Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
duTrieux.
Oct 9, 2003


what the gently caress

Adbot
ADBOT LOVES YOU

Winkle-Daddy
Mar 10, 2007

If you want to play with this, I wrote a quick Golang tool to do so: https://github.com/ZedCode/autofill-pwn
code:
 ./autofill-pwn -p 8080 -f index.html
2017/01/05 12:41:24 Starting server...
2017/01/05 12:41:29 Serving GET Request...
2017/01/05 12:41:30 Serving GET Request...
2017/01/05 12:41:31 Field address = []
2017/01/05 12:41:31 Field postal = []
2017/01/05 12:41:31 Field city = []
2017/01/05 12:41:31 Field country = []
2017/01/05 12:41:31 Field name = [abc]
2017/01/05 12:41:31 Field email = [abc@yahoo.com]
2017/01/05 12:41:31 Field phone = []
2017/01/05 12:41:31 Field organization = []
2017/01/05 12:41:31 Serving GET Request...
^C
It just has one URL route (to the file you specify) and will display the file, or all of the POST data it receives. Stupid and simple but maybe interesting if someone wanted to investigate that whole thing further.

30 TO 50 FERAL HOG
Mar 2, 2005




ahahahaha

Sharktopus
Aug 9, 2006

if you're scrolled above a full address form and half of it is off screen do you think autofill should fill the whole form or just the fields you can see???

Trabisnikof
Dec 24, 2005


Lol

Winkle-Daddy
Mar 10, 2007

Sharktopus posted:

if you're scrolled above a full address form and half of it is off screen do you think autofill should fill the whole form or just the fields you can see???

I'm pretty sure it should only auto-fill fields you can see, otherwise you don't know what it's filling in. If you care about this kind of poo poo you're not using auto fill in the first loving place, though.

pseudorandom name
May 6, 2007

does it autofill credit card information?

Winkle-Daddy
Mar 10, 2007

pseudorandom name posted:

does it autofill credit card information?
maybe, but you'd have to have your browser set to auto fill that (please don't do this)

30 TO 50 FERAL HOG
Mar 2, 2005



Winkle-Daddy posted:

maybe, but you'd have to have your browser set to auto fill that (please don't do this)

safari does this in a good way, it is totally separate than auto filling name/email/whatever and also has Visa/Mastercard/Amex logos in the autofill drop down to make it super obvious that youre about to put your CC in

itll be nice when more people start doing applepay through their site though

Winkle-Daddy
Mar 10, 2007
is autofill per domain? I'm copying various login page form fields and serving it and it's not auto completing poo poo.

e: maybe this could happen if someone doesn't turn off autocomplete on that form field?

Winkle-Daddy fucked around with this message at 22:09 on Jan 5, 2017

flakeloaf
Feb 26, 2003

Still better than android clock

not in chrome it isn't

pseudorandom name
May 6, 2007

so the way to fix this would be making autofill a two step process where it displays a dialog box asking if you want to give this list of personal facts to blah.com

Winkle-Daddy
Mar 10, 2007
I don't see the auto-fill behavior described in Chromium. When I test it, I have to click into each form field to see a list of options. I don't seem to have a way to auto fill the whole form? maybe someone else can do something more interesting with my code.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Chrome will auto fill CC#s but you have to provide the CVN in a modal outside of page at least for cards I have in Google's system

Luigi Thirty
Apr 30, 2006

Emergency confection port.

https://twitter.com/zackwhittaker/status/817127114969403393

geek squad was literally the Stasi and used data recovery tools to look for poo poo on your hard drive that would earn them FBI bounties

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
all bets are off with physical access

flakeloaf
Feb 26, 2003

Still better than android clock

Luigi Thirty posted:

https://twitter.com/zackwhittaker/status/817127114969403393

geek squad was literally the Stasi and used data recovery tools to look for poo poo on your hard drive that would earn them FBI bounties

if you give your computer, which contains evidence of you committing crimes, to someone else, you are a moron

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

OSI bean dip posted:

all bets are off with physical access

that was kind of what made mr. robot good

and sneakers

Trabisnikof
Dec 24, 2005

flakeloaf posted:

if you give your computer, to geeksquad, you are a moron

ate shit on live tv
Feb 15, 2004

by Azathoth

flakeloaf posted:

if you give your computer, which contains evidence of you committing crimes, to someone else, you are a moron

Fortunately the 4th amendment isn't means tested to only apply to non-morons.

redleader
Aug 18, 2005

Engage according to operational parameters
chrome's stored credit card stuff is actually super helpful when you're slamming through a buttload of test orders on your bespoke ecommerce system. and yeah, in my experience you still need to manually enter the cvv

i do wonder how many regular people use chrome cc autofill

Celexi
Nov 25, 2006

Slava Ukraini!
chrome cc autofill shows the card logo when filling a card , and its separate from the name/address

Pile Of Garbage
May 28, 2007



pr0zac posted:

What are you up to currently and why wouldn't you wanna move? secops can be fun, get to play with a bunch of cool security tools

im doing mainly infra ops stuff at the moment, pretty much everything server-side from hypervisor up to software but for the last year i've been heading up an office 365 project. i already do a fuckton of security stuff and am the defacto security liaison of sorts for my team. i guess i'm worried about being pigeonholed should i move into secops proper. then again at the same time i can prolly affect change in practice better from there because things at the moment are very....relaxed.

guess i need to think on it.

flakeloaf
Feb 26, 2003

Still better than android clock

ate poo poo on live tv posted:

Fortunately the 4th amendment isn't means tested to only apply to non-morons.

i agree there's a difference between a guy searching your drive because he's bored and a guy searching your drive cause his fbi handlers told him to, cause one's just poo poo luck and the other's a giant problem

lol who am i kidding of course they were agent police

Segmentation Fault
Jun 7, 2012

Trabisnikof posted:

quote:

Geeksquad, a moron

negromancer
Aug 20, 2014

by FactsAreUseless
So water dispensers, huh

https://twitter.com/find_evil/status/816846566799470593?s=01

Segmentation Fault
Jun 7, 2012

I'm the embedded system running standard Windows 7

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer
lol if you use auto-form in any way

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
hmmm?

Only registered members can see post attachments!

apseudonym
Feb 25, 2011

Wiggly Wayne DDS posted:

whoever was complaining about signal's egypt approach earlier:

https://twitter.com/whispersystems/status/817062093094604800

That was me, and I'm gonna stand by that with skill its not impossible to catch using things like timing and sizes and such signals, I worked with people who built tools for this kind of stuff (and sold them to lovely human being :smith:) and I hosed a lot of lovely tor stealth projects that tried to mask as other things.

Thankfully Egypt blows and hasn't blown the money on people who can :toot:

hobbesmaster
Jan 28, 2008

Segmentation Fault posted:

I'm the embedded system running standard Windows 7

oh no, its worse

hobbesmaster
Jan 28, 2008

a true embedded system would be running linux with a bsp not updated since 2004

Pile Of Garbage
May 28, 2007



https://twitter.com/GossiTheDog/status/817089856316784643

lol

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



hobbesmaster posted:

a true embedded system would be running linux with a bsp not updated since 2004

yeah windows is probably safer out of the box than a lot of the Linux distros

they should probably make the update spinner brandable tho

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

why wouldn't you just download the official iso. did you know? if you don't activate windows 10, a few features are locked out but it mostly works?

Achmed Jones
Oct 16, 2004



I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

Shaggar
Apr 26, 2006

hackbunny posted:

why wouldn't you just download the official iso. did you know? if you don't activate windows 10, a few features are locked out but it mostly works?

the torrent is probably advertised as activation cracked

Segmentation Fault
Jun 7, 2012

still getting mileage out of the cloud to butt extension

hackbunny posted:

why wouldn't you just download the official iso. did you know? if you don't activate windows 10, a few features are locked out but it mostly works?

a lot of people don't know that microsoft hands out the install media no questions asked

Midjack
Dec 24, 2007



hackbunny posted:

why wouldn't you just download the official iso. did you know? if you don't activate windows 10, a few features are locked out but it mostly works?

a lot of people discover torrents and immediately forget that there's any other way to acquire software.

Adbot
ADBOT LOVES YOU

pseudorandom name
May 6, 2007

wasn't there a brief period of time where you straight up
couldn't download the windows ISO from Microsoft?

  • Locked thread