Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
neutral milf hotel
Oct 9, 2001

by Fluffdaddy
:nsa::respek::nsa:

Adbot
ADBOT LOVES YOU

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Captain Foo posted:

Root of thread trust chain posting

looks like we found the first vulnerability of this thread lol

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Powercrazy posted:

What is the public PGP key of this thread so I know I'm getting an authenticated yospos security fuckup experience?

FCKGW

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
can someone add me to their gang tag list?

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Subjunctive posted:

IDK how long it takes to clear whatever cache of things and stuff, but:

uncurable mlady
fishmech
Crusader
jre
Captain Foo
Storysmith
Westie
Mad Wack
Testiclops
BeOSPOS

should all be set.

:woop:

thanks subj

just gotta wait for the cache to clear

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

spankmeister posted:

Umm there are 35 trillion 184 billion 372 million 88 thousand 832 /48 blocks in the currently allocated ipv6 address space

that's a lot of Internet of poo poo devices to connect :eyepop:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

OSI bean dip posted:

Happy Badlock Day!

:toot:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

moonshine is...... posted:

So apparently this is a thing https://deaddrops.com/ a friend of mine told me her techie friend is really into it. So that's fun.

a museum I worked at some years back did something like that. I forget how it ended up but it was popular enough

e. nice finally saw my gangtags :cheers:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Parallel Paraplegic posted:

i have pictures of butts permanently tied to my google account, and when i get a new picture google displays it in a gallery and if I accidentally swipe left or right whoops now it's a butt

it's not my butt, at least

was it 10 gigs of butts?

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
no starch press is running a deal with humble bundle to sell a bunch of their ebooks for cheap. it includes Hacking: The Art of Exploitation and Practical Malware Analysis (these two start at the $15 tier but well worth it imho)

https://www.humblebundle.com/books/no-starch-hacking-books

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Volmarias posted:

Well, what are you going to do? Go with another registrar for .as?

I have a .as domain, this doesn't fill me with warm fuzzies, but my options are "bear it" and "pull the domain that a bunch of your stuff is inextricably tied to."

volmari.as?

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

El Mero Mero posted:

I dissected the post I was making and found it was this that was combination of letters within my post that was triggering it:




lol

everyone post ur best sql injection strings

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Symbolic Butt posted:

cjs: thinking about rolling my own crypto :ohdear:

:nadim:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

ewiley posted:

oh boy where to begin

post that image from the Simpsons where the screen door was left unlocked in the secure facility

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

BangersInMyKnickers posted:

Lol, PHP announce list doesn't validate senders so this gem just came through to everybody


bless u Sajin

lol

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

~Coxy posted:

and there was at least one ring-O cold boot vulnerability


hackbunny posted:

lol you jerk :xd:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Phone posted:

i've coded gotos in tyool 2016

no amount of showers have made me feel clean about it

GOTO gbs;

neutral milf hotel
Oct 9, 2001

by Fluffdaddy
I use base5318008 :heysexy:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Captain Foo posted:

lol has evolved into lmao!

:eyepop:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

anthonypants posted:

i did a security fuckup last night, where i overwrote the root user's authorized_keys file on all the linux servers without looking to see if all of them had stuff in them, because i spot-checked a few servers and most didn't even have an .ssl folder. so i made a key for nessus and configured nessus to use it and went home

this morning our oracle contractors complained that the disaster recovery backups didn't work because their script or whatever used a key. so i made an even bigger security fuckup and put all our servers' public keys in every other server's authorized_keys file.

in my defense we have exactly two root passwords on ~20 linux servers and one of those passwords is the name of our company, in lowercase. next week on monday i get to meet with one of the linux contractors and discuss some of the changes i want to make, like doing patches to our servers and making user accounts and getting rid of accounts for people who don't work here anymore.

e: forgot to mention that while i was explaining to my boss what i did wrong (he is not a linux person) he thought that the private key went on the server. i tried to explain it to him like how his password isn't stored on the server but i'm not sure he got it.

so is it oracle or Oracle or 0racle?

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

thehustler posted:

any good pokemon secfuck writeups/blogs yet?

blog writers are too busy playing Pokemon games and getting mugged by teens

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

pr0zac posted:

gently caress ya i can finally talk about this
http://newsroom.fb.com/news/2016/07/messenger-starts-testing-end-to-end-encryption-with-secret-conversations/
https://fbnewsroomus.files.wordpress.com/2016/07/secret_conversations_whitepaper-1.pdf
was working on it a bit before I left fb, same crypto thats used by signal and whatsapp
was driving me nuts not being able to mention it during all of the "facebook hates privacy" arguments in the grey forums

cool. does fb still do invasive tracking even for logged out users :allears:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

this is really handy! I might share this with others

quote:

unrelatedly, my mom just passed away so I've spent most of today trying to get her affairs in order, its kind of ridiculous how easy it is to take over all of someone's internet accounts with only a small amount of personal knowledge, especially once i got into her email and found a chain email questionnaire thing which was basically "answers to every common security question"
accessed her email, facebook, paypal, both bank accounts, and credit card starting with just her mother's maiden name and a call to her cellular company

:(

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Bhodi posted:

environment variables are bad but it's the best of a sometimes necessary solution; there are no good universal credential stores like there are on windows. All stock solutions are compromised the same way, if you have access to that user, you have access to that user's process memory and storage; you can read files and obscure poo poo via 0400 perms but at the end of the day it's all the same security context and since the code is being read and probably stored you can sniff any decryption keys/salts as-needed, the best you can do is obscure and isolate with unique passwords, at least env variables aren't passed into process lists

dehumanize yourself, etc

this is a good answer

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

daft punk railroad posted:

passwords are like underwear: usually lovely

dsyp

- a cool guy

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

oh shi :stare:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Travis is a drat wizard

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Blinkz0rz posted:

not to doxx myself but corp communications just emailed the company telling us to look for our logo in the new bourne movie and it gave me a hearty lol

are you the bad guys in the movie?

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Jimmy Carter posted:

oh sweet the talk about master-keyed systems is up

http://livestream.com/internetsociety/hopeconf/videos/131176042

the session is real entertaining but the tl;dr is that tons of manufacturers/entities are lazy so they go with the cheapest and most available lock sets so having 2 or 3 keys means you can open a surprising amount of poo poo

the Chinese lock talk was also pretty interesting

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

I'm the reaction gif bookmark

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Captain Foo posted:

snowden talkin on tweetz0r that the equation group hack is likely russians demonstrating CCNE in order to show that they can prove U.S. responsibility of any attacks sourcing from that server, which he speculates is now being made more public in order to halt escalation of attribution in the DNC hack

what's ccne?

this whole ordeal is sounding more like a spy novel :hchatter:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Perplx posted:

this privacy doesn't sound pretty good at all

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Parallel Paraplegic posted:

I should really get back to reverse engineering that smart plug i have, maybe I can turn my toaster into a bomb

carbs are poison so the toaster is already doing its job :tipshat:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

dadsec joke

hey Phil, can you make me an account on the Dev server?

Phil: *taps you on the head* now you're an account on the Dev server! :haw:

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

VikingofRock posted:

So one of the science organizations that I work for has a bunch of non-public data in a database. To log into this database you use an automatically generated password which is literally your name + a string which is the same for everyone. This string is posted on our (private) wiki, but on the wiki one of the characters in the string is incorrect, which led to me not being able to log in. Upon being informed that the string was off by one character, I asked whether I should fix this on the wiki, and the answer was "no, because it helps security through obscurity".

hunter3

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

apseudonym posted:

Some of us work on TLS stuff :colbert:


atomicthumbs posted:

what if we forked SSL into another thread so that this one would only have interesting things in it

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Acer Pilot posted:

Do you guys think that if I made my security question "make them spell out the random characters below," the csr might actually enforce it?

pro tip: the person answering the phone doesn't care and doesn't flinch at yet another puny caller

Adbot
ADBOT LOVES YOU

neutral milf hotel
Oct 9, 2001

by Fluffdaddy

Phone posted:

some would say that he's living large

he ate all the FAT32 partitions

  • Locked thread