Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Root of thread trust chain posting

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BeOSPOS posted:

looks like we found the first vulnerability of this thread lol

lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chris Knight posted:

Whack for my Larry-o
There's a keystore in the JAR-o

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

cheese-cube posted:

i'll buy this tag for the next 10 ppl who quote this post (might take me a couple of days to do so, ive just moved house and have no internet yet)

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

anthonypants posted:

idk who that guy is but he sure is good at run-on sentences, and woo uh oops

He's a Good Linux Dude

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Three men went a-hunting
And something they did find
They came upon Norton
And that they left behind
The Irishmam said it was Norton
The Scotsman he said nay
The Welshman said it's the end of the world
Let's go back the other way

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Subjunctive posted:

IDK how long it takes to clear whatever cache of things and stuff, but:

uncurable mlady
fishmech
Crusader
jre
Captain Foo
Storysmith
Westie
Mad Wack
Testiclops
BeOSPOS

should all be set.

I'm phone posting and something.apk doesn't respect gang tags but 👍 third party av check

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

RZA Encryption posted:

just look at the post where you requested it

tag check

e- gently caress yeah thanks bruh

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


extremely sweet

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Chris Knight posted:

whoa baud betty bam a lam

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

APT just means "definitely from china or russia" instead of "probably from china or russia"

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

goddamnedtwisto posted:

The funny thing is there is a name for that technique, but nobody's going to call their product "sheep dip". Well, maybe people who make sheep dips.

you dip one sheep...

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

anyone know of any good opsec education resources? classes, texts, stories, anything that's accurate and educational really

@thegrugq

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Cocoa Crispies posted:

granny natting, not double dmz natting like you should be

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

tik tok on the clock dj blow my servers up

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

:f5:

oh god why do we have a meeting schedule rn

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

lomarf at all this buildup

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

spankmeister posted:

I know this thread can seem a bit intimidating but your reasoning isn't that far out there so really, don't be afraid to ask questions.

gently caress yeah if we've learned anything it's to question poo poo that seems obvious

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


jfc ayy

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

quote:

Abstract
In December 2015, Juniper Networks announced that
unknown attackers had added unauthorized code to
ScreenOS, the operating system for their NetScreen VPN
routers. This code created two vulnerabilities: an authentication
bypass that enabled remote administrative access,
and a second vulnerability that allowed passive decryption
of VPN traffic. Reverse engineering of ScreenOS binaries
revealed that the first of these vulnerabilities was a conventional
back door in the SSH password checker. The
second is far more intriguing: a change to the Q parameter
used by the Dual EC pseudorandom number generator. It
is widely known [7, 33] that Dual EC has the unfortunate
property that an attacker with the ability to choose Q can,
from a small sample of the generator’s output, predict all
future outputs. In a 2013 public statement, Juniper noted
the use of Dual EC but claimed that ScreenOS included
countermeasures that neutralized this form of attack.
In this work, we report the results of a thorough independent
analysis of the ScreenOS randomness subsystem,
as well as its interaction with the IKE VPN key establishment
protocol. Due to apparent flaws in the code,
Juniper’s countermeasures against a Dual EC attack are
never executed. Moreover, by comparing sequential versions
of ScreenOS, we identify a cluster of additional
changes that were introduced concurrently with the inclusion
of Dual EC in a single 2008 release. Taken as a
whole, these changes render the ScreenOS system vulnerable
to passive exploitation by an attacker who selects
Q. We demonstrate this by installing our own parameters,
and showing that it is possible to passively decrypt
a single IKE handshake and its associated VPN traffic in
isolation without observing any other network traffic.

http://dualec.org/DualECJuniper-draft.pdf

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


lmao this is perfect

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

good thread title change

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BangersInMyKnickers posted:

store the passwords with reversible encryption and check them

heh
hehehe
hehehehehennnnrrgggggh

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

cheese-cube posted:

this is technically a secfuck i guess: earlier this week we had a line-card fail on the core router at our DC which caused some knock-on storage issues and took our first exchange CAS server offline for about 12 hours. due to our dumb network inbound SMTP only goes to the first CAS server even though there are two in an array. at around the 12 hour mark i said "lol that server aint coming back" and got the network dudes to change the static NAT mapping to direct mail to the second CAS server. when we did that we expected that a flood of mail queued by messagelabs would come through but only new emails were coming through.

turns out the secondary inbound route for mail in messagelabs was pointing to an email continuity service (messageone) which we no longer used. so when our primary CAS server went down messagelabs started forwarding all inbound mail to this provider and their MTA happily accepted it.

so for 12 hours all inbound mail was going to a third-party which we have no control over or association with. about 39K emails went to this third-party and for all we know they still have them, sitting in a postfix queue on some AWS server somewhere. apparently the lawyers are speaking to messageone and demanding that they handover the emails lollll

lol!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

cool article but 2 bytes to 951 million dollars just doesn't have the same ring as 2 minutes to midnight imo

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


this is a good song

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'



Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Dessert Rose posted:

lol @ you loving idiots making fun of a military encryption device having clearly labeled interfaces and buttons

yeah, it's totally hilarious to have the clear text and crypto interfaces as physically far apart as possible so idiot with a HS diploma doesn't accidentally beam the clear text across the public unsecured network

and it should definitely not have an easy to access button to destroy all the crypto material in the device if the enemy is overrunning the base

how does someone with your av and gangtag gently caress up the interpretation of posting so incredibly badly

go 'yobbin or something

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

im just gonna start quoting parts of this at people in irc

lolol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

surebet posted:

as a long time reader and irregular poster in the secfuck threads, would it be a faux pas to grab the gangtag? i'm doing an av swap and i'd like to dual wield gangtags

dual wielding is better than dual ec, I can tell u that

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

~Coxy posted:

and there was at least one ring-O cold boot vulnerability

poo poo!!

Midjack posted:

had some real problems if you didn't defragment it very carefully too

gently caress!!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

i remember way back when the family had a diskette labeled F-PROT BOOT DISK and it was like some sort of holy relic, pretty much the only disk i wasn't allowed to touch

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

ymgve posted:

spoiler: it was your dads porn

lol

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

cheese-cube posted:

that plus the RSA conference goatse are gold-medal goatses

gold-medal goatse is a great phrase

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

imagemagick allowed me to make huge.jpg back in 2001 :unsmith:

you son of a bitch :unsmith:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BeOSPOS posted:

I use base5318008 :heysexy:

heeeeyoooo look at this guy

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Crust First posted:

i've always preferred base675309 (base675309)

hehe nice

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Shaggar posted:

I did my CMS security awareness cbt!!! check out security man here 2 protect your cyber


this would make a p deece av with a little editing

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

@taviso and @grittygrease (of CloudFlare) getting into it on twitter right now :allears:

Adbot
ADBOT LOVES YOU

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

anthonypants posted:

at the end of the conversation it looks like the cloudflare guy is trying to recruit him but the way he starts off makes him seem like an incredibly smug rear end in a top hat https://twitter.com/grittygrease/status/728253015719743488

yeah shaming someone's current job isn't a great way to get on their good side


ayy lmao this is fantastic

  • Locked thread