Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

CommieGIR posted:

And BMW, and Mercedes, and basically everyone.
japan is that scene in Iron Sky where finland admits they’re the only country in the world that didn’t sneak nukes into orbit

Adbot
ADBOT LOVES YOU

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
it feels lame to post articles from the research group of my day job but everyone loves an AV fuckup right?

https://medium.com/tenable-techblog/comodo-from-sandbox-to-system-cve-2019-3969-b6a34cc85e67

quote:

The signature check was simply bypassed however by….wait…let’s see if you can see the problem. Here is CmdAgent.exe resolving the COM client’s process name to later invoke a signature check from disk:

(diagram showing call to GetModuleFileNameEx)

As you may know, GetModuleFileNameEx just queries the target process’ PEB->Ldr->InMemoryOrderModuleList for full image name. This is in our control of course and can be easily changed within our own process.
the article then goes on to use process hollowing instead of simply changing the executable name, for bonus points I guess

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

CommieGIR posted:

Caveat: SSH should always be behind a VPN. Always.
why is exposing (pubkey-based) ssh less secure than a vpn endpoint?

edit: to be clear: for a home network

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
it's never a conscious choice, just a series of decisions between the benefits/risks of just-one-more-line vs a rewrite

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://twitter.com/kcimc/status/1099934485301276673
was this already in the thread? w/e it was new to me.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://www.reddit.com/r/sysadmin/comments/dpbt3t/the_perils_of_security_and_how_i_finally_resolved/
suspicious charges repeatedly show up on amazon account despite 2fa etc, is maybe tracked to hidden smart TV attached to account :waycool:

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

Midjack posted:

iirc there’s something in the pci spec that requires a human readable number on the card for offline processing
my apple card has no numbers on it at all (only my name and three corporate logos/brands). i guess if you’re apple you can get away with things though.

(there is a fixed number, you can reveal it using the phone app, or it’s autofilled in macOS / iOS as needed. and the magstrip has it encoded)

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

motoh posted:

possibly stdh, but also, brilliant capturing of hostile resources
for anyone that didn't get to the very end of the last image for the punchline: these were trivial to detach and inside was a sim card w/ an unlimited data plan that worked for months before being disabled

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
i don't see that anyone pasted the actual details of yesterday's windows vuln. i guess you can spoof any EC-using CA by using the spoofed CA's pubkey as the generator

https://twitter.com/tqbf/status/1217518138885115906

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

"Correction: This post has been updated to remove mention of a vulnerability that Microsoft had not actually disclosed."
https://mobile.twitter.com/malwrhunterteam/status/1237445289914634240

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
i was reading taviso's twitter timeline and i just got to the part where he doesn't have fingerprints

https://twitter.com/taviso/status/1173366802333626368

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
edit: i was pages behind, n/m

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
did they get a bearhug at least

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://www.youtube.com/watch?v=1hs451PfFzQ

using Bayesian analysis on the Zelda Windwaker RNG to write tools to help speedrunners get through the battleship minigame.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://www.howmanydayssinceajwtalgnonevuln.com

Hahahahahahahaha How The gently caress Is Alg=none Real Hahahaha Just Reject The Token Like Say No Haha

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
speaking of, look who still uses WordPerfect 6.2 For DOS: https://news.ycombinator.com/item?id=24411333

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://twitter.com/Laughing_Mantis/status/1308220848981962753 this subthread was fun too.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
Context: Microsoft has already confirmed next update for Windows 10 will automatically remove Flash Player.

quote:

While millions of kids are doing remote learning? That seems like a terrible idea, there is tons of educational sites using flash.

quote:

my kids' teachers have still been assigning Flash websites as school tasks - "play this educational game" sort of stuff - in recent months.

quote:

My teachers are also using Flash-enabled sites for their quiz and presentation :(
:unsmigghh:

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

evil_bunnY posted:

my favorite secfuck was a customer putting a not-free coffee machine by the consultants' offices, and us figuring out how to make it spit free coffee in exactly one day.
you mean a zeroday java sandbox escape

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

some HN commenter posted:

I'm surprised congressional office's laptops do not embed remotely detonated explosives/destruction devices triggered with sat or cellular comms.
:hmmyes:

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
Most of mine are locked away behind forums search.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://cookieconsentspeed.run
:golfclap:

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://twitter.com/kenklippenstein/status/1376572360770383876

quote:

An Amazon engineer thought @amazonnews had been hacked because its tweets are so “unnecessarily antagonistic”, per internal problem ticket leaked to me (screenshot below)

quote:

According to Recode, the suspicious tweets in fact came at the behest of Amazon CEO Jeff Bezos, who had recently conveyed disappointment to Amazon officials that the company was not pushing back against criticisms that he considered misleading.

it never occurred to me that i can just report lovely exec behavior to our infosec team

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
not looking good for my newborn son i named "asdf lkjasdf;"

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
related tweet https://twitter.com/tonyhawk/status/1117312699703152645

code:
                          ———————
You must be this rad:   ->
to rent a vehicle

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
it is also a "security button"

Buck Turgidson posted:

couldn't you just make it one key

this way you can have 7 different passwords tho

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
the crime is... in the computer?

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
lucida sans? tell it to the judge, hippie

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
dang it i missed text/i18n chat. oh well, posting anyway:

Shaggar posted:

case sensitive file systems are incredibly stupid
but dealing with homograph and normalization attacks in your fs is awful too

so is the fact that your case smashing rules change in e.g. german vs french locales

maybe it's human text that is incredibly stupid, has anyone removed humans from computers

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
well it’s definitely an opinion

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
mild effort post:

in the Turkish locale “i” and “I” are different letters and each has a corresponding dotted / dotless glyph in the opposite case.

in the dutch locale ijssel == IJssel != Ijssel (technically)

uppercase ß turns into SS in German, but not always vice versa for lowercase. there’s also a uppercase ß which you shouldn’t use because gently caress you, but you still need to handle it and keep it equivalent to SS and ß.

traditionally you are not supposed to keep the accents on capitals in French (but this is changing)

speaking of accents there are at least two ways to represent every common accented character in unicode (ref unicode normalizations, NF / NFK)

if you want to have case insensitive filesystems (and they’re probably the better choice for users) you need to put all of the above into your stdlib or fs drivers. and it’s going to be full of bugs and probably exploits.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
forgot to answer the specific question about French vs German capitalization rules. really it’s french vs everyone else in this case but every locale has quirks like this.

in french accents on capitals are optional, so in French locale ë == Ë == E but in German ë == Ë != E

so what does your filesystem do if your German user makes two files E.txt and Ë.txt, puts it on a drive and gives it to their colleague on the other side of the Rhine?

Ulf fucked around with this message at 17:21 on Aug 31, 2021

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
it got adopted into "American style" but it was originally because publishers / typesetters thought it looked "more balanced" / "more pleasing".

these days we're moving to "British style" and soon it'll be a relic like double-spacing and New Yorker diaereses.

Shaggar posted:

non-english languages should just be abandoned rather than trying to cater to all their stupid, pointless edge cases.

i think i i18n-pilled shaggar

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

BrianRx posted:

So uh... is this thread remarkably linguistically diverse (for a US message board), are polyglots overrepresented in the security community, or what? This is all super interesting to me, but this is not the subforum where I expected to read it.
I'm US-based and only know 2-ish languages but I also have a career in i18n. You learn the quirks of each language because you can't safely process text without some idea of them.

Internationalization is very much on topic for the security thread .

Ulf fucked around with this message at 17:37 on Aug 31, 2021

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

spankmeister posted:

nah this is one of his gimmicks

of course it makes perfect sense for them to substitute the sz character with ss and not sz like the character is called because of course
(:godwin:)

also the fact that "there is no majuscule for ß" and yet it exists (ẞ) is a perfect encapsulation of the joy of text

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

spankmeister posted:

Its only saving grace is that it's so ubiquitous.
in english we say that english is the lingua franca

Methanar posted:

my favorite language fact is that the finnish language has no future tense.
perkele is, perkele was, but perkele will not be

Ulf fucked around with this message at 22:51 on Aug 31, 2021

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

Shame Boy posted:

in the specific case of "weird letters for S" it's because the long S and the german ß were both descended from the same original character (do not steal) in ancient roman cursive

ß is just a ligature of ſ + s (well, ſ + z according to the name, but it's ſ + s in appearance). This is the fuzzy zone in Unicode where the only difference between a font making a ligature for two characters next to each other such as "fi" or having it be its own code point is the various accidents of history.

Security related content: if fuzzing for buffer overflows in displays the widest character in unicode is ﷽ which is a ligature for "In the name of Allah the Merciful". The longest ligature decomposition (afaik) is ﷺ ("peace and blessings of Allah be upon him"), which decomposes to U+0635 U+0644 U+0649 U+0020 U+0627 U+0644 U+0644 U+0647 U+0020 U+0639 U+0644 U+064A U+0647 U+0020 U+0648 U+0633 U+0644 U+0645 and is useful for tickling normalization overflows.

The way many of these get into unicode is via unicode's goal of being a superset of all other charsets; if it's gone into any of the hundreds of pre-unicode charsets it gets into unicode.

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
is this an arg

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
kjs501

Adbot
ADBOT LOVES YOU

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
https://www.pcmag.com/news/microsoft-patent-describes-tracking-brain-activity-to-mine-cryptocurrency

lovely cyberpunk near future posted:

The application, entitled “Cryptocurrency System Using Body Activity Data” explains how a “brain wave or body heat emitted from the user when the user performs the task provided by an information service provider, such as viewing an advertisement or using certain internet services, can be used in the mining process.”

By tracking brainwaves when someone watches an advert, Microsoft hopes to use the data generated as a “proof-of-work.” This is the validation of a transaction, or the completion of a task, in a blockchain system, and the way in which creation of currency is validated in a cryptocurrency model.
what if langford’s basilisk was a crypto miner served by the doubleclick ad network

good thing the article is laughable bullshit

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply