Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
spankmeister
Jun 15, 2008






0floor

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






i put forth a proposal for a new gang tag for the thread:

spankmeister
Jun 15, 2008






http://www.bishopfox.com/blog/2016/04/if-you-cant-break-crypto-break-the-client-recovery-of-plaintext-imessage-data/

iMessage ran js in messages...

spankmeister
Jun 15, 2008






anthonypants posted:

the http://rebootmymodem.net/ url is prompting me for a google login so i guess i'm not going to see if it works on my sb6120, but it probably does

its a blogger blog that's invite only now

spankmeister
Jun 15, 2008






cheese-cube posted:

i'll buy this tag for the next 10 ppl who quote this post (might take me a couple of days to do so, ive just moved house and have no internet yet)

spankmeister
Jun 15, 2008






Subjunctive posted:

I got you dude


also you

how does one add gang tags? just [img] in the av text?

they have to be on SA's servers so the way it's usually done that you buy it as an avatar for yourself (or someone else but it's more expensive) and then you can use the image in img tags.

spankmeister
Jun 15, 2008






very nice, many thanks!

spankmeister
Jun 15, 2008






cheese-cube posted:

big thanks to spankmeister for the tag. also apologies for making GBS threads up the secfuck thread with gang tag stuff.

yw I took it from Blocktronics' recent art pack and scaled it down for a gang tag.

You can check out the art pack here:

http://pc.textmod.es/pack/blocktronics_baud_dudes/

spankmeister
Jun 15, 2008






takes a while for the memcached to update i think

spankmeister
Jun 15, 2008






RZA Encryption posted:

Don't you hate it when people pronounce this like a past-tense verb?

yeah I also like a pronounced D.

spankmeister
Jun 15, 2008






yeah :airquote: APT's :airquote: often don't need to use custom bespoke 0days when their targets are companies with poor patching habits so if you can get in with a 4 year old exploit then why not? saves you from exposing your 0days for softer targets

spankmeister
Jun 15, 2008







NICE

kinda weird you put it on top but eh

spankmeister
Jun 15, 2008






reminder that :siren: badlock :siren: drops tomorrow

spankmeister
Jun 15, 2008






Carbon dioxide posted:

Ah, some of the most visited Dutch websites had ads serving malware for a few hours yesterday. Always fun.

Yeah it was Angler if anyone wants to know.

spankmeister
Jun 15, 2008






Parallel Paraplegic posted:

I get the feeling that ISP's will automatically set this up if you bought their routers but who knows.

Aren't you precious. :allears:

spankmeister
Jun 15, 2008






i'm going to sned the whole of wikipedia to your printer for your perusal fishmech :v:

spankmeister
Jun 15, 2008






Kazinsal posted:

Hurricane Electric hands out /48s like candy and it's fantastic. I have two /64s and a /48 from them for a grand total of five devices.

IPv6 is what happens when 32-bit exhaustion becomes a real thing and the reaction is to jack up the address space to solve the problem. everyone sees the increased address space and goes hog-wild dividing it up. free /48s are cool and I'm not going to turn down one now while IPv6 is still fairly unused, but using /64s for point-to-point links is pretty nutty.

Umm there are 35 trillion 184 billion 372 million 88 thousand 832 /48 blocks in the currently allocated ipv6 address space

spankmeister
Jun 15, 2008








it's pretty good op

spankmeister
Jun 15, 2008






Shaggar posted:

If a government agency is storing user creds in reversible form for one of their applications, what is the best way to get them to fix it? I've emailed the responsible organization w/ details and suggestions. Should I do anything else?

try US-CERT

spankmeister
Jun 15, 2008






pretty sure there are CIA manuals for that kind of thing

spankmeister
Jun 15, 2008






pro watch:

https://www.youtube.com/watch?v=EcKxaq1FTac

spankmeister
Jun 15, 2008






BiohazrD posted:

so its the 12th, whats the deal with airline food badlock?

embargo ends in about 2h45m

spankmeister
Jun 15, 2008






http://www.timeanddate.com/countdown/launch?iso=20160412T17&p0=1440&msg=%23Badlock&font=cursive&csz=1

spankmeister
Jun 15, 2008






FopeDush posted:

Anyone have the link to that hour-ish long youtube video about selinux that was being posted a while ago in the old thread? I've got free time at work today so I figure I should edumacate myself

https://www.youtube.com/watch?v=MxjenQ31b70

spankmeister
Jun 15, 2008






I have a nice 10yo rum from Barbados. I am ready.

spankmeister
Jun 15, 2008






Parallel Paraplegic posted:

I had to reset my 2-FA with Gandi and they actually required that I send them a scan of a government-issued photo ID because they're Actually Good At Things :3:

yeah or you just show them one of these that you had made:

https://shop.digitalcourage.de/lichtbildausweis-mit-selbst-gewaehlten-daten.html

spankmeister
Jun 15, 2008






I too, buy hosting at a place with cheap in the name and expect high standards.

spankmeister
Jun 15, 2008






https://www.samba.org/samba/history/security.html still not updated wtf <:mad:>

spankmeister
Jun 15, 2008






Wiggly Wayne DDS posted:

http://badlock.org/

The security vulnerabilities can be mostly categorised as man-in-the-middle or denial of service attacks.

Man-in-the-middle (MITM) attacks:
There are several MITM attacks that can be performed against a variety of protocols used by Samba. These would permit execution of arbitrary Samba network calls using the context of the intercepted user.

Impact examples of intercepting administrator network traffic:
Samba AD server - view or modify secrets within an AD database, including user password hashes, or shutdown critical services.
standard Samba server - modify user permissions on files or directories.

Denial-of-Service (DoS) attacks:
Samba services are vulnerable to a denial of service from an attacker with remote network connectivity to the Samba service.

booooooooooooooooooring

:flaccid:

spankmeister
Jun 15, 2008






I was edging the whole time but now i'm limp

spankmeister
Jun 15, 2008






not even gonna out of band patch this on my home setup

spankmeister
Jun 15, 2008






FopeDush posted:

I was eagerly awaiting the first earth-shattering vuln that would render all of the remaining XP boxes well and truly dangerous

This isn't it :(

this wouldn't be it anyway

spankmeister
Jun 15, 2008






Number19 posted:

netapp just posted their bulletin and the older, legacy mode for their OS has it's own unique CVE with a higher score than anything in badlock

so more lols might still be coming

linku?

e: nvm found it https://kb.netapp.com/support/index?page=content&id=9010080&actp=LIST

spankmeister
Jun 15, 2008








http://arstechnica.com/gadgets/2016/04/usb-if-battles-malware-and-bad-chargers-with-type-c-authentication-spec/


chargers, with encryption....

spankmeister
Jun 15, 2008






yeah also watch apple use this so that you can only use apple branded chargers

spankmeister
Jun 15, 2008






yeah i know but the macbook uses usb c for charging now

spankmeister
Jun 15, 2008






Slanderer posted:

I think they fixed that so that it increments the counter first, IIRC

that only works on ios 7 or maybe 8 iirc

spankmeister
Jun 15, 2008






thehustler posted:

gotta be a troll, that

spankmeister
Jun 15, 2008






:airquote: APT's still mostly rely on phishing emails so probably, yeah

Adbot
ADBOT LOVES YOU

spankmeister
Jun 15, 2008






I know this thread can seem a bit intimidating but your reasoning isn't that far out there so really, don't be afraid to ask questions.

  • Locked thread