Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shaggar posted:

those look more like convenience things rather than "bloatware" . like some desktop support guy probably created this for setting up new computers. its that classic thing where someone knows just enough to do some damage, but not enough to automate it via gpos and system imaging.

there's a few of those options that will almost certainly break the user profile during certain update scenarios, and i can only imagine the mess the "reg keys" functions will create because dollars to donuts it's not just the keys gpos create. some of the likely candidates require taking ownership of the keys to modify or prevent windows from resetting the values, which makes a huge loving mess during OS version upgrades

while the more obvious problem is microsoft creating a market for this bullshit in the first place, the real issue is still training people to just pipe random poo poo from the web into an elevated command prompt as a solution to anything, ever.

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Tankakern posted:

doesn't the auto installer work still? just did that on a win 10 computer a few days ago

the first thing requiring 3.5 will spawn a dialog in windows asking if you want to download and install it

it works in unmanaged environments iirc, it doesn't always work in wsus managed environments, depending on the update types enabled on your wsus servers

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
if your wsus servers aren't configured for whatever update classification the .net installer is under the client just throws an error message that's generally weird for the context, because they've queried the server and the feature files don't exist

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Main Paineframe posted:

it's more like a virtual sweatshop

most of the actual players are in very poor Southeast Asian countries where a couple bucks a day is a decent wage. they get into the game via sponsorship by American crypto investors, who pay their initial signup fees in exchange for most of their game earnings, forever

this sounds like the most perfect implementation of capitalism yet

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

ate poo poo on live tv posted:

What's wrong with an old honeywell mercury switch thermostat? You set it to the temperature you want, and then leave it alone. Easy peasy.

mine works, i adjust it twice a year.

i also have radiant heat and no ac, so there's very little for it to do

obviously this isn't for everyone

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
also, host all your own services on-premises

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i can't get into my garage because my oauth provider is having dns issues

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
more details on the ka-sat outages

someone pushed malware to the modems themselves over a management channel

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

that's a major security risk, someone could just roll it away

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
naturally, three olives bought one

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Chris Knight posted:

fighting Norton360 to try to get access to my late father's password vault using the pw I wrote down like 2 years ago because it seemed to work at the time. loving pain in the rear end.

i'm sorry chris, about all of that, really

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Cold on a Cob posted:

*fires a shitload of missiles into the geographical centre of the united states*

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
the crimes of a nation, at your doorstep

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BattleMaster posted:

is that the setup that caused someone on this forum to have a meltdown because they were so sure that it had to do with child porn somehow or am I thinking of some other jank-rear end hardware setup?

yeah, nbsd loving owned himself over the abomination that was that project

loving brilliant, that was

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Methanar posted:



mostly unrelated but I just remembered more funny networking poo poo at that last job.

We had this horrible ghetto custom hardware situation we built out. And the wired were so poorly laid out with unshielded network cables directly against these huge power lines powering 15 devices that sometimes because of all the electromagnetic interference would cause things to auto negotiate down to 100mbps lmao

i love this whole thing simply for being built, because it's so profoundly bad.

i could have sworn it was a university project or something because there was just no way someone would try to build an actual product like that, but welp.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
you monster

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
did you make that in coreldraw?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
someone appears to have built an APT that isn't pants-on-head stupid and blaring its presence to all and sundry. it turns out it's actually fairly difficult to detect and remove.

who knew?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
thank you achmed, i will endeavour to be more accurate in my choice of terms when linking external sites

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
man, i hate drop bears

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
so... the discord is the honeypot, right?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

KirbyKhan posted:

Two years ago I spent too much time in LinkedIn researching and launching a career change and it was the most psychically damaging platform to post on I have ever been.

LinkedIn Sherpa is still doing the heavyish lifting. She has built a couple resume templates and tested them against a suite of ATS software to see which combinations of words get picked up better depending on formatting. They maintain a jobs portal of nonautomated and curated job postings. They also do resume reading, workshopping, and one on one interview prep. Career Team is separate from Instructor Staff and looks to be about 6 people deep servicing a student population of aroundish 500-800 depending on cohort cycle. Idk I'm not paying for this, but the government put about $30k in funding for lil ol me and if I don't get employed they don't get paid.

I've been in like 3 different CARES ACT funded programs and this has been most value and least scammy, but... That is a condemnation of CARES not of this course.

i'm happy for you though
or sorry that happened

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
thinkin' about butts

that's really cool though. and lmao at sending unfiltered user biometric data to some random rear end s3 bucket, just because

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shame Boy posted:

i was thinking, as hard as i possibly could, "rip stebe, died of ligma" over and over

its not even going into any sort of structure or database either, it's just writing to "$userId_$timestamp" files that it rotates every minute or so. i thought it was writing the converted-to-float values originally too but i just checked and it's the straight up raw bytes.

another interesting thing is if you have the headband powered on but not on your head, it can't actually tell and will happily pick up and heavily amplify all the low-frequency electrical noise around it. you can immediately tell that's what it is too because the amplitude is way higher than when it's actually on a head (and the SDK seems like it actually uses this as a signal that it needs to tell you to adjust the thing cuz it's not getting good contact). so somewhere out there is the remnants of an S3 bucket containing among other things a bunch of people's 2016-era low frequency RF environment signatures i guess, i wonder what you could do with that.

the traditional startup "eh, we'll probably do something with it, just store it and we'll figure it out later"

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shame Boy posted:

thanks, i'm glad y'all like it cuz i have no idea what i'm gonna do with it now lol. probably take it apart, the kickstarter claims it has some magic EEG chip in it that implements cutting-edge filtering and signal processing, but i super doubt that because the SDK had to do all that poo poo in software and the output really seems to just be raw ADC readings

nothing about that in the SDK but i swear i felt a weird tingling at one point coming from the electrodes :ohdear:

again, startup mentality, the product features are entirely aspirational and what shipped was an entirely fudged tech demo

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

hell yeah, this'll be a party

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shaggar posted:

both bad for different reasons, but the later works on mobile devices.

and thus progress is made

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

flakeloaf posted:

lazy nerds will log in as user because local policy requires it, then use runas to pop an admin-level command prompt or powershell window to do admin stuff, and just leave it open because lol who cares

sudo bash

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

now that's a ui

every option i could possibly need, at my fingertips

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BattleMaster posted:



I don't think the problem here is disabling fixes for CPU bugs

what the gently caress

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i mean, i guess that's sort of what you'd expect from someone going out of their way to disable any and all security mitigation on their system in the name of performance, but still

lmao

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

what does #include do? posted:

noibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off tsx=on tsx_async_abort=off mitigations=off

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
oh ho

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

burning swine posted:

this is not particularly contemporary, but a friend of mine (forums poster Malathion) just told me about this guy that he encountered: https://www.commandlinefu.com/commands/view/13858/run-vlc-as-root

It's from 2014 but the stubborn rear end in a top hat computer toucher vibe is amusing and embarrassingly relatable to positions I've personally taken in past lives

secfuck thread 18.14: I do not see how can a movie or a music file can compromise my system

iirc you could embed at least scripts and possibly executable code in wmv

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
are you suggesting that the person who insists on running everything as root does not have a fulsome understanding of exploit methods?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Kazinsal posted:

security fuckup megathread 18.15: some dickhead is probably already doing this in rust

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shame Boy posted:

yeah i checked the URL too and like, i could kind of understand (though not agree with, but understand) if it were a list of poo poo that changed all the time and you wanted to make sure you always had the latest list, but why the hell wouldn't you just set something like this up once, does he think the list is going to be constantly updated??

well, start with making a terrible decision for arbitrary and likely poorly understood reasons and work from there

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Subjunctive posted:

always do, buddy. always do

it's good to have a process

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Vanadium posted:

I've been very fond of this email I got at work:

:hmmyes:

unrelated, i have been asked to give a presentation on IT security to a client at their company retreat next week.

should be hilarious.

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
hacking into the worldwide jacuzzi network

quote:

The login works by sending the username and password to Auth0. On success, access and ID tokens are returned. The access token is then sent to Auth0’s /userinfo endpoint and this information is returned:


This information contains a list of roles, and isAdmin is checking whether Admin is there. In my case, it is not. If the HTTP response could be intercepted to add in the missing Admin role, it’s possible the unauthorized page would no longer show. I used Fiddler to modify the HTTP response accordingly, and I was finally able to access the admin panel in full.

lol

infernal machines fucked around with this message at 00:33 on Jun 22, 2022

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply