Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Also: https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce

18 year old college student punches App Engine, $36k falls out.

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

rjmccall posted:

cache reveals everything around me

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

rjmccall posted:

cache reveals everything around me

:drat:

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

rjmccall posted:

cache reveals everything around me

Samuel L. ACKSYN
Feb 29, 2008


the pentium was a mistake


im going back to a 486, its the year of windows 3.1 on the desktop

Raere
Dec 13, 2007

Schadenboner posted:

Is encryption of swap a thing?

absolutely

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

rjmccall posted:

cache reveals everything around me

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


mrmcd posted:

Also: https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce

18 year old college student punches App Engine, $36k falls out.

Please stop exploring this further, as it seems that you could easily break something using these internal APIs.

always a good sign

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

rjmccall posted:

cache reveals everything around me

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


https://www.politico.com/story/2018/05/21/trump-phone-security-risk-hackers-601903

Pile Of Garbage
May 28, 2007



rjmccall posted:

cache reveals everything around me

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Hey, if Baron says it's ok, I'm sure it's fine

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

rjmccall posted:

cache reveals everything around me

Potato Salad
Oct 23, 2014

nobody cares


mrmcd posted:

Also: https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce

18 year old college student punches App Engine, $36k falls out.

I'm the $35k payout with a $1,337 bonus.

Potato Salad
Oct 23, 2014

nobody cares



It's okay, I'm using [VPN service lacking per-customer out of band key exchange]

Schadenboner
Aug 15, 2011

by Shine

Potato Salad posted:

I'm the $35k payout with a $1,337 bonus.

Nice N1c3!

ozymandOS
Jun 9, 2004

rjmccall posted:

cache reveals everything around me

Achmed Jones
Oct 16, 2004



it was $31337 for rce and $5k for a different issue

Shame Boy
Mar 2, 2010


quote:

The president uses at least two iPhones, according to one of the officials. The phones — one capable only of making calls, the other equipped only with the Twitter app and preloaded with a handful of news sites — are issued by White House Information Technology and the White House Communications Agency, an office staffed by military personnel that oversees White House telecommunications.

lmao they gave him a phone just for twitter and fox news presumably because he kept trying to install twitter on his other secret white house phone

e: lmao

quote:

The White House declined to comment for this story, but a senior West Wing official said the call-capable phones “are seamlessly swapped out on a regular basis through routine support operations. Because of the security controls of the Twitter phone and the Twitter account, it does not necessitate regular change-out.”

Trump’s call-capable cellphone has a camera and microphone, unlike the White House-issued cellphones used by Obama. Keeping those components creates a risk that hackers could use them to access the phone and monitor the president’s movements. The GPS location tracker, however — which can be used to track the president’s whereabouts — is disabled on Trump’s devices.

The West Wing official refuted the idea that the presence of a camera and microphone on the president’s phone posed any risk, telling POLITICO, “Due to inherent capabilities and advancement in technologies, these devices are more secure than any Obama-era devices.”

we got the most securest twitters and cameras unlike obama

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

quote:

Trump’s call-capable cellphone has a camera and microphone, unlike the White House-issued cellphones used by Obama.

they gave Obama a phone without a mic? he’d just listen and send back DTMF?

Potato Salad
Oct 23, 2014

nobody cares


Like, if you're living in DC and have access to even middling funds and support from an XYZ-istani intelligence agency, how could you resist loving stinging the everliving poo poo out of the mobile device of POTUS and his staff

His phone is a playground for script kiddies with cheap wifi APs and nation states with stingers alike

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Potato Salad posted:

Like, if you're living in DC and have access to even middling funds and support from an XYZ-istani intelligence agency, how could you resist loving stinging the everliving poo poo out of the mobile device of POTUS and his staff

the threat of going to prison forever, OP

Shame Boy
Mar 2, 2010

Subjunctive posted:

they gave Obama a phone without a mic? he’d just listen and send back DTMF?

literally yes, they did - if you read the full article his phone couldn't even make calls and he described it as "a toy phone you'd give a 3 year old"

redleader
Aug 18, 2005

Engage according to operational parameters

Lutha Mahtin posted:

the threat of going to prison forever, OP

yes the threat of prison is a well-known deterrent that has completely solved the problem of foreign intelligence operatives

Potato Salad
Oct 23, 2014

nobody cares


Lutha Mahtin posted:

the threat of going to prison forever, OP

lol selling out or beating your wife is how you get a loving appointment these days

spankmeister
Jun 15, 2008






rjmccall posted:

cache reveals everything around me

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

rjmccall posted:

cache reveals everything around me

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Raere posted:

absolutely

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

can we just change the thread title already?

akadajet
Sep 14, 2003


neat

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Oh yeah, there's this too:

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Subjunctive posted:

can we just change the thread title already?
:yossame:

rjmccall posted:

Security Fuckup Megathread - v16.1 - cache reveals everything around me

crazysim
May 23, 2004
I AM SOOOOO GAY

BangersInMyKnickers posted:

Oh yeah, there's this too:



it would be awesome if that interacted with the encryption one to do a "throw away key" delete. but i doubt it does and i guess it's still not really "clearing".

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

crazysim posted:

it would be awesome if that interacted with the encryption one to do a "throw away key" delete. but i doubt it does and i guess it's still not really "clearing".

Yeah, that does a zero overwrite on the blocks allocated to the pagefile so the data isn't recoverable. The EFS encryption of the pagefile doesn't have the concept of disposable keys like you are describing to my knowledge.

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

rjmccall posted:

cache reveals everything around me

jammyozzy
Dec 7, 2006

Is that a challenge?
The other day I put a '#' in my WebEx password and now I cannot login through our web portal, although the desktop connection tools program still works fine.

I'm not even sure if this counts as a real secfuck or not but it's bloody annoying all the same. :thumbsup:

haveblue
Aug 15, 2005



Toilet Rascal

jammyozzy posted:

The other day I put a '#' in my WebEx password and now I cannot login through our web portal, although the desktop connection tools program still works fine.

I'm not even sure if this counts as a real secfuck or not but it's bloody annoying all the same. :thumbsup:

it could probably be upgraded easily to a secfuck because someone is sanitizing inputs wrong

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Potato Salad posted:

Like, if you're living in DC and have access to even middling funds and support from an XYZ-istani intelligence agency, how could you resist loving stinging the everliving poo poo out of the mobile device of POTUS and his staff

as if every network tech in dc doesn't have a half-dozen business cards for three letter agencies on their cube wall

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

by "XYZ-istani" they meant other countries

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

still holds, they just don’t know it

  • Locked thread