Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
cinci zoo sniper
Mar 15, 2013




0day

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




ZeusCannon posted:

Innovative automated self touching poo pro ++

touching-as-a-service

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

autonomous poop

Autobutts, assemble!

cinci zoo sniper
Mar 15, 2013




apseudonym posted:

Did we touch the poop again?

new version commits clogged the pipe so much the poop couldnt find its way here

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

wife just linked me this:



brilliant :allears:

:staredog:

cinci zoo sniper
Mar 15, 2013




can we make images thread titles yet

cinci zoo sniper
Mar 15, 2013




JewKiller 3000 posted:

3do didn't have anything worth stealing either, though

unless you really like fmv

what the gently caress did you just say about heroes of might and magic 3

cinci zoo sniper
Mar 15, 2013




Wiggly Wayne DDS posted:

it's confirmed:
https://twitter.com/PolarToffee/status/879709615675641856

congrats on people not patching after the previous major incident

that's the wannacry 2: electric tears?

cinci zoo sniper
Mar 15, 2013




Wiggly Wayne DDS posted:

considering there isn't a domain to conveniently sinkhole just prior to the us business networks waking up ya

welp time to start the hospital counter i guess :rip: hopefully someone learned

cinci zoo sniper
Mar 15, 2013




ratbert90 posted:

hahahhhahahahahhaa.

i know, right. im just really not looking forward to a major life/-support system being hit by this poo poo, affect it me or not

cinci zoo sniper
Mar 15, 2013





no wanna no cry

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

You don't go to def con for the talks tbqh

you go there to have a runin with exceptionally smelly mcaffee?

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

serious post: other than putting books back and organizing stuff and otherwise managing a library what do you actually, like, do, i'm sure it's more than that but i've never really been clear

community outreach, collaboration with municipal entities (especially education-related), event planning and organising - if it's anything like in latvia. my mother has been working as a librarian for more than 30 years and ive spent a lot of time at her job

cinci zoo sniper
Mar 15, 2013




library managing like giving and taking books back is mostly computer these days. actual library book work is more related to catalogue and archive expansion/deprecation/maintenance

cinci zoo sniper
Mar 15, 2013




also, in a rural latvian library, there's a lot of basic it skill teaching done by librarians. how to use computer, what is google, how to write a cv, etc

cinci zoo sniper
Mar 15, 2013




ratbert90 posted:

Taking a shower at the gym I realized that anybody flushing the toilets makes the water temp go up by 10F.

MitM attack if I have ever seen one.

*nods in russian as 10 men flush toilet at once*

cinci zoo sniper
Mar 15, 2013




syscall girl posted:

lol how do you nod in russian?

slav squat and a curious gesture of the eyes?

you dont nod

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I agree with both of you. To me it's abundantly clear what the purpose of this malware is.

pls share, ive been only halfassedly reading about petya

cinci zoo sniper
Mar 15, 2013




infernal machines posted:

Another live fire exercise on Ukranian infrastructure, with a side of collateral damage, made to be plausibly connected to previous ransomware attacks?

that i kinda assumed it's russians just ukraining it away, i more thought some specific computer level macro objectives petya had that spankmeister may have implied

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

The initial infection vector is from a Ukranian company that makes tax return software. This company was hacked and made to push a malicious update to its users. A lot of businesses and government in Ukraine and businesses that deal with Ukraine use this software because it's one of the few that's allowed for use by the government.

So that makes it clear that Ukraine was the target.

Now the malware itself looks like a variant of Petya, which is an existing ransomware family. This is a false flag, smoke and mirrors. Why? Because there is no way of getting your files decrypted. This is because it generates a unique "Installation ID" which you're supposed to send along with your bitcoin wallet address that you made the payment from to an email address. They use a single hardcoded bitcoin wallet for every infection. This method requires manual verification and is completely ludicrous for a malware that has such aggressive spreading methods. Modern ransomware uses a more sophisticated backend that generates a unique bitcoin wallet for each infection which allows payments to be automatically verified over a tor backend.

Stupid verification method aside, the installation ID is completely random. There is _no_ way to link this ID to a specific infection. The malware authors cannot determine which key it belongs to. So there is no chance of this ever working as a "legitimate" ransomware.

And like Wiggly Wayne DDS said, Petya was a perfectly functional ransomware, there was no reason to make the changes that they did.

:tipshat: this is very interesting, and confusing

cinci zoo sniper
Mar 15, 2013




ThePeavstenator posted:

Well this morning certainly has been interesting.

I work at a large global company that makes lawn equipment and engines. Our manufacturing line computers were infected with ransomware last year and had to be shut down until hundreds of thousands of dollars were payed out.

I work in the equipment testing lab. The lab manager (who btw owns) and I are the people that maintain and develop software that handles all the test requests and test data, among other things.

I go into his office this morning and we notice that a folder in the network drive where all of our test data is stored had a bunch of [document in the folder filename].locky files. We immediately wrote a ticket, which immediately got escalated to the head of global network security. I then noticed that all the locky files were 0 bytes and I right clicked on the properties to see the owner. Every file was owned by the same guy and we work fairly closely with him so we messaged him right away. He tries being all coy saying he had no idea what we're talking about *wink*. Turns out they're all just empty and it was just a "prank".

Our IT sends out almost daily memos reminding people what to look for in a phishing attempt after we had production shut down last year. They were making GBS threads themselves this morning and wanted to speak with him right away. We told him this and his defense was "well I was just trying to check up on you guys, IT sends out phishing tests to employees all the time too!!"

looks like he found a vuln in his employment status

cinci zoo sniper
Mar 15, 2013




ThePeavstenator posted:

I guess it should also be noted that he's not a computer toucher, he's an electrical technician, so I don't think he knew the level of reaction this was going to get.

uhhhh

cinci zoo sniper
Mar 15, 2013




ThePeavstenator posted:

hey man I never said he was smart
not blaming you or anything, just didnt expect that it wasnt even a computer toucher. this is getting into windows xp screenshot wallpaper tier of pranks, only in the worst place at the worst time

cinci zoo sniper
Mar 15, 2013




Meat Beat Agent posted:

i bet that dude will WannaCry after he gets fired lol

:wow:

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

Anybody know what services or processes need to be whitelisted on the windows firewall to make updates work on an outbound deny default config? I've cleared both BITS and WU services but it still fails and I see something hitting 443 outbound and getting dropped but I am having a hell of a time figuring out what process or service its associated with. I made a blanket 443 out allow rule and it started working again but there's something else that is now a dependency for updates to work properly and this poo poo isn't documented by MS.

you need 80 and 443 for http and https wsus access respectively. restrict the ports to

code:
http://windowsupdate.microsoft.com 

http://*.windowsupdate.microsoft.com 

https://*.windowsupdate.microsoft.com 

http://*.update.microsoft.com 

https://*.update.microsoft.com 

http://*.windowsupdate.com 

http://download.windowsupdate.com

http://download.microsoft.com 

http://*.download.windowsupdate.com 

http://wustat.windows.com 

http://ntservicepack.microsoft.com

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

Windows firewall doesn't whitelist on domains, I need to know what process is initiation the connection.

wuauclt.exe i think

cinci zoo sniper
Mar 15, 2013




Ciaphas posted:

Reminds me of that guy who "pranked" his fellows at some chemical lab by putting almond extract into an A/C intake

im not sure what effect that does but ive seen some of my coworkers smoking next to the intake of building-wide air ventillation system

cinci zoo sniper
Mar 15, 2013




vOv posted:

it doesn't do anything per se but usually smelling almonds in a chemical plant means 'cyanide spill'

:chanpop:

cinci zoo sniper
Mar 15, 2013




French Canadian posted:

Is it called cyber because trump called it cyber in a debate? So now they have to adjust their marketing?

yeah trump constantly refers to itsec and everything related with an umbrella term "the cyber"

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

As a Mozilla dev I,

as a thundeahahhahahaha

cinci zoo sniper
Mar 15, 2013




http://www.zdnet.com/article/secure-pc-self-destruct-data-tampered-with/

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

Wish your posting rig would self destruct

its close, has been rattling for a while now

cinci zoo sniper
Mar 15, 2013




French Canadian posted:

Indeed, and I know cyber "whatever" has been around forever but I am unaware of when just "cyber" became a term. It's like saying "I like mountain" and forgetting to add "climbing", "biking" or "making GBS threads".

so you have not heard a word uttered out loud by new american president who honest to god is worse at english than me, english as a fourth language foreigner with combined 4 months of residence in an englisn speaking country in my entire lifetime

cinci zoo sniper
Mar 15, 2013





So we have to get very, very tough on cyber and cyber warfare. It is a, it is a huge problem. I have a son.

He's 10 years old. He has computers. He is so good with these computers, it's unbelievable. The security aspect of cyber is very, very tough. And maybe it's hardly do-able. But I will say, we are not doing the job we should be doing, but that's true throughout our whole governmental society. We have so many things that we have to do better, Lester and certainly cyber is one of them.

cinci zoo sniper
Mar 15, 2013




jesus christ how the gently caress is everyone this dense. cyber became a standalone thing last year, during.presidential debates in the american elections. specific excerpt above

cinci zoo sniper
Mar 15, 2013




no but really cinco de mayshroom, i get that, but what about this cyber thing

cinci zoo sniper
Mar 15, 2013




but enough about your yiffing adventures. hasn't been part of mainstream discourse for last decade at least

cinci zoo sniper
Mar 15, 2013




Cocoa Crispies posted:

just because a fat orange shithead with holes in his brain got caught using it once last year doesn't make it mainstream

"once" :laffo: oh you sweet summer child

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

this but unironically
yeah, i always wanted to try factorio

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Shaggar posted:

theres litterrally us cyber command. cyber is old as heck.

cyber as adjective is old as hell, sure. cyber as a noun has not been widely used in public formal contexts for past decade

  • Locked thread