Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
negromancer
Aug 20, 2014

by FactsAreUseless
Those new Chromebook Pros might be nice to throw Kali onto as a quick laptop to do some wireless pen testing and whatnot when I don't feel like carrying a MBP.

Adbot
ADBOT LOVES YOU

negromancer
Aug 20, 2014

by FactsAreUseless
So water dispensers, huh

https://twitter.com/find_evil/status/816846566799470593?s=01

negromancer
Aug 20, 2014

by FactsAreUseless

Achmed Jones posted:

I'm a founding member of my company's new security team. A week ago, I was a hobbyist with an OSCP certification. We're starting on risk assessment, prioritization, and all that, but I'd love any links y'all might have (or books to read) that'll help us out.

I don't currently have the link (on mobile and too lazy) but it's called "Security Risk Assessment" and it's a Syngress Press book. It's pretty much my risk assessment Bible for audit stuff and basically what I used to write the closing on what a company needs to focus on and do at 30 days, 90 days, etc based on what was found during the audit.

negromancer
Aug 20, 2014

by FactsAreUseless

Subjunctive posted:

are background checks reliable in Russia anyway?

In Mother Russia, you run in the background towards a check

negromancer
Aug 20, 2014

by FactsAreUseless

reminder that when I met him he told me that I reminded him a lot of himself and wasn't sure how to take that.

negromancer
Aug 20, 2014

by FactsAreUseless

Tayter Swift posted:

Security
Hardware for the
Internet of
Things

:perfect:

negromancer
Aug 20, 2014

by FactsAreUseless

Wheany posted:

our tester was trying to connect to a server with winscp. it gave a warning about changed fingerprint and posted a screenshot "the new fingerprint is wh:at:ev:er:th:ef:uc:k"

i tried if my connection still worked. it did.

so i tried to find the fingerprint. maybe i'm just dumb, but i just can't find it anywhere in either winscp or putty ui.

putty stores some super loving long hex string in the registry that looks nothing like the one shown in the dialog.

i finally found out the fingerprint by enabling logging in winscp and looking at the log file. it didn't match

screenshot or didn't happen

I believe you I just want to see it

negromancer
Aug 20, 2014

by FactsAreUseless

Wheany posted:

yes, the fingerprint wasn't literally whateverthefuck, i'm not going to transcribe some screenshot for a yospost

the point was that as far as i can tell, there is no way of finding out the saved fingerprint for a given server so that i can compare them

well, with putty you can get some really long hex string from the registry, but its way too long and it's not in the same format as the one in the dialog. (two hex digits, colon, two hex digits, colon etc)

so the warning is "YOUR poo poo MIGHT HAVE BEEN HACKED, check this fingerprint:" and there is no way to get a known-good value from another instance of winscp or putty to compare them.

why have a thought this whole time the fingerprint was stored on your end after the first connect, and you could just compare that to whatever was in some Linux file (its 5am and I'm high).

negromancer
Aug 20, 2014

by FactsAreUseless

uncurable mlady posted:

wait, I'm high, isn't that literally just the pubkey? and the thing that's displayed is the md5 hash?

YES! it's stored in ~/.ssh/authorized_keys I thought?

see, that's why I only run scripts at night, and write them in the daytime. The strength of weed I get from my friend ranges from "nice realizing high" to "I might be in a coma so I'm gonna watch Oceans Eleven on repeat".

negromancer
Aug 20, 2014

by FactsAreUseless

Storysmith posted:

authorized_keys stores client keys for authentication. you're thinking of the known_hosts file, which stores server keys you've connected to, and is implemented as a flat file (that you need to use ssh-keygen to interact with on modern openssh installs because they hash hostnames to make the files less useful for folks who hack a box and pivot)

putty/winscp apparently don't use that mechanism and figuring out an existing stored hash is difficult

I say "apparently" here because I am trusting you people at your word that there isn't some known_hosts file lurking about

that's why you use mobaxterm on windows and stop using putty and winscp like it's 2004.

negromancer
Aug 20, 2014

by FactsAreUseless

Fergus Mac Roich posted:

i use extraputty with awful lua scripts right now. there's even a portable version of this. thank you for pointing out this program and ending my nightmare.

it was pointed out to me in 2013 and a coworker was like "yeah I know about it, but I'm gonna stick to putty, it's reliable, and I've been in sysadmin 14 years, so trust me"

he's still a junior sysadmin at a poo poo tier hosting company, so no, don't trust him. Use Mobaxterm.

jre posted:

gently caress, that looks good. How long has that existed ?

at least 2012.

It's basically having actual Linux on windows. You can run a scary amount of Linux commands on there and sometimes I forget I'm on a windows box.

negromancer
Aug 20, 2014

by FactsAreUseless

Ur Getting Fatter posted:

why do all of these sites about tools to connect securely to your server via SSL refuse to implement https on their loving geocities website?

i love giving out my private keys to .exes i got off some unauthenticated ftp server

Ur Getting Fatter posted:

why do all of these sites about tools to connect securely to your server via SSL refuse to implement https on their loving geocities website?

i love giving out my private keys to .exes i got off some unauthenticated ftp server

not sure what you're referring to.

negromancer
Aug 20, 2014

by FactsAreUseless

Heresiarch posted:

the mobaxterm site is http and their download is http

oh yeah. I don't know when that happened. at one point as far as I can remember it was https, and then when I went back in summer 2016 it was http and I was 🤔

but I had a portable version from like December 2015 that's fine, so I use that.

negromancer
Aug 20, 2014

by FactsAreUseless

jre posted:

If you are using this professionally why would you even blink at $50 for something that will improve your productivity

yep. I don't even notice it (probably because it comes out the same time as Burp Suite and I make sure wherever I work compensates me for using my personal licenses).

negromancer
Aug 20, 2014

by FactsAreUseless

Wheany posted:

i'm not that sure that a better ssh client would improve my productivity very much.

if you don't think mobaxterm isn't leaps and bounds ahead of fuckin putty, I don't know what to tell you.

negromancer
Aug 20, 2014

by FactsAreUseless

OSI bean dip posted:

i dunno about you but i can get mobaxterm's cygwin terminal by installing ubuntu for windows, x11 support by installing xming, and ssh support by either using ubuntu for windows or using kitty, which is a better version of putty (which by default does have an https download)

mobaxterm requires you to pay for more than three ssh sessions

No it doesn't.

negromancer
Aug 20, 2014

by FactsAreUseless
If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

negromancer
Aug 20, 2014

by FactsAreUseless
I have VMs for that there, good sir.

negromancer
Aug 20, 2014

by FactsAreUseless

Wheany posted:

i thought that it meant that you can only have 12 saved sessions, not 12 sessions open at the same time.

that's what it means, but I'm letting him have his fun. I've had more than 20 sessions open at once on the free version before.

Adbot
ADBOT LOVES YOU

negromancer
Aug 20, 2014

by FactsAreUseless

ate all the Oreos posted:

yeah but you had to, like, know what a linux is for that


at work we just bought a 55" TV that is "a giant android tablet" since it runs android and has a capacitive touchscreen and everyone in the office but me thinks it's so cool and amazing and i'm just like "lol it's gonna get ransomware and become a $5000 wall decoration goatse mural"

  • Locked thread