Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp

infernal machines posted:

i've recently seen a bug with replies to emails from an iphone using ios mail app where in some cases the signature image in the message replied to from the phone is not the original signature image, but presumably another image on their phone with the same name. this has caused some issues internally as people get antsy when they see the wrong picture under their name

argh my gambit of naming my sig image throbbingcock.jpeg is foiled

Adbot
ADBOT LOVES YOU

sadus
Apr 5, 2004

pseudorandom name posted:

tricking people into sending +++ is ancient, sending +++ to them to disconnect them (without them having to repeat it back via e.g. a ICMP ping packet payload) was relatively late, iirc

This was kind of dumb, but back when everyone first started scripting MUDs to play 24x7, little old me on a lovely ancient computer mad that I couldn't script too, would broadcast stuff like "Blah moves to attack you!" "HP=-1" "You drop to the ground!" to the global chat and laugh as 95% of the people logged in would hang up to try to avoid getting fully killed.

Even more dumb was holding pillows over the modem to try and mute the dial up noises at 3AM to avoid detection for months if not years before I learned ATM0. 2400 baud for life

sadus fucked around with this message at 11:01 on Dec 28, 2021

Beve Stuscemi
Jun 6, 2001




cinci zoo sniper posted:

https://news.ycombinator.com/item?id=29705957 a lot of commotion around what could be a fresh round of lastpass being a well made product

just use Bitwarden, folks, sheesh

Presto
Nov 22, 2002

Keep calm and Harry on.

sadus posted:

This was kind of dumb, but back when everyone first started scripting MUDs to play 24x7, little old me on a lovely ancient computer mad that I couldn't script too, would broadcast stuff like "Blah moves to attack you!" "HP=-1" "You drop to the ground!" to the global chat and laugh as 95% of the people logged in would hang up to try to avoid getting fully killed.
So you're the reason we had to get rid of echoall on Discworld.

HELLOMYNAMEIS___
Dec 30, 2007

https://twitter.com/YNizry/status/1475764153373573120

Truman Peyote
Oct 11, 2006



infernal machines posted:

i've recently seen a bug with replies to emails from an iphone using ios mail app where in some cases the signature image in the message replied to from the phone is not the original signature image, but presumably another image on their phone with the same name. this has caused some issues internally as people get antsy when they see the wrong picture under their name

"but I thought hello.jpg was an innocuous name"

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

ahahahahahaha

cinci zoo sniper
Mar 15, 2013




i hope it involves emojis

Sarah Problem
Sep 24, 2002

Because, if you confess with your mouth that Witten is Lord and believe in your heart that God raised him from the dead, you will be saved

Log4j is going to cause my death

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
Oh holy poo poo please no

RFC2324
Jun 7, 2012

http 418

Wat

tak
Jan 31, 2003

lol demowned
Grimey Drawer
Idgi

Another l4j rce to add to the pile?

cinci zoo sniper
Mar 15, 2013




tak posted:

Idgi

Another l4j rce to add to the pile?

yes

crazysim
May 23, 2004
I AM SOOOOO GAY
and on the 5th week of december another log4j vulnerability came to me

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

crazysim posted:

and on the 5th week of december another log4j vulnerability came to me

Agile Vector
May 21, 2007

scrum bored



crazysim posted:

and on the 5th week of december another log4j vulnerability came to me

animist
Aug 28, 2018
a parser with an rce

haveblue
Aug 15, 2005



Toilet Rascal
log4ever

Potato Salad
Oct 23, 2014

nobody cares


animist posted:

a parser with an rce

yeah what year is it

4lokos basilisk
Jul 17, 2008


ah i should have thought about a monkey paw scenario when i wished i had some clear todo list to start the new year

im sorry

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
log 4 january

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

cinci zoo sniper posted:

https://news.ycombinator.com/item?id=29705957 a lot of commotion around what could be a fresh round of lastpass being a well made product
and the winner is...
https://twitter.com/campuscodi/status/1475887569011453957

cinci zoo sniper
Mar 15, 2013





sounds like someone is combing through an older breach

mystes
May 31, 2006

Lol why are people reusing passwords for their password manager

cinci zoo sniper
Mar 15, 2013




i meant that as in older lastpass breach, but it’s definitely fair to expect a good number of people reusing a “super serious” password for a number of sites like gmail or online banking portal alongside their password manager vault

Beve Stuscemi
Jun 6, 2001




more like LastAss

Shame Boy
Mar 2, 2010

last, rear end or grass

mystes
May 31, 2006

cinci zoo sniper posted:

i meant that as in older lastpass breach, but it’s definitely fair to expect a good number of people reusing a “super serious” password for a number of sites like gmail or online banking portal alongside their password manager vault
Well if you find any feel free to yell at them

Dylan16807
May 12, 2010

https://twitter.com/YNizry/status/1475916671953117184

Truman Peyote
Oct 11, 2006




i would be very stoked if this means i can stop using last rear end at work

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
okay, so pending the blog post, sounds like:
  • you can configure log4j to log to different data sinks (“appenders”)
  • one of those possibilities is an arbitrary relational database, whose driver will be invoked via the standard jdbc interfaces (“jdbc appender”)
  • the driver has to be explicitly specified in a configuration file
  • log4j by default will honor multiple ways of specifying the driver to load, including jndi, which can trigger remote packages to get loaded into the process
  • the fix makes log4j only allow local classes by default

so if you don’t have a trust boundary between your thing and its logging configuration file (???) you should be fine. or if you’ve completely disabled remote loading in your vm

Shaggar
Apr 26, 2006
im trying to imagine a legitimate scenario where someone has access to modify the configuration but not the deployed binaries

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
yeah, this kind of "vulnerability" always annoys me for exactly that reason. you should be thinking of configuration files as code unless you've got rigorous reasons to think otherwise. i'm not saying it isn't good to chase out stuff like crashes in the parser, but the only situation where malicious configuration is a real vulnerability is when you've got something like a system-level service that parses and respects user-level configuration files

Beve Stuscemi
Jun 6, 2001




just chmod 777 / :dukedog:

Progressive JPEG
Feb 19, 2003

if you steal the computer you can pretty much do whatever you want to it! where's my CVE

Shaggar
Apr 26, 2006

rjmccall posted:

yeah, this kind of "vulnerability" always annoys me for exactly that reason. you should be thinking of configuration files as code unless you've got rigorous reasons to think otherwise. i'm not saying it isn't good to chase out stuff like crashes in the parser, but the only situation where malicious configuration is a real vulnerability is when you've got something like a system-level service that parses and respects user-level configuration files

the only thing i can think of is an application allowing runtime configuration of logging through its own UI, but even then i'd blame the application and not log4j.

i know jira lets you configure component logging levels through its UI, but last time i checked the appenders themselves had to be configured in log4j.properties

this specific issue seems like them being overly cautious.

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
yeah. i mean, it's probably good, in the sense that probably every use of these apis that can trigger jndi (or remote loading in general) should have to explicitly authorize it, e.g. by passing the allowed schemas in and not providing an "allow anything" default. but it's not something that people need to run in and hot-patch unless i'm completely misunderstanding

Dr. Kayak Paddle
May 10, 2006

rjmccall posted:

okay, so pending the blog post, sounds like:
  • you can configure log4j to log to different data sinks (“appenders”)
  • one of those possibilities is an arbitrary relational database, whose driver will be invoked via the standard jdbc interfaces (“jdbc appender”)
  • the driver has to be explicitly specified in a configuration file
  • log4j by default will honor multiple ways of specifying the driver to load, including jndi, which can trigger remote packages to get loaded into the process
  • the fix makes log4j only allow local classes by default

so if you don’t have a trust boundary between your thing and its logging configuration file (???) you should be fine. or if you’ve completely disabled remote loading in your vm

Here's the post
It's the same JNDI:LDAP deserialization, but from a different place...

https://checkmarx.com/blog/cve-2021-44832-apache-log4j-2-17-0-arbitrary-code-execution-via-jdbcappender-datasource-element/

Dr. Kayak Paddle fucked around with this message at 00:11 on Dec 29, 2021

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe
yeah, ok, so that’s just what i was saying

although they do say that jog4j has its own mechanisms for doing remote configuration? presumably ones you have to opt into with local configuration, though

Adbot
ADBOT LOVES YOU

El Mero Mero
Oct 13, 2001

cinci zoo sniper posted:

https://news.ycombinator.com/item?id=29705957 a lot of commotion around what could be a fresh round of lastpass being a well made product

yeah I had an account I set-up a long time ago with nothing in it and I got a notification that someone was trying to use my (auto-generated) master password there to log-in from India.

Lastpass is such garbage.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply