Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

that stinks of a misconfigured pulse vpn portal using the old network connect client

Adbot
ADBOT LOVES YOU

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
its actually array networks https://ouvpn-us.oracle.com

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

lol gross

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


i just wish that either we could use a version of kronos that doesnt require java or hr would go back to doing their job so we dont need to use kronos

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

my employer uses kronos and it doesn't integrate at all with our industry-specific groupware/ERP vendor so i have to manually enter my weekly time tracking in like 3 and a half different places. one of them is a Word doc where i put different client names all right next to each other, totally not a privacy issue at all (jk it probably is)

Michael Transactions
Nov 11, 2013

Looks like we got another gently caress up fellas. LOL

(USER WAS PUT ON PROBATION FOR THIS POST)

cybrancyborg
Jan 24, 2008

How this ends still hasn't been unwritten...

duz posted:

i just wish that either we could use a version of kronos that doesnt require java or hr would go back to doing their job so we dont need to use kronos

Specifically Java 1.7u9? 'cause my employer thinks that will work fine, forever.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
as per usual, a lot of non-technical people are mad that taviso dropped it at the 90-day deadline

https://twitter.com/taosecurity/status/1138490944347619329

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

qa delays from the company that fired practically all their qa people? lets give them the benefit of the doubt here

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
people: we want microsoft to be more responsive to security issues

also people: we want microsoft to stop blowing up our machines with half-baked updates

microsoft:

Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

qa delays from the company that fired practically all their qa people? lets give them the benefit of the doubt here

well yeah they're not the microsoft of 1999 anymore they're the microsoft of 2019 and they don't write bugs into the software anymore so they don't need qa :colbert:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
qa is just a subset of development, right? we already pay developers, so why would we pay for qa?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
beta tested in the future

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
have i been pwned is up for sale

https://www.troyhunt.com/project-svalbard-the-future-of-have-i-been-pwned/

dougdrums
Feb 25, 2005
CLIENT REQUESTED ELECTRONIC FUNDING RECEIPT (FUNDS NOW)
Who needs a qa department when you have github?

Kazinsal
Dec 13, 2011



I honestly don't get how companies don't have any email from taviso immediately go to every important security person plus maybe their phone system to ring a few SIP enabled klaxons

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


cybrancyborg posted:

Specifically Java 1.7u9? 'cause my employer thinks that will work fine, forever.

probably, i know i have to keep acknowledging that it is insecure for it to display anything

Diva Cupcake
Aug 15, 2005

Lain Iwakura posted:

as per usual, a lot of non-technical people are mad that taviso dropped it at the 90-day deadline
should we really be considering Bejtlich non-technical?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Diva Cupcake posted:

should we really be considering Bejtlich non-technical?

in this case, yes

Potato Salad
Oct 23, 2014

nobody cares


how does troy hunt not want to make a larger security company out of pwned? does he just not want to raise capital himself?

He's sitting on one of the most universally beloved security tools of the decade and doesn't want to build a company out of it himself?

flakeloaf
Feb 26, 2003

Still better than android clock

lots of great cooks would make lovely restauranteurs

Proteus Jones
Feb 28, 2013



Potato Salad posted:

how does troy hunt not want to make a larger security company out of pwned? does he just not want to raise capital himself?

He's sitting on one of the most universally beloved security tools of the decade and doesn't want to build a company out of it himself?

Doesn't he have an actual day job and a young family? The way the site has exploded these last few years I can imagine he's entering burn-out territory.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Potato Salad posted:

how does troy hunt not want to make a larger security company out of pwned? does he just not want to raise capital himself?

He's sitting on one of the most universally beloved security tools of the decade and doesn't want to build a company out of it himself?

He answered that question in the blog post. He wants to actually be able to take time off, not have to worry about growing a business with VC funding or anything right now.

Trabisnikof
Dec 24, 2005

Potato Salad posted:

how does troy hunt not want to make a larger security company out of pwned? does he just not want to raise capital himself?

He's sitting on one of the most universally beloved security tools of the decade and doesn't want to build a company out of it himself?

he's working with kpmg's m&a group and promises to stay with the company after its sold. so basically he's skipping all those steps and going straight to the payout/aquihire stage

Wiggly Wayne DDS
Sep 11, 2010



Potato Salad posted:

how does troy hunt not want to make a larger security company out of pwned? does he just not want to raise capital himself?

He's sitting on one of the most universally beloved security tools of the decade and doesn't want to build a company out of it himself?
he's sitting on a trove of questionably sourced dumps with public access and an expectation for it to forever expand and let's ignore the legal pitfalls with a global userbase

getting out now is a bit late tbh, and i seriously question how universally beloved it is. it's a good pr tool at most

Agile Vector
May 21, 2007

scrum bored



infernal machines posted:

i don't know how that guy isn't waking up with a horse's head in his bed every day

what and turn down all that free horse meat?

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
it's me, im the sec fuckup that clicked the obvious One Drive phishing link from a clearly compromised client (i did not give credentials but lol if I didn't blindly click those links).

I should just not use the internet when I'm tired. or at all.

Soricidus
Oct 21, 2010
freedom-hating statist shill

Perplx posted:

they are up to java 12 but only java 8 will work in a browser (IE 11 is the only java capable browser now)
they still patch java 8 but it is behind an oracle login now

since oracle is incompetent and evil to this day you need ie11, java8 and ActiveX to install vpn software to get at their remote training environment

don’t worry I’m sure someone is working on a java applet interpreter in wasm or something

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Ur Getting Fatter posted:

it's me, im the sec fuckup that clicked the obvious One Drive phishing link from a clearly compromised client (i did not give credentials but lol if I didn't blindly click those links).

I should just not use the internet when I'm tired. or at all.

I really wish microsoft could figure out how to effectively filter those because they explicitly target o365 domains and it's a huge pain in the dick explaining to clients why they can't actually trust shared document links sent from people they know irl because there's a good chance it's one of these

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
lmao. literally just had a client in o365 almost certainly hit by one of these. whoever got their credentials used it to organize a wire transfer for like $30k $50k, which the bank happily processed entirely via email

fml

e: n/m they flagged it and it didn't go through, well good new there i guess

e2: they flagged it as suspicious, then the account manager violated policy and processed the transaction anyway.

lmao. someone is getting hosed for this.

infernal machines fucked around with this message at 23:12 on Jun 12, 2019

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

he's sitting on a trove of questionably sourced dumps with public access and an expectation for it to forever expand and let's ignore the legal pitfalls with a global userbase

the "questionably sourced dumps" part combined with massive burn out is why i got out of this

evil_bunnY
Apr 2, 2003

BangersInMyKnickers posted:

qa delays from the company that fired practically all their qa people? lets give them the benefit of the doubt here
Yeah I was suprised Tavis didn't mention that to the dweeb. You don't get QA extensions after you get rid of your QA folks.

Applebees
Jul 23, 2013

yospos

quote:

Also, the PoC uses terminal escape sequences to hide the modeline when the content is printed with cat. (cat -v reveals the actual content.)

Is this default behaviour of cat useful for anything other than tricking people?

Raere
Dec 13, 2007

jfc Microsoft 90 days is enough to develop a patch, test it, and deploy. Devs should be starting work on day 1 on an e-mail from taviso. It's not asking for an entire service pack, it's to fix a bug or two. Get your poo poo together.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
otoh the bug is in every secure channel thing in every version of windows, so wherever it's located it's exposed to a lot of stuff. possibly stuff that breaks in exciting ways if some specific stupid behaviour changes

Wiggly Wayne DDS
Sep 11, 2010



okay alternative scenario: this is being actively exploited in the wild. can you solve it in 90 days?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Kazinsal posted:

I honestly don't get how companies don't have any email from taviso immediately go to every important security person plus maybe their phone system to ring a few SIP enabled klaxons

I wonder how to do that in gsuite.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Subjunctive posted:

I wonder how to do that in gsuite.

Sorry, the klaxons were deprecated after everyone got promotions due to lower than expected usage

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Subjunctive posted:

I wonder how to do that in gsuite.

i think it goes something like this

https://www.youtube.com/watch?v=BpsMkLaEiOY

Adbot
ADBOT LOVES YOU

30 TO 50 FERAL HOG
Mar 2, 2005



to be fair I don't think the button on any smoke detector ive ever owned actually silences the loving thing

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply