".
that's real dumb

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

yeah its cause theres no such thing as a federal id so you basically have this stupid rear end card you're supposed to keep around from birth that identifies you even tho their not supposed to be used for id.
what about passport?

cinci zoo sniper
Mar 15, 2013




Maximum Leader posted:

i heard modified android
i saw some article today about 1r grand android "secphone"

cinci zoo sniper
Mar 15, 2013




kalstrams posted:

i saw some article today about 1r grand android "secphone"

http://www.engadget.com/2016/05/31/solarin-labs-moshe-hogeg-interview/

cinci zoo sniper
Mar 15, 2013




doctorfrog posted:

https://www.kickstarter.com/projects/preevio/silentkeys-a-keyboard-that-protects-your-privacy-a

It's a bootable flash drive glued into a keyboard.

I mean, it's a magic keyboard that foils governments, hackers, and corporations!

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

that authentication could be through an oauth redirect to a government sign in page or it could be through a chip and pin auth with a smart card or any other token based auth mechanism. point is the sensitive data is only handled by the central ID provider and the 3rd party requesting verification doesn't need to see it or care about it.
we have this in latvia, you can with with state id card, as well as via landing pages of number of banks that support online banking properly

cinci zoo sniper
Mar 15, 2013




Triglav posted:

but there's existing case law for fax


is sweden still trying to get rid of physical cash to push ppl to use banking more?
yeah and it works well for people. One in five transactions happen in cash in sweden now. in two years of life there ive paid with cash thrice - berries from farmer, public toilet at train station, and refugee barber

cinci zoo sniper
Mar 15, 2013




count_von_count posted:

Is there a good overview of the current vulnerabilities in TeamViewer? Asking for a friend.
let me pm you my 0day spreadsheet

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

it's a keyboard so you can be safe from keyloggers. really
yes, the keys are fake

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

we use it at work to connect to remote non-vpn users
i use it to janitor parents' computres, but they know to turn it off once im done

cinci zoo sniper
Mar 15, 2013




*cheks if airvpn is on the list* phew

cinci zoo sniper
Mar 15, 2013




cinci zoo sniper
Mar 15, 2013




was
https://www.youtube.com/watch?v=NSioTiaX_-Q&hd=1
posted?

cinci zoo sniper
Mar 15, 2013




:rip:

cinci zoo sniper
Mar 15, 2013




https://github.com/laginimaineb/ExtractKeyMaste :eyepop:

cinci zoo sniper
Mar 15, 2013




Mr. Nice! posted:

fixed your link you forgot an r
now i can blame you for touching poop *cartoonishly laughs into hidden nsa microphone*


thanks :v:

cinci zoo sniper
Mar 15, 2013




Star War Sex Parrot posted:

did you not read the article to go along with that github repo a few days ago?

http://bits-please.blogspot.com/2016/06/extracting-qualcomms-keymaster-keys.html
i did read a different article on it, slightly less involved

cinci zoo sniper
Mar 15, 2013




e: java != javascript

e2: hmm so javascript has just double float with inf/nan?

cinci zoo sniper fucked around with this message at 00:48 on Jul 6, 2016

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

+inf, -inf, +0, -0, NaN
oic, though im not sure what good is to have explicit -0 and +0 if +0 === -0. i mean, i get the division sign think for +- inf, but i imagine that could probably have been done in some different way too. anyways, terrible programming thread is for me showing blazing incompetence, rather than secfuc.

speaking of secfucks, here's something hopefully not yet discussed, a keylogger reverse engineered to an extent it's author got an e-mail

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Powercrazy posted:

A powerful self-own.

Is TP-Link widely deployed? I'd never heard of it.
not sure if i understand the question correctly, but it's easily one of the more popular private and small enterprise router brands in eastern/northern europe

  • Locked thread