Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
jre
Sep 2, 2011

To the cloud ?



http://www.bbc.co.uk/news/technology-38415067

quote:

Security firms have launched routers at CES that can stop smart household gadgets being hijacked by hackers.
Symantec, BitDefender and Intel unveiled devices that scrutinise data as it flows across home networks.
The companies say routers with built-in defences will be essential as homes are filled with net-connected gadgets.
The routers also come with parental control features that help manage how much time children spend online and what they see.
Home invasion
"You will have to buy a security solution for your internet-of-things," said Alex Balan, chief security researcher at BitDefender.

quote:

"You will have to buy a security solution for your internet-of-things," said Alex Balan, chief security researcher at BitDefender.

quote:

"You will have to buy a security solution for your internet-of-things,"

quote:

"You will have to buy a security solution for your internet-of-things,"

quote:

"You will have to buy a security solution for your internet-of-things,"

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?



https://www.theguardian.com/world/2017/jan/06/russian-hacker-putin-election-alisa-shevchenko

quote:

Young Russian denies she aided election hackers: ‘I never work with douchebags’
White House claims Alisa Shevchenko was involved in hacking the US election but in an interview she says authorities misinterpreted facts or were fooled

She said she dropped out of three different universities, as she was passionate about learning but did not enjoy the structure of a university course. Around 2004, she joined Kaspersky Lab, a high-profile Russian cybersecurity firm.

She left to set up her own company, initially called Esage Lab (“I was thinking of something ‘sage’, as in a wizard or a magician,” she said). Later, she changed its name to ZOR.

im_zor.gif

jre
Sep 2, 2011

To the cloud ?



ohgodwhat posted:

Relatively tame but this guy's not off to a good start:
http://security.stackexchange.com/questions/147216/hacker-used-picture-upload-to-get-php-code-into-my-site

Roughly, "I don't know how this hacker is getting PHP files past my client side validation!"

quote:


I can tell that the picture upload box was definitely the problem based on the file name of the PHP code that was uploaded. Example, I ended up with logo1234567.php (tells me it's coming from the File Upload box that handles logo pics When I store data from edit boxes, I use all three of PHP's functions to clean it:
code:
$cleanedName = strip_tags($_POST[name]); // Remove HTML tags 
$cleanedName = htmlspecialchars($cleanedName); // Allow special chars, but store them safely. 
$cleanedName = mysqli_real_escape_string($connectionName, $cleanedName);

:discourse:

jre
Sep 2, 2011

To the cloud ?



negromancer posted:

that's why you use mobaxterm on windows and stop using putty and winscp like it's 2004.

gently caress, that looks good. How long has that existed ?

jre
Sep 2, 2011

To the cloud ?



Wheany posted:

that does look good, but i don't feel like paying over $50 per year(?) to replace putty (and to a lesser extent, winscp)

If you are using this professionally why would you even blink at $50 for something that will improve your productivity

jre
Sep 2, 2011

To the cloud ?




:eyepop: well that escalated quickly

zen death robot posted:

Here's the rub. While I might be able to do it, I do not feel comfortable in doing so because that's not my area of expertise.

Absolutely the correct answer.

jre
Sep 2, 2011

To the cloud ?



Number19 posted:

yossec: who's a good ssl cert vendor in 2017? let's encrypt won't work for this. I've had a recommendation for alphassl but i want to see who else is decent these days. i need a wildcard cert for part of the project.

Go to name cheap and pick the vendor of your choice


edit: They only do comodo now, arse.

jre fucked around with this message at 20:22 on Jan 11, 2017

jre
Sep 2, 2011

To the cloud ?



mod saas posted:

test korea best korea

jre
Sep 2, 2011

To the cloud ?



pixaal posted:

Ticket phone call email all came in at the same time.

Someone is quitting in style:
All printed items now show the company name as WE SUCK DICKS 8====D

The "all users" permissions in our ERP software for some reason includes the ability to edit the company name. My favorite part is logging is disabled since everything already logs a username next to it so it just doubles up on everything (but a few functions that don't). Last time it was enabled it crippled the old server. Maybe my request to test logging on the new hardware will be approved.

We have hundreds of custom permission groups with tons of overlap and most people are members of 50+. I'm going to have to audit every one of these next week now. Which is also something I said should be done and have never been given time to do!

jre
Sep 2, 2011

To the cloud ?



Fuzzy Mammal posted:

it may be happening

What was the background to this again, Symantec issuing certs for google domains ?

jre
Sep 2, 2011

To the cloud ?



Bonfire Lit posted:

misissued certs for test.com and example.com (and some other certs/precerts that contain obviously bogus data)

again

Oh, test korea best korea. Cool :suspense:

jre
Sep 2, 2011

To the cloud ?



apseudonym posted:

I dont understand how that thread is so good at bringing out weird views on security.

Honeypot

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

dipshit greys do not last long in here hth


uncurable mlady posted:

i see this is your first eripsa encounter then

jre
Sep 2, 2011

To the cloud ?



flosofl posted:

Jesus, shut the gently caress up. You're gonna get the thread closed. Go to D&D and masturbate about laws and civil resistance there.

Oh no! off topic posts, in yospos ? aaaaaaaah !

jre
Sep 2, 2011

To the cloud ?




Jesus christ this guy is a menace :stare:

jre
Sep 2, 2011

To the cloud ?



ratbert90 posted:

Today in non-sec fuckups I made a tool that chunks through all of the packages in Buildroot and if it's hosted on GitHub or PyPI it checks to see if there's an update and if so auto-generates a patch to submit to the Buildroot team.

Almost 60% of the python libraries were out of date.
40% of those were out of date by more than 2 major revision numbers.

Lol that's obnoxious and they will kill you if actually run it

jre
Sep 2, 2011

To the cloud ?



ratbert90 posted:

Oh I talked to the maintainers and they were all for it. 58 patches submitted!

This is totally retarded and will almost certainly break stuff. How did you check that bumping libraries major versions hasn't broken functionality ?
There are already tools (e.g. https://snyk.io , https://pypi.python.org/pypi/dependency-check/ ) which scan your dependancies for known vulnerabilities so you can limit the updates to things that actually matter.

jre fucked around with this message at 22:20 on Feb 19, 2017

jre
Sep 2, 2011

To the cloud ?



ratbert90 posted:

I actually scanned the dependencies if there was a dependencies.txt, I tried to import the module as well, and then if there was example code I tried to run that.

Out of the 58 patches, 3 were broken as far as I could tell.


I am embedded, this is just a side project for fun. :)


quote:

As far as I could tell ...

Hey I've just changed 58 dependancies without reading the change logs for those dependancies. I've done no meaningful tests so gently caress knows if this breaks the app, I've also not profiled what the effect of new versions on mem / cpu / io is. Nor did I actually check for advisories so the new versions are just as likely as the old to have horrible vulnerabilities in them.

What do you mean your taking away my push privs ?

jre
Sep 2, 2011

To the cloud ?




I was staring at that for ages going, what's wrong with a minimum of 8 chars, mix of caps , small and numbers?


:psyduck: wtf ?

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

It doesn't matter to me if you're "rich", you're as white as many other posters in this thread and unlike many people who are not white, you've had the ability to get a degree that enabled you to teach at two post-secondary institutions. Like many other white males such as yourself, you've also attempted to go into business in a white male-dominated field--we're talking about your failed cryptocurrency nonsense.

Now as a white male, you're trying to impose a social order that again will make white males such as yourself have a privileged position. How can someone who makes minimum wage who is just as likely to not be a white male like yourself be able to afford an 8x8 grid of "EMV chips" (again something you have failed to explain) when they cost an exorbitant amount of money that they're unlikely to be able to put aside?

quote:

Sorry for bursting your tender white male bubble, Eripsa, but no matter what you say you're as white as they come. I'm Irish and by that definition I am not technically "white" but guess what? I am and so are you. Where you were raised, what level of education your parents have, or where you were born are completely irrelevant to me. You have the privilege of being white and just like most people with attitudes like yours, you don't understand it.

You're white.


I enjoyed the posts where you told the hispanic guy that he wasn't dark enough to be an ethnic minority, that was good. I'm surprised you didn't quote these brutal owns yourself.

jre
Sep 2, 2011

To the cloud ?



Wiggly Wayne DDS posted:

we've been trying to get osi to stop posting for years to no effect

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

I regret that post and I acknowledged in the thread it was wrong of me

Cool, can we go back to laughing at sec fucks and not have to wade through you quoting your own dick waving posts from else where in the forums ?

jre
Sep 2, 2011

To the cloud ?




owns owns owns

jre
Sep 2, 2011

To the cloud ?



Wiggly Wayne DDS posted:

cloudflare reverse proxies are dumping uninitialized memory: https://bugs.chromium.org/p/project-zero/issues/detail?id=1139

loving hell :stare:

quote:

We fetched a few live samples, and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users. Once we understood what we were seeing and the implications, we immediately stopped and contacted cloudflare security.

jre
Sep 2, 2011

To the cloud ?



anthonypants posted:

Needless to say, this did not convey to me that they take the program seriously.


Savage

jre
Sep 2, 2011

To the cloud ?




While claiming a 3 month average is taking the piss a bit, they are correct that the speed with which they fixed this and deployed to massive infra is impressive.

jre
Sep 2, 2011

To the cloud ?




gently caress, outdone :magical:

jre
Sep 2, 2011

To the cloud ?




I think you're being trolled.

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

it's hard to tell really

:smith:

jre
Sep 2, 2011

To the cloud ?



sarehu posted:

It's very easy to test my hypothesis. Take my 8 characters-and-less passwords on websites I use (they go down to 6), count how many times my accounts have been lost from the password being hacked, and compare the results with your however-long passwords that make you feel secure.

I've never lost any account to somebody brute forcing my password over the wire. Or from anybody getting the password database and cracking it offline. That would be doable, but there's minimal harm that could be done on any service for which that could be accomplished.
:suicide:

jre
Sep 2, 2011

To the cloud ?



ate poo poo on live tv posted:

*millions of dollars in lost revenue for customers*


If you are only in 1 region and being down for 10 hours costs you significant money you're the fuckup

jre
Sep 2, 2011

To the cloud ?



Truga posted:

the s in iot stands for security

jre
Sep 2, 2011

To the cloud ?



Zero One posted:

I have a login for a top-5 global bank that allows me to process international funds transfers (on behalf of my clients) worth millions of dollars.

It has 2FA which is in the form of a little authenticator with a keypad they mailed to me. I log into their website and then it prompts me to enter an 8 number challenge code into the device. It then gives me an alpha-numeric response to type into the website. Then I have a personal password.

Over the past few months I've discovered the website re-uses challenge codes. And not just like the same one after 60 days... I will often get the same code several times a week. There appear to be a max of 10 codes or so. Then the authenticator will give the same response to the same challenge code. It isn't salted based on the time or date or anything.

This has resulted in me memorizing the codes (I login and out multiple times a day) so I don't need to use the authenticator anymore.

Depressing but not surprising

jre
Sep 2, 2011

To the cloud ?



OSI bean dip posted:

browse the site from tor:



:allears: legit amazing

What ya gonna do, when the austrian police come from you ?

jre
Sep 2, 2011

To the cloud ?




jesus gently caress :stare:

jre
Sep 2, 2011

To the cloud ?



They made an ssh -> tcp -> cache noise protocol
:vince:


quote:

Even in the presence of extraordinarily high system activity, we can maintain a transmission rate between 34.27 KBps and 45.09 KBps with an error rate of 0% on Amazon EC2 virtual machines, which is three orders of magnitude higher than previous covert channels on Amazon EC2. Based on this error-free covert channel, we built the first implementation of TCP through a cache covert channel. We verified the practical applicability of our error- free TCP connection by tunneling SSH and telnet connections reliably between two colocated Amazon EC2 virtual machine

jre fucked around with this message at 22:48 on Mar 30, 2017

jre
Sep 2, 2011

To the cloud ?



and I just can't hide it

jre
Sep 2, 2011

To the cloud ?



CRIP EATIN BREAD posted:

oh jesus the IP to that thing is in one of the videos.

:suspense:

jre
Sep 2, 2011

To the cloud ?



apseudonym posted:

Its not janky :colbert:

It's non existent

Adbot
ADBOT LOVES YOU

jre
Sep 2, 2011

To the cloud ?




Oh have they finally fixed the problem of 99.9% of android devices never getting an update security or otherwise once they leave the factory ?
I must have missed that.

  • Locked thread