Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender


code:
PATCH NOTES FOR 13.0
* Avoids slamming car doors into genitals
* Removed conversation that belongs in D&D

PATCH NOTES FOR 12.0
* A whole new version to reflect the ever-changing threat landscape
* Official HTTPS support--it only took Lowtax like a decade to get it to work properly

PATCH NOTES FOR 11.4
* Added details at end of OP for why the thread is called "You're busted, dude"

PATCH NOTES FOR 11.3
* POP POP of unsigned ints

PATCH NOTES FOR 11.0
* new version with less bloat
* all anime removed and hopefully forever

PATCH NOTES FOR v10.1
* no patch notes required

PATCH NOTES FOR v10.0

* decided that 8 and 9 were bad numbers and skipping to '10' would make us look cooler.
* js crypto added in for the sake of an internet argument

PATCH NOTES FOR v7.69

* Added 1.2 billion passwords from Russian hacker forums

PATCH NOTES FOR v7.2 "BoringSFM"

* The name is aspirational and not yet a promise

PATCH NOTES FOR V1.0.1g

* changed version number

PATCH NOTES FOR V0.9.8

* once again removed LF and Fishmech corruption from the last thread
* added a new feature that enables the mods/admins to go ahead and probate/ban as necessary if LF'n poo poo happens
* added heartbeat feature to non-existent SSL layer on the forums

PATCH NOTES FOR V69

* removed LF and Fishmech corruption from last thread
* new "hello" service for conference attendees
* blocking of js crypto through message relay services like twitter

PATCH NOTES FOR V1.2

* made more efficient for version 1.2 after having removed fishmeching and talk about credit card contracts

PATCH NOTES FOR V1.1

* don't loving use any of these goddamn exploits you dumbshits


join us on irc: irc.synirc.net #yossec

useful news resource for information security professionals: http://reddit.com/r/netsec/

risky business podcast is worth listening to and yospos has been mentioned in it before

here are some old threads that haven't been archived:

Security Fuckup Megathread - v12.2 - you have slammed your dick in the car door (apr 2016-jan 2017)
Security Fuckup Megathread - v11.4 - who u gonna snitch to pussy bitch gently caress u (apr 2015-apr 2016)
Security Fuckup Megathread - v10.1 (Hackers can turn your gas station into a bomb) (nov 2014-apr 2015)
Security Fuckup Megathread - v7.69 (stay safe security ghost) (aug-nov 2014)
Security Fuckup Megathread - v7.2 "BoringSFM" (jun-aug 2014)

Alereon posted:

seriously though people dont post anything that would allow a lurker from gbs to gently caress with anything

Lain Iwakura fucked around with this message at 18:27 on Jan 5, 2017

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
updated the op to include the secthread officially approved podcast, risky business

(the previous thread was mentioned in an episode)

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
if a yossec twitter list is created and doesn't look like poo poo, i'll make it official

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Segmentation Fault posted:

speaking of secfucks and reddit, https://www.reddit.com/r/TronScript/ is a pretty good collection of "good at computers" types who believe in the "run a magical program" school of infosec

i'm the batch files committed to github

https://github.com/bmrf/tron/tree/master/resources

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://bugcrowd.com/netgear

quote:

Payout Expected Outcome
$15,000 Unauthorized access to NETGEAR cloud storage video files for all customers
$15,000 Unauthorized access to live video feeds of all NETGEAR customers
$15,000 Remote Unauthorized access to administer another NETGEAR customer's router (via the publicly accessible internet )
$10,000 Unauthorized access to only a single NETGEAR customer live video feed
$10,000 Unauthorized access to only a single NETGEAR customer cloud storage video files
$10,000 Retrieve all customer's payment information -16 Digit credit card numbers, CVV
$5,000 Retrieve only a single customer payment information
$5,000 Retrieve complete NETGEAR customer's database -Must have elements: Name, Email address, Password, Products owned
$1,500 Working SQL Injection on Cloud Infrastructure (excluding Firmware, Web Management & Client Apps)
$1,000 Working Stored XSS from lower to higher privilege users on Cloud Infrastructure (excluding Firmware, Web Management & Client Apps)
$750 CSRF against critical functions within an admin interface
$300 Working SQL Injection on Firmware, Web Management & Client Apps
$150 Open Redirection

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
all bets are off with physical access

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
r/netsec proves to be the best place to see painful discussions on password managers

https://www.reddit.com/r/netsec/comments/5mahfl/1password_is_still_using_full_dropbox_access_to/

quote:

1Password on iOS doesn't even promote good security. It allows copying text to the clipboard. Any third party app can read the clipboard – users have to manually clear the clipboard by copying over it.

[...]

I really wish Apple would implement a secure copy function. I.e: a clipboard item type that cannot be pulled via a public API and must be pasted via the action menu. I've thought about implementing such functionality as a jailbroken tweak.

yes. jailbreak your device to fix a problem with 1password's innocuous copy and paste method

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

reminder that when I met him he told me that I reminded him a lot of himself and wasn't sure how to take that.

Did he smell like smokes too because that is what I remember of him

I got to meet him at DEFCON in 2015

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

FileZilla is pretty good so idk why you'd do this.

it's great if you want a tool that doesn't update itself effectively and has zero integration into AD

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
never mind the fact that ftp is a garbage protocol

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

if you don't think mobaxterm isn't leaps and bounds ahead of fuckin putty, I don't know what to tell you.

i dunno about you but i can get mobaxterm's cygwin terminal by installing ubuntu for windows, x11 support by installing xming, and ssh support by either using ubuntu for windows or using kitty, which is a better version of putty (which by default does have an https download)

mobaxterm requires you to pay for more than three ssh sessions

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

why would it need integration into AD?

if it has no AD integration it has no business in an enterprise

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

or are you talking about FileZilla server? cause yeah i wouldn't use that.

yes. this is likely what atomicthumbs is talking about

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Westie posted:

just got owned via plesk, i'd like to sha-



maybe not

reversing that will be difficult due to its use of perl

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

No it doesn't.

You are right. It is 12 sessions and I am limited to two SSH tunnels. It is a terrible SSH client otherwise.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

negromancer posted:

If you have more than 12 sessions open you either need to start using config management or screen sessions there buddy.

it's the ssh tunnels that kill me more than the 12 sessions

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
enough chat about garbage ssh clients

https://www.assetstore.unity3d.com/en/#!/content/27938
https://www.gofundme.com/buy-secure-http-without-https

:psyduck:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://www.semographics.com/smaes/

quote:

Your plain URL text.

code:
http://www.yourdomain.com/smaes/test_get.php?returnval=Secure_HTTP_without_HTTPS!
Encrypted URL text with "Secure HTTP without HTTPS"
(you may use SMUtil.encryptURL(str) in client.)

code:
http://www.yourdomain.com/smaes/test_get.php?deviceid=4b46360202cfc0bb2c9924c5f0441cf4c2593131&returnval=LNzFB2E5cDj26AnYpbAHywucM0U/dfte+oytIMCfuGE=$&returnval_PC=3A4pJwrOgL4Aw2welnT7NE51HO4TqSsVxPyPWIXQ4oM=$


Server accepts the request and sends the result encrypted text.

code:
LNzFB2E5cDj26AnYpbAHywucM0U/dfte+oytIMCfuGE=$
Decrypted result text in Client
(You may use SMAES.decryptIf(str) in client)

Secure_HTTP_without_HTTPS!

:psypop:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Migishu posted:

wasn't there some thing about the [any oss project] guy being an absolute rear end in a top hat for not patching known, ancient, bugs or some poo poo about him being stupidly arrogant?

anyway he has an apk

http://www.semographics.com/smaes_webplayer/secure_http.apk

if i had time i'd probably tear it apart

too bad nothing seems to use it on github

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tiny Brontosaurus posted:

Yeah I heard but I'm not even looking. gently caress it. I have avs off anyway because that poo poo's annoying. An admin doxxed the credit card that bought my account and my IP info and is passing it around on offsites because they're mad at some person I'm not who was apparently getting them salty before I had so much as a facebook account. I get a pm inbox full of rape and death threats and gore but it's not actionable because "you can't prove anything." I'm not putting my own money into this shithole.

"Don't take the bait." gently caress all of you.

FactsAreUseless posted:

No mods or admins have access to your credit card information, or any other user's. I just want to make sure everyone knows this. We do not see this information at all ever. It is not associated with your account. There are actual federal regulations dealing with how CC information is handled.

negromancer posted:

As someone who worked at Steadfast (where the servers for this site are housed), that isn't true at all.

Subjunctive posted:

How would the hosting provider know? Are they looking at private customer data?

negromancer posted:

Because

a) the actual factual servers are there
b) places like steadfast do more than just swap out hard drives. It was expected to do pretty much whatever was asked by the customers, and the concept of within reason hadn't made it to this company.
c) I work in information security and I'm not an idiot and know more about PCI-DSS and CC processing regulatory stuff than most, considering a former boss helped write the poo poo.

:allears:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

LeftistMuslimObama posted:

just want to point out that tiny brontosaurus is legitimately a good poster who is constantly harassed because she calls out racist posts. that it's escalated to people doxxing her is horrible and it is an irl secfuck that the moderation here doesn't give a poo poo at all because she calls them out on their poo poo too.

oh. it wasn't directed their way. i'm more interested in seeing what comes out of this

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Powaqoatse posted:

tiny brontosaurus is cool

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this is getting interesting

negromancer posted:

ate all the Oreos posted:

Everyone I've ever met who worked at hosting providers with explicit rules to not look at customer data still constantly looked at customer data.

Especially if the customer is losing their poo poo about something being hosed up on the server and threatening to leave. The higher ups would tell you "just log in as root and fix it".

FactsAreUseless posted:

Okay, then who has access to it? Because I sure as poo poo don't.

Literally any steadfast employee has root access, on top of anyone who may have written down passwords or created user accounts on the servers themselves (lol if you think they do password rotations on every server). And of course whoever Lowtax has given access to.

FactsAreUseless posted:

So Steadfast has access to it? If you think credit card info isn't secure, tell Lowtax. Either way it's not something the mods and admins can find.

I'm not getting paid to do that, so no.

Subjunctive posted:

Is that a "yes"? Did you look at the server contents?

Maybe. I don't remember every ticket I did for Lowtax, but I feel like I've actually done something on the load balancers at one point.

Doc Hawkins posted:

No one thinks you're an idiot, people just aren't sure what you're claiming, including me. The easiest way to get PCI 3 is to just use a payment processor and not store the payment card information yourself. But the billing address isn't covered, so you could store that, and it could be recoverable from the service anyway (at least it was at the one I worked at). So are you saying that a steadfast employee, having physical access to the servers, could eventually get read access to databases running on them, including any stored billing addresses? And they would do this if a customer asked them to? Wouldn't the customer already have remote access anyway? And what does this have to do with mods?

Yes, and they don't use a direct payment processor. Data is still retained by Lowtax (for accounting purposes). And 2 years ago the CDE was not separated properly from the rest of the environment, so...

The first rule of internet security is physical access is full access. And the reasons why we would log into customers servers is because most hosting customers are dumb as the gently caress. They forget passwords, wipe out data, gently caress up configs, etc

negromancer posted:


zen death robot posted:

Negromancer you are painfully full of poo poo and I already called you out on this once. gently caress off before I ban you for spreading bullshit info to scare people.

Oh so I didn't work at Steadfast?

Ok.


Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
years and years and years ago there was a claim that fistgrrl was keeping track of registrations using credit card numbers to see if anyone who's not supposed to come back does

that is where the rumours stem from

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Segmentation Fault posted:

Security Fuckup Megathread - v13.1 - $10 for SA's customer CC info

i got one better

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i have proof

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tesseraction posted:

Once on the SA servers it's saved to /tmp/Wiggly Wayne DDS.details until the folder is cleared out at midnight.

also pls never ever use the term "military grade" thx

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
how are the sa gift certificates generated?

if you care not to divulge, can you tell us if they're generated in an idiotic manner?

is "kjs500" used as a seed anywhere in the code or have you seen it anywhere else?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tayter Swift posted:

it's kinda amazing that sa has gone as long as it has without getting completely owned in some fashion

SA has been owned. There's a username and password dump floating about from 2004/2005

Wiggly Wayne DDS posted:

someone was dumb enough to use heartbleed

Not a big deal though!

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Tayter Swift posted:

that was twelve years ago

that may be but you didn't specify a time frame either

also search has had stored xss issues as of last year

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
remember firesheep?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

DuckConference posted:

SA got banned from paypal a long time ago, the bittorrent forums or chargebacks or the katrina donation drive or something I don't really remember anymore.

It wasn't that SA got banned but rather Lowtax got pissed off at how PayPal handled large sums of money coming in. He was annoyed that they froze the funds and wouldn't let him give it to the Red Cross.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

gonna be a cold four years talking about secfucks without being able to mention us policy ever

this is the security fuckup thread; not the journalism integrity one

if you want to talk about how much buzzfeed and vox suck, go make a new thread


e:

here you go:
https://forums.somethingawful.com/showthread.php?threadid=3804977

Lain Iwakura fucked around with this message at 18:43 on Jan 11, 2017

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
more ssl fuckery:

https://groups.google.com/forum/?hl=en#!msg/mozilla.dev.security.policy/Htujoyq-pO8/uRBcS2TmBQAJ

quote:

Since many web servers are configured to include the URL of the request in the body of a 404 (not found) response, and the URL also contained the random code, any web server configured this way caused domain control verification to complete successfully.

at least it didn't involve some random chinese outfit

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ErIog posted:

im the /var/log folder on a pacemaker

2017, the year of Linux everywhere but the loving desktop apparently

https://msdn.microsoft.com/en-us/commandline/wsl/about

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/CiPHPerCoder/status/819418588582965248

This guy...

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Thanks Ants posted:

has anyone got any pointers on what to look for when hiring a firm/consultant to do penetration testing? it seems there's a ton of charlatans in the industry.

im currently looking at ones that publish their own research and show up at cons rather than simply blogging about things, but would be interested to hear about how this is usually approached.

Usually a warning sign for me is when there are more marketing people than actual technical people.

Adbot
ADBOT LOVES YOU

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Wiggly Wayne DDS posted:

in non-piss news cellebrite was hacked sometime last year and 900GB of data has been handed to at least motherboard https://motherboard.vice.com/read/cellebrite-sold-phone-hacking-tech-to-repressive-regimes-data-suggests

i've been asking about for the data to no avail

McGlockenshire posted:

he's nuts, but he's also one of the only loud voices in the PHP community talking about security

he's also the kind of nuts that ports libsodium to pure PHP

i admire him for trying but i agree that he's insane for trying to fix the turd that is php

  • Locked thread