Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Soricidus
Oct 21, 2010
freedom-hating statist shill

Boiled Water posted:

friends don't let friends telnet jesus

jesus is always listening, even on port 23

Adbot
ADBOT LOVES YOU

abigserve
Sep 13, 2009

this is a better avatar than what I had before
There's No Key To Dial Jesus And His Words Are Always Clear Text

Partycat
Oct 25, 2004

In this case assuming the traffic is not being captured , telnet or SSH or whatever doesn’t matter - same dif

The Fool
Oct 16, 2003


i didn't know telnet supported cert authentication

Soricidus
Oct 21, 2010
freedom-hating statist shill

The Fool posted:

i didn't know telnet supported cert authentication

$ telnet secure.yourcompany.biz
login: root
is your certificate valid? [Y/n] :ins:

DrPossum
May 15, 2004

i am not a surgeon
Just tunnel telnet over ssh

Soricidus
Oct 21, 2010
freedom-hating statist shill
ok i configured telnetd to listen on port 22 instead, that's what you meant right?

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
one time I added a nginx block to respond with the exact header response some metasploit script was expecting based on the hardcoded input, instead of fixing the CVE. is that a fuckup?

(the exploit only applied to apache but the testers dont understand that for some reason)

Potato Salad
Oct 23, 2014

nobody cares


DrPossum posted:

Just tunnel telnet over ssh

Life got way easier when I first put a foot down and insisted DBAs use ssh to the exclusion of everything else for remote access

Shaggar
Apr 26, 2006
why would a dba be using ssh or telnet?

Luigi Thirty
Apr 30, 2006

Emergency confection port.

why would a DBA not use SQL Server Management Studio?

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Lain Iwakura posted:

newer hyundais run android. there's an escape for my 2017 ioniq floating about that is more or less useless for me since i use iOS

the password to get into engineering mode is literally the clock's time


which clock though?

ewiley
Jul 9, 2003

More trash for the trash fire

Soricidus posted:

jesus is always listening, even on port 23

Jesus take the Sguil

DrPossum
May 15, 2004

i am not a surgeon
jesus sees all my dirty bits

Crime on a Dime
Nov 28, 2006
nazi pants fall off

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Crime on a Dime posted:

nazi pants fall off

now im thinking of the song with these lyrics and im lollin at work

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Athena Health are a bunch of dipshits who don't know email from the puddle of brain that leaked out the side of their idiot heads

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

waa waa waa! you're email gateway isn't secure because it doesn't enforce strict TLS transport and RC4 is on despite it not having a viable attack vector on SMTP.

waa waa waa! you broke delivery of our loving temp password emails when you turned on strict transport because we send those plaintext.

waa waa waa! our stuff is getting sinkholed because our lovely IPs are on a million block lists because our boxes keep getting popped and we don't check mail logs for the very clear notification message that comes back.

30 TO 50 FERAL HOG
Mar 2, 2005



email is always bad, just move to exchange in teh cloud and never touch it again imo

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Shaggar posted:

why would a dba be using ssh or telnet?

tunnelling traffic through a bastion server imo

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

BangersInMyKnickers posted:

Athena Health are a bunch of dipshits who don't know email from the puddle of brain that leaked out the side of their idiot heads

all healthcare IT is and will forever remain a dumpster fire, moreso than regular IT

one of my fave epic systems cool features was the "use TLS when communicating with the DB" switch that did literally nothing (or maybe something, but definitely didn't turn on TLS) and went unnoticed forever until the navy finally bothered to look at some pcaps.

when NMCI is somehow more on the ball than you wrt IT best practices you've hosed up p drat hard.

Workaday Wizard
Oct 23, 2009

by Pragmatica

florida lan posted:

one of my fave epic systems cool features was the "use TLS when communicating with the DB" switch that did literally nothing (or maybe something, but definitely didn't turn on TLS) and went unnoticed forever until the navy finally bothered to look at some pcaps.

can they get sued for fraud? :kiddo:

Soricidus
Oct 21, 2010
freedom-hating statist shill

florida lan posted:

one of my fave epic systems cool features was the "use TLS when communicating with the DB" switch that did literally nothing (or maybe something, but definitely didn't turn on TLS)

for efficiency, instead of wasting valuable resources on encryption, it just flipped the tcp "treat as encrypted" bit, which the nsa and other surveillance agencies have all solemnly promised to respect

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



servers could have been configured with null_null fallback the "we tried nothing and nothing worked" of encryption

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Munkeymon posted:

servers could have been configured with null_null fallback the "we tried nothing and nothing worked" of encryption

i would die laughing if the "use TLS" option deliberately negotiated TLS_NULL_WITH_NULL_NULL on both sides

Potato Salad
Oct 23, 2014

nobody cares


Pass your security audit with this one WEIRD trick!

socket dumps to /dev/null

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Shame Boy
Mar 2, 2010


i sat here for like 10 to 15 seconds carefully reading the left-hand text to figure out why you'd link this, then was just like "oh" out loud

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


im very immature

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
Pounded in the Butt by my Law Enforcement Network

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

Ur Getting Fatter posted:

Pounded in the Butt by my Law Enforcement Network

Midjack
Dec 24, 2007



Ur Getting Fatter posted:

Pounded in the Butt by my Law Enforcement Network

pseudorandom name
May 6, 2007

good news everyone Intel is pushing out microcode updates for new CVEs that become public on the 14th

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

pseudorandom name posted:

good news everyone Intel is pushing out microcode updates for new CVEs that become public on the 14th

hell yeah I love microcode updates

haveblue
Aug 15, 2005



Toilet Rascal

Ur Getting Fatter posted:

Pounded in my Law Enforcement Network by the Butt

post hole digger
Mar 21, 2011


lol new jersey

FMguru
Sep 10, 2003

peed on;
sexually
this times 1000

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

BangersInMyKnickers posted:

hell yeah I love microcode updates

gentlemen, update your boot loafers

pseudorandom name
May 6, 2007

BangersInMyKnickers posted:

hell yeah I love microcode updates

looks like there's also OS updates to go along with it and OS devs aren't happy that Lenovo leaked the CVE reveal dates.

Adbot
ADBOT LOVES YOU

evil_bunnY
Apr 2, 2003

pseudorandom name posted:

good news everyone Intel is pushing out microcode updates for new CVEs that become public on the 14th
loving urgh

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply