Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


code:
PATCH NOTES FOR 14.0
* New thread because I was tired of seeing my old forums name in the bookmarks
* True origins of DEFCON have been made clear

PATCH NOTES FOR 13.0
* Avoids slamming car doors into genitals
* Removed conversation that belongs in D&D

PATCH NOTES FOR 12.0
* A whole new version to reflect the ever-changing threat landscape
* Official HTTPS support--it only took Lowtax like a decade to get it to work properly

PATCH NOTES FOR 11.4
* Added details at end of OP for why the thread is called "You're busted, dude"

PATCH NOTES FOR 11.3
* POP POP of unsigned ints

PATCH NOTES FOR 11.0
* new version with less bloat
* all anime removed and hopefully forever

PATCH NOTES FOR v10.1
* no patch notes required

PATCH NOTES FOR v10.0

* decided that 8 and 9 were bad numbers and skipping to '10' would make us look cooler.
* js crypto added in for the sake of an internet argument

PATCH NOTES FOR v7.69

* Added 1.2 billion passwords from Russian hacker forums

PATCH NOTES FOR v7.2 "BoringSFM"

* The name is aspirational and not yet a promise

PATCH NOTES FOR V1.0.1g

* changed version number

PATCH NOTES FOR V0.9.8

* once again removed LF and Fishmech corruption from the last thread
* added a new feature that enables the mods/admins to go ahead and probate/ban as necessary if LF'n poo poo happens
* added heartbeat feature to non-existent SSL layer on the forums

PATCH NOTES FOR V69

* removed LF and Fishmech corruption from last thread
* new "hello" service for conference attendees
* blocking of js crypto through message relay services like twitter

PATCH NOTES FOR V1.2

* made more efficient for version 1.2 after having removed fishmeching and talk about credit card contracts

PATCH NOTES FOR V1.1

* don't loving use any of these goddamn exploits you dumbshits


join us on irc: irc.synirc.net #yossec

useful news resource for information security professionals: http://reddit.com/r/netsec/

risky business podcast is worth listening to and yospos has been mentioned in it before

here are some old threads that haven't been archived:

Security Fuckup Megathread - v13.69 - plugins may violate privacy (jan-jun 2017)
Security Fuckup Megathread - v12.2 - you have slammed your dick in the car door (apr 2016-jan 2017)
Security Fuckup Megathread - v11.4 - who u gonna snitch to pussy bitch gently caress u (apr 2015-apr 2016)
Security Fuckup Megathread - v10.1 (Hackers can turn your gas station into a bomb) (nov 2014-apr 2015)
Security Fuckup Megathread - v7.69 (stay safe security ghost) (aug-nov 2014)
Security Fuckup Megathread - v7.2 "BoringSFM" (jun-aug 2014)

Alereon posted:

seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything


Talk about opsec and government fuckups in this thread.

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Trabandiumium posted:

3 pages short of 219 my dude

i noticed. fucks given: zero

just uninterested in seeing my old forums name haha

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

syscall girl posted:

and OP, apologies for the stuxnet parking lot reference, it's very political but also one of the biggest secfucks we've seen so it balances out

no worries. nobody in the thread did anything wrong. like i said, i was tired of seeing my old forums name show up in my bookmarks and was, "enh gently caress it"


these forums are the least of my problems for name changes

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

vOv posted:

are you implying what i think you're implying here b/c if so then good luck with everything and godspeed

(feel free to be brief or whatever if you don't want to clog up the thread)

yep :love: :bigtran:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

congratulations on finally breaking that $25k barrier, you made it

ayyy lmao

but yeah. i came out in april and sort of disappeared for a while because of it. will be kicking rear end soon enough!

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

cis autodrag posted:

oh that was why you changed your name? fwiw i tried to get away from my old forums name too and people insist on using it when they quote me anyway :(

congrats friend.

yeah. i sort of got it in a mod challenge once and never really liked it but just owned it anyway. i chose this one because it was femme and still rad :)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

apseudonym posted:

Did we touch the poop again?

nope. just me being a princess

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ate all the Oreos posted:

wife just linked me this:



brilliant :allears:

:staredog:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
No Defcon for me this year but likely next.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i've always liked anime. i just never really post about it anywhere anymore

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

is the secfuck thread going to get gassed or shutdown for too much off-topic posting already? it's just barely on page 3

i'll let this slide for tonight but tomorrow, there better be some gently caress ups

tonight i am doing some groundwork for 3DO RE work

https://twitter.com/KateLibc/status/879536662031638528

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

infernal machines posted:

3do didn't have any kind of drm did it?

my old fz-1 is finicky, but it'll play burned discs without any mods

zero

it just has a really wonky disc format that required me to setup a linux vm running kernel 2.6 to properly read them

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Doom Mathematic posted:

So this is from where, exactly? Or is it just a mockup?

It came from the same people who came up with those abusive volume sliders.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
we haven't had some grey forum quotes to mock lately

Ganson posted:

I also thank my lucky stars every day that our entire dev department is on Macs (with like one or two exceptions), production is all Linux, and it's not my job to give a crap about user endpoints anymore.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i'm so glad that this is the library thread. i totally misread the title when i clicked on it i guess

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

the supported cipher list from a major industrial controls vendor's monitoring and remote access platform:

TLS_RSA_WITH_NULL_MD5 (0x1) INSECURE 0
TLS_RSA_WITH_NULL_SHA (0x2) INSECURE 0
TLS_ECDHE_RSA_WITH_NULL_SHA (0xc010) ECDH sect571r1 (eq. 15360 bits RSA) FS INSECURE 0
TLS_ECDH_anon_WITH_NULL_SHA (0xc015) INSECURE 0
TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8) INSECURE 40
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14) DH 512 bits FS INSECURE 40
TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA (0x19) INSECURE 40
TLS_RSA_WITH_DES_CBC_SHA (0x9) INSECURE 56
TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15) DH 1024 bits FS INSECURE 56
TLS_DH_anon_WITH_DES_CBC_SHA (0x1a) INSECURE 56
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) WEAK 112
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16) DH 1024 bits FS WEAK 112
TLS_DH_anon_WITH_3DES_EDE_CBC_SHA (0x1b) INSECURE 112
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (0xc012) ECDH sect571r1 (eq. 15360 bits RSA) FS WEAK 112
TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA (0xc017) INSECURE 112
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) DH 1024 bits FS WEAK 128
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) ECDH sect571r1 (eq. 15360 bits RSA) FS 128
TLS_DH_anon_WITH_AES_128_CBC_SHA (0x34) INSECURE 128
TLS_ECDH_anon_WITH_AES_128_CBC_SHA (0xc018) INSECURE 128

so... rockwell?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

There are many vendors in this space and my advice is to validate anything they tell you with regards to cryptography

i'm very aware of the ics space

i was more or less curious which vendor you're talking about in particular here because the stupid poo poo i see in it is overwhelming

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

reminds me of how a customer at $av_vendor was pissed off when we told them that we wouldn't give them follow the sun support for their inability to understand that you don't go and update the software across the board. that said, the software was poo poo but still you don't go deploying crap without testing how it'll affect things

these idiots installed the av software on loving medical devices and blindly updated the version

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech posted:

for further context on that chat snippet:
- the software they are talking to the support engineering team for is the 5 year old version too
- the bug they have was fixed in an update 4 years ago
- they claim it would be too hard to update all 5000 of their endpoints to a new version, but
- it is impossible to fix this, even with a custom patch, without updating all the endpoints to a new version, because the bug exists both client and server side

"eat poo poo"

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Jabor posted:

just lol if you can't do zero-downtime updates

let's talk about ics then. you cannot believe the nightmares that come with it

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/882644229901529089

and this is why we're doomed

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

just do it via dns authentication

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Arcsech posted:

why doesnt this guy ever find earthshattering oh-poo poo vulns on like, monday morning or something

always like thursday or friday afternoon

we find it's always better to release details on a friday. studies have statistically shown that there's less chance of an incident if you do it at the end of the week

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
code:
15:44 < user1> company doing pentest on us is pissed at us.. one of our engineers uploaded
                their 0day exploit to virustotal and MSFT picked it up and tweeted about it
15:45 < user2> lmao
15:46 < user3> hahahahaha rekt.
15:46 < user4> Oops
15:46 < user4> Where's the tweet?
15:46 < user3> Of all the poo poo ways to burn an 0day.
15:46 < user3> That's probably the worst
15:49 < user1> [link to tweet]
15:49 < user1> MSFT picked it up from virustotal
15:49 < user1> and tweeted about it.. all in a span of about 25 minutes
https://twitter.com/JohnLaTwC/status/883057609023959040

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Rufus Ping posted:

What's "0 day" about this, it looks like some run of the mill macro poo poo

no idea

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/justin/status/883171036283285508

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

goddamnedtwisto posted:

i genuinely thought this was a repost, wasn't there someone else complaining about the exact same thing a few months ago?

it's just another example of why sms 2fa is dumber than poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powerful Two-Hander posted:

i had to use an internet cafe today to do some work bullshit while on holiday and 1) holy poo poo internet cafes still exist 2) they give you local admin which was handy because i had to install java to get our garbage remote access software working*

the guy next to me was trying to open some random file type and asked the staff about installing something and they went 'it's not a virus right?' and just did it


*recently upgraded to use a java desktop app that has to be manually set up to point to the java exe and so breaks on every java version update because environment variables are hard

you used a public computer to connect to work resources?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this font poo poo while hilarious is best suited for the opsec thread

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
word on the street is that Mafiaboy is involved

if so then lol

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
cruel idea: call up a random security person and claim that you're brian krebs
crueler idea: call up said random security person at 4:30 pm on a friday claiming to be krebs
cruelest idea: call up said security person at 4:30 pm on a friday, claim you're krebs, and also introduce someone claiming to be tavis ormandy

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i have nexus which is global entry for us canadians

i prefer it over having to deal with bullshit questions

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

stalking my friends eh? :P

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/kaepora/status/890640307729047552

glass houses, etc

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
SHUT
THE
gently caress
UP
ABOUT
THIS
poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Cybernetic Vermin posted:

haha, oh come on, what are you even trying to achieve? i have made only one post about corporations, but all i did was note that they are legal constructs, never mentioning people. and you can't seriously think that there aren't things that corporations can do that people cannot (though i'd buy share #1 when the fishmech ipo happens). i will yield since i assume people will want to get back to a buffer overflows or something, but you are spewing absolute nonsense man

Lain Iwakura posted:

SHUT
THE
gently caress
UP
ABOUT
THIS
poo poo

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

spankmeister posted:

Don't fishmech this thread

don't worry; he's now whining to me in PMs

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Jabor posted:

It's almost like having the opsec thread as containment for the security-relevant-yet-somewhat-d&dish discussions was actually a good thing

agreed

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

fishmech posted:

defcon was mostly lame this year

"this year" as opposed to never every other year

  • Locked thread