Two fun facts about IT

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • choof
    Banned
    FFR Simfile Author
    • Nov 2013
    • 8563

    #1

    Two fun facts about IT

    Today is April 8th. For those who may not be up to date in the world of computers, today officially marks the end of Windows XP support. It's probably safe to assume that in the upcoming months, all forms of attacks on the operating system will increase exponentially. If you have XP for personal use, I recommend you either switch to Linux and use XP when not connected to the internet, or upgrade to Win 7. If you work at a place that still uses XP, may god have mercy on your soul.

    And secondly!


    The bug, which is officially referenced as CVE-2014-0160, makes it possible for attackers to recover up to 64 kilobytes of memory from the server or client computer running a vulnerable OpenSSL version.
    While this may not largely affect most of you, if you're currently studying network or systems security (Halogen and litodude come to mind), you should be aware of this bug. The specifics have been leaked into the public as well, so you can find documentation and find out a way to combat it.
  • Charu
    Snivy! Dohoho!
    FFR Simfile Author
    • Mar 2006
    • 6161

    #2
    Re: Two fun facts about IT

    My work station uses Windows XP.

    Good thing I never use for anything serious, lmao.


    Originally posted by JohnRedWolf87
    Charu the red-nosed Snivy
    Had a very shiny nose
    And if you ever saw it
    You could even say it glows

    All of the other Snivies
    Used to laugh and call him names
    They never let poor Charu
    Join in any Snivy games

    (Click the arrow to see the rest)


    Originally posted by Vendetta21
    All in all I would say that Charu not only won this game, his play made me reconsider how I play it.

    Comment

    • Pseudo Enigma
      ごめんなさい (/ω\)
      • Aug 2012
      • 2290

      #3
      Re: Two fun facts about IT

      ugh looks like it's time to go get a job and finally grab a computer that doesn't turn into a pile of shit when it has Win7.

      Comment

      • dAnceguy117
        new hand moves = dab
        FFR Simfile Author
        • Dec 2002
        • 10097

        #4
        Re: Two fun facts about IT

        Originally posted by Pseudo Enigma
        ugh looks like it's time to go get a job and finally grab a computer that doesn't turn into a pile of shit when it has Win7.
        maybe switch to a lightweight linux distro for now?

        Comment

        • benguino
          Kawaii Desu Ne?
          • Dec 2007
          • 4185

          #5
          Re: Two fun facts about IT

          Originally posted by choof
          If you work at a place that still uses XP, may god have mercy on your soul.
          For anyone that does use XP at the workplace it would probably be best for them to alert their supervisor or superiors; perhaps they are unaware of the situation or the implications of XP no longer getting support.
          AMA: http://ask.fm/benguino

          Not happening now! Don't click to join!



          Originally posted by Spenner
          (^)> peck peck says the heels
          Originally posted by Xx{Midnight}xX
          And god made ben, and realized he was doomed to miss. And said it was good.
          Originally posted by Zakvvv666
          awww :< crushing my dreams; was looking foward to you attempting to shoot yourself point blank and missing

          Comment

          • igotrhythm
            Fractals!
            • Sep 2004
            • 6535

            #6
            Re: Two fun facts about IT

            Originally posted by reuben_tate
            For anyone that does use XP at the workplace it would probably be best for them to alert their supervisor or superiors; perhaps they are unaware of the situation or the implications of XP no longer getting support.
            Yeah, and since when have managers of cubicle dwellers worried at all about the problems their workers face? Any Dilbert comic will tell you that the answer is "never."

            More info about the so-called Heartbleed bug, which is still making stuff vulnerable after the patch: http://arstechnica.com/security/2014...oulette-style/
            Originally posted by thesunfan
            I literally spent 10 minutes in the library looking for the TWG forum on Smogon and couldn't find it what the fuck is this witchcraft IGR

            Comment

            • Bluearrowll
              ⊙▃⊙
              FFR Simfile Author
              • Nov 2007
              • 7376

              #7
              Re: Two fun facts about IT

              I work in a test data centre at a bank and a significant chunk of machines are XP run. The UK Government forked out 12 million pounds to Microsoft to continue support for a year. 64KB is a large enough amount of memory that could cause passwords / emails / private keys to be compromised. The timing of the reveal of this bug is very unfortunate.

              Useful links on Heartbleed:


              Check to see if a server you care about is affected:
              1st in Kommisar's 2009 SM Tournament
              1st in I Love You`s 2009 New Year`s Tournament
              3rd in EnR's Mashfest '08 tournament
              5th in Phynx's Unofficial FFR Tournament
              9th in D3 of the 2008-2009 4th Official FFR Tournament
              10th in D5 of the 2010 5th Official FFR Tournament
              10th in D6 of the 2011-2012 6th Official FFR Tournament

              FMO AAA Count: 71
              FGO AAA Count: 10

              Bluearrowll = The Canadian player who can not detect awkward patterns. If it's awkward for most people, it's normal for Terry. If the file is difficult but super straight forward, he has issues. If he's AAAing a FGO but then heard that his favorite Hockey team was losing by a point, Hockey > FFR
              PS: Cool AAA's Terry
              - I Love You


              An Alarm Clock's Haiku
              beep beep beep beep beep
              beep beep beep beep beep beep beep
              beep beep beep beep beep
              - ieatyourlvllol

              Comment

              • Spenner
                Forum User
                • Nov 2006
                • 2403

                #8
                Re: Two fun facts about IT

                Got XP on all the store computers where I work too, though it's not used for much. But still... having a POS system become vulnerable, yikes.

                Comment

                • dAnceguy117
                  new hand moves = dab
                  FFR Simfile Author
                  • Dec 2002
                  • 10097

                  #9
                  Re: Two fun facts about IT

                  (from the OpenSSL bug article)

                  "Bugs in single software or library come and go and are fixed by new versions," the researchers who discovered the vulnerability wrote in a blog post published Monday. "However this bug has left a large amount of private keys and other secrets exposed to the Internet. Considering the long exposure, ease of exploitations and attacks leaving no trace this exposure should be taken seriously."
                  yep, gotcha. so how long has it been?

                  Fully recovering from the two-year-long vulnerability may also require revoking any exposed keys, reissuing new keys, and invalidating all session keys and session cookies.
                  TWO YEARS

                  WHAT

                  Comment

                  • Pseudo Enigma
                    ごめんなさい (/ω\)
                    • Aug 2012
                    • 2290

                    #10
                    Re: Two fun facts about IT

                    Originally posted by Bluearrowll
                    Check to see if a server you care about is affected:
                    http://filippo.io/Heartbleed
                    rip

                    Comment

                    • MrGiggles
                      Senior Member
                      • Aug 2005
                      • 2846

                      #11
                      Re: Two fun facts about IT

                      The heartbleed bug is almost as cool as that CryptoLocker thing that came out a while back

                      almost

                      Comment

                      • Bluearrowll
                        ⊙▃⊙
                        FFR Simfile Author
                        • Nov 2007
                        • 7376

                        #12
                        Re: Two fun facts about IT

                        Originally posted by Pseudo Enigma
                        rip
                        This bug attacks HTTPS port 443 - flashflashrevolution is using port 80 and as such would not show up as an infected website. seagateshare where my network drive is hosted on however...
                        1st in Kommisar's 2009 SM Tournament
                        1st in I Love You`s 2009 New Year`s Tournament
                        3rd in EnR's Mashfest '08 tournament
                        5th in Phynx's Unofficial FFR Tournament
                        9th in D3 of the 2008-2009 4th Official FFR Tournament
                        10th in D5 of the 2010 5th Official FFR Tournament
                        10th in D6 of the 2011-2012 6th Official FFR Tournament

                        FMO AAA Count: 71
                        FGO AAA Count: 10

                        Bluearrowll = The Canadian player who can not detect awkward patterns. If it's awkward for most people, it's normal for Terry. If the file is difficult but super straight forward, he has issues. If he's AAAing a FGO but then heard that his favorite Hockey team was losing by a point, Hockey > FFR
                        PS: Cool AAA's Terry
                        - I Love You


                        An Alarm Clock's Haiku
                        beep beep beep beep beep
                        beep beep beep beep beep beep beep
                        beep beep beep beep beep
                        - ieatyourlvllol

                        Comment

                        • dAnceguy117
                          new hand moves = dab
                          FFR Simfile Author
                          • Dec 2002
                          • 10097

                          #13
                          Re: Two fun facts about IT

                          Originally posted by Pseudo Enigma
                          rip
                          the "uh-oh" message doesn't mean the server is vulnerable, it means something else happened during the test.

                          Comment

                          • arcnmx
                            nanodesu~
                            • Jan 2013
                            • 503

                            #14
                            Re: Two fun facts about IT

                            Yeap heartbleed is quite the bug. Stupid simple mistake of passing memcpy the wrong length, huge consequences.

                            Originally posted by Bluearrowll
                            64KB is a large enough amount of memory that could cause passwords / emails / private keys to be compromised. The timing of the reveal of this bug is very unfortunate.
                            Note that you can just repeat the attack over and over to get a new random set of memory from the server each time, so you can obtain a lot more than just 64KB of data with this attack.

                            And yeah, FFR isn't vulnerable because lolnohttps. Ironically any sites that use no encryption are potentially safer than those that do - at least an attacker needs to be in a privileged position to sniff sensitive data from HTTP.


                            FMO AAAs (1): Within Life :: FGO AAAs (1): Einstein-Rosen Bridge

                            Comment

                            • Reincarnate
                              x'); DROP TABLE FFR;--
                              • Nov 2010
                              • 6332

                              #15
                              Re: Two fun facts about IT

                              I don't know shit about encryption so can someone ELI5 for me -- how does this bug get fixed? What should the average person do to protect him/herself in the meantime?

                              Comment

                              Working...