Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
hobbesmaster
Jan 28, 2008

BeOSPOS posted:

this. they don't come with personal butt/cloud activated by default


this all explains this cryptic email from synology to upgrade to a new version (I've never received such an email from them before). No word of ransomware

it is slightly disconcerting to page through options and see so many buttons that are terrible ideas

on the other hand the same is true of the sonicwall the synology is behind so

Adbot
ADBOT LOVES YOU

vOv
Feb 8, 2014

BeOSPOS posted:

personal butt/butt

spankmeister
Jun 15, 2008






yeah i'd pcap the poo poo outta that ssh session. I wonder what the authentication is like though. Either public key auth or a password but the password would probably be derived from the serial number or smth via some kind of algorithm. Hmmm....


in other news: some more data leak news:

http://mobile.nytimes.com/2014/08/0...&_r=3&referrer=

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

goddamnedtwisto posted:

also with a properly-shaped bit of metal and a microwave

(yet another spy catcher reference but one of peter wrights many little achievements was working out how the soviets were bugging the us ambassador in moscow's office - turns out that a large carved seal of the united states, presented to him by the russian boy scouts, was carved to be a good acoustic conductor and the metal bracket holding it up could be read from across the street using a microwave beam)

iirc this was actually a device designed for this, not a bracket

http://en.wikipedia.org/wiki/Thing_(listening_device)

designed by Leon Theremin, who was also famous for inventing the theremin.

computer toucher
Jan 8, 2012

spankmeister posted:

yeah i'd pcap the poo poo outta that ssh session. I wonder what the authentication is like though. Either public key auth or a password but the password would probably be derived from the serial number or smth via some kind of algorithm. Hmmm....


in other news: some more data leak news:

http://mobile.nytimes.com/2014/08/0...&_r=3&referrer=

"We have data. No you can't see data, but if you pay us, we'll tell you if your data is in there."

Seems pretty legit. Where can I insert moneys?

ChickenOfTomorrow
Nov 11, 2012

god damn it, you've got to be kind

computer toucher posted:

Where can I insert moneys?

:goatsecx:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.washingtonpost.com/news/morning-mix/wp/2014/08/06/russian-hackers-steal-a-billion-passwords-security-firm-seizes-opportunity/

quote:

It appears the firm initially planned to charge for its services. According to Forbes reporter Kashmir Hill, after the Times story ran Hold Security’s Web site advertised its services to potential victims of the breach for “as low as 120$/month [sic]” with a “money back guarantee.”

so i counter:
https://twitter.com/afreak/status/497022527710179328

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://canarypw.wordpress.com/2014/08/06/canary-will-not-charge-you-to-find-out-if-youre-affected-by-a-breach-also-we-want-volunteers/

And an official response.

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

vOv posted:

https://www.youtube.com/watch?v=FKXOucXB4a8

video on recovering speech using high-speed cameras recording shiny surfaces

:aaaaa:

the rolling shutter part is just fantastic

Bloody
Mar 3, 2013

ultramiraculous posted:

:aaaaa:

the rolling shutter part is just fantastic

yeah

jre
Sep 2, 2011

To the cloud ?





Nice ads

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

jre posted:

Nice ads



cyber criminal? looking to flee the country? click here now!

spankmeister
Jun 15, 2008






So FireEye and Fox-IT "acquired" the private keys for CryptoLocker and are offering a free online decryption service.

https://www.decryptcryptolocker.com/

Here's a google translate version of the news article reporting on this:

https://translate.google.com/transl...ware&edit-text=

Just-In-Timeberlake
Aug 18, 2003

spankmeister posted:

So FireEye and Fox-IT "acquired" the private keys for CryptoLocker and are offering a free online decryption service.

https://www.decryptcryptolocker.com/

Here's a google translate version of the news article reporting on this:

https://translate.google.com/transl...ware&edit-text=

i am hoping against hope that this decrypts and steals your bitcoins

spankmeister
Jun 15, 2008






Just-In-Timeberlake posted:

i am hoping against hope that this decrypts and steals your bitcoins

Ronald Prins, founder of Fox-IT is a bitcoiner soooo....

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

jre posted:

Nice ads



thx

i need to move off of wordpress' poo poo

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

So FireEye and Fox-IT "acquired" the private keys for CryptoLocker and are offering a free online decryption service.

https://www.decryptcryptolocker.com/

Here's a google translate version of the news article reporting on this:

https://translate.google.com/transl...ware&edit-text=
here's fireeye's english blogpost about it: http://www.fireeye.com/blog/corporate/2014/08/your-locker-of-information-for-cryptolocker-decryption.html

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:

hobbesmaster posted:

it is slightly disconcerting to page through options and see so many buttons that are terrible ideas

on the other hand the same is true of the sonicwall the synology is behind so

actually sonicwall is pretty decent for the smb sphere.

hobbesmaster
Jan 28, 2008

CISADMIN PRIVILEGE posted:

actually sonicwall is pretty decent for the smb sphere.

there are some buttons that amount to "reduce security to zero"

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:
hmm what's the feeling about major sites that allow for unfiltered http redirects.


https://www.majorbrand.com/redirect.aspx?&t=pos&r=http%3a%2f%2fmalware.com%2fbadthing.html

vOv
Feb 8, 2014

CISADMIN PRIVILEGE posted:

hmm what's the feeling about major sites that allow for unfiltered http redirects.


https://www.majorbrand.com/redirect.aspx?&t=pos&r=http%3a%2f%2fmalware.com%2fbadthing.html

good way to phish people

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

CISADMIN PRIVILEGE posted:

actually sonicwall is pretty decent for the smb sphere.

it's a long, long time since i used a sonicwall but aren't they one of the worst offenders for "really easy to use ui" paired with "really, really easy to completely gently caress things up"?

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

CISADMIN PRIVILEGE posted:

hmm what's the feeling about major sites that allow for unfiltered http redirects.


https://www.majorbrand.com/redirect.aspx?&t=pos&r=http%3a%2f%2fmalware.com%2fbadthing.html

this doesn't work in chrome for the record

spankmeister
Jun 15, 2008






Heresiarch posted:

this doesn't work in chrome for the record

uhhhh


you clicked the link?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

hobbesmaster posted:

there are some buttons that amount to "reduce security to zero"

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:

Heresiarch posted:

this doesn't work in chrome for the record


spankmeister posted:

uhhhh


you clicked the link?

yeah, i changed the details to protect teh site but it does work in chrome and ie.

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:

goddamnedtwisto posted:

it's a long, long time since i used a sonicwall but aren't they one of the worst offenders for "really easy to use ui" paired with "really, really easy to completely gently caress things up"?

That's a valid criticism, and the UI should do a better job of alerting you that what you are doing is dumb. However, it's pretty easy to do dumb poo poo to reduce security in anything if you don't know what you're doing. In terms of what you get at the price point assuming it's properly configured it's probably as a good as anything out there.

Wiggly Wayne DDS
Sep 11, 2010



when i see major sites who'd care i report it to them, although i check how they're redirecting to see if it's worse than an unfiltered redirect

CISADMIN PRIVILEGE
Aug 15, 2004

optimized multichannel
campaigns to drive
demand and increase
brand engagement
across web, mobile,
and social touchpoints,
bitch!
:yaycloud::smithcloud:

Wiggly Wayne DDS posted:

when i see major sites who'd care i report it to them, although i check how they're redirecting to see if it's worse than an unfiltered redirect

i reported since i work indirectly for them.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

thats no worse than things built into the ipsec rfcs https://www.ietf.org/rfc/rfc2410.txt

that entire thing reads like a joke

by 'reads like' i mean 'literally is'

quote:

NULL is a block cipher the origins of which appear to be lost in antiquity. Despite rumors that the National Security Agency suppressed publication of this algorithm, there is no evidence of such action on their part. Rather, recent archaeological evidence suggests that the NULL algorithm was developed in Roman times, as an exportable alternative to Ceaser ciphers. However, because Roman numerals lack a symbol for zero, written records of the algorithm's development were lost to historians for over two millennia.

...

test_case = 2
data = "Network Security People Have A Strange Sense Of Humor"
data_len = 53
NULL_data = "Network Security People Have A Strange Sense Of Humor"

reidscones
Apr 5, 2007

:snoop: deserve got nothin to do with it :snoop:
finnfisher got hacked woops!!! wooooops!!!!!!!!

https://netzpolitik.org/2014/gamma-finfisher-hacked-40-gb-of-internal-documents-and-source-code-of-government-malware-published/

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
there will be embarrassment and indignation and in the end nothing will change.

Jail Santa

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sonicwall is turds and I'm so glad I was able to ditch mine

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

spankmeister posted:

uhhhh


you clicked the link?

yes because i knew that it was supposed to be a spoofed redirect so i wasn't going to do anything stupid

pseudorandom name
May 6, 2007

yeah, nothing stupid like running a browser zero day on your own computer

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

pseudorandom name posted:

yeah, nothing stupid like running a browser zero day on your own computer

he described what it was and linking to actual malicious poo poo is bannable

you do have a point but the real argument is should i trust goons or not

Wiggly Wayne DDS
Sep 11, 2010



Heresiarch posted:

he described what it was and linking to actual malicious poo poo is bannable

you do have a point but the real argument is should i trust goons or not
you do remember the last few security threads right

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Heresiarch posted:

yes because i knew that it was supposed to be a spoofed redirect so i wasn't going to do anything stupid

Security gently caress up, inside the thread, etc

Heresiarch
Oct 6, 2005

Literature is not exhaustible, for the sufficient and simple reason that no single book is. A book is not an isolated being: it is a relationship, an axis of innumerable relationships.

Wiggly Wayne DDS posted:

you do remember the last few security threads right

yeah okay i'm not firing on all cylinders today

it was dumb and i'll stop trying to justify it

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

Captain Foo posted:

Sonicwall is turds and I'm so glad I was able to ditch mine

really haven't had any problems with mine; well excepting overloading a poor little tz100

  • Locked thread