Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
geonetix
Mar 6, 2011


I do. It's just run of the mill grc work like you see everywhere, where everyone you speak to still assumes you're configuring firewalls and don't understand why loss of availability would be a risk worth addressing from a security perspective.

It's drat hard, nigh impossible to stay engaged.

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


Oh and it never really gets any busier than what you're currently doing, for most commercial companies it really is basically a check-the-box-position.

geonetix
Mar 6, 2011


it’s an incredibly tedious type of work and I wouldn’t recommend it. it does involve talking to people that should work the policies and continuously wondering why they don’t so it’s not just office365 work, but it is a well paying joke of a job regardless

geonetix
Mar 6, 2011


doesnt every Oracle agreement disallow any posts or comparison about their products? be careful before their army of lawyers take all of lowtax’s spine cash

geonetix
Mar 6, 2011


I’ve been trying to read the Wireguard documentation today but I’m not good enough for this... or everyone just uses terminology that doesn’t match up with anything I know.

any good posts on how to set up client/server wg that an idiot like me can use?

geonetix
Mar 6, 2011


the wg writeup is great, thanks!

geonetix
Mar 6, 2011


duz posted:

if thats what it takes to get people to keep their dependencies up to date...

I ran a snyk test on our companies repo once. panicked, closed the terminal, and went to find another job.

worked out great thusfar

geonetix
Mar 6, 2011


isn’t the master key something idiotic like 9876 or 9999 anyway, since even the hotel personnel is too lazy to pick something meaningful?

geonetix
Mar 6, 2011


exactly

geonetix
Mar 6, 2011


Soricidus posted:

the latest amd cpus literally came with a hardware rng that always returns -1

that number was carefully selected with several dice rolls by a committee

geonetix
Mar 6, 2011


it’s a beauty

apparently it was worth $10000 if they posted it to 0dayium instead of anonymously to the fd list

geonetix
Mar 6, 2011


doubt the SA vbulletin is new enough to hit the minimum version

geonetix
Mar 6, 2011


so thats everyone

geonetix
Mar 6, 2011


i can’t wait for the first 4% fine to happen

geonetix
Mar 6, 2011


Volmarias posted:

Extremely same but I'm not holding my breath.

didn't BA get hit with 1.8% (or was it 2.8%?) of revenue for being magecarted? nice last in-eu-move by the ICO

geonetix
Mar 6, 2011


yes but we can’t patch because [insert idiotic reason here]

sucks that these people are typically considered not the best protected, hope autoriteit persoonsgegevens and police can do anything and that they change literally everything..

ancilla probably has a valid opinion about this

geonetix
Mar 6, 2011


for as much as I’ve read about it the ec council seems the biggest ripoff for everything they do

geonetix
Mar 6, 2011


I think he posted later it’s cloud related

geonetix
Mar 6, 2011


no but docker always runs with root privs

geonetix
Mar 6, 2011


Cocoa Crispies posted:

yeah there was a fun challenge in the cccamp19 ctf where you used a docker image that lets you run commands as root to escalate your host privilege (I used root in the docker to make a bash executable setuid root on a host volume)

all the docker sandbox escapes I’ve seen in ctfs or challenges the last couple years were all dirtycow based

also fun but I guess a lot less realistic nowadays

geonetix
Mar 6, 2011


what’s a leaked root ca if it cures lowtax’s spine

geonetix
Mar 6, 2011


Share Bear posted:

gonna guess this is still correct? https://gist.github.com/grugq/353b6fc9b094d5700c70

someone put that in the first post

what makes freedome an acceptable vpn?

geonetix
Mar 6, 2011


i'm still on safari for some reason, but i seem to be alone in the infosec community

geonetix
Mar 6, 2011


Tankakern posted:

bah, let's post php 0-days to hn

https://github.com/neex/phuip-fpizdam

update your php's, especially if running nextcloud

not exactly responsible disclosure

Pretty sure I read about it before these flurry of releases now also, probably in some nginx or php-fpm advisory. this publication is fine

geonetix
Mar 6, 2011


https://twitter.com/a_tweeter_user/status/1188811977851887616?s=21

im still stuck on the kaka ‘n peepee, but I guess a compromised nuclear power plant is also serious

geonetix
Mar 6, 2011


the actual release from the admin seems to be specifically about the operational tech, not the it infra

but who knows, iran also never admitted to being stuxnetted i think

geonetix
Mar 6, 2011


Carbon dioxide posted:

This poo poo absolutely wouldn't be allowed in the Information Security Policy at my job. In this case the company would probably decide, with the CISO's approval, to stop all cooperation with this audit company.

in a real company the CISO would be told by the ceo or cfo that the exercise is not for security but commercial reasons and just “fix it” when it’s over

geonetix
Mar 6, 2011


ST is just upgrading stuff i think. afaik no hardware change is really necessary?

geonetix
Mar 6, 2011


they just should’ve used magic links in emails and noone would’ve complained

geonetix
Mar 6, 2011


bunq, a dutch online bank, used cvvs as totp at some point. It was great, but for some reason they turned it off.

geonetix
Mar 6, 2011


Midjack posted:

that was a good talk and I’m glad i was there for it.

it was a good one to get the day started for sure

geonetix
Mar 6, 2011


pseudorandom name posted:

Zoom doesn't have end-to-end encryption

IIRC Zoom’s recorded meetings are obscure URL only protected

geonetix
Mar 6, 2011


hey the founder moved away from cisco, what do you expect he knows about cryptography

geonetix
Mar 6, 2011


lord fifth posted:

hi friends, i hope this is on topic given the subject manner

what are your favorite dumbass service vulnerabilities? like something a high schooler could figure out and exploit. i have been charged with crafting a competition and have hit a brick wall

use ckeditor in your php website and leave the demo directory.

(it contains upload.php. it uploads any file. also php files.)

geonetix
Mar 6, 2011


while it does sound very culty wasn’t there a botnet that used kardashian Instagram comment sections as C2?

geonetix
Mar 6, 2011


Oh right! I think that's an enjoyable factoid wrt malware

geonetix
Mar 6, 2011


I'm shocked (well not really) by how slow people are patching. someone figured earlier that to this day not even 5% of the exchange hosts were actually patched in my country.

We can all worry about giant 0days and everything but a large part of those 95% unpatched exchanges haven't patched since 2017 probably. I can only laugh at how depressing it is

geonetix
Mar 6, 2011


shaggar was right

2021 what are you doing

geonetix
Mar 6, 2011


there’s a difference between asking for all types and software and completely pwning your it department because you’re a hostile rear end in a top hat who can’t adapt or ask questions and explain needs

Adbot
ADBOT LOVES YOU

geonetix
Mar 6, 2011


rip mcafee I guess

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply