Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
geonetix
Mar 6, 2011


me, trying to get some NIST references into some documentation.



thanks US Government. at least the banner works great with amberpos

anyone know of copy of all the NIST documentation?

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


is that why leap years exist?

anyway fixed it with the help of the way back machine, thanks archive.org

geonetix
Mar 6, 2011


James Baud posted:

Junior devs and interns, sometimes people even let them review each other's code without additional oversight.

a company I used to work for allows developers to write in any language they please and now they have a bunch of ocaml code in production that nobody understands but the original author, it has been "code reviewed" which means it got an approved label in github

every-startup-ever.txt

geonetix
Mar 6, 2011


yes. yes it is. and also

https://twitter.com/HackerGiraffe/status/1080702645051056128

e: they deleted it. admitted to being bad at opsec and hoping nobody would care too much. poop touchers being dumb confirmed

geonetix fucked around with this message at 15:45 on Jan 3, 2019

geonetix
Mar 6, 2011


“hacking” anno 2019 is literally nothing else than looking for an open mongodb or scada port on shodan and hoping for the best

e: oh and give it a funky name and logo

geonetix
Mar 6, 2011


the truth is still that domestic routers are generally terrible

even if chromecast wasn't upnping its way onto the world wide web

geonetix
Mar 6, 2011


because, did you expect anything else?

https://twitter.com/doctorow/status/1083444065146789889?s=21

geonetix
Mar 6, 2011


re SEP im 75% sure it’s just taviso sending them a poc again

re bigotry maybe create another generic thread, this is a massive issue in general and lgbt people or women or other minded people on conferences and everywhere else have been harassed greatly and it’s unnecessary and sad and while it’s a valuable discussion it’s not necessarily infosec specific?

geonetix
Mar 6, 2011


BangersInMyKnickers posted:

tavis isn't sending my loving desktops payloads to make the IPS engine throw SEHOP faults and die, this thing is in the wild

lmao ok, the 25% it is. do you have samples? I like to toss it into mcafee and other poo poo tier stuff

geonetix
Mar 6, 2011


Blinkz0rz posted:

a product manager literally just asked me if i have any concerns about allowing paid users to upload selenium jars and exes which our product will process

trying to figure out a diplomatic way to say "absolutely not why would you think this is a good idea?"

the only diplomatic way is to "demo the concept of the system" using kournikova.jps.vbs

geonetix
Mar 6, 2011


BIGFOOT EROTICA posted:

are there any actually good security consulting firms?

yes

geonetix
Mar 6, 2011


BIGFOOT EROTICA posted:

would u like to elaborate, im trying to find one thats actually good to consult on a v large project

i could, the problem is it’s extremely local. i know the folks personally at some level in the orgs i work with and they haven’t failed to deliver

so

unless you’re in literally my city or country (NL) I’m not much of a help

geonetix
Mar 6, 2011


it’s just a shift of approach and I think the big so-many SVs don’t care and just adapt. nothing matters until it affects the bottom
line, which security and privacy simply don’t do

geonetix
Mar 6, 2011


it’s simply the cost of doing business in china and basically any company operating there does this, its much more interesting to ask how isolated the systems are and how much control the companies yielded

if anything is morally bankrupt according to anyone’s standards its likely to be much more the chinese government than apple, or bmw, or anyone else operating there

geonetix
Mar 6, 2011


apseudonym posted:

C/C++ should not be used for parsing things.


youre right, that’s what regex is for

geonetix
Mar 6, 2011


Blinkz0rz posted:

did you just tell me to go gently caress myself?

i believe i did, Blinkz0rz

geonetix
Mar 6, 2011


not sure if posted before but holy wow

https://www.cnet.com/news/chinese-facial-recognition-company-left-database-of-peoples-location-exposed/

https://twitter.com/0xDUDE/status/1095702540463820800

(thread)

https://twitter.com/0xDUDE/status/1096099456922148864

geonetix
Mar 6, 2011


https://text.npr.org

geonetix
Mar 6, 2011


imagine all those bank accounts with personal details of people (recipients/senders) who did not agree to access

geonetix
Mar 6, 2011


you can it's probably on an insecure samba share exposed to the internet. just portscan them

geonetix
Mar 6, 2011


ErIog posted:

I have a secfuck question where I'm looking in the mirror and wondering if the secfuck is me.

I'm getting some poo poo from an auditor about libxml2. They had brought it up previously, and I was able to respond to it with "lol, noob, learn how the gently caress package versions work on RHEL, none of these CVE's apply."

It has been brought up again, but this time I'm not so sure I can reply with that same response because there's actually a bunch of low/medium CVE's listed for libxml2 in the RHEL CVE database with the status "Won't Fix" or "May be fixed in the future :iiam:" even for RHEL7.

What are Wizard Security Professionals doing for this case? libxml2 seems like a package that would be installed quite a lot.

libxml2 works fine with cves in it as long as it’s not used to process input or generate output. so eh yeah patch it

geonetix
Mar 6, 2011


youre right vim should be default on all systems

geonetix
Mar 6, 2011


I have a feeling that investigation should be done by a third party instead

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


well someone is having fun with matrix.org

https://github.com/matrix-org/matrix.org/issues

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply