Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

SIGSEGV posted:

"no more version numbers they are confusing" stupidity

he was right about that

Adbot
ADBOT LOVES YOU

Sharktopus
Aug 9, 2006

yeah its like how am i supposed to memorize every single number that exists????

sure everyone knows 5 is more than 4, but what about 56203 being more than 52300

i wanna know who has the space in their brain to memorize all those dang numbers!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

yeah its like how

i don't think this scenario is quite like how

computer toucher
Jan 8, 2012

spankmeister posted:

GCCS is top govt level like ministers and stuff, NCSC One is more operational so it has more cool people

:agreed:

pseudorandom name
May 6, 2007

Sharktopus posted:

yeah its like how am i supposed to memorize every single number that exists????

sure everyone knows 5 is more than 4, but what about 56203 being more than 52300

i wanna know who has the space in their brain to memorize all those dang numbers!

given that Firefox operates on a fixed six week update cycle, version numbers are fairly useless.

month and year as the version would make more sense

SIGSEGV
Nov 4, 2010


Subjunctive posted:

he was right about that

i'm gonna disagree given his proposed implementation

Nintendo Kid
Aug 4, 2011

by Smythe

pseudorandom name posted:

given that Firefox operates on a fixed six week update cycle, version numbers are fairly useless.

month and year as the version would make more sense

no that's dumb.

it's dumb when ubuntu does it and its dumb here too.

SIGSEGV
Nov 4, 2010


including the release date in the version number makes sense, especially if it is tagged as a date

pretending there aren't actually versions anymore, loving around with the interface all the time, making it uglier and uglier and trying to kill the school/enterprise versions is stupid

EMILY BLUNTS
Jan 1, 2005

[version].[month].[day].[build]

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

EMILY BLUNTS posted:

[version].[month].[day].[build]

219.420.69.1488

Deacon of Delicious
Aug 20, 2007

I bet the twist ending is Dracula's dick-babies

Sharktopus posted:

yeah its like how am i supposed to memorize every single number that exists????

sure everyone knows 5 is more than 4, but what about 56203 being more than 52300

i wanna know who has the space in their brain to memorize all those dang numbers!

it's not too bad, the biggest number is only 24

spankmeister
Jun 15, 2008






i use goog :chome: and idc about the version b/c it just updates itself

SIGSEGV
Nov 4, 2010


spankmeister posted:

i use goog :chome: and idc about the version b/c it just updates itself

i care about such things because i used to be bothered by inflexion points in the texture of those grainy paints when i was younger (and still am more than i'm comfortable with)

Raere
Dec 13, 2007

cyber warfare translates to wizard warfare which sounds really cool

PleasingFungus
Oct 10, 2012
idiot asshole bitch who should fuck off

EMILY BLUNTS posted:

[version].[month].[day].[build]

SIGSEGV
Nov 4, 2010


i wonder what he'll put in the version number when the people ingame will achieve sapience

a cyberpunk goose
May 21, 2007


lol loving children

spankmeister
Jun 15, 2008






:siren: MS15-034 is now winbleed :siren:

https://twitter.com/julianor/status/588434794595385344
https://twitter.com/julianor/status/588471579186700288

EMILY BLUNTS
Jan 1, 2005

it would have been wittier to reference something about rolling backwards
oh well

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.
epic winbleed

computer toucher
Jan 8, 2012


so you can get a few bytes from the machine your exploit then bluescreens? Doesn't seen very exploitable if I understood correctly what this does.

spankmeister
Jun 15, 2008






computer toucher posted:

so you can get a few bytes from the machine your exploit then bluescreens? Doesn't seen very exploitable if I understood correctly what this does.

depends, it needs further investigating

computer toucher
Jan 8, 2012

spankmeister posted:

depends, it needs further investigating

I will rate this a solid "maybe" on a scale of "lol" to "omg".

pseudorandom name
May 6, 2007

it's a remote kernel exploit, you can extract literally anything if you upload the right payload

computer toucher
Jan 8, 2012

pseudorandom name posted:

it's a remote kernel exploit, you can extract literally anything if you upload the right payload

I'm not quite understanding the nature of this exploit - how does it exactly work? It's not a RCE though. How does the payload determine what ends in the dump? Can you target it? If it comes from memory, doesn't ASLR mitigate targeting some important part of the memory to retrieve, for example, private keys? Does this exploit also crash the server or can you just string requests together to extract data from memory?

Rizzo says he can get "extra bytes", which doesn't sound very scary unless there's a way to string together various requests or build a payload that will return more than just a few bytes.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
it won't be another heartbleed because no one uses iis for important poo poo

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Parallel Paraplegic posted:

because they're a windows user and they don't have any actually useful programs on windows

windows doesn't come with telnet either though

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

ymgve posted:

it won't be another heartbleed because no one uses iis for important poo poo

IIS is used for a tonne of important poo poo, it's just that not much of it is publicly accessible

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



our head cj punked us all this morning by changing a setting in the internal proxy server to strip any http headers not on a white list

notably not included in the built-in list was Access-Control-Allow-Origin

oh hey why are all of our client integrations looking broken suddenly

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Shaggar is too silent on this matter

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?





ruhroh

Hed
Mar 31, 2004

Fun Shoe
wasn't that very mainframe in that DEFCON talk that someone in here gave (along with all the cool GIFs)?

Wiggly Wayne DDS
Sep 11, 2010



it's only been network accessible for at least a year

vOv
Feb 8, 2014

Munkeymon posted:

our head cj punked us all this morning by changing a setting in the internal proxy server to strip any http headers not on a white list

notably not included in the built-in list was Access-Control-Allow-Origin

oh hey why are all of our client integrations looking broken suddenly

why would you even do that

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Hed posted:

wasn't that very mainframe in that DEFCON talk that someone in here gave (along with all the cool GIFs)?

ya, thats me

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Wiggly Wayne DDS posted:

it's only been network accessible for at least a year

Well, last year it wasn't full of all those cool programs:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Hed posted:

wasn't that very mainframe in that DEFCON talk that someone in here gave (along with all the cool GIFs)?
that someone is the poster above you, what you should really be asking yourself is who @mainframed767 is :ssh:

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



vOv posted:

why would you even do that

"you can have malicious headers, right?"

the cto has him on a security kick because he (cto) wants to look good to a potential buyer so he can get his payout and retire

they're talking about taking away my local admin rights because some poo poo idiot ~web designer~ was running a pirate bay branded torrent client (and the malware that came with it lol) so letting devs install stuff on they own machines is now scary and dangreous

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Countries YOSPOS cannot visit so far:
Russia
Egypt

Adbot
ADBOT LOVES YOU

Luigi Thirty
Apr 30, 2006

Emergency confection port.

fly safe security ghost

  • Locked thread