Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Midjack
Dec 24, 2007




the token ringu

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



anatoliy pltkrvkay posted:

and it will be fishmeched again in the future. fishmeching never ends.

in secfuck news apparently bevmo was storing entire CC numbers because PCI auditors are good at their jobs.

lmbevmo

Midjack
Dec 24, 2007



marketing fuckup

Midjack
Dec 24, 2007



that fax machine talk was good at defcon this year, check it out here for sure.

Midjack
Dec 24, 2007



Raere posted:

What's the consensus on running AV on Macs (for myself)? Do they just increase the attack surface like they tend to do on PCs, or is it actually a useful extra layer of defense?

it's not useful unless you are specifically trying to disinfect some old rear end file from 1996 that isn't available without the malware anymore.

Midjack
Dec 24, 2007



BattleMaster posted:

it's also why mongo db makes me vaguely uncomfortable (aside from the things that are obviously wrong with it :xd:)

i thought mongo in mongodb got there via humongous so it should be ok.

Midjack
Dec 24, 2007




You can download it and cut out the pieces. It's not sold as a box game:

https://pen-testing.sans.org/blog/2018/10/02/sans-pen-test-poster-pivots-payloads-boardgame

Midjack
Dec 24, 2007



Shame Boy posted:

yeah those have been going around, i posted a few in the last thread. did it say you have ~UNBRIDLED FANTASY~ 'cuz that's my favorite one :allears:

when i read about this scam i'm always reminded of the story about when the cia tried to blackmail sukarno with a fake sex film and he thought it was awesome and asked them for copies to send to his friends.

Midjack
Dec 24, 2007



Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

awful chavs done quick

Midjack
Dec 24, 2007



Cocoa Crispies posted:

my brothers and I got our parents a smart lock for Christmas

reported for elder abuse

Midjack
Dec 24, 2007




wrong ministry

Midjack
Dec 24, 2007



that's why they're telling you to fax it, duh.

Midjack
Dec 24, 2007



Shame Boy posted:

while waiting in the parking lot of my wife's office today i noticed that there was an open, unprotected wifi network...

...called "WiFi_ODBII" :allears:

ol dirty bastard lives!

Midjack
Dec 24, 2007



Volmarias posted:

:piss:

Sounds like Apple would be within their rights to nuke all of their certs at this point

cook vs zuck

whoever loses, we lose

Midjack
Dec 24, 2007




if apple revokes facebook's app, zuck will simply announce a partnership with huawei.

Midjack
Dec 24, 2007



rjmccall posted:

hmm, probably does not count as intent to obtain a benefit, to injure or defraud another or to facilitate an unlawful activity

benefit was gaining information about the security posture of their network

Midjack
Dec 24, 2007



Salt Fish posted:

DNA has 4 amino acids as it's alphabet, how do you encode an escape sequence? Like what the heck kind of processing is that lovely?

a lot of science and medical device control software is amazingly terrible on all fronts including security and data validation.

Midjack
Dec 24, 2007



apseudonym posted:

Security Fuckup Megathread - v17.1 - Validate your DNA inputs

a condom is a firewall for your dick. also vag depending on your attitude wrt safe sex.

Midjack
Dec 24, 2007



haveblue posted:

the best phish training email I've seen was one that claimed to be from our security team containing a list of people who fell for the last phish training email

:yeshaha:

Midjack
Dec 24, 2007



https://mobile.twitter.com/Shadow0pz/status/1092437873205362689

fully online cyber farming

Midjack
Dec 24, 2007



Soricidus posted:

could have been worse, could have been blockchain

they can still cram that in there too.

Midjack
Dec 24, 2007



redleader posted:

nah, blockchain is old news and no longer hip

that fits, military it is waaaaaaaaay out of date.

Midjack
Dec 24, 2007



GWBBQ posted:

someone compromised an email provider's primary and backup servers, formatted them, and destroyed 20 years of data. the company apparently had no cold storage backups.

https://arstechnica.com/information...ZigasqormT3brUE

somebody wanted that provider eradicated, impressive.

Midjack
Dec 24, 2007



this isn't a secfuck on its own but may be setting up some people for one with the list of trustworthy tlds:



yup, definitely never seen bullshit hosted on a .org or .com

Midjack
Dec 24, 2007



from the corporate america thread:

Ashcans posted:

Also this morning, I come to you with a tale of IT security. We use a secure file service, where people can upload documents to you and you get an email notification, log in and access them, I assume this is a pretty typical tool. When we started using this, you could allocate permissions so that someone else in the system could look at your received files. Which is ideal for when you have some old senior staff who are not prepared to handle document security, they just forward the notification to their staff and someone can log in and access the documents.

Well, a little while ago the secure file service stripped out this feature because, I dunno, I guess maybe sharing access was not considered best practice? Or more accurately, they made it so that in order to access anyone else's files, you have to be an administrator. So we were faced with two options; give all these staff admin privileges, or force senior staff to learn to use the service and spend time accessing/sharing documents. Yea, no. So the office settles on a third option; put our senior staff login information and passwords in a word file on the server, so when they forward something you can login as them and get what you need. But that's clearly not great either, so.... they password-lock the word file. But now how do people get the password for the word file with the passwords they need to get the files?

It is written on a notepad, which is kept under someone's file tray on their desk.

This is definitely a better system.

Midjack
Dec 24, 2007



BIGFOOT EROTICA posted:

there was a talk that i believe was posted in this thread (or its progenitors) a while back about hacking airline booking backends (and i think through exposed portals for travel agents??) including being able to get any persons boarding passes and stuff like that

anyone remember this?

karsten nohl from 33c, maybe? https://www.youtube.com/watch?v=vjRkpQever4

Midjack
Dec 24, 2007



pseudorandom name posted:

gage is a correct spelling

i’m sure it’s serviceable for your purposes.

Midjack
Dec 24, 2007



we should probably get back to languages like java and erlang in this thread though.

Midjack
Dec 24, 2007



duz posted:

the it aup we all had to sign at my school included that we would not use the computers to influence the vote of a senator

that seems strangely specific.

Midjack
Dec 24, 2007




:nsavince:

Midjack
Dec 24, 2007



Methanar posted:

When lowtax dies. ZDR still has the keys to get in right?

zdr ghosted several months ago but returned just now citing a broken phone.

i’m sure it had nothing to do with lowtax calling him out in the thread.

Midjack
Dec 24, 2007



just click on lowtax’s posts in this (warning gbs) thread for the story so we don’t derail this any further:

https://forums.somethingawful.com/showthread.php?threadid=3884184

that said, i really like you guys and this thread especially and I will miss this place whenever it finally disappears.

Midjack
Dec 24, 2007



Midjack
Dec 24, 2007



Bhodi posted:

listen kid, you aren't a real security professional unless you know a group that was last relevant before you were born

this is kind of like saying lenin doesn’t matter because he’s been dead for a hundred years.

Midjack
Dec 24, 2007




101

Midjack
Dec 24, 2007



~Coxy posted:

our IS implemented some kind of internal firewall that kills any extant connection after an hour, no matter what

boy it was fun implementing auto-reconnect in our DB layer

ahahah

Midjack
Dec 24, 2007



crazypenguin posted:

I'm about to accept (I think) a new job where my task might be to fix this mess for the whole industry. I'd say more, but I don't really know yet and/or am under NDA.

Any general thoughts you're willing to share on the "automate all the networking configuration bullshit, and make it Actually Good" front? This isn't my background (my background is that "sanity-checking requires a lot of complicated logic" part), so I have a lot to learn on the state of the industry and what the pain-points are.

:rip:

Midjack
Dec 24, 2007




pegged by asus

Midjack
Dec 24, 2007



Shinku ABOOKEN posted:

i love seeing traffic from java.exe. what could it be? who cares.

motherfuckers act like they forgot about jre

Adbot
ADBOT LOVES YOU

Midjack
Dec 24, 2007



Cybernetic Vermin posted:

fde keyed to your key fob is the correct solution either way, no need to invent less convenient solutions just because doing the fde requires a slight redesign

keeping in mind that multiple fobs enrolled in the same car are distinct units and not clones of each other.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply