Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

geonetix posted:

in other news i just bought some domain names that make sense to me, any ideas how to get internet rich out of this?

you can make :10bux: an install pushing fake video codec updaters on your visitors

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
if you can pretend to be a female popstar and not melt down on twitter about once a month there's a vacancy going

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Avenging_Mikon posted:

I wanna come back to this because I would like to know, what's the best way to handle something like this (user generated urls that you don't get to know in advance)? I get wildcard certs are bad and evil, but is the only other options really "URL gets submitted to you, and you manually update relevant certs"?

doesnt have to be manual. you can automate the process of getting a cert from LE and pushing it to whatever handles your tls termination in under a minute

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Lain Iwakura posted:

code:
15:44 < user1> company doing pentest on us is pissed at us.. one of our engineers uploaded
                their 0day exploit to virustotal and MSFT picked it up and tweeted about it
15:45 < user2> lmao
15:46 < user3> hahahahaha rekt.
15:46 < user4> Oops
15:46 < user4> Where's the tweet?
15:46 < user3> Of all the poo poo ways to burn an 0day.
15:46 < user3> That's probably the worst
15:49 < user1> [link to tweet]
15:49 < user1> MSFT picked it up from virustotal
15:49 < user1> and tweeted about it.. all in a span of about 25 minutes
https://twitter.com/JohnLaTwC/status/883057609023959040

What's "0 day" about this, it looks like some run of the mill macro poo poo

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
nought-day

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
someone probably tried to turn on strict origin cert CN validation in cloudflare

https://crt.sh/?id=168610427

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
fair enough. richard wont get very far with that one though

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
yeah fb can't do normal totp without a phone any more, i got caught out by this recently, it's lame

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

yeah it disables itself when you remove your phone number

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Thanks Ants posted:

you can disable facebook sms



huh mine has the disable button but when i click it:

Only registered members can see post attachments!

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
public transport apps are pretty lovely in my experience

last year i reverse engineered the one used by a ton of different companies here and someone less honest than me could theoretically have been using a fake app ever since without anyone realising

https://twitter.com/hilare_belloc/status/715585400933392384

https://twitter.com/hilare_belloc/status/715586306986917888

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

maskenfreiheit posted:

so I'm at Defcon.

got decent 4g coverage for first time this weekend so doing a little shitposting

Well i'm bored in vegas, got no plans till an early dinner meetup tonight and already got my defcon badge so i will answer questions till my mifi is nearly out of batteries


to be clear, jello, you insipid loving backwoods redneck moron, i banned business catte because i had people at work being tracked down to be asked questions about me by the yospos irc sewing circle and frankly i didn't need that much internet in my real life. i still don't, so i'll ban this account too when my batteries get low and you can go back to being constantly wrong for another year. you kids proved that you aren't capable of being even vaguely grownup about people being honest in here about who they are or what they do, so i can't leave the two connected


btw i'm not answering anything about work that is either obvious trolling or over the line with poo poo i shouldn't/can't talk about, or poo poo i just don't feel like answering, but other than that let er rip

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

are you kidding me with this poo poo

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

spankmeister posted:

A straight religious clothing ban would be discrimination, can't have that of course

tell it to french workers in public-serving roles

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
algo is pretty nice but
- the strongswan network-manager applet for linux doesnt support split tunnelling so it breaks connectivity to your lan
- if you use pppoe or something then you might have to gently caress with your mtu to get it to work properly

openvpn otoh works fine and is pretty easy to set up

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
grsecurity are suing bruce perens for writing this

https://perens.com/blog/2017/06/28/warning-grsecurity-potential-contributory-infringement-risk-for-customers/

filing here https://regmedia.co.uk/2017/08/03/grc_lawsuit.pdf

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
certified kali linux child

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Lain Iwakura posted:

if you want to attack tor, just start memory dumping the tor daemon while you're acting as an hsdir

you're conflating attacks on end users with attacks on onion services

with the way hidden service descriptors currently work you can, at best, knock them offline (this is fixed in prop 224)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

yoloer420 posted:

Did anyone here implement the malicious hsdir thing for tor hidden service discovery? I'd appreciate any info you might have, does it still work etc?

read this https://donncha.is/2013/05/trawling-tor-hidden-services/

it still works in the current stable version of tor

prop224 fixes the problem and initial support for this is included in 0.3.2.1-alpha, released earlier this week

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Subjunctive posted:

you encrypt, not sign.

same difference

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Volmarias posted:

No but now I'd like to know more

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

infernal machines posted:

so how long ago did she open it?

rack em

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
cant believe glenn greenwald replaced morgan m-b with 2 brazilian orphans

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

there's a similar thing in the UK, but it's even worse because it's used for payments

the four uk mobile phone operators have conspired with the 12 companies listed here http://www.payforit.org/api/ to provide a one-click "charge it to my phone" service

this has two parts:

- "header enrichment", in which the telco intercepts traffic destined for the partner payment processors, and injects the visitor's mobile phone number into the http headers. that's the theory anyway. they also sometimes gently caress up and inject it into every request to every website https://nakedsecurity.sophos.com/2012/01/25/smartphone-website-telephone-number/

- a private api which the payment processors can use to put a charge on a phone bill, given a phone number and amount. they are supposed to only issue charges through this api when the phone owner has given them explicit permission to do so

however at least one of the companies (txtnation) has/had a bug in their code that lets retailers circumvent the "are you sure" payment confirmation. as recently as last year, this was being exploited in the wild via rogue ads to hit people with charges without any confirmation

when a payment goes through, your mobile phone operator sends an sms receipt. there are two problems with this:
- it looks scammy as gently caress and people will likely not understand the message and ignore it
- if you can't receive sms's - e.g. if you're using a mobile internet dongle on a laptop - you never see the sms so you don't even know you've been hit. (because the header enrichment occurs on the upstream network, this scam can be triggered through normal desktop browsing too, you don't have to be using a mobile phone just the mobile phone network)

in summary mobile phone operators are loving scum

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
exactly, he's being sarcastic

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
halifax is part of lloyds banking group, they all use the same website with different branding (as do bank of scotland)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Powaqoatse posted:

im saying maybe "fighting words" dont have to be in person

you wanna take this outside buddy

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
the long tweets are just links that didnt get an <a href> put round them when displayed for whatever reason. hidden somewhere in the middle of one was ".cc/"

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

minato posted:

I don't know if this counts as a security fuckup, but I was talking to an Uber engineer today who told me a couple of interesting scams they encountered the past couple of years.

Apparently Uber got heavily scammed in China by people exploiting the subsidies used to incentivize drivers to cruise around waiting for fares.

The first scam involved phone emulators and fake GPS units to organize fake trips. When scammers tried to parallelize the system with multiple fake driver accounts, Uber caught on when they saw "snakes" of cars moving around the map.

The second scam involved the drivers deliberately putting up scary profile pictures, making the driver look like a vampire or a ghost. The hope was that the customer would be so put off that they'd cancel the ride before pickup, which would give the driver a few yuan as compensation for the cancelled ride. Uber had to implement a facial recognition system that ensured profile pictures closely matched their owner.

edit:

razor and blade spotted

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
imagine i photoshopped the uber app onto that screen

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Main Paineframe posted:

and every site that did that kind of thing got banned from the Twitter API

they went further, and looked up all the api keys created by the same person as the offending one, then looked at the accounts using those keys to tweet

i had a couple of private accounts with 0 followers keeping tabs on people's deleted tweets and they got shut down at the same time as a big public one i ran

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
nothing but the streaming api gives you notifications about deleted tweets (their ID only, not the text itself) in real time which is very appealing

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
yeah level3 leaked more specific versions of prefixes belonging to comcast and got overwhelmed

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

flakeloaf posted:

and facebook can't let people hash teh photos themselves and just send them the hashes becaaaaaaaaaause

Midjack posted:

someone in the bubble thread had the idea to scrape reddit and 4chan for memes and upload them to get hashed and added to the banlist

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
the russians? they used a pencil.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
classic Mr Hands

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Subjunctive posted:

the document on this phenomenon is likely even findable from Edge

you got a link to this doc please

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

cheese-cube posted:

wtf?

https://twitter.com/taviso/status/941710362717470720

apparently microsoft are bundling a vulnerable version of keeper with win10 because...?

good to know that Keeper made the same mistake as that guy in sh/sc who wrote his own password manager that runs its js in the context of the page youre trying to log into

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

hobbesmaster posted:

linus probably saw one too many “root access allows you to run arbitrary commands” vulns and blew up at them

can’t blame him tbh, maintaining the kernel must be painful

whats painful is that hes too pigheaded to hire spender so instead gets people to reimplement his work, poorly

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Inexplicable Humblebrag posted:

genuine asking-from-ignorance question - what should they be doing?

Cocoa Crispies posted:

there's no generally cross-browser-compatible way

https://caniuse.com/#feat=getrandomvalues

  • Locked thread