Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
thank you, based mods

Adbot
ADBOT LOVES YOU

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/andrew___morris/status/1120297095108485120 interesting

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
oh

https://www.sudo.ws/alerts/minus_1_uid.html

no..

patch your loving linux boxes i guess lmao

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

D. Ebdrup posted:

Every single docker and kubernetes container image, probably?

Yeah, this is mostly the sort of thing I’m worried about here.

Rooney McNibnug fucked around with this message at 23:34 on Oct 14, 2019

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
Symantec fucks up again:

https://www.zdnet.com/article/symantec-antivirus-crashes-something-again-this-time-chrome-78-browsers/ posted:

For the fourth time in three months, a Symantec security product is crashing user apps, and this time it's the latest Chrome release, v78, which rolled out earlier this week, on Tuesday, October 22.

According to reports on Reddit [1, 2] the Google support forums [1, 2], and in comments on the official Google Chrome blog, Symantec Endpoint Protection 14 is crashing Chrome 78 instances with an "Aw, Snap! Something went wrong while displaying this webpage." error, as seen in the screenshot above.

Users have been unable to use Chrome 78 at all, according to reports, with the browser refusing to load any web pages.

...

Symantec blamed the issue on Microsoft's Code Integrity security feature, which Google uses to protect the Chrome browser process.

As a temporary solution, Symantec recommends that users exclude Chrome from receiving protection from their antivirus product, or modify their Chrome clients, so the browser starts without Code Integrity protections.

Their "fix"..:

code:
Chrome.exe –disable-features=RendererCodeIntegrity 
https://support.symantec.com/us/en/article.tech256047.html

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

ratbert90 posted:

HOO loving BOY!

SADDLE UP BOYS! It's time for ~*~*SECURITY AUDIT*~*~ SEASON!

The company doing the audit? They want our AWS server private keys.

What the gently caress? Why do you ask?
Because they use Alienvault which needs a private key!
Fine I say, how about YOU generate a private key and give us your public key, then I can add you to the authorized_key's of our servers.
The result is the email chain so far:

I'm sorry, I just wanted to say please inject this type of horrible poo poo directly into my veins :five:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
didn't expect lurking this thread would make me hungry, but here we are.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://seclists.org/oss-sec/2019/q4/122

quote:

I am reporting a vulnerability that exists on most Linux distros, and
other *nix operating systems which allows a network adjacent attacker
to determine if another user is connected to a VPN, the virtual IP
address they have been assigned by the VPN server, and whether or not
there is an active connection to a given website. Additionally, we are
able to determine the exact seq and ack numbers by counting encrypted
packets and/or examining their size. This allows us to inject data into
the TCP stream and hijack connections.

Most of the Linux distributions we tested were vulnerable, especially
Linux distributions that use a version of systemd pulled after November
28th of last year which turned reverse path filtering off. However, we
recently discovered that the attack also works against IPv6, so turning
reverse path filtering on isn't a reasonable solution, but this was how
we discovered that the attack worked on Linux.

:stonkhat:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
they do not.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
The Dialectics of SecFuck.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/taviso/status/1237105815414124549

he showered again!?

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
Not a secfuck, but lol at this stupid new cookie warning




(I promise i didn't edit html myself in dev tools)

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
Today has been a bit overbearing in terms of vuln releases/info, hasn't it...

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/Kensan42/status/1237492959496544256

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Pile Of Garbage posted:

does pihole support DNS-over-TLS yet? my fortigate firewall does, it's p neat

I think Quad9 servers have that option via Pi-hole config now?

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Squinky v2.0 posted:

I stopped using pihole for a few months because I borrowed the pi for something else

went back to using it this weekend and it’s amazing how much snappier the whole internet feels

pretty gross that I can block a full third of the requests coming from my home network and nothing of value is lost.

It's a beautiful thing.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
yeah just don't get anything with a camera/mic in it, drop ~$25 extra on a raspberry pi, set up a pi-hole and you should be alright. you don't need to buy a gigantic expensive PC monitor...

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/bcrypt/status/1250870148858179584

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
No more HTTP option for login on these cursed forums, nice.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
"As just one example (unrelated to what follows), [Cellebrite] bundles FFmpeg DLLs that were built in 2012 and have not been updated since then. There have been over a hundred security updates in that time, none of which have been applied."

lol

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
I installed Gentoo successfully and now the old laptop I put it on just sits there collecting dust. Has been this way for months since the install was completed. :zen:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Waterslide Industry Lobbyist posted:

Just had a helpdesk guy send me this, this is their fix for a known issue about not being able to add more lines.



:sickos:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/U039b/status/1469375014046687239

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

post hole digger posted:

i was supposed to have today off :/

same lmao

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://twitter.com/cryps1s/status/1469493965804036100

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
oops

Rooney McNibnug fucked around with this message at 21:26 on Dec 12, 2021

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt

"We discovered a Local Privilege Escalation (from any user to root) in polkit's pkexec, a SUID-root program that is installed by default on every major Linux distribution

...

- pkexec is installed by default on all major Linux distributions (we exploited Ubuntu, Debian, Fedora, CentOS, and other distributions are probably also exploitable);

- pkexec is vulnerable since its creation, in May 2009 (commit c8c3d83, "Add a pkexec(1) command");

- any unprivileged local user can exploit this vulnerability to obtain full root privileges;

- although this vulnerability is technically a memory corruption, it is exploitable instantly, reliably, in an architecture-independent way;

- and it is exploitable even if the polkit daemon itself is not running."

:holymoley:

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
I believe so, yes

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Malloc Voidstar posted:

this part's also good


okay i don’t use lastpass but.. i imagine exporting to unprotected .xlsx is NOT a feature

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
i guess what i mean to say is exporting your domain admin passwords from a password manager into an unprotected spreadsheet to float around is not ideal

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Ulf posted:

a little sneak peek at the QUIC page that I'm writing up.

while reading through the key derivation processes for QUIC i ran into this value used to create the init-phase encryption keys:
code:
initial_salt = 0x38762cf7f55934b34d179ae6a4c80cadccbb7f0a
... snip ...
in cryptography you don't use constants like this without some explanation of how you derived it, a concept called a "nothing-up-my-sleeve number". you make it the first 32 digits of pi in hex, or the first hundred primes, or the hash of an empty string, or whatever. i went looking for how they'd come up with this one, expecting a link to some ietf list email.

this value wasn't derived in any of the usual ways. it's a trophy. when google research co-created the SHAttered attack on SHA-1 this was the first collision they found.

they put the corpse of SHA-1 into their next cryptographic protocol. :black101:

Looking forward to reading more

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

CommieGIR posted:

I got my thing, so now to copy everyone's access cards:



I've been going ham with mine, especially collecting infrared stuff: https://github.com/RooneyMcNibNug/Flipper-nil/tree/main/Infrared

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Rooney McNibnug posted:

I've been going ham with mine, especially collecting infrared stuff: https://github.com/RooneyMcNibNug/Flipper-nil/tree/main/Infrared

My neighbor also keeps wondering why his Tesla's charger port keeps opening "out of nowhere" :ghost:

Adbot
ADBOT LOVES YOU

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
lmao what a gift on this cursed monday

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply