Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
compuserved
Mar 20, 2006

Nap Ghost
i am protected

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
updated the op to include the secthread officially approved podcast, risky business

(the previous thread was mentioned in an episode)

Pile Of Garbage
May 28, 2007



pr0zac posted:

posting on the first page and all that

and good lord we need to get some better resource links for newbies than r/netsec, like its good for a reddit but its still reddit

we're better than reddit by virtue of not being reddit

https://www.youtube.com/watch?v=DOqb_UzJSUQ

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

cheese-cube posted:

thankyou for doing the needful afreak.

for content my ops mgr has asked me if i want to move to the secops team. talk about a secfuck. not the first time he's asked me either, i turned him down in february 2015 becos lol

What are you up to currently and why wouldn't you wanna move? secops can be fun, get to play with a bunch of cool security tools

cheese-cube posted:

we're better than reddit by virtue of not being reddit

https://www.youtube.com/watch?v=DOqb_UzJSUQ

meant it more for the industry as a whole as opposed to this thread, its kind of nuts that the best source for infosec news (wtf did i write newbies?) is a god drat subreddit

wasnt meant as reddit hate either, though i did send that video to my brother over the holidays after he kept sending me stupid dumb reddit links

Wiggly Wayne DDS
Sep 11, 2010



best source is still curated twitter unfortunately

Shame Boy
Mar 2, 2010

pr0zac posted:

What are you up to currently and why wouldn't you wanna move? secops can be fun, get to play with a bunch of cool security tools


meant it more for the industry as a whole as opposed to this thread, its kind of nuts that the best source for infosec news (wtf did i write newbies?) is a god drat subreddit

wasnt meant as reddit hate either, though i did send that video to my brother over the holidays after he kept sending me stupid dumb reddit links

my gf got invited to move to the sec team because once the boss of the team couldn't tell if a super obvious phishing scam letter was actually a phishing letter and she was like "uh yeah it clearly is, you idiots" and they were like "wow you're real smart!"

her boss rejected the transfer though because he's short staffed, so she'll stay at her current position

...which is tier III tech support :smith:

Shame Boy
Mar 2, 2010

Wiggly Wayne DDS posted:

best source is still curated twitter unfortunately

infosectaylorswift and thegrugq, ignore basically everything they post themselves and just read the retweets

Wiggly Wayne DDS
Sep 11, 2010



neither of them are on my list tbh

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
if a yossec twitter list is created and doesn't look like poo poo, i'll make it official

Segmentation Fault
Jun 7, 2012

pr0zac posted:

posting on the first page and all that

and good lord we need to get some better resource links for newbies than r/netsec, like its good for a reddit but its still reddit

speaking of secfucks and reddit, https://www.reddit.com/r/TronScript/ is a pretty good collection of "good at computers" types who believe in the "run a magical program" school of infosec

Workaday Wizard
Oct 23, 2009

by Pragmatica
swiftonsecurity is 99% noise

Segmentation Fault
Jun 7, 2012
also @taviso, @briankrebs, and occasionally @puellavulnerata for yossec twitter

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."


https://www.bleepingcomputer.com/news/security/killdisk-ransomware-now-targets-linux-prevents-boot-up-has-faulty-encryption/

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Celexi posted:

Did i get on first page

nope (just posting to boomark, honestly)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Shinku ABOOKEN posted:

swiftonsecurity is 99% noise

and 100% furry windows AV janitor

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Segmentation Fault posted:

speaking of secfucks and reddit, https://www.reddit.com/r/TronScript/ is a pretty good collection of "good at computers" types who believe in the "run a magical program" school of infosec

i'm the batch files committed to github

https://github.com/bmrf/tron/tree/master/resources

Wiggly Wayne DDS
Sep 11, 2010



i change who's on my list frequently (usually if something big happens), and kick off people who are just noise but this has done me well so far: https://twitter.com/zylche/lists/security

mostly i just look there for what's happening and if there's any big news my bigger follow list will have something to say/retweet someone of value

Shame Boy
Mar 2, 2010


quote:

The KillDisk ransomware variant that targets Windows machines worked by encrypting each file via an AES-256 key, and then encrypting the AES keys with a public RSA-1028 key.

4 extra bits to make it 4 times more secure

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

Rufus Ping posted:

and 100% furry windows AV janitor

swiftonsecurity has me blocked for some reason

i can only imagine it had to do with me wondering aloud if they were being paid to tweet positive comments about norton AV

Truga
May 4, 2014
Lipstick Apathy


center for strategic and int'l studies wizard policy task force. has the wizard glasses to prove it

2017 is going to be a very good year for wizard security, i can tell already

Proteus Jones
Feb 28, 2013



Migishu posted:

Security Fuckup Megathread - v13.0.1 - looks like them secfuck boys are at it again

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

Truga posted:



center for strategic and int'l studies wizard policy task force. has the wizard glasses to prove it

2017 is going to be a very good year for wizard security, i can tell already

please, no security wizard would be caught dead in those

AAB
Nov 5, 2010

"what level computer wizard are you, fellow tech janitor?"
"oh, I don't classify by level, I'm with The Foundation"

Wiggly Wayne DDS
Sep 11, 2010



whoever was complaining about signal's egypt approach earlier:

https://twitter.com/whispersystems/status/817062093094604800

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

i'm the 222 btc fee

Workaday Wizard
Oct 23, 2009

by Pragmatica

Wiggly Wayne DDS posted:

i change who's on my list frequently (usually if something big happens), and kick off people who are just noise but this has done me well so far: https://twitter.com/zylche/lists/security

mostly i just look there for what's happening and if there's any big news my bigger follow list will have something to say/retweet someone of value

link doesn't work

redleader
Aug 18, 2005

Engage according to operational parameters
so browsers, huh

https://twitter.com/anttiviljami/status/816585860661518336

flakeloaf
Feb 26, 2003

Still better than android clock


well that sure is something

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

Wiggly Wayne DDS posted:

best source is still curated twitter unfortunately

I actually felt sad reading this. Because its true.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Migishu posted:

i'm the 222 btc fee

what, you don't have files valuable enough to pay $200k for a small chance to get them back?

(I assume it's supposed to be milliBTC but lol)

BONGHITZ
Jan 1, 1970


lol

Wiggly Wayne DDS
Sep 11, 2010



https://www.ftc.gov/news-events/press-releases/2017/01/ftc-charges-d-link-put-consumers-privacy-risk-due-inadequate

quote:

...
According to the FTC’s complaint, D-Link promoted the security of its routers on the company’s website, which included materials headlined “EASY TO SECURE” and “ADVANCED NETWORK SECURITY.” But despite the claims made by D-Link, the FTC alleged, the company failed to take steps to address well-known and easily preventable security flaws, such as:

“hard-coded” login credentials integrated into D-Link camera software -- such as the username “guest” and the password “guest” -- that could allow unauthorized access to the cameras’ live feed;
a software flaw known as “command injection” that could enable remote attackers to take control of consumers’ routers by sending them unauthorized commands over the Internet;
the mishandling of a private key code used to sign into D-Link software, such that it was openly available on a public website for six months; and
leaving users’ login credentials for D-Link’s mobile app unsecured in clear, readable text on their mobile devices, even though there is free software available to secure the information.
According to the complaint, hackers could exploit these vulnerabilities using any of several simple methods. For example, using a compromised router, an attacker could obtain consumers’ tax returns or other files stored on the router’s attached storage device. They could redirect a consumer to a fraudulent website, or use the router to attack other devices on the local network, such as computers, smartphones, IP cameras, or connected appliances.

The FTC alleges that by using a compromised camera, an attacker could monitor a consumer’s whereabouts in order to target them for theft or other crimes, or watch and record their personal activities and conversations.
...

complaint & exhibits: https://www.ftc.gov/system/files/documents/cases/170105_d-link_complaint_and_exhibits.pdf

spankmeister
Jun 15, 2008






ymgve posted:

what, you don't have files valuable enough to pay $200k for a small chance to get them back?

(I assume it's supposed to be milliBTC but lol)

nah. the current idea is that it's not "real" ransomware but instead meant to cover the tracks of a targeted attack

FlapYoJacks
Feb 12, 2009

quote:

In a statement emailed to Consumerist, D-Link responds to the lawsuit:
D-Link Systems, Inc. is aware of the complaint filed by the FTC. D-Link denies the allegations outlined in the complaint and is taking steps to defend the action. The security of our products and protection of our customers private data is always our top priority.

Are they denying that their software had hard coded usernames and password?

Or are they denying that their private keys were publicly available for 6 months on the internet?

Lmbo

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

OSI bean dip posted:

updated the op to include the secthread officially approved podcast, risky business

(the previous thread was mentioned in an episode)

they need to get back with the 2017 episodes stat. i can't handle much more steptoe's politicizing

Moist von Lipwig
Oct 28, 2006

by FactsAreUseless
Tortured By Flan

Truga posted:



center for strategic and int'l studies wizard policy task force. has the wizard glasses to prove it

2017 is going to be a very good year for wizard security, i can tell already

those wizard glasses are extremely powerful

Sharktopus
Aug 9, 2006


https://github.com/anttiviljami/browser-autofill-phishing/blob/master/index.html#L17

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

i don't know poo poo when it comes to law, is any of this meaningful in the sense that it's likely to end with more than dlink going "lol" and maybe paying a :10bux: fine? or set any precedent for further cracking down on security bullshit in the long term?

Sharktopus
Aug 9, 2006

sir i havings submitted bug reporting to your platform

add negative margin on form field style and clicking autofill. autofill still fill form even when not on screen!

can send bank info or addrss for reward pls 6 years old issue!

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://bugcrowd.com/netgear

quote:

Payout Expected Outcome
$15,000 Unauthorized access to NETGEAR cloud storage video files for all customers
$15,000 Unauthorized access to live video feeds of all NETGEAR customers
$15,000 Remote Unauthorized access to administer another NETGEAR customer's router (via the publicly accessible internet )
$10,000 Unauthorized access to only a single NETGEAR customer live video feed
$10,000 Unauthorized access to only a single NETGEAR customer cloud storage video files
$10,000 Retrieve all customer's payment information -16 Digit credit card numbers, CVV
$5,000 Retrieve only a single customer payment information
$5,000 Retrieve complete NETGEAR customer's database -Must have elements: Name, Email address, Password, Products owned
$1,500 Working SQL Injection on Cloud Infrastructure (excluding Firmware, Web Management & Client Apps)
$1,000 Working Stored XSS from lower to higher privilege users on Cloud Infrastructure (excluding Firmware, Web Management & Client Apps)
$750 CSRF against critical functions within an admin interface
$300 Working SQL Injection on Firmware, Web Management & Client Apps
$150 Open Redirection

  • Locked thread