Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
ate shit on live tv
Feb 15, 2004

by Azathoth
What is the public PGP key of this thread so I know I'm getting an authenticated yospos security fuckup experience?

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

anthonypants posted:

here is a security fuckup for the new thread:

at my last job, they used solarwinds and most of the stuff piped logs to some server that it monitored. their "ids" solution was a script that checked logs for false ssh entries, and on the 100th hit, it would send a ticket to the noc. the noc was responsible for pulling that ip address, going back into solarwinds to make sure that they were really an active threat, and not some guy who only made two or three invalid attempts in the past hour, and then fed that ip address into another script that null routed that ip to some of the routers. this script was very old and did not affect the routers for the somewhat newer pci/compliance environment.

oh, and solarwinds was helpful in pulling the ptr for ip addresses that had one, and if you had a domain name that didn't have an a record, it couldn't get added to the null route table

Boy it sure is a good thing this hacker registered his source IP in our domain before he started brute forcing SSH logins. :wtc:

ate shit on live tv
Feb 15, 2004

by Azathoth

OSI bean dip posted:

i'm the sec fuckup. i published my sa password to github :rip:

(yes. this is still me)

Heh

ate shit on live tv
Feb 15, 2004

by Azathoth

lulz. Yea that's a fuckup. But you caught it, so no harm done :)

ate shit on live tv
Feb 15, 2004

by Azathoth

Cocoa Crispies posted:

eh, ever have some crook run up a $400 AWS bill mining bitcoins on your behalf?

400? My company employee a Russian company whose employees all work remote deploy dev boxes at AWS. Last month's bill? ~39k

ate shit on live tv
Feb 15, 2004

by Azathoth

CRIP EATIN BREAD posted:

granted, some of those requirements published by NIST actually REDUCE entropy, you still gotta play by the rules

Dont work for the government, or do government related contract work, problem solved.

ate shit on live tv
Feb 15, 2004

by Azathoth
I use the OSX 10.11 "El Capitan" integrated key-store. It fits my needs very well for all browser based services that require passwords.

For SSH stuff I use a corporate 1password account for the shared vaults.

ate shit on live tv
Feb 15, 2004

by Azathoth

CRIP EATIN BREAD posted:

Why are you using password authentication for SSH?
Local accounts for backdoor access.

ate shit on live tv
Feb 15, 2004

by Azathoth

Parallel Paraplegic posted:

i'm not sure what a "guest pass" is but you could set up a separate AP on a vlan.

Do this OP and never under any circumstances should you be attempting to log guests. It does nothing but create liability. Captive Portal with a Terms and Conditions splash screen accept to allow internet access.

ate shit on live tv
Feb 15, 2004

by Azathoth

Antillie posted:

So a bank lost $81 million because they were too cheap to buy vlan capable switches and a few hardware firewalls for their network.

I work with banking networks and I cannot comprehend how these guys managed to end up with a network made of unmanaged consumer switches while being a loving bank. It doesn't even *thought process* ERROR, ERROR, STUPID.

quote:

The shortcomings made it easier for hackers to break into the Bangladesh Bank system earlier this year and attempt to siphon off nearly $1 billion using the bank's SWIFT credentials, said Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police's criminal investigation department.

Pro-tip. If you are going to rob a bank, which is a bad idea for a number of reasons, with the guarantee of the missing funds being noticed as number 1, you should go big. You will end up in the same prison for $10,000 or $1 billion assuming you get caught and really the penalty isn't much different. Hell if you are clever you could even use the 1 billion you stole as leverage for a lighter sentence.

ate shit on live tv
Feb 15, 2004

by Azathoth

Midjack posted:

lotta wizard security on that plane

TBF, were I to live within the magical halls Hogwarts, wizard security would be a good feature for a plane to have.

ate shit on live tv
Feb 15, 2004

by Azathoth

It's probably something like these,

https://en.wikipedia.org/wiki/TACLANE

Lots of vendors do it nowadays, but 10 year's ago you needed that. And they were often locked in tamper-proof cages.

ate shit on live tv
Feb 15, 2004

by Azathoth

Rufus Ping posted:

the cloudflare thing is their lovely WAF thinking every post is a sqli
Pedantically they are correct.

ate shit on live tv
Feb 15, 2004

by Azathoth
SELECT from USERNAME 'Technogeek' drop;
""

ate shit on live tv
Feb 15, 2004

by Azathoth

pr0zac posted:

you should post more about military crypto opsec stuff it sounds real cool </seriouspost>

They use IRC for interfleet communications within carrier groups.

ate shit on live tv
Feb 15, 2004

by Azathoth

pr0zac posted:

wait

are we talking about eve online now?

Nope, we are talking about the United States Navy, a global force for good.

ate shit on live tv
Feb 15, 2004

by Azathoth
Though tbf, that is certainly not their only, or even their primary form of communication, but it's still pretty funny.

ate shit on live tv
Feb 15, 2004

by Azathoth

darthbob88 posted:

Army and Air Force as well, AFAIK. On the one hand, it's readily available, solid bandwidth, legitimately a good means for tactical text communication. On the other, I'm not sure how comfortable I am knowing that air strikes are being directed over the same protocol 4chan uses to discuss anime porn.

I think it's a fine choice, it's just an amusing factoid.

ate shit on live tv
Feb 15, 2004

by Azathoth
Hold up, now stop me if it's crazy, but what if the "hack" was coming from INSIDE the firewall?

ate shit on live tv
Feb 15, 2004

by Azathoth

ewiley posted:

There's no way you're defeating quantom physic randomization :colbert:

IIRC quantum tunneling is how a cryptographically secure RNG works.

ate shit on live tv
Feb 15, 2004

by Azathoth

I mean it makes sense and it's much better then xXx_420GokuHitler_xXx

ate shit on live tv
Feb 15, 2004

by Azathoth

spankmeister posted:

$45K a year is pretty good for an intern

I think that's what I pulled in when I was an intern. P-dece imo.

ate shit on live tv
Feb 15, 2004

by Azathoth

Pro as gently caress prob. A PROb if you will..

ate shit on live tv
Feb 15, 2004

by Azathoth
Season or Month + Year + ! for all your dumbass password requirement needs.

Password Manager for everything else.

ate shit on live tv
Feb 15, 2004

by Azathoth
Do people think base64 encoding is a security feature and not realize it's an encoding that was literally invented for the purposes of transferring data between systems that may have different character sets?

ate shit on live tv
Feb 15, 2004

by Azathoth

I LIKE TO SMOKE WEE posted:

Completely interchangeable with any and all uses of encryption, duh :smug:

When you think about it encoding is just encryption but everyone already knows the password, also there isn't a password. So pretty much the same.

ate shit on live tv
Feb 15, 2004

by Azathoth
"These things clearly only exist to torment me. "

Yes, I'm sure the modern banking system with accounting and routing numbers and the fun vulnerabilities those entail, exist because the knights of templar knew that in TYOOL 2016 there would be a GIRL on the INTERNET!

ate shit on live tv
Feb 15, 2004

by Azathoth

apseudonym posted:

I see we don't like hyperbole when it's written by GIRLS on the INTERNET

flakeloaf posted:

the internet white knights tour

ate shit on live tv
Feb 15, 2004

by Azathoth

jre posted:

I am glad that the infosec community are continuing to be approachable and non judgmental

The greatest feature of the internet is people who are smart and knowledgable about a subject will eventually encounter someone who is smarter and more knowledgable. How the person who thought he knew everything reacts tells a lot about that person. It's also hilarious when it's over social media and they have to delete their dumb opinion.

ate shit on live tv
Feb 15, 2004

by Azathoth

Thermopyle posted:

It also tells you a lot about the smarter and more knowledgable person.

I bet we'd disagree on what it tells you!
:agreed:

Though the "smarter and more knowledgable person" might be the one who thought he knew everything.

ate shit on live tv
Feb 15, 2004

by Azathoth

ChickenOfTomorrow posted:

i do not think this is something of which you should be proud

also gently caress me, 2 years ago i trusted the grey forum rec on SSDs and bought an 850 840 EVO, ugh

I bought an 850, is that a gently caress up?

:ohdear:

ate shit on live tv
Feb 15, 2004

by Azathoth
Advised by the greys, vindicated by the 'pos. :cool:

ate shit on live tv
Feb 15, 2004

by Azathoth

The terrorists have won. They don't even need to do anything to disrupt transportation infrastructure.

ate shit on live tv
Feb 15, 2004

by Azathoth

qntm posted:

believe it or not, mild transportation disruption is not the terrorist endgame

Then I wish we'd stop loving around with security theater that has nothing to do with stopping terrorists.

ate shit on live tv
Feb 15, 2004

by Azathoth

Ulf posted:

i was going through this yesterday and thank you for trying so that i did not have to

"what was your favorite class in high school" [dropdown of 5,000 possible answers]

5000? Lol try like 3.

What's that you forgot your password? Well lets verify your identity via 5 static questions with 3 possible answers each.

ate shit on live tv
Feb 15, 2004

by Azathoth

Malloc Voidstar posted:

a forum focused around “extreme anal dilation and anal fisting,” according to security researcher Troy Hunt.

He actually goes by Mike.

ate shit on live tv
Feb 15, 2004

by Azathoth

It angers me that there has to be a lawsuit over this instead of it being something that is automatic and expected for continuing PCI compliance.

ate shit on live tv
Feb 15, 2004

by Azathoth
Does reputation even matter? If the product gets traction, security poo poo can be fixed whenever. Does anyone say "This is a great program/piece of hardware that I would like to use. Oh it looks like thy rushed it to market and since then have made a few security improvements, never mind, their reputation sucks. I'm out."

And besides that unlikely scenario rebranding can always be done as well.

Basically security is a cost center that very rarely helps your product/service sell.

ate shit on live tv
Feb 15, 2004

by Azathoth

Parallel Paraplegic posted:

oh wait it's http/s wasn't exposed to the internet in any case though because i'm not incompetent, never mind

I thought the whole idea of ubiquity was that they were "cloud managed" how can they reach the management platform if they aren't exposed to the Internet.

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth
Pretty much nothing people claim on twitter is true.

  • Locked thread