Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


code:
PATCH NOTES FOR 17.1a
* Added JRE appreciation

PATCH NOTES FOR 17.0
* New codebase to avoid a new round of Fishmeching and apparently Fortnite bashing
* New IoT support since everyone is getting Christmas gifts that plug into the Internet unnecessarily

PATCH NOTES FOR 16.0
* Tavis is taking a vacation so we're making a new thread
* This thread is not a place for discussing rape apology, mens rights activism, how much you want to talk about MRAs, Wikileaks, how Wikileaks is not a wiki, and Julian Assange

PATCH NOTES FOR 15.0
* Thread now has a 30% slowdown

PATCH NOTES FOR 14.0
* New thread because I was tired of seeing my old forums name in the bookmarks
* True origins of DEFCON have been made clear

PATCH NOTES FOR 13.0
* Avoids slamming car doors into genitals
* Removed conversation that belongs in D&D

PATCH NOTES FOR 12.0
* A whole new version to reflect the ever-changing threat landscape
* Official HTTPS support--it only took Lowtax like a decade to get it to work properly

PATCH NOTES FOR 11.4
* Added details at end of OP for why the thread is called "You're busted, dude"

PATCH NOTES FOR 11.3
* POP POP of unsigned ints

PATCH NOTES FOR 11.0
* new version with less bloat
* all anime removed and hopefully forever

PATCH NOTES FOR v10.1
* no patch notes required

PATCH NOTES FOR v10.0

* decided that 8 and 9 were bad numbers and skipping to '10' would make us look cooler.
* js crypto added in for the sake of an internet argument

PATCH NOTES FOR v7.69

* Added 1.2 billion passwords from Russian hacker forums

PATCH NOTES FOR v7.2 "BoringSFM"

* The name is aspirational and not yet a promise

PATCH NOTES FOR V1.0.1g

* changed version number

PATCH NOTES FOR V0.9.8

* once again removed LF and Fishmech corruption from the last thread
* added a new feature that enables the mods/admins to go ahead and probate/ban as necessary if LF'n poo poo happens
* added heartbeat feature to non-existent SSL layer on the forums

PATCH NOTES FOR V69

* removed LF and Fishmech corruption from last thread
* new "hello" service for conference attendees
* blocking of js crypto through message relay services like twitter

PATCH NOTES FOR V1.2

* made more efficient for version 1.2 after having removed fishmeching and talk about credit card contracts

PATCH NOTES FOR V1.1

* don't loving use any of these goddamn exploits you dumbshits


join us on irc: irc.synirc.net #yossec

useful news resource for information security professionals: http://reddit.com/r/netsec/

risky business podcast is worth listening to and yospos has been mentioned in it before

here are some old threads that haven't been archived:

Security Fuckup Megathread - v16.2 - /home/land/security/theatre (may-dec 2018)
Security Fuckup Megathread - v15.1 - Stop!!! I Kill You Researcher (jan-apr 2018)
Security Fuckup Megathread - v14.1 - Hello, is this a delivery order? (jun 2017-jan 2018)
Security Fuckup Megathread - v13.69 - plugins may violate privacy (jan-jun 2017)
Security Fuckup Megathread - v12.2 - you have slammed your dick in the car door (apr 2016-jan 2017)
Security Fuckup Megathread - v11.4 - who u gonna snitch to pussy bitch gently caress u (apr 2015-apr 2016)
Security Fuckup Megathread - v10.1 (Hackers can turn your gas station into a bomb) (nov 2014-apr 2015)
Security Fuckup Megathread - v7.69 (stay safe security ghost) (aug-nov 2014)
Security Fuckup Megathread - v7.2 "BoringSFM" (jun-aug 2014)



just a reminder: this is for sec gently caress ups. if you want to talk about telecoms or politics (including wikileaks), make a new thread

Somebody fucked around with this message at 20:09 on Mar 27, 2019

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
the fax talk is strong and hilarious

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Daman posted:

TDO is back, looks like they're trying to ransom a US government agency this time.

FAA maybe?

https://pastebin.com/fyyBT9W8

too bad there's no money

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

how long until we get a ps4 or xbone jailbreak

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
let's shut the gently caress up about upnp

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

Researchers have identified a critical "hard-coded credentials" vulnerability (CVE-2018-7800) affecting Schneider Electric floor-standing EVLink Parking units (version 3.2.0-12_v1 and earlier) that could allow attackers to compromise the EVLink Parking device, according to reports. While researchers say it is unclear what additional access can be obtained by compromising the EVLink Parking device, they point out that the device is part of the EVLink Parking network that is remotely managed by a cloud-based central system. According to Schneider, the flaw can be addressed by applying the provided patch or mitigated using a firewall configured to block unauthorized access from remote or external users.

this is good

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/1082687485887471616

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Midjack posted:

You can download it and cut out the pieces. It's not sold as a box game:

https://pen-testing.sans.org/blog/2018/10/02/sans-pen-test-poster-pivots-payloads-boardgame

yeah. i should have linked to the pdf. i get lots of stuff from sans but i only do a course every few years. the only one i've really liked was the ics one i did years back

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Bhodi posted:

Did chrome stop trusting disa.mil government CA? https://www.disa.mil/cybersecurity/network-defense/antivirus

:tinfoil:

https://twitter.com/KateLibc/status/1082756012396797952

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

trust chain on that is completely hosed. you're not allowed to have an upstream trust intermediate have an expiration before the expiration of the downstream trust.

how do you even achieve that

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

okay welcome to the loving dumbest pki implementation I have ever seen:

wwww.disa.mil exp 11/18/19
DOD ID SW CA-38 exp 9/23/21
DoD Root CA 3 exp 2/17/19 <-- lol
DoD Interop Root CA 2 exp 8/15/19 <-- lolč
Federal Bridge CA 2016 exp 5/15/20
TSCO SHA256 Bridge CA exp 2/19/19 <-- who the gently caress is this?
Alexion Pharmaceuticals Issue 2 CA exp 8/2/27 <-- WHO THE gently caress IS THIS??

Why the gently caress doesn't this stop at DoD Root CA 3 is beyond me but even that they hosed up your root should always have the last expiration date

holy heck

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

quote:

This year, we had to handle issues that honestly, as an adult, we would never expect to have to handle from other adults. Conferences in general have shifted focus to not upsetting individuals and having to police people’s beliefs, politics, and feelings. Instead of coming to a conference to learn and share, it’s about how loud of a message a person can make about a specific topic, regardless of who they tear down or attempt to destroy. To put it in perspective, we had to deal with an individual that was verbally and mentally abusive to a number of our volunteer staff and security to the point where they were in tears.

[...]

Admittedly, we had no idea how to handle this person, and in fear of repercussion of removing this person, allowed them to stay at the conference in order to “not upset the masses”. The best we could do was just apologize, for other apologies, and apologize more for another’s actions. This is just one example of many we have had to deal with over the past few years, and each year it becomes increasingly harder for us to handle. We do everything as a conference to ensure the safety, security, and go above and beyond that of others. Maybe that puts us on a different level where something that would normally not be an issue explodes into a catastrophic situation on social media.

what's the story here? i ignore con drama

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i ended up ranting in a thread about my dislike of infosec yesterday

https://twitter.com/KateLibc/status/1084506853042733056

someone decided that a klout-like website for infosec persons (really just men who are "thought leaders" with a few token women) would be a grand idea. it's everything i hate about infosec in one website

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

i went to HOPE last year and it was complete trash. friends of mine were harassed to say the least

considering they kept deadnaming chelsea manning unnecessarily citing "historical record" or whatever, it's no surprise they're inept about their problems. when i made a beef about it on twitter that summer, their response to me invited a small amount of harassment my way

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

apseudonym posted:

They dont even have natashenka on there, nice.

why would they put a girl on there who is only known for having tamagotchis?

she is one of the nicest people in infosec i bet

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

florida lan posted:

RSA is still a security conference?

boy i could talk endlessly about rsa if i wasn't bound by ndas

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Loky11 posted:

All Twitter drama aside, Derbycon was my favorite con. I'd been since Adrian Crenshaw decided to do a Metasploit class that turned into Derbycon. Sad to see it go, however, I'd started to get the Defcon and megacon vibe this past year. So maybe all good things must come to an end.

adrian crenshaw is a garbage individual who deserves to be thrown out with the trash

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Loky11 posted:

is this about the time he got kicked out of the Indiana University MBA for repeatedly bringing up Nazi Germany in an econ class?

Or other number X of Y instances?

the laundry list is long. he's a total shithead. i've refused to be on a panel with him because of how foul of a person he is

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
cis white men who tell me that there are no problems in infosec are typically the problem in infosec (this goes the same for any other tech sector)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
after coming out, i made a choice to not engage as much into the whole infosec community and since then have sparingly attended meetups or talked much with people online. i am still in some circles due to legacy or if they're a majority non-men, but it's overall toxic and unnecessary for me to be part of. aside from a few garbage posters in this thread, this is one the spaces i still like

i may make an appearance at defcon this year but only because work is paying for it and i would like to attend one conference this year

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Loky11 posted:

being told "you don't get LGBT issues" while being LGBT myself and growing up not ever talking about it with people outside my close friends is frustrating. Maybe it's a generational thing. Good luck bringing up things on social media. It's just not my style and try maybe, to at least give people the benefit of the doubt. I will too.

just as a reminder, i am in the LGBTQ+ community myself and i will not ever speak on behalf of those who are not me. heck i will not even talk on behalf of all lesbians or transgender women because that is not what i am here for (i describe myself as "queer woman" and typically refrain from talking about my being trans because it's irrelevant to who i am daily).

it's usually poor form to speak on behalf of the whole community when these matters affect a small subset. we're talking about the treatment of non-men at conferences and not specifically anything else here. i have a problem with infosec because i work in it and have to deal with all sorts of nonsense with it being transphobic, sexist, or just outright ignorance

you may get the issues that you face as part of the LGBTQ+ community but your views do not necessitate everyone as a whole. i am not asexual so i never talk on behalf of those who are aces nor am i bisexual so i cannot comment on their challenges either. this is something that should always remain in mind for anyone under our colourful umbrella as it helps not step on toes

Lain Iwakura fucked around with this message at 21:13 on Jan 16, 2019

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
in sec news on my end, i am finally starting my years long security orchestration project

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

BangersInMyKnickers posted:

global rm -rf / job on puppet

you have no idea how tempting that is

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
yeah. i got one of those e-mails and it had my password from the lastfm breach. it shook me to my bones :laugh:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
can we move on? i am tired of bad opinions in here about non-secfuck stuff

Lain Iwakura fucked around with this message at 02:42 on Jan 18, 2019

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
it won't fit and it would be v17.1, not v18.0 thanks

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/magen_wu/status/1086394054265458689

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
hey. if you're gonna go murdering people...

https://www.runnersworld.com/news/a25924256/mark-fellows-runner-hitman-murder/

quote:

A British runner, cyclist, and mob hitman has been convicted for the murders of two rival gangsters, in part, because of his GPS watch. Mark “Iceman” Fellows, 39, was found guilty by a jury at Liverpool Crown Court of killing organized crime leader Paul “Mr. Big” Massey and his associate John Kinsella, 55 and 53 at the time of their deaths. Massey and Kinsella were also career criminals, part of a gang scene near Manchester, England, with a reputation known across Europe, according to the Manchester Evening News.

Though police already suspected Fellows in Kinsella’s death, it was his Garmin Forerunner that linked him to Massey’s unsolved 2015 murder. While detectives were investigating Fellows, they came across a photo of the suspect wearing his Garmin Forerunner during 2015’s Great Manchester 10K (he ran 47:17, pictured above) two months before the murder of Massey that July. Detectives then located the device at Fellows’s home and checked its GPS data for files that could link him to Massey.

They found that the runner plotted these murders with the attention and precision of any serious athlete, and accordingly, he recorded his recon missions. (Runner’s World has not been able to link Fellows to a public Strava or Garmin account.)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Raere posted:

osint is being intellegent about operating systems

Your Operating System Is Not Trash

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powerful Two-Hander posted:

good to see the speed running community are still setting new times in Hitman

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/shivasinghal00/status/1086665612326105089

simmer down everyone, okay?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
considering that i had met the quadriga cx people at some local event, none of this surprises me

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
anyone ever done some siem integrations into gapps? i'm looking to pull whatever data they have available on there and am looking around to see what others have done

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
we've got a genius in the sec help thread

Carbon dioxide posted:

I think it's nonsense to assume all VPN providers are unsafe.

A lot of the bigger ones have gotten external audits and yes, it turns out they actually don't log poo poo.

Also, even if they log stuff, does it matter whether it's your ISP logging things or some foreign company? I'd rather have it be the latter, because they at least can't be ordered around by *my* government.

For me, the main reason for using a VPN is so that websites I visit don't know where I'm from, because they have no right to that information. On top of that, it allows me to visit websites that are otherwise unavailable because of location-based blocking.

If you're looking for a VPN I suggest starting here: https://thebestvpn.com/

I'm using ExpressVPN now. They're a bit expensive compared to some others but what's nice is that they have a test kit to see if all your data goes through the VPN and actual humans you can talk to if you can't figure it out. There's a bunch of gotchas, such as that normally DNS traffic (the bit of the internet that when you type in 'somethingawful.com' figures out where the server for somethingawful.com is actually located) and ipv6 (new internet protocol standard) traffic go over a plain connection, skipping your VPN entirely. That means websites still can figure out where you're from. The better VPN providers such as ExpressVPN actively help you prevent that.
Tbf I think Nord is a bit lacking in that regard.

:allears:

Lain Iwakura fucked around with this message at 16:13 on Feb 16, 2019

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/KateLibc/status/1098258502714183680

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
nadim is back

https://twitter.com/isislovecruft/status/1098270385148022784

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

so who wrote this crap? their website is all sorts of vague. i am not even sure where to start with an llc search since every state handles it--assuming they even exist

the fact that they are centerzero.org and not .com or whatever is even more weird

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

drop this conversation; it's not even security-related jfc

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
x-posting

Lain Iwakura posted:

So in an effort to get back into doing fun coding things again, I'm going to probably demonstrate how I worked with breach data via Twitch streams. Still trying to come up with an angle I like but I feel like it's time to let people know that I am a terrible software developer and have bad ideas on how I approached the entire mess.

I'm not going to release the Canario source code but I'll probably rewrite it for funsies and dump that on Github as I go along.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply