Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

fisting by many posted:

krebs released his big expose on the mirai author

https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/

it's minecraft and anime all the way down

yeah been reading this, it's a lot of words even for krebs

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
They make L3 switches which are technically routers I suppose but we're splitting hairs here.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
i'm DJGPP

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

A Man With A Plan posted:

Cool, just wanted to make sure. My secfuck of the day was some idiot sending possibly the worst phishing attempt I've ever seen to my entire alma mater. Looked like

code:
From: "Dr. University President" <studentname@otherUniversity.edu>
To : "Me" <me@myUniversity.edu>

Dear members of the university,

Please see my attached statement.
<president_statement.pdf>

Sincerely,
Dr. President
Office of the President
The person apparently used their own university email to send out the phishing emails. I wonder how lenient the courts will be.

Probably their account got hijacked because of easy to guess credentials. University email accounts are a popular target for spammers and scammers.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

OSI bean dip posted:

i was going to make a joke about conscription coming to cyberwar but it's already a thing

We already have "cyber reservists" here.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

ate all the Oreos posted:

nah he lives in the netherlands

Which university?

if it's a proper uni they should have internet via the Dutch NREN and those guys have proper DDoS mitigation.

So he's probably at a poo poo-tier one.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Cocoa Crispies posted:

even then DDoS mitigation can be predicated on the backend actually being able to handle things

like if it's a slow rear end J2EE poo poo with lots of remote stuff and talking to something slow like oracle or mysql you don't need to D your DoS between more than like six attackers that send HTTPS requests

Yeah an L7 attack could work but they have stuff to deal with that as well.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Shaggar posted:

part of me wishes the US would standardize national identity management, but the other part knows they'd just gently caress it up horribly.

the us can't do poo poo like that it'd get bogged down by politics and terrible contractors

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Also while Azure AD would be a decent choice, price concerns notwithstanding, Australian citizens might object to hosting their PII in the US or on systems possibly controlled by a US company under the Patriot Act.

Although Australia being a FVEY member that might be less of an issue.

e: I know the average EU citizen would probably flip their poo poo about hosting their government PII in the US. (Even though most of them share everything anyway through social media.)

spankmeister fucked around with this message at 18:07 on Jan 23, 2017

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Yeah for all my governments failings they do have actual standards and laws and stuff for storing and processing data.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Chalks posted:

Yeah, but they have azure datacenters in the EU so that we don't need to worry about that so much.

Apparently they have two datacenters in Australia as well from looking at their regions list.

Depending on your interpretation of the Patriot Act, the US government could compel Microsoft to hand over data stored in foreign countries.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

hackbunny posted:

and remember, you heard it first here: it's a Dead Gay Forums Exclusive™ - Where Your :10bux: Count

:swoon:

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Automated malware analysis sandboxen often used small disks and XP so it sort of makes sense.

I'd say the malware author is up on the state of the art of malware analysis from a couple of years ago.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
All I can find so far is a Romanian company that goes by that name, not a Singaporean one.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

cheese-cube posted:

maybe it's these dinguses only without the owners knowledge http://www.globalsystem-sg.com/? their site is either a honey pot or it's already been completely compromised (massive surface area including mysql and VNC, looks like a server 2k3 box exposed completely to the net without fw). also their "mail server" mail.globalsystem-sg.com is equally exposed.

funny thing i'm p sure i saw their logo around pioneer shipyard in SG last time i was there

Ah yeah maybe! My idea was to look in the singaporean chamber of commerce but their web sight seems broken.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
There's some good stuff in the Mirai source code:

code:
                table_unlock_val(TABLE_KILLER_ANIME);
                // If path contains ".anime" kill.
                if (util_stristr(realpath, rp_len - 1, table_retrieve_val(TABLE_KILLER_ANIME, NULL)) != -1)
                {
                    unlink(realpath);
                    kill(pid, 9);
                }
                table_lock_val(TABLE_KILLER_ANIME);
Seems that Mirai was a variant of killallnerds.exe all along.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Security Fuckup Megathread - v13.2 - Naive, I know, but at least I can play my video games.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

OSI bean dip posted:

pls do not d&d this thread

it's not d&d it's just alternative secfucks

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
you just downloaded a bunch of malware good job

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

the latest innovation in wizardsecurity: just use regular locks

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
PC LOAD A4

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Midjack posted:

this is almost always the right answer. electronic locks are always expensive, complex, and lovely; the only reason to use them is a massive facility with huge turnover, like a hotel where you can replace a lost magnetic key for a nickel and don't have to touch the door to invalidate the old one rather than pay $25 to install a new cylinder

I agree but you have to appreciate the irony and sheer ridiculousness of the fact that using regular old door locks is considered "innovative"

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

I didn't know tcpdump was an adobe product.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Jabor posted:

I'm still not sure why people habitually use -f when deleting stuff.

Because it complains about directories otherwise.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Powaqoatse posted:

uh thats the -r

-f is force

learn 2 linux


smdh

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Cybernetic Vermin posted:

encountering systems now and then where rm has been aliased to rm -i, end up just doing -f every time rather than bothering to discover that. meaning to delete a non-writeable file is far more common than being actually warded away from deleting one. not that clear what *not* having -f ever gives you, for example in this case i imagine they could have deleted the database just fine without it

Yeah that's it p much. A lot of distros have rm aliased to rm -i

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Cryptkeeper go p p

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

ate all the Oreos posted:

that's actually what i'm tasked with implementing but i'm not going to do it by loading an external website through a weird proprietary browser

bonus:

after going through their documentation it seems the wifi/ethernet versions of this printer have a telnet server enabled by default with a root password of "public"

also to connect to it the first time you "set a temporary IP address" which apparently means loving with your ARP table and then pinging it


i mean i guess that works but... :psyduck:

Haha that gives me flashbacks of setting up ST microconnects, you had to do the same thing.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Fix the netcode pls my mario party games always desync.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
I wonder if an old star LC-20 or w/e would still work on win 10

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Ah good it hit international media, shame about the Wilders pic though.


Wilders is gonna Make The Netherlands Great Again

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
"Dutch officials are already on alert for signs of possible cyber hacking "



CYBER


HACKING

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

ate all the Oreos posted:

why is the Netherlands apparently filled with Hunger Games people



Wilders is Trump lite. He has weird hair hangups too lmao

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

CommunistPancake posted:

I assume it says something like "industry standard encryption," so that means they can get away with 3DES.

Which would be dumb, but not completely terrible.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
At least this guy prints out harmless messages instead of weev and his nazi propaganda.

spankmeister fucked around with this message at 12:59 on Feb 5, 2017

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Capcom probably hosed up the implementation of the DRM and now denuvo is getting the bad press lol

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
I built an TRNG based on nuclear decay and the thing with natural sources of entropy is that they're either very slow, or it's fast but the quality of randomness isn't very good. Both things are solvable with seeding a CSPRNG with the output of a TRNG. This is how most of these devices are implemented.

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

Meat Beat Agent posted:

universal serial butt

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!
Stop making GBS threads this thread up with D&D'ing

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008
Probation
Can't post for 8 hours!

power botton posted:

the weakest part of AD is all the servers and desktops storing kerberos tickets and hashes in memory to get retrieved with mimikatz et al, but MS keeps adding new features to minimize that. the chance of your average Fortune 500/1000 enabling them is nonexistent but hey.

the adsecurity.org guy cares way too much about AD security and has easy to read and well cited articles if you want to read more.

don't post shaggar's blog


Hah the shaggar wishes he would be that good

  • Locked thread