Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
fishmech
Jul 16, 2006

by VideoGames
Salad Prong

pseudorandom name posted:

wasn't there a brief period of time where you straight up
couldn't download the windows ISO from Microsoft?

yeah because there was a bug in the new iso they'd put up, but they didn't want to put back up the outdated iso. so it was just not availalbe until they got a newer version up

Adbot
ADBOT LOVES YOU

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

pseudorandom name posted:

wasn't there a brief period of time where you straight up
couldn't download the windows ISO from Microsoft?

you still can't download a windows 7 ISO from MS afaict, but they even have a tool for downloading windows 10

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
that's because windows 10 is free software

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
what the gently caress, Citibank





edit: greenpos bestpos

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
I'm the USBDepository

negromancer
Aug 20, 2014

by FactsAreUseless

Achmed Jones posted:

I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

I don't currently have the link (on mobile and too lazy) but it's called "Security Risk Assessment" and it's a Syngress Press book. It's pretty much my risk assessment Bible for audit stuff and basically what I used to write the closing on what a company needs to focus on and do at 30 days, 90 days, etc based on what was found during the audit.

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

Ur Getting Fatter posted:

what the gently caress, Citibank





edit: greenpos bestpos

u can hack atms like in the Fallout games :eyepop:

BONGHITZ
Jan 1, 1970

Achmed Jones posted:

I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

just have everyone buy macs

Pile Of Garbage
May 28, 2007



negromancer posted:

I don't currently have the link (on mobile and too lazy) but it's called "Security Risk Assessment" and it's a Syngress Press book. It's pretty much my risk assessment Bible for audit stuff and basically what I used to write the closing on what a company needs to focus on and do at 30 days, 90 days, etc based on what was found during the audit.

is it this one (PDF)? http://www.grc.net.br/attachment.php?attachmentid=46&d=1307706976

Luigi Thirty
Apr 30, 2006

Emergency confection port.

flakeloaf posted:

i agree there's a difference between a guy searching your drive because he's bored and a guy searching your drive cause his fbi handlers told him to, cause one's just poo poo luck and the other's a giant problem

lol who am i kidding of course they were agent police

and also the part where they were like "well we can't indict on a single deleted image because you can't prove intentional possession or who possessed it... so let's just not tell the prosecutor it was deleted"

Luigi Thirty
Apr 30, 2006

Emergency confection port.

Ur Getting Fatter posted:

what the gently caress, Citibank





edit: greenpos bestpos

you hacked a bank across state lines? that's monumentally stupid!

Wiggly Wayne DDS
Sep 11, 2010



Ur Getting Fatter posted:

what the gently caress, Citibank





edit: greenpos bestpos
common error screen on ncr machines, nothing to be overly worried about

spankmeister
Jun 15, 2008






apseudonym posted:

That was me, and I'm gonna stand by that with skill its not impossible to catch using things like timing and sizes and such signals, I worked with people who built tools for this kind of stuff (and sold them to lovely human being :smith:) and I hosed a lot of lovely tor stealth projects that tried to mask as other things.

Thankfully Egypt blows and hasn't blown the money on people who can :toot:

Yeah but can you do all that on a national scale?

apseudonym
Feb 25, 2011

spankmeister posted:

Yeah but can you do all that on a national scale?

Sure, why wouldn't you? The information you get at a national scale makes it easier to spot outliers.

But y'know, :effort: and :10bux:

Segmentation Fault
Jun 7, 2012

Heresiarch posted:

you still can't download a windows 7 ISO from MS afaict, but they even have a tool for downloading windows 10

Microsoft's website will give you a Windows 7 ISO if you give them a valid key

Last Chance
Dec 31, 2004

Segmentation Fault posted:

Microsoft's website will give you a Windows 7 ISO if you give them a valid key

i remember i tried this with a key i got through some MS win 7 upgrade promotion and it would only let me download a french or korean windows 7 iso lol

ala this poor gently caress

https://answers.microsoft.com/en-us...d0-62ca58d027cb

Shame Boy
Mar 2, 2010

apseudonym posted:

That was me, and I'm gonna stand by that with skill its not impossible to catch using things like timing and sizes and such signals, I worked with people who built tools for this kind of stuff (and sold them to lovely human being :smith:) and I hosed a lot of lovely tor stealth projects that tried to mask as other things.

Thankfully Egypt blows and hasn't blown the money on people who can :toot:

wanna talk about how to not broadcast traceable signals if you know about it?

Shame Boy
Mar 2, 2010

Heresiarch posted:

you still can't download a windows 7 ISO from MS afaict, but they even have a tool for downloading windows 10

i am so loving glad microsoft is making this easy now so i don't have to clean viruses from torrented ISO's my friends got because they had a license but not a CD, which has happened several times

Silver Alicorn posted:

that's because windows 10 is free software

not anymore :sigh:

30 TO 50 FERAL HOG
Mar 2, 2005




yeah it is just run the installer and itll still activate just fine lmao

Shame Boy
Mar 2, 2010

BiohazrD posted:

yeah it is just run the installer and itll still activate just fine lmao

you sure it didn't have an OEM license attached to the computer at all? because my friend thought this with a new built computer and it required a key.

Flagrama
Jun 19, 2010

Lipstick Apathy
windows 10 clean install was never free. upgrade from win7/8/8.1 was free and then would activate on your hardware even if you installed again clean.

Shame Boy
Mar 2, 2010

Flagrama posted:

windows 10 clean install was never free. upgrade from win7/8/8.1 was free and then would activate on your hardware even if you installed again clean.

yeah that's what i thought

Dylan16807
May 12, 2010

Flagrama posted:

windows 10 clean install was never free. upgrade from win7/8/8.1 was free and then would activate on your hardware even if you installed again clean.

and that upgrade still is free. the 'deadline' was only there to fight procrastination

Segmentation Fault
Jun 7, 2012
you can still get a free upgrade if you jump through some sort of user accessibility hoop, I don't know anything about that specifically

You can still get the install media for Win10 from Microsoft and install it without a valid license just fine, it just locks you out of some features like Hackbunny said

Winkle-Daddy
Mar 10, 2007
Hey sec fuckup thread! I know I've seen some awesome posts about what cipher suites should be enabled...does anyone have a config or can link to an ideal nginx SSL config? Specifically for ssl_protocols and ssl_ciphers?

Truga
May 4, 2014
Lipstick Apathy

Segmentation Fault posted:

you can still get a free upgrade if you jump through some sort of user accessibility hoop, I don't know anything about that specifically

You have to pinky swear you'll use accessibility features (like, say, hotkeys) when using windows, and you can still install it from here: https://www.microsoft.com/en-us/accessibility/windows10upgrade That's it.

Also, lol that microsoft themselves don't offer a torrent of their iso, it's a much better protocol for downloading large files than http if your internet isn't very fast (so, majority of the world that doesn't have win10 yet). Are there even any browsers out there that can resume http downloads today?

Winkle-Daddy posted:

Hey sec fuckup thread! I know I've seen some awesome posts about what cipher suites should be enabled...does anyone have a config or can link to an ideal nginx SSL config? Specifically for ssl_protocols and ssl_ciphers?

My personal procedure is to use https://www.ssllabs.com/ssltest/analyze.html until it shows A or A+. It says what the problematic ciphers are if you have them enabled.

Winkle-Daddy
Mar 10, 2007

Truga posted:

My personal procedure is to use https://www.ssllabs.com/ssltest/analyze.html until it shows A or A+. It says what the problematic ciphers are if you have them enabled.

Yeah, I use that too, but this isn't internet accessible, so I was just hoping for a solid config for those two options.

spankmeister
Jun 15, 2008






Winkle-Daddy posted:

Hey sec fuckup thread! I know I've seen some awesome posts about what cipher suites should be enabled...does anyone have a config or can link to an ideal nginx SSL config? Specifically for ssl_protocols and ssl_ciphers?

Here u go: https://wiki.mozilla.org/Security/Server_Side_TLS

e: might be worth putting this in the OP

e2: the config generator: https://mozilla.github.io/server-side-tls/ssl-config-generator/

spankmeister fucked around with this message at 17:54 on Jan 6, 2017

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

Heresiarch posted:

you still can't download a windows 7 ISO from MS afaict, but they even have a tool for downloading windows 10

no one should be running windows 7 when win10 is a free upgrade

Tankakern
Jul 25, 2007

pr0zac posted:

no one should be running windows

Segmentation Fault
Jun 7, 2012

pr0zac posted:

no one should be running windows 7 when win10 is a free upgrade

but windows 10 spies on you!

Anyway check out my android

Truga
May 4, 2014
Lipstick Apathy

however, if you have to

pr0zac posted:

no one should be running windows 7 when win10 is a free upgrade
this, and installing 7 and upgrading isn't needed either.

windows 10 installer will take a windows 7 product key even on a fresh install in my experience, even after the period ended.

Winkle-Daddy
Mar 10, 2007

this is awesome. thank you!

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Achmed Jones posted:

I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

are you already familiar with this article? https://medium.com/starting-up-security/starting-up-security-87839ab21bae

Shaggar posted:

the torrent is probably advertised as activation cracked

once I needed a windows vm and was anxious about it. I bit down and just downloaded and installed windows 10, figuring that I'd just reinstall the vm if the evaluation period ran out. instead it turned out that windows works at, like, 99% capacity without activation. you can't configure telemetry, personalize the taskbar, things like that

Heresiarch posted:

you still can't download a windows 7 ISO from MS afaict, but they even have a tool for downloading windows 10

downloading windows was, for the longest time, exclusively allowed to msdn subscribers. except windows 2000, because it had java built in and the settlement with sun means they can't distribute it any longer in any way or form, you have to find a 3rd party reseller that still has it

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
r/netsec proves to be the best place to see painful discussions on password managers

https://www.reddit.com/r/netsec/comments/5mahfl/1password_is_still_using_full_dropbox_access_to/

quote:

1Password on iOS doesn't even promote good security. It allows copying text to the clipboard. Any third party app can read the clipboard – users have to manually clear the clipboard by copying over it.

[...]

I really wish Apple would implement a secure copy function. I.e: a clipboard item type that cannot be pulled via a public API and must be pasted via the action menu. I've thought about implementing such functionality as a jailbroken tweak.

yes. jailbreak your device to fix a problem with 1password's innocuous copy and paste method

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
I wonder if 1password could use a custom keyboard instead of the clipboard, as an interface between password database and applications

Shame Boy
Mar 2, 2010

Winkle-Daddy posted:

Yeah, I use that too, but this isn't internet accessible, so I was just hoping for a solid config for those two options.

check out sslscan which does most of the things ssl labs does but you can run it locally.


yeah i think that's where i originally got mine from, then i massaged it until i was happy. here's mine if anyone cares:

code:
ssl_prefer_server_ciphers on;
ssl_protocols             TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers               "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH EDH+aRSA !RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS";
other useful settings you should read up about and probably use are:

- ssl_dhparam
- ssl_session_*
- ssl_stapling

also if you're a cool ssl bro and are 100% sure you'll only use SSL forever you wanna do:

code:
add_header                Strict-Transport-Security "max-age=15768000; includeSubdomains;";

FlapYoJacks
Feb 12, 2009
Random question:

Is there a way for me to NOT have a self-signed certificate on an production embedded device that may not be connected to the internet?

30 TO 50 FERAL HOG
Mar 2, 2005



hackbunny posted:

I wonder if 1password could use a custom keyboard instead of the clipboard, as an interface between password database and applications

or people could just use icloud keychain like a normal person

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






ate all the Oreos posted:

check out sslscan which does most of the things ssl labs does but you can run it locally.


yeah i think that's where i originally got mine from, then i massaged it until i was happy. here's mine if anyone cares:

code:
ssl_prefer_server_ciphers on;
ssl_protocols             TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers               "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH EDH+aRSA !RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS";
other useful settings you should read up about and probably use are:

- ssl_dhparam
- ssl_session_*
- ssl_stapling

also if you're a cool ssl bro and are 100% sure you'll only use SSL forever you wanna do:

code:
add_header                Strict-Transport-Security "max-age=15768000; includeSubdomains;";

Yeah I janitored my own bespoke artisanal cipher suite, but the mozilla one is a very good starting point and you wouldn't be bad off at all if you left it.

  • Locked thread