Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Proteus Jones
Feb 28, 2013



Lain Iwakura posted:

code:
15:44 < user1> company doing pentest on us is pissed at us.. one of our engineers uploaded
                their 0day exploit to virustotal and MSFT picked it up and tweeted about it
15:45 < user2> lmao
15:46 < user3> hahahahaha rekt.
15:46 < user4> Oops
15:46 < user4> Where's the tweet?
15:46 < user3> Of all the poo poo ways to burn an 0day.
15:46 < user3> That's probably the worst
15:49 < user1> [link to tweet]
15:49 < user1> MSFT picked it up from virustotal
15:49 < user1> and tweeted about it.. all in a span of about 25 minutes
https://twitter.com/JohnLaTwC/status/883057609023959040

:lol::lol:

https://twitter.com/loneferret/status/883084028546568192

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



Phone posted:

is this an "oh day"?

It's more of an "oh poo poo"

Proteus Jones
Feb 28, 2013



spankmeister posted:

Oh fun fact: the wifi chip in macs is a bcm43xx so it's vulnerable to broadpwn

Wasn't that addressed by the security patch just issued within the last week or so for iOS and macOS?

Proteus Jones
Feb 28, 2013



spankmeister posted:

it was, but i think it's interesting because people focus on mobile devices but it's a lot of aiport devices as well

It is interesting that the same vulnerability could be leveraged across phones, laptops and desktops. That's an intersection you don't see a lot of.

Proteus Jones
Feb 28, 2013



ate all the Oreos posted:

*squints and examines carefully to try and find anyone who isn't a dude*

maybe that blob of blond hair in the center left? or maybe in the right-foreground, though i kinda think that looks more like a guy with long, pretty hair

I think I found the unicorn (that was like a horrifying game of Where's Waldo)

Proteus Jones
Feb 28, 2013



ate all the Oreos posted:

for some reason all the cultist christian ones i've found were for small amounts like $1

also last time i found one it was actually in a very heavily christian town already so uh good job going out of your way to find new prospects you guys

But those are the wrong kind of christian. Our kind will get raptured, not those other, wrong ones.

Proteus Jones
Feb 28, 2013



spankmeister posted:

Maybe they think he emptied the bitcoins

While in custody?

Proteus Jones
Feb 28, 2013



Phone posted:

popehat's been posting all day?

He was given a 12 hour posting ban, thanks to the slap fight he's having with that Texas lawyer/bigot.

https://www.popehat.com/2017/08/03/how-i-got-barred-from-posting-on-twitter/

Proteus Jones
Feb 28, 2013




I'm getting a real vibe of this guy said something stupid and sarcastic online= and the FBI is taking it at face value.

Proteus Jones
Feb 28, 2013



mdl posted:

let it be known that Wiggly Wayne DDS, authority of good posting, has deemed a massive potential security risk for anyone using a mozilla product or a piece of software that depends on ca-certificates unworthy of discussion in the security thread

:lol::lol::lol:

Proteus Jones
Feb 28, 2013



Volmarias posted:

Are you thinking of Pakistan attempting to null route YouTube

Really there's too many to count.

BGP hijacks will never not be funny.

Proteus Jones
Feb 28, 2013




:drat:

Proteus Jones
Feb 28, 2013




Isn't there some issue with insulin pumps that's being brushed off by the manufacturer as well?

Proteus Jones
Feb 28, 2013



BangersInMyKnickers posted:

This seems like a pretty comprehensive biometric factor the way apple is doing it through they're betting the farm on this not having some kind of trivial exploit that cannot be easily patched with touchid gone

I think the biggest indicator is that it's used to authenticate ApplePay.

I'm not saying there's zero chance of there being an unforeseen weakness, but I'm willing to bet all the low-hanging fruit exploits, like photographs or masks, have been addressed.

Proteus Jones
Feb 28, 2013



flakeloaf posted:

yeah whatever happened to that fangled microsoft webcam technology that was supposed to be able to do this

Probably what happens to a lot of the nifty stuff MS R&D comes up with. When you leave a controlled lab environment, poo poo gets hard to do.

Proteus Jones
Feb 28, 2013



Avenging_Mikon posted:

What if your eye lids have been removed?

Or they use those eye-spreader things to unlock your phone before they bombard you with the Faces of Death series.

Proteus Jones
Feb 28, 2013



Notorious b.s.d. posted:

yeah make sure you tattoo your password underneath your scrote to create a presumption of privacy

That taint a good way to store your password.

Proteus Jones
Feb 28, 2013




Wow

Proteus Jones
Feb 28, 2013



https://twitter.com/me_irl/status/911328527248699392

Proteus Jones
Feb 28, 2013



Shinku ABOOKEN posted:

yes. i pranked a guy stupid enough to have iframes allowed in his vbulletin board by changing my sig to a funny iframe and having some script in the frame request the user control panel to change the user sig to the same iframe.

next day the forum was wiped :xd:

Shinku ABOOKEN posted:

rip geocities.


iframe not a thing until 1997.
Geocities not a thing until 1994.
vBulletin not a thing until 2000.

But yeah, you totally did xss in 1990

EDIT: Had to look it up, but HTML WAS NOT A THING UNTIL 1993 (at least in terms of the first draft of how we know it)

Proteus Jones fucked around with this message at 02:37 on Sep 23, 2017

Proteus Jones
Feb 28, 2013



Shinku ABOOKEN posted:

he said the 90s of which 1997 or whatever belongs. also i am pretty sure vbulletin existed before that.

He said 1990, and not according to wikipedia. It was developed in 1999 and first released in 2000.

OK, misread I get it. I was just like "Wha? WTF is he on about?"

Proteus Jones
Feb 28, 2013




There was a whole bunch of people who are responsible for this, you lying sack. Trying to pin this on ONE person is lovely.

Proteus Jones
Feb 28, 2013




LOL

Proteus Jones
Feb 28, 2013



EssOEss posted:

2015 were different times.

Yes, they are super secure now.

https://twitter.com/EclipsingR/status/917135137971822592

Proteus Jones
Feb 28, 2013



ate all the Oreos posted:

they were emailed the password

Come now, I'm sure they had the standard disclaimer in the footer that if the person wasn't the intended recipient to delete the message. No one disregards those.

Proteus Jones
Feb 28, 2013



http://www.zdnet.com/article/secret-f-35-p-8-c-130-data-stolen-in-australian-defence-contractor-hack/

quote:

In November 2016, the Australian Signals Directorate (ASD) was alerted by a "partner organisation" that an attacker had gained access to the network of a 50-person aerospace engineering firm that subcontracts to the Department of Defence.

Restricted technical information on the F-35 Joint Strike Fighter, the P-8 Poseidon maritime patrol aircraft, the C-130 transport aircraft, the Joint Direct Attack Munition (JDAM) smart bomb kit, and "a few Australian naval vessels" was among the sensitive data stolen from a small Australian defence contractor in 2016.

Proteus Jones
Feb 28, 2013



Well, poo poo; I was going to post that.


quote:

In May credit reporting service Equifax's website was breached by attackers who eventually made off with Social Security numbers, names, and a dizzying amount of other details for some 145.5 million US consumers. For several hours on Wednesday the site was compromised again, this time to deliver fraudulent Adobe Flash updates, which when clicked, infected visitors' computers with adware that was detected by only three of 65 antivirus providers.

Proteus Jones
Feb 28, 2013



hackbunny posted:

I have google authenticator on my iphone :confused:

1Password will also generate OTP for Google Auth as well. I would imagine Keypass can as well.

Proteus Jones
Feb 28, 2013




Marriott got hit with a $600,000 fine by the FCC for knocking customer's personal hotspots out of the air because they wanted to force conferences using their facilities to use their Guest connections (which they charged for) using wireless IPS. While you *can* use deauth/disassoc packets to maintain your wireless security, you have to be really, really sure what you're knocking off the air. The FCC takes a real dim view of interfering with unlicensed spectrum and can hit with up to $50K per occurrence.

It was only a matter of time. I know for a fact Marriott was advised to NOT do what they ended up doing by people who knew the minefield of using de-auth as a defensive measure.

e; poo poo. fb.

Proteus Jones fucked around with this message at 05:49 on Oct 16, 2017

Proteus Jones
Feb 28, 2013



cheese-cube posted:

i use WPA2-Enterprise with PEAP at home because lol why not. is that affected by this krackhole dealio or does that only affect TKIP/AES-CCMP?

Nope you're affected.

Also, who's calling it krackhole? I haven't seen a reference to it outside of here.

Proteus Jones
Feb 28, 2013



anthonypants posted:

there was a github link with the html page it looks like they'll be using for the #branding of this latest exploit

Christ, this "branding of vulnerabilities" fad needs to die.

gently caress it. It's late, I'm cranky and started tilting windmills.

Proteus Jones
Feb 28, 2013



cinci zoo sniper posted:

thanks, but now to my question, what is aslr and what does it do :v:

Adress space randomization. Makes it harder to take advantage of buffer overflows.

Proteus Jones
Feb 28, 2013




Isn't that a pretty old version? I thought FortiOS 5 had been out for years now.

Proteus Jones
Feb 28, 2013




AHAHAHAHAHAHAHA

Proteus Jones
Feb 28, 2013



As secfuck year 2017 approaches a close, jumping up and down from the back of the room waving its arms, Oracle screams "Don't forget about me!" like a kick to dick.

http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html

quote:

This Security Alert addresses CVE-2017-10151, a vulnerability affecting Oracle Identity Manager.This vulnerability has a CVSS v3 base score of 10.0, and can result in complete compromise of Oracle Identity Manager via an unauthenticated network attack.

Proteus Jones
Feb 28, 2013



Lightbulb Out posted:

is lastpass the bad one?

Yes

Proteus Jones
Feb 28, 2013




https://twitter.com/Nfinit/status/926223332147687425

Proteus Jones
Feb 28, 2013



duTrieux. posted:

no s/he didn't

quote:

“We have learned that this was done by a Twitter customer-support employee who did this on the employee’s last day. We are conducting a full internal review,” Twitter said in a tweet late on Thursday.

Sounds deliberate to me.

Proteus Jones
Feb 28, 2013



Lol. Shitter forTwitter. That's funny. Personally, I like Micro$soft. That's instead of Microsoft if you didn't know.

Adbot
ADBOT LOVES YOU

Proteus Jones
Feb 28, 2013



haveblue posted:

what prevents watchdogs from using a non-api scraper to save deleted tweets

Probably nothing, but they would scrape a poo poo ton more tweets and be a lot more efficient in general using the API

  • Locked thread