Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

CRIP EATIN BREAD posted:

do you think the cops will care at all in this situation? they're not going to arrest the guy, nor are they going to investigate it. they aren't equipped for this sort of thing.

yeah, they'll tell you it's a civil matter most likely, unless someone is itchy to flex their CYBER TERROR law or something

Adbot
ADBOT LOVES YOU

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Could be vandalism, but lol if the cops will understand let alone give a poo poo.

Clark Nova
Jul 18, 2004

the cops will like the cut of his jib and offer him a job as their new sysadmin

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

you can make the computer racist???

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

here is one million taxpayer dollars

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

BangersInMyKnickers posted:

you can make the computer racist???

always has been

Pile Of Garbage
May 28, 2007



Soricidus posted:

I’m saying two things: 1. it is rather implausible that any part of the British civil service had a policy of hiring 50% women before 1946, given the incredibly misogynistic policies that were definitely in place; and 2. it is rather implausible that they decided during the Bletchley era that it was useful for employees to marry each other, given that they literally lost an employee any time that happened

I’m not sure which of those statements requires me to be high but I sure wish I was

1. my bad! you're specifically talking to what goddamnedtwisto said

goddamnedtwisto posted:

gchq has had a policy of employing 50% women since its establishment

i don't think there was ever such a policy and in my previous posts i was referring more to organic processes that would have lead to a higher than usual for the time employment of women.

2. the perceived benefits around inter-service marriage was re background checks and vetting, specifically risk mitigation rather than workforce availability. idk if it was an actual policy but UK intel services have a hilarious track record when it comes to being drilled by the KGB, e.g. kim philby (and i'm inclined to believe peter wright's allegation that former MI5 director roger hollis was a KGB agent).

also i apologise for saying that you were high, that was crass and rude!

Soricidus
Oct 21, 2010
freedom-hating statist shill
no worries I agree with the things you have just said and there’s nothing wrong with a little rudeness in the pos

EIDE Van Hagar
Dec 8, 2000

Beep Boop

xtal posted:

Canada is an American client state so all of our agencies are modeled after the American one but we need to put a C in so it doesn't look like one of theirs

i heard the canadian intelligence agency did bay of pigs can you confirm

Pile Of Garbage
May 28, 2007



i don't recall canada issuing any apologies to cuba so it's not likely :D

Wiggly Wayne DDS
Sep 11, 2010



neat https://bugs.chromium.org/p/project-zero/issues/detail?id=2070

Issue 2070: Github: Widespread injection vulnerabilities in Actions posted:

Github Actions supports a feature called workflow commands
(https://docs.github.com/en/actions/reference/workflow-commands-for-github-actions) as a
communication channel between the Action runner and the executed action. Workflow commands are
implemented in runner/src/Runner.Worker/ActionCommandManager.cs
(https://github.com/actions/runner/blob/0921af735a3c8fb6cf22ddc8a868b742816e24cf/src/Runner.Worker/ActionCommandManager.cs)
and work by parsing STDOUT of all executed actions looking for one of two
command markers.

V2 commands have to start at the beginning of a line and look like this “::workflow-command
parameter1={data},parameter2={data}::{command value}”. V1 commands can also start in the middle of
a line and have the following syntax: “##[command parameter1=data;]command-value”. The current
version of the Github action runner supports a small number of different commands but the most
interesting one from a security perspective is “set-env”. As the name suggests, “set-env” can be
used to define arbitrary environment variables as part of a workflow step. A simple example (in V1
syntax) would be ##[set-env name=VERSION;]alpha, which puts VERSION=alpha in the environment of all
succeeding steps in a workflow.

The big problem with this feature is that it is highly vulnerable to injection attacks. As the
runner process parses every line printed to STDOUT looking for workflow commands, every Github
action that prints untrusted content as part of its execution is vulnerable. In most cases, the
ability to set arbitrary environment variables results in remote code execution as soon as another
workflow is executed.
I’ve spent some time looking at popular Github repositories and almost any project with somewhat
complex Github actions is vulnerable to this bug class. A couple of examples to show how this bug
can be exploited in practice:

VSCode and CopyCat:

VSCode has a workflow for newly opened issues which runs
https://github.com/microsoft/vscode-github-triage-actions/blob/master/copycat/CopyCat.ts to copy
new issues into other repositories. As CopyCat prints the untrusted issue.title to stdout, it is
vulnerable to a workflow command injection.
Exploiting this instance is as easy as opening a new issue with the title “##[set-env
name=NODE_OPTIONS;]--experimental-modules
--experimental-loader=data:text/javascript,console.log(Buffer.from(JSON.stringify(process.env)).toSt
ring('hex'));//”

This will set the environment variable NODE_OPTIONS to the string “--experimental-modules
--experimental-loader=data:text/javascript,console.log(Buffer.from(JSON.stringify(process.env)).toSt
ring('hex'));//” which will get parsed by the Node interpreter during later execution steps. My
payload simply dumps the process environment in hex-encoded form to bypass secret redaction, but of
course more complex payloads are possible.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

EIDE Van Hagar posted:

i heard the canadian intelligence agency did bay of pigs can you confirm
no way, eh?

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop

EIDE Van Hagar posted:

i heard the canadian intelligence agency did bay of pigs can you confirm

Oh it was George Bush Sr. Of the known named Operations of the CIA, Operation Zapata is understood to be Bay of Pigs. Back when he was active, apparently they were not too secure with picking codenames randomly, instead making coy references to himself. "Zapata" == "Zapata Offshore", his oil company based in Houston. "Barbara", and "Houston", the name of his wife and current residence, but also the names printed on two of the ships used by the Cuban "exiles".

An excerpt from "George Bush: The Unauthorized Biography; The rise of the Bush dynasty and the political career of George H.W. Bush"

quote:

According to reliable sources and published accounts, the CIA code name for the Bay of Pigs invasion was 'Operation Zapata', and the plan was so referred to by Richard Bissell of the CIA, one of the plan's promoters, in a briefing to President Kennedy in the Cabinet Room on March 29, 1961 [7]. Does Operation Zapata have anything to do with Zapata Offshore? The run-of-the-mill Bushman might respond that Emiliano Zapata, after all, had been a public figure in his own right, and the subject of a recent Hollywood movie starring Marlon Brando. As J. Hugh Liedtke had observed, he was the classic figure for the revolutionary-cum-bandit. A more knowledgeable Bushman might argue that the main landing beach, the Playa Giron, is located south of the city of Cienfuegos on the Zapata Peninula, on the south coast of Cuba.

Then there is the question of the Brigade 2506 landing fleet, which was composed of five older freighters bought or chartered from the Garcia Steamship Lines, bearing the names of Houston, Rio Esondido, Caribe, Atlantic, and Lake Charles. In addition to these vessels, which were outfitted as transport ships, there were two somewhat better armed fire support ships, the Blagar and the Barbara. (In some sources Barbara J.) [8]. The Barbara was originally an LCI (Landing Craft Infantry) of earlier vintage. Our attention is attracted at once to the Barbara and the Houston, in the first case because we have seen George Bush's habit of naming his combat aircraft after his wife, and, in the second case, because Bush was at this time a resident, booster, and Republican activist of Houston, Texas. But of course, the appearance of names like "Zapata," Barbara, and Houston can by itself only arouse suspicion, and proves nothing.

....
(etc, it goes on and on to continue building a stronger case for Bush Sr's early life being CIA)
https://modernhistoryproject.org/mhp?Article=BushBook&C=8.2#Pigs



Another thing that occurred to me the other day is that the Kennedy Assassination happened within his territory (Dallas).

Happy Thread fucked around with this message at 20:26 on Nov 2, 2020

Achmed Jones
Oct 16, 2004



quote:

revolutionary-cum-bandit

:snoo:

Pile Of Garbage
May 28, 2007



Happy Thread posted:

Another thing that occurred to me the other day is that the Kennedy Assassination happened within his territory (Dallas).

lee harvey gottem

Happy Thread
Jul 10, 2005

by Fluffdaddy
Plaster Town Cop

DoomTrainPhD posted:

SECFUCK TIME!

I got emails from SpaceX! I am not employed by SpaceX, but I do work on Buildroot which SpaceX uses!

- My name and all of the other Buildroot developers have emails attached to many of the packages SpaceX is using.
- Their email scraper probably didn't filter out emails not ending in SpaceX
- All of the Buildroot maintainers/developers now have every engineer who is working on Starlinks email address lmao.

The various Musk threads would enjoy this. Alternatively, craft a bitcoin wallet scam as an e-mail spoofed with Musk as the sender and mass send to all of those addresses to rake in some dough

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


BangersInMyKnickers posted:

you can make the computer racist???

I mean obviously, look at all the white space

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Powerful Two-Hander posted:

I mean obviously, look at all the white space

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Soricidus posted:

sounds like propaganda rather than reality, given that gchq was established in 1919 and the uk civil service only employed single women until 1946 (if you got married you were required to resign)

not much point hiring women to marry your men if you’re going to fire them as soon as they did so

gchq was established in 1946

(its main forerunner agency, gc&cs, *was* founded in 1919 but the role (and size and budget) were so hugely different by the end of ww2 that it's not like it was just a rebranding exercise, gchq is a completely different beast from gc&cs that just happened to have shared some staff with it)

flakeloaf
Feb 26, 2003

Still better than android clock

Powerful Two-Hander posted:

I mean obviously, look at all the white space

Soricidus
Oct 21, 2010
freedom-hating statist shill

goddamnedtwisto posted:

gchq was established in 1946

(its main forerunner agency, gc&cs, *was* founded in 1919 but the role (and size and budget) were so hugely different by the end of ww2 that it's not like it was just a rebranding exercise, gchq is a completely different beast from gc&cs that just happened to have shared some staff with it)

... ok? I guess you should tell that to all the historians who were perfectly happy recognising its centenary last year

xtal
Jan 9, 2011

by Fluffdaddy

Soricidus posted:

... ok? I guess you should tell that to all the historians who were perfectly happy recognising its centenary last year

Who are they? I absolutely will.

Soricidus
Oct 21, 2010
freedom-hating statist shill

xtal posted:

Who are they? I absolutely will.

Richard Aldrich for one. John Ferris for another. it’s not a controversial position.

Soricidus fucked around with this message at 15:30 on Nov 3, 2020

Beve Stuscemi
Jun 6, 2001




yoloer420 posted:

How have there been so few hilarious security fuckups lately? It's been really disappointing.

Fingers crossed that things get fun again sometime soon. For the first time in forever I've found pentesting to be a grind :(

there is this one waiting in the wings: https://us-cert.cisa.gov/sites/defa...alth_Sector.pdf

I whipped up some power shell scripts to check for the indicators of compromise and I run those every so often, butt..........

Shame Boy
Mar 2, 2010

wasn't there a real fun windows RCE recently that let you get domain admin because they used a weird-rear end cipher mode wrong or was that actually like 6+ months ago, my perception of time is completely broken now

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

wasn't there a real fun windows RCE recently that let you get domain admin because they used a weird-rear end cipher mode wrong or was that actually like 6+ months ago, my perception of time is completely broken now

I think it was in the last month?

Wiggly Wayne DDS
Sep 11, 2010



it felt like last month, but it was august: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472

there'll be two next week but only one is pre-auth

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

christ, August?

Shame Boy
Mar 2, 2010

i think once 2020 is over all memory of it is just going to like, dissolve somehow, and whenever i try to remember anything from this year i either won't be able to or i'll think it actually happened a decade before or after

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

anyone done ephemeral ssh keys on top of EC2 connect? this is the sort of thing I have in mind, but I'm not expert enough in EC2 connect at the least to know if I'm secfucking myself by pursuing it

https://z0mbix.io/2020/04/10/essh-ephemeral-ssh-keys-for-ec2-hosts-using-ec2-instance-connect/

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shame Boy posted:

i think once 2020 is over all memory of it is just going to like, dissolve somehow, and whenever i try to remember anything from this year i either won't be able to or i'll think it actually happened a decade before or after

my medium-to-long-term memory has noticeably degraded over the year, to the point that I'm probably going to get tested periodically to track any further decline

Truga
May 4, 2014
Lipstick Apathy
https://twitter.com/lrvick/status/1320246266270519297

lolling irl

Cybernetic Vermin
Apr 18, 2005

Shame Boy posted:

i think once 2020 is over all memory of it is just going to like, dissolve somehow, and whenever i try to remember anything from this year i either won't be able to or i'll think it actually happened a decade before or after

i think 2020 is the one year i'll remember, to a point where of any further past memory surfaces i will assume it happened 2020 (or possibly i will remember it only in a 2020 context)

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
oh is THAT how the youtube-dl branch was attached?

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
oh, all forks of a repo are stored in the same location in the backend, so you can reach any branch of a fork from any repo, which is how that works.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

wasn't there a real fun windows RCE recently that let you get domain admin because they used a weird-rear end cipher mode wrong or was that actually like 6+ months ago, my perception of time is completely broken now

yeah you basically had a one in 256 chance of jackpotting it and there was zero rate limiting or protections from it on the DC side

haveblue
Aug 15, 2005



Toilet Rascal

BangersInMyKnickers posted:

yeah you basically had a one in 256 chance of jackpotting it and there was zero rate limiting or protections from it on the DC side

yeah somebody at MS tried to ~roll their own crypto~

shame on an IGA
Apr 8, 2005

Subjunctive posted:

anyone done ephemeral ssh keys on top of EC2 connect? this is the sort of thing I have in mind, but I'm not expert enough in EC2 connect at the least to know if I'm secfucking myself by pursuing it

https://z0mbix.io/2020/04/10/essh-ephemeral-ssh-keys-for-ec2-hosts-using-ec2-instance-connect/

https://siliconangle.com/2011/08/01/third-largest-bitcoin-exchange-bitomat-lost-their-wallet-over-17000-bitcoins-missing/

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


ephemeral keys, not ephemeral nodes/storage

that's a classic, though

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock


same, op

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply