Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Trabandiumium posted:

3 pages short of 219 my dude
rip

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
congratulations on finally breaking that $25k barrier, you made it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

wife just linked me this:



brilliant :allears:
:five:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

if you can pretend to be a female popstar and not melt down on twitter about once a month there's a vacancy going
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
is the secfuck thread going to get gassed or shutdown for too much off-topic posting already? it's just barely on page 3

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

maskenfreiheit posted:

so i heard defcon is cancelled
ok

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
"three weeks ago tavis said a dll had never been fuzzed. we asked microsoft and they said they used fuzzing." great work

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

WAR DOGS OF SOCHI posted:

does anyone here have a good sec twitter list they can point me to? i'd really appreciate it, because left to my own devices i'd probably end up with dudes like thrurrott on my list and my pants on my head.
@thegrugq is the first one who comes to mind, just follow good people and you'll find them

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
five pages, a new record

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

syscall girl posted:

we can do it!


i attempted to re-open infernal machine's opsec thread to vent political nonsense here

https://forums.somethingawful.com/showthread.php?threadid=3825132
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lain Iwakura posted:

i'm so glad that this is the library thread. i totally misread the title when i clicked on it i guess
imho it was a pretty good troll to close the secfuck thread before it could get to page 219 and then replace it with a library thread

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
oops https://www.washingtonpost.com/news/the-switch/wp/2017/06/28/fedex-delivery-unit-hit-by-worldwide-cyberattack/

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pseudorandom name posted:

does ExPetr actually rely on ETERNALBLUE or did the Russians just throw that in there to blame the NSA?
it is allegedly one of the transmission vectors but it also uses psexec so

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Meat Beat Agent posted:

i bet that dude will WannaCry after he gets fired lol
:thurman:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

the supported cipher list from a major industrial controls vendor's monitoring and remote access platform:

TLS_RSA_WITH_NULL_MD5 (0x1) INSECURE 0
TLS_RSA_WITH_NULL_SHA (0x2) INSECURE 0
TLS_ECDHE_RSA_WITH_NULL_SHA (0xc010) ECDH sect571r1 (eq. 15360 bits RSA) FS INSECURE 0
TLS_ECDH_anon_WITH_NULL_SHA (0xc015) INSECURE 0
TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8) INSECURE 40
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14) DH 512 bits FS INSECURE 40
TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA (0x19) INSECURE 40
TLS_RSA_WITH_DES_CBC_SHA (0x9) INSECURE 56
TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15) DH 1024 bits FS INSECURE 56
TLS_DH_anon_WITH_DES_CBC_SHA (0x1a) INSECURE 56
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) WEAK 112
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16) DH 1024 bits FS WEAK 112
TLS_DH_anon_WITH_3DES_EDE_CBC_SHA (0x1b) INSECURE 112
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (0xc012) ECDH sect571r1 (eq. 15360 bits RSA) FS WEAK 112
TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA (0xc017) INSECURE 112
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) DH 1024 bits FS WEAK 128
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) ECDH sect571r1 (eq. 15360 bits RSA) FS 128
TLS_DH_anon_WITH_AES_128_CBC_SHA (0x34) INSECURE 128
TLS_ECDH_anon_WITH_AES_128_CBC_SHA (0xc018) INSECURE 128
whoof

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
part of me believes that there's got to be some off-by-one error going on there, i just don't want to believe someone configured that intentionally

can you tell us what kind of server it is? iis on windows, apache on linux, etc.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

MononcQc posted:

and here I am with a work computer that has cylance running on it, which just loves to randomly decide vim or scp are viruses and quarantines them
it is my understanding that this is how cylance works

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

Microsoft should go the apple route and only execute signed code without a prompt and force some kind of manual intervention for anything unsigned
this would simultaneously own so hard and destroy any business-line applications. a win-win

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
one of our dbas is having trouble browsing to a network share presented by our backup appliance from his workstation and my first guess is that it's using smbv1. this should be good.

e: slightly disappointed that wasn't it. welp

anthonypants fucked around with this message at 19:17 on Jun 30, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cis autodrag posted:

you contradict yourself :v:
if it didn't work then it wouldn't be quarantining executables, now would it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
a good blog, and the "things i won't work with" is just a section of it

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Midjack posted:

some of the senile flag officers and senior executives of the defense and intelligence organizations think "information operations" has to do with propaganda and "cyber operations" is very definitely computers so it's really more of an anti age-discrimination thing
holy poo poo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cinci zoo sniper posted:

"once" :laffo: oh you sweet summer child

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

fortinet apparently give zero fucks about their gear appearing in that vid

https://twitter.com/Fortinet/status/882620985874173952

e: actually it's dumb piss who cares
actually it's deleted so maybe they do care

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
one of our dbas recently stopped being able to navigate to the backup appliance from his desktop using the cifs shares. turns out the backup appliance, using firmware from december 2016, only supports smbv1. boss tests this out on his laptop by re-enabling smbv1, and is now in the process of re-enabling smbv1 on the dba's and other workstations. maybe we'll update the firmware on our backup appliance next week :iiam:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Rufus Ping posted:

doesnt have to be manual. you can automate the process of getting a cert from LE and pushing it to whatever handles your tls termination in under a minute
i know what that's supposed to be but i can't help reading it as Law Enforcement

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/taviso/status/883070732573392897 :f5:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i think it's going to be another ms defender exploit

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if you're doing a pentest how do you expect to be able to stop your client from uploading suspicious poo poo to virustotal or whatever

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ratbert90 posted:

Hey, these are actually really neat! Do you mind also handling libressl as well? Thanks!
i'm fairly certain that it uses the same ciphers as openssl

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

mrmcd posted:

sms_is_not_secure_2fa_part1000000.txt
well paypal doesn't have any other type of 2fa, are you saying people should just stop using paypal???????

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i've only ever pronounced and heard it pronounced zero-day in real life, maybe actual scene hackers pronounce it differently but who cares

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

did anyone else notice SA was down for two hours due to a bad SSL certificate
i only noticed for like an hour, yes

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

FAT32 SHAMER posted:

I like how the pentesters are popping out of the woodwork to diss a guy for calling their job a relatively large scam
i don't know who this mister manuts thinks he is, but i bet his employer won't appreciate his tone when they find out

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

hackbunny posted:

is that seriously the thing that worries you the most in "my phone provider reassigned my phone number to someone else"
apparently he got his carrier to admit that someone had been trying to access his account over the phone, failed a ton, but eventually got a csr to bypass their checks

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md google's going to get their fork of openssl (or part of it) fips 140-2 certified

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

maskenfreiheit posted:

Speaking of certificate errors:

what's firefox complaining about

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

isn't that happening for many millions of users in China?
lol

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

wolrah posted:

The first hardware 2FA token I ever had was for PayPal. Are you saying they stopped offering this or even the smartphone-based varieties?
he says in his blogpost that paypal only supports 2fa over sms, and agrees that sms 2fa is garbage

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Chris Knight posted:

top of the pops 2fa? so you have to mime playing an instrument? :P
no they're saying that paypalxsms is the true otp (totp)

  • Locked thread