Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Lucky goldstar (LG) is what you may say out loud when using LG stuff. Unfortunately, today I have to tell you that lucky is not so goldstar.

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

du -hast posted:

it's me, im the guy who goes to a security conference to pick up women :rms:
yeah who would do that in vegas :confused:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
that's the Manjaro Linux difference. Enjoy the simplicity

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Aleksei Vasiliev posted:

The certificate expired on 4/6/2015 1:42 AM. The current time is 4/9/2015 2:42 AM.
3 days without a fix and according to the forums they have a HSTS header so it's entirely unusable to any browser that's ever visited it before
also unless i misunderstood something (probably, lol timezones) their "fix" sets you to 18 minutes post-expiration
it's a little under 11 hours pre-expiration

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

cannot wait to see peerio get breached now...


yes. please piss on moxie there, nadim. it's not going to lead you down a road of hurt at all
jfc that last paragraph

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Nintendo Kid posted:


From CSI: Cyber S1E5 “Crowd Sourced”. Supposedly, this is the source code of a web site that interfaces with a bomb– and more specifically, a “dead man’s switch” that immediately detonates the bomb if any of the code is modified.
to be fair this is a lot better than some random webpage or github project

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Carbon dioxide posted:

Back in my high school, it was fine to play browser games or do whatever on the library computers, as long as there weren't any kids waiting to use the computers for actual school work. They usually didn't even mind if you hacked it somewhat, because that allowed the IT guy to see where he could improve the system security.

I got detention once, for subverting their block on chat protocols. I think I managed to log in to MSN Messenger or somesuch. I got detention because chatting from the school computers was absolutely banned. They said the reason was that online communities are full of rapists and the school didn't want any possibility of being held responsible if someone meets their future rapist online.
my school had a ban on forums and instant messenger but i never got an explanation for it. and i was a lil smartass so i argued with him that if instant messaging was banned how come email wasn't????

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cheese-cube posted:

also don't buy symantec
a v controversial post

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

UAC has had an elevation bypass vuln since Win7 preview builds and Microsoft has refused to fix it all the way up through Win10 because "UAC is not a security feature" even though it clearly is and they have said as much numerous times
tbf it's not very strange for microsoft to admit that UAC isn't actually intended for their customers' security, it's actually there to make their users hate their product

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ultramiraculous posted:

cheese-cube,

seriously this whole thing sounds like a complete poo poo show. you have prod servers running unknown code and a proxy into your network.

burn all of it down before you're found to be in possession of child snuff porn and running a tor node for isis.
how did you gently caress up Parallel Paraplegic's name like that

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Mr.Radar posted:

remember that dlink router exploit that let anyone run root commands with no authentication? turns out dlinks patch not only doesnt fix the problem but actually introduces a new bug which can be exploited exactly the same way.


lmao

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Sharktopus posted:

paging shager to tell us why this is user error
wait a week or two for the QA team to finish and he'll tell you

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
why does it have to be telnet and not like, netcat or wget or something

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
according to this tweet if you do this
code:
curl -v -H "Range: bytes=234234-28768768" "http://host/a.png" -o a.png
and it returns HTTP 416 = vuln, and HTTP 20X = not

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Parallel Paraplegic posted:

does a.png actually have to exist? because I'm getting 404.


EDIT: tried it with a file I knew to exist and it returned 416 woo
it looks like you got a 416 on the telnet one too

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

canis minor posted:

sorry, i don't like wizards :(
mods please ban this bigot

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Hed posted:

wasn't that very mainframe in that DEFCON talk that someone in here gave (along with all the cool GIFs)?
that someone is the poster above you, what you should really be asking yourself is who @mainframed767 is :ssh:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
and now it's microsoft's problem :newlol:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Segmentation Fault posted:

Honestly just skip the private disclosure step and make it public. Lighting a fire underneath a dev's rear end (particularly a gamedev) is the only way to get them to do anything
and sometimes not even then, like when super meat boy had a mysql server open to the internet

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
stanford's online crypto i course begins in an hour

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
but how am i supposed to fly the plane without hacking it first

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

pseudorandom name posted:

do they have stuff like "access control lists" for the "remote procedure calls" that prevent "invocation" of the "cancel the autopilot" and "enter simulation mode" methods?
sounds like someone wants a lil visit from the feds

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Winkle-Daddy posted:

Anyone else sign up for the Stanford crypto course getting errors? On this page: https://www.coursera.org/course/crypto the green link to the course is grayed out and says "Starts 10 hours ago". When I go to my dashboard and click to resume the course, I get the error "Error Message: Sorry, this class site is currently closed. Please check back later. We will send you another email when the class opens." Do these things normally open up "sometime" during the day they're supposed to start? Or did I get kicked out somehow?
if you click on that button it says they'll send you an email when it starts

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Winkle-Daddy posted:

it just seems weird that it said it started 10 hours ago and that it's not open yet. they need to fix their messaging because it just looks kinda broken, imo.
yes, we get it, you've never taken an online college course before

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

yeah I'm not even bothering looking at the coursework for crypto I until tomorrow night. its structured in weekly blocks, get to it when you can
the first problem set is due may 14, you've got plenty of time

here's the syllabus:

week 1
  • Background and overview.
  • One-time encryption using stream ciphers.
  • Semantic security.
week 2
  • Block ciphers and pseudorandom functions.
  • Chosen plaintext security and modes of operation.
  • The DES and AES block ciphers.
week 3
  • Message integrity. CBC-MAC, HMAC, PMAC, and CW-MAC.
  • Collision resistant hashing.
week 4
  • Authenticated encryption. CCM, GCM, TLS, and IPsec.
  • Key derivation functions.
  • Odds and ends: deterministic encryption, non-expanding encryption, and format preserving encryption.
week 5
  • Basic key exchange: Diffie-Hellman, RSA, and Merkle puzzles.
  • A crash course in computational number theory.
  • Number theoretic hardness assumptions.
week 6
  • Public key encryption.
  • Trapdoor permutations and RSA.
  • The ElGamal system and variants.

anthonypants fucked around with this message at 23:12 on Apr 20, 2015

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
since when is loving websense a "cybersecurity" company

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Winkle-Daddy posted:

I'm the
code:
char big_b00bz[] =
text me

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Nintendo Kid posted:

security fuckup: the massachusetts dmv or whatever's custom license plate page:

http://www.massrmv.com/vanityplaterequirements.aspx
works for me

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

MALE SHOEGAZE posted:

the more you fill me up, the happier i am
https://www.youtube.com/watch?v=54OYS_mZlBE

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

EAT THE EGGS RICOLA posted:

someone link the website that has a timeline of when cryptocat had which vulnerabilities pls
here you go: http://tobtu.com/decryptocat.php

also, before there was a twitter bot of deleted nadim tweets, there was a tumblr, which used to be at cryptocat.tumblr.com until nadim gave tumblr a takedown notice and made them change the name

cryptocat.tumblr.com is blank and unused, of course

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

uncurable mlady posted:

gf probably has better opsec than the militaries of several small nations, combined
remember when vilerat threatened to offline core stations in illum because someone leaked his awful tattoo pic

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Iridium posted:

sorry, a little behind and a little irrelevant, but

https://soundcloud.com/shutupandshave/gently caress-goons
on the opposite spectrum https://www.youtube.com/watch?v=Vfv1QtZDirY

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

hobbesmaster posted:

which part? ffxiv is unplayable for me on twc but works perfectly using battleping. I didn't believe it either until I personally experienced it
i've heard this from other people too, i can only guess that it gets around traffic shaping/qos that isps totally don't do

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Erwin posted:

not sure what's worse, the "roll your own crypto" morons or the "I have a degree in this stuff" anime idiot
she's actually really good and not an idiot at all :ssh:

https://www.youtube.com/watch?v=5N1C3WB8c0o

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Optimus_Rhyme posted:

Oh also, wish me luck yossec, I'm about to go tell IBM how to fix their mainframe poo poo
:hellyeah:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Chris Knight posted:

lol if you don't follow @afreak

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Winkle-Daddy posted:

I don't follow afreak, but I'm being quoted often enough it wouldn't be a bad idea to do the Twitter thing. Is it bad form to steal from the "if I were a cyberpunk my handle would be..." thread?
see if anyone else on twitter is using it first

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

i know exactly where you stole that joke from buddy
my guess is el reg

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Tiny Bug Child posted:

sorry weev is not and has never been a nazi
lmao if you believe this

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
my bank has a three-factor auth thing for when i log in from a computer i haven't set the cookie on, the two extra factors are four-digit pin and security question, and i just found out that the security questions only cares about the first six characters in the security answer. lol banks

e: actually it's not the first six characters but it does let you omit or replace a few characters on the end, and how many characters you can replace looks like a percentage of the length of each answer

anthonypants fucked around with this message at 11:24 on May 9, 2015

  • Locked thread