Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Captain Foo posted:

0day poastin'

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/xkeepah/status/817597393449271296

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

I preferred the previous thread title tbh

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

negromancer posted:

that's why you use mobaxterm on windows and stop using putty and winscp like it's 2004.
i'm still trying to get my coworkers to stop using filezilla

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

FileZilla is pretty good so idk why you'd do this.
it's adware

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

my favorite thing is ssh-copy-id root@[servername]

i do need to get around to disabling sudo on the lxss tho. that poo poo is annoying and worthless.
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Segmentation Fault posted:

iirc filezilla is bundled with adware when it's offered through sourceforge but that's an issue with sourceforge and not filezilla itself
i didn't know you could download it from anywhere other than sourceforge, is that recent?

my favorite winscp feature is support for pageant, which makes it easy for non-technical women and children to connect to sftp sites

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

PCjr sidecar posted:

uh always looking for an improvement to putty but a built-in chat server (not enabled by default) and the ability to store passwords (duh don't use that lol) makes me somewhat uncomfortable? what features are good?
i would hope Ed25519 support which afaik is only available on putty through the nightlies

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

this should be probatable
imho if they didn't want a probe they wouldn't have posted the ip address of their server to the secfuck thread

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

MononcQc posted:

haha holy poo poo here's the signing to prevent tampering:
they call hash an optional module, but mcrypt is required!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
by default it looks like the /smaes/test_console.php file is visible to the world, which is a log of everything his php thing is doing

in fact, that's the way he's got it set up on his website. and if you visit any of the php sites in this screenshot


you'll see your ip address show up here http://www.semographics.com/smaes/test_console.php

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
http://www.csoonline.com/article/3155397/security/esea-hacked-1-5-million-records-leaked-after-alleged-failed-extortion-attempt.html oops

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

abraham linkedin posted:

lol i used to use that site

it didn't used to have ssl on any pages (not even login) except for a self-signed cert, and you had to manually use https because it didn't redirect

i posted about it and was like "hey this is hosed up, if a bunch of people from ESEA go to a LAN they could get their credentials stolen"

a bunch of people responded like "lol u dont know anything" and "what does it matter they don't store payment info"

bunch of dipshits on there
the esea was the one with a secret bitcoin miner in the client so i don't feel too bad for them

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

quote:

Update:


In an emailed statement, a spokesperson for ESL Gaming (parent company to Turtle Entertainment) confirmed that the hacker did in fact attempt to extort money, but the sum demanded was "substantially higher" than the $50,000 previously mentioned.

quote:

Update 2:


In an official statement posted to their website, ESEA says that the hacker demanded a $100,000 ransom.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

remember firesheep?
i was trying to remember the name of this one

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
every single one of the claims made against trump is completely unverifiable, and buzzfeed believes that journalism means publishing every claim so that the american people can figure out what's real and what's not by themselves. everything in those highlighted printouts is bullshit, and you would be a humongous gullible idiot for taking any of those claims seriously.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pr0zac posted:

This claim is just as unsupported and rejecting everything completely outright makes you just as much of a gullible idiot as anyone taking them as gospel.
well YOUR claim is also unsupported therefore YOU are also just as much the gullible idiot. check mate

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
gonna be a cold four years talking about secfucks without being able to mention us policy ever

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

this is the security fuckup thread; not the journalism integrity one

if you want to talk about how much buzzfeed and vox suck, go make a new thread
iirc the last time you got upset we were discussing the credulity of present-day spy agencies

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:




buzzfeed published a story about the fact that an intelligence report contained those allegations, and explicitly said they couldn't verify the claims themselves. it's like writing a story "trump appointee claims climate change a hoax".


e: whoops new page
that's not what happened at all, but nice try

e: whoops new page

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Munkeymon posted:

actually no some total loving dipshit will brag about doing it and be taken seriously enough for someone to pull logs and tens of other cases will be discovered

one of those
in your first scenario the family is waaaaaaaaaaaaaay too busy fighting over who gets the money to care at all about the dead guy

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

yeah i'm not sure what to think

accessible security is important, and while php is accessible, that accessibility has made it a complete shitshow for doing things securely
here is his pinned tweet

https://twitter.com/CiPHPerCoder/status/794587430108168194

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

redleader posted:

remember, always feel free to roll your own crypto
in the first line of that project's github readme is, "Not as quick as FastAES"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

The_Franz posted:

you can't hack something that nobody uses
actually lots of people use openssh

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rooney McNibnug posted:

I use OpenBSD for a lot of things, actually.. I really also like their new pledge() restricted-service operating mode option for stuff.
i saw theo de raadt's talk on pledge() and what they're trying to accomplish sounds really cool

https://www.youtube.com/watch?v=F_7S1eqKsFk

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/sarahjeong/status/819710944095809536

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i got a tp-link ac3200 and it's needs-suiting, do you care about custom firmware or anything here's his first tweet in that thread: https://twitter.com/ErrataRob/status/819738590116716544

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

Installing Linux isn't a realistic option for most end users, and buying a MBP costs a lot of money said user may not have.

Assuming they're even aware of this, which they're likely not.
windows 7 is still supported and is way easier to get around the windows updates that drop telemetry patches

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

then how do they check it for valuable bomb components
they probably do that before in front of you, like if they want to inspect your gun case

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/admung/status/820518665783156736

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

geonetix posted:

welcome back thread!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

MS has gotten pretty good about being able to make guarantees that your tenant will only be hosted out of the geographic area you specify and considering the relatively small amount of bandwidth going in and out of that country I would have to imagine there's already a substantial datacenter presence in the country. higher ed does similar things with guarantees that they're tenant will only be hosted inside the continental US
plus if microsoft can get them to build a datacenter in aus, or get the government to give them huge waivers on taxes/whatever for that datacenter, it will be a win for microsoft

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wiggly Wayne DDS posted:

an argument's brewing over there
https://twitter.com/FiloSottile/status/823669045245321221

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias posted:

Never stop please, these are always interesting

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

ESXi 6.5 gives you a 1 vCPU with 256MB memory and 8GB disk VM if you select XP Pro 32/65-bit as the guest OS.
esxi 5.5 also has an 8GB vm for xp pro 32/64

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
we're implementing a new product that wants us to disable active scanning on a couple folders, and i put some policies into place that would do that. to test it i thought i'd drop in a file with the eicar test string in it and see what sophos did, and it didn't do anything no matter what folder it was in. active scanning reported eicar but that was useless. so instead of a safe little eicar.txt file i have to copy pskill.exe around to test with. gently caress you sophos

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anthonypants posted:

we're implementing a new product that wants us to disable active scanning on a couple folders, and i put some policies into place that would do that. to test it i thought i'd drop in a file with the eicar test string in it and see what sophos did, and it didn't do anything no matter what folder it was in. active scanning reported eicar but that was useless. so instead of a safe little eicar.txt file i have to copy pskill.exe around to test with. gently caress you sophos
User: DOMAIN\user
Scan: Right-Click Scan
Machine: WP-NTBK-0003

File "C:\Users\user\Downloads\eicar.txt" belongs to virus/spyware 'EICAR-AV-Test'.

Registry value "HKU\S-1-5-21-2084071808-2144819180-1538882281-4090\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet" belongs to virus/spyware 'EICAR-AV-Test'.

Virus/spyware 'EICAR-AV-Test' has been detected.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/dogboner/status/824355598565330944

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Shaggar posted:

lol. like you had any recourse against the government when it was "illegal"
shaggar is right

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

anthonypants posted:

gonna be a cold four years talking about secfucks without being able to mention us policy ever

  • Locked thread