Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
KozmoNaut
Apr 23, 2008

Happiness is a warm
Turbo Plasma Rifle


rjmccall posted:

your log files probably have a lot more redundancy than an ip list. even if every line is timestamped, a lot of lines probably have long common sequences, a lot longer than ~15 characters max

Derp, I was counting 256^4, but forgot that an IPv4 address is up to 16 bytes long in ASCII including the periods :downs:

So actually my example with the 66GB of log files is the closer equivalent. Yeah, that ain't ever getting down to 50MB.

Adbot
ADBOT LOVES YOU

BlankSystemDaemon
Mar 13, 2009



but op, they're bitmasks

VikingofRock
Aug 24, 2008




Shoulda made it a postscript file instead of .txt, then you could make it drat small by encoding the ip-generating program in the document itself

BrianRx
Jul 21, 2007

How else would you store all the 1s and 0s? .docx?

ewiley
Jul 9, 2003

More trash for the trash fire
Hmm, so the former president known for stupid grifter ideas is launching a social media network... let's check in to see how that's go..


https://twitter.com/stevanzetti/status/1451031457590353922?s=20

..ah

e: boo, fake :(

https://twitter.com/ThatNotoriousK/status/1451001274980241410

ewiley fucked around with this message at 11:48 on Oct 21, 2021

some kinda jackal
Feb 25, 2003

 
 
lmao I was going to come in here to post "placeholder for when this piece of poo poo gets hacked" and life beat me to the joke

cinci zoo sniper
Mar 15, 2013




https://www.vice.com/en/article/5dgm5k/truth-social-is-mastodon-trump

mastodon about to get free pentesting

Shame Boy
Mar 2, 2010


quote:

“Based on the screenshots I have seen, it absolutely is based on Mastodon,” Eugen Rochko, founder and lead developer of Mastodon told Motherboard in an email. He pointed to one screenshot of Truth Social’s error message, which is using the default Mastodon elephant mascot.

ahahahah

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
its as if all these guys are grifters and not single competent person would work for them

mystes
May 31, 2006

They'll just arrest anyone who looks at the mastodon source code.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

mystes posted:

They'll just arrest anyone who looks at the mastodon source code.

You joke but this is probably what Trump will demand, publicly.

cinci zoo sniper
Mar 15, 2013




demonrats mastadont look at the code!!!

jesus WEP
Oct 17, 2004


small pentest humiliation

Shifty Pony
Dec 28, 2004

Up ta somethin'


from the Musk thread:



Just-In-Timeberlake posted:

lol, not only did they crack the encryption, the released the tools publicly so anybody can do it.

https://jalopnik.com/you-can-now-directly-read-data-logs-from-tesla-vehicles-1847910795

e: git repo

frh
Dec 6, 2014

Hire Kenny G to play for me in the elevator.

duz posted:

idk, he sounds knowledgeable about technology

https://twitter.com/GovParsonMO/status/1448697768311132160


So this chud got so loving owned by people making fun of him that he actually put out an ad yesterday about how viewing html source code is illegal:

https://www.youtube.com/watch?v=9IBPeRa7U8E

some kinda jackal
Feb 25, 2003

 
 

Blooster posted:

So this chud got so loving owned by people making fun of him that he actually put out an ad yesterday about how viewing html source code is illegal:

https://www.youtube.com/watch?v=9IBPeRa7U8E

No no no, dig UP, stupid!

flakeloaf
Feb 26, 2003

Still better than android clock

ewiley posted:

Hmm, so the former president known for stupid grifter ideas is launching a social media network... let's check in to see how that's go..


https://twitter.com/stevanzetti/status/1451031457590353922?s=20

..ah

e: boo, fake :(

https://twitter.com/ThatNotoriousK/status/1451001274980241410

interesting account you got there

flakeloaf
Feb 26, 2003

Still better than android clock

KozmoNaut posted:

Derp, I was counting 256^4, but forgot that an IPv4 address is up to 16 bytes long in ASCII including the periods :downs:

So actually my example with the 66GB of log files is the closer equivalent. Yeah, that ain't ever getting down to 50MB.

would quartets of ascii characters work?

Achmed Jones
Oct 16, 2004



holy poo poo i am so glad to have left the midwest/south. i want to say that where i grew up wasn't that dumb but, well, i'm probably missing something

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Volmarias posted:

You joke but this is probably what Trump will demand, publicly.

One of these times, its going to hit a chud judge who is going to legislate from the bench and no matter what kind of "oh dear no please, please donate to us!" response the EFF gives, it wont be enough to overturn it.

Simply using a computer as a non-client role is going to become illegal if trumpism gets a 2nd chance

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

flakeloaf posted:

would quartets of ascii characters work?

you can store ip addresses more and more compactly but they're correspondingly going to get harder and harder to compress

Hunter2 Thompson
Feb 3, 2005

Ramrod XTreme

Sniep posted:

One of these times, its going to hit a chud judge who is going to legislate from the bench and no matter what kind of "oh dear no please, please donate to us!" response the EFF gives, it wont be enough to overturn it.

Simply using a computer as a non-client role is going to become illegal if trumpism gets a 2nd chance

then it's a good thing i'm a software engineer so i can press f12 without fear

what? no, i don't have a license

mystes
May 31, 2006

Blooster posted:

So this chud got so loving owned by people making fun of him that he actually put out an ad yesterday about how viewing html source code is illegal:

https://www.youtube.com/watch?v=9IBPeRa7U8E
Oh my god, lmao

GWBBQ
Jan 2, 2005


In other news, we will be protecting IKEA's intellectual property rights by making it a Class A felony to read the manual, and capital punishment will be on the table if you can read Swedish or use translation software.

Methanar
Sep 26, 2013

by the sex ghost
anyone who buys more than 50lb of fertilizer, a van, or a computer should be put on a terrorist watch list

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
The "you wouldnt steal a car" ad except now it reads "view a webpage"

haveblue
Aug 15, 2005



Toilet Rascal
when you view source, you're viewing the source of hitler

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

jesus WEP posted:

small pentest humiliation

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Hunter2 Thompson posted:

then it's a good thing i'm a software engineer so i can press f12 without fear

what? no, i don't have a license

you know what i mean, come on

it will be a reason to put people in jail if they computer wrong is what im saying. they'll probably bolt on terrorism too.

Stereotype
Apr 24, 2010

College Slice
the goal of the establishment is to make laws that are entirely selectively enforceable but are obfuscated in such a way that they seem like they are being applied fairly. "using a computer wrong" being a crime just means you can arrest your political rivals at any time and everyone will just nod along like of course no problems there the guy is a criminal. there are tons of laws like this already that primarily target black people, but now they're going to have to start targeting people who could theoretically recognize and publicize the wild corruption of the powerful.

Hunter2 Thompson
Feb 3, 2005

Ramrod XTreme

Sniep posted:

you know what i mean, come on

it will be a reason to put people in jail if they computer wrong is what im saying. they'll probably bolt on terrorism too.

sorry, i wasn't taking a dig at what you wrote. i was just being an idiot, ignore me

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Hunter2 Thompson posted:

sorry, i wasn't taking a dig at what you wrote. i was just being an idiot, ignore me

o ok just post on then my friend i didnt mean to infer anything that wasnt there!

kitten smoothie
Dec 29, 2001

Shaggar posted:

if it is a viewstate gently caress up theress a wide range of gently caress ups that are possible from something basic like exposing data you didnt intend, to sql injection or privilege escalation thru viewstate modification. viewstate sucks and nobody should use it even if you know how to set it up properly.

thats said if it was them disclosing the information in the viewstate directly, how do you gently caress that up? You'd have to basically query all the SSNs and then stick them into the viewstate for some reason. Why would you ever do that? the only thing i can think of is maybe they thought they were caching the query results and then selecting only the current user from the results, but thats pretty far fetched.

modifying the viewstate to alter or replace a sql query would make more sense, but idk if that really matches the description from the article.

they sent the Missouri state police after a professor who advised the newspaper in verifying the problem, and the professor has since lawyered up and sent the state a litigation hold for all their documents about this. The letter from the lawyer mentions how it happened and it was indeed a view state fuckup.

https://www.kansascity.com/news/politics-government/article255184572.html

quote:

In the letter, Gross describes the actions Khan took to verify the flaw. It involved viewing the public webpage’s source code and “identifying a suspicious piece of the source code referred to as ‘View State.’ “ Such code “can contain security flaws like the one found here” and that “translating the source code into plain text...can also be done by anyone.”

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

GWBBQ posted:

In other news, we will be protecting IKEA's intellectual property rights by making it a Class A felony to read the manual, and capital punishment will be on the table if you can read Swedish or use translation software.
BORN TO HACK
WORLD IS A SECFUCK
View Em All 1990
I am source man
410,757,864,530 LIVE SSNS

Raere
Dec 13, 2007

How big would a compressed text file containing every social security number be

pseudorandom name
May 6, 2007

depends on the compression algorithm, my custom SSN compression algorithm reduces the input to zero bytes

Stereotype
Apr 24, 2010

College Slice

Raere posted:

How big would a compressed text file containing every social security number be

just the numbers? just write something that counts from 0 to a billion (the maximum possible number of social security numbers, which are only 9 digits)

Garrand
Dec 28, 2012

Rhino, you did this to me!

Pretty certain someone already did that, posted it to Twitter as a joke and got suspended/banned for doxxing or whatever

Stereotype
Apr 24, 2010

College Slice
code:
f"%09d"%numpy.random.randint(1e9)

Adbot
ADBOT LOVES YOU

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

Stereotype posted:

just the numbers? just write something that counts from 0 to a billion (the maximum possible number of social security numbers, which are only 9 digits)

not sure about prosecuted but i believe people have been at least arrested for doing just this

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply