Page 42 of 44 FirstFirst ... 32 40 41 42 43 44 LastLast
Results 821 to 840 of 875
  1. #821
    Ridill
    Join Date
    Jul 2008
    Posts
    11,321
    BG Level
    9

    Quote Originally Posted by synistar View Post
    Along a similar subject, just an IT fail for Riot - https://x.com/Dexerto/status/2008159160358117830

    The SSL cert for LOL was renewed for 100 years now.
    Jesus christ....certs are NOT that hard to figure out. Setting it to 100yrs is stupid

  2. #822
    Pay No Attention to the Man Behind the Curtain
    Join Date
    Jan 1970
    Posts
    3,493
    BG Level
    7
    FFXIV Character
    Ragns Meuhie
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut
    Blog Entries
    173

    Hackers are bypassing Twitch's 2FA by stealing the user's cookie and changing streamers' payment methods to steal their money: https://thecybersecguru.com/news/twi...ck-2fa-bypass/

    Even BG Forum validates user cookies against their partial IP and user agent before doing anything important. INB4 Ksandra complains about this

  3. #823
    Ridill
    Join Date
    Jul 2008
    Posts
    11,321
    BG Level
    9

    Quote Originally Posted by Ragns View Post
    Hackers are bypassing Twitch's 2FA by stealing the user's cookie and changing streamers' payment methods to steal their money: https://thecybersecguru.com/news/twi...ck-2fa-bypass/

    Even BG Forum validates user cookies against their partial IP and user agent before doing anything important. INB4 Ksandra complains about this
    A sophisticated new wave of cyberattacks is targeting Twitch streamers, successfully bypassing Two-Factor Authentication (2FA) to drain earnings.
    "Sophisticated" my ass lol, it's Twitch not even doing the bare minimum for security. What the ever living fuck. It's a basic tenant of Zero Trust, just enabling 2FA and SAML doesn't suddenly make you impervious. It's like these companies that "encrypt" their data in base64 text files on a web accessible site but oh hey it's not plaintext!

    The 2FA Crisis This event is a wake-up call for the entire tech industry. 2FA via SMS is dead. 2FA via App is vulnerable to cookie theft. The only true defense remaining is Hardware Security Keys (FIDO2/WebAuthn) like YubiKeys, which require a physical touch to authenticate a new session.
    Like Ragns said, if user agent or IP change you have to reauth.... 2FA via SMS isn't fully dead, you can't suddenly expect everyone to get a hardware token. Just handle shit better. Don't allow your 2FA SMS to spam a user to the point they just accept out of frustration...don't let your 2FA via web app to trust everything because a user authenticated one time 5hrs ago and has since seemingly moved to a different country with a new IP.

  4. #824
    BG Content
    Join Date
    Jul 2007
    Posts
    22,408
    BG Level
    10
    FFXI Server
    Lakshmi
    Blog Entries
    1

    You can send whatever you want as the user agent string, so it doesn't increase security notably to include it, but I guess it doesn't hurt. IP isn't completely foolproof either but it's at least harder to spoof. You're basically checking for hacker incompetence, but most of them are incompetent.

  5. #825
    Ridill
    Join Date
    Jul 2008
    Posts
    11,321
    BG Level
    9

    Quote Originally Posted by Byrthnoth View Post
    You can send whatever you want as the user agent string, so it doesn't increase security notably to include it, but I guess it doesn't hurt. IP isn't completely foolproof either but it's at least harder to spoof. You're basically checking for hacker incompetence, but most of them are incompetent.
    True, but updating your payout or credit card info or anything like that, even password change should prompt a mandatory authentication check.

  6. #826
    BG Content
    Join Date
    Jul 2007
    Posts
    22,408
    BG Level
    10
    FFXI Server
    Lakshmi
    Blog Entries
    1

    Quote Originally Posted by Meresgi View Post
    True, but updating your payout or credit card info or anything like that, even password change should prompt a mandatory authentication check.
    Yeah, for sure. I just found it funny to be like "they stole a cookie. Surely checking the user agent string will stop them."

    Most hackers are bad programmers so it probably would a shocking amount of the time, but it's just dotting is and crossing ts.

  7. #827
    Pay No Attention to the Man Behind the Curtain
    Join Date
    Jan 1970
    Posts
    3,493
    BG Level
    7
    FFXIV Character
    Ragns Meuhie
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut
    Blog Entries
    173

    IMO it's so stupid that Twitch, a company backed by AWS, has the same security failures as PHP-Nuke in the early 2000s.

  8. #828
    BG Content
    Join Date
    Oct 2005
    Posts
    70,206
    BG Level
    10
    FFXIV Character
    Six Souls
    FFXIV Server
    Gilgamesh
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Malorne
    Blog Entries
    9

    Nike - 1.4TB, 200k of the files have been leaked to the dark web

  9. #829
    Ridill
    Join Date
    Jul 2008
    Posts
    11,321
    BG Level
    9

    https://arstechnica.com/security/202...-chain-attack/

    Notepad++ said that officials with the unnamed provider hosting the update infrastructure consulted with incident responders and found that it remained compromised until September 2. Even then, the attackers maintained credentials to the internal services until December 2, a capability that allowed them to continue redirecting selected update traffic to malicious servers. The threat actor “specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.” Event logs indicate that the hackers tried to re-exploit one of the weaknesses after it was fixed but that the attempt failed.

    According to independent researcher Kevin Beaumont, three organizations told him that devices inside their networks that had Notepad++ installed experienced “security incidents” that “resulted in hands on keyboard threat actors,” meaning the hackers were able to take direct control using a Web-based interface. All three of the organizations, Beaumont said, have interests in East Asia.

    This is hilariously bad...like wipe your system bad but it's too late now anyways

  10. #830
    It's all dicks and airplanes
    Join Date
    Jun 2009
    Posts
    2,303
    BG Level
    7
    FFXIV Character
    Cia Mir
    FFXIV Server
    Balmung

    suppose I'm lucky that I never reinstalled it after I reinstalled windows

    Still the best notepad program around so hopefully they're alright in the long run

  11. #831
    Mr. Bananagrabber
    Sweaty Dick Punching Enthusiast

    Join Date
    Dec 2005
    Posts
    55,583
    BG Level
    10
    FFXI Server
    Asura

    The auto updater is what got compromised. Installing through the website was/is fine

  12. #832
    Ridill
    Join Date
    Jul 2008
    Posts
    11,321
    BG Level
    9

    Quote Originally Posted by Madeline View Post
    suppose I'm lucky that I never reinstalled it after I reinstalled windows

    Still the best notepad program around so hopefully they're alright in the long run
    Not the 1st or last time this will happen. 10yrs ago the CIA had hacked them lol

  13. #833
    She Shoots For The Stars
    Join Date
    Aug 2009
    Posts
    1,650
    BG Level
    6
    FFXIV Character
    Elizara Paksenarrion
    FFXIV Server
    Excalibur
    FFXI Server
    Quetzalcoatl

    Lol. thank goodness for a while I was updating manually. It's still one of my go tos for a lot of script stuff. Thank heaven for Patch My PC, which I use once a week.

    I'm gonna keep to updating manually for now.

  14. #834
    Pay No Attention to the Man Behind the Curtain
    Join Date
    Jan 1970
    Posts
    3,493
    BG Level
    7
    FFXIV Character
    Ragns Meuhie
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut
    Blog Entries
    173

    Quote Originally Posted by Meresgi View Post
    https://arstechnica.com/security/202...-chain-attack/




    This is hilariously bad...like wipe your system bad but it's too late now anyways
    FFS... if you installed any version from 8.8.2 to 8.8.8 using the auto-updater you're fucked.

    Also, apparently the update files were hosted on a infected WordPress server.

  15. #835
    Ayn
    Ayn is offline
    Yoshi P
    Join Date
    Jan 2006
    Posts
    5,282
    BG Level
    8
    FFXI Server
    Sylph

    Haven't used it in forever. Looks like I'm on 8.7.4.0

  16. #836
    Mr. Bananagrabber
    Sweaty Dick Punching Enthusiast

    Join Date
    Dec 2005
    Posts
    55,583
    BG Level
    10
    FFXI Server
    Asura

    If you were on version 8.8.2 through 8.8.8 you'd need to be concerned

  17. #837
    Weaboo of the House of Weave
    Join Date
    Mar 2005
    Posts
    10,484
    BG Level
    9
    FFXIV Character
    Arthur Pendragon
    FFXIV Server
    Gilgamesh

    8.6.x lol it is and always has been one of my biggest procrastinated updates as far as apps are concerned. Lucky me

  18. #838
    BG's #1 Hatsune Miku fan!
    Join Date
    Dec 2009
    Posts
    10,079
    BG Level
    9

    I wonder how this could have happened?

    cough:trumpexecutiveorder14306:cough

  19. #839
    BG Content
    Join Date
    Oct 2005
    Posts
    70,206
    BG Level
    10
    FFXIV Character
    Six Souls
    FFXIV Server
    Gilgamesh
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Malorne
    Blog Entries
    9

    https://venturebeat.com/security/cla...security-stack

    The Mexican government via Claude and ChatGPT. 150GB of data including 195M taxpayer records, voter records, government credentials, & civil registry files. Despite both chat bots having guardrails against such actions, users used prompts that gave a detailed step by step guide on how to carry out the attacks, which is something that the programmers hadn't considered.

  20. #840
    Duplicitous Jew with Political Aspirations
    Join Date
    Dec 2015
    Posts
    18,775
    BG Level
    9

    Claude accidentally posted their entire source code during an update and now it's all over the internet for free; someone rewrote it from scratch so their version isn't subject to DMCA strikes and is presumably available forever.

    Sent from my SM-S938U using Tapatalk

Page 42 of 44 FirstFirst ... 32 40 41 42 43 44 LastLast