Go Back   Flash Flash Revolution > General Discussion > Chit Chat
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
Old 04-8-2014, 02:33 PM   #1
choof
Banned
Retired StaffFFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Join Date: Nov 2013
Posts: 8,563
Default Two fun facts about IT

Today is April 8th. For those who may not be up to date in the world of computers, today officially marks the end of Windows XP support. It's probably safe to assume that in the upcoming months, all forms of attacks on the operating system will increase exponentially. If you have XP for personal use, I recommend you either switch to Linux and use XP when not connected to the internet, or upgrade to Win 7. If you work at a place that still uses XP, may god have mercy on your soul.

And secondly!
http://arstechnica.com/security/2014...eavesdropping/

Quote:
The bug, which is officially referenced as CVE-2014-0160, makes it possible for attackers to recover up to 64 kilobytes of memory from the server or client computer running a vulnerable OpenSSL version.
While this may not largely affect most of you, if you're currently studying network or systems security (Halogen and litodude come to mind), you should be aware of this bug. The specifics have been leaked into the public as well, so you can find documentation and find out a way to combat it.
choof is offline   Reply With Quote
Old 04-8-2014, 02:40 PM   #2
Charu
Snivy! Dohoho!
FFR Simfile AuthorFFR Veteran
 
Charu's Avatar
 
Join Date: Mar 2006
Age: 33
Posts: 6,161
Default Re: Two fun facts about IT

My work station uses Windows XP.

Good thing I never use for anything serious, lmao.
__________________


Quote:
Originally Posted by JohnRedWolf87 View Post
Charu the red-nosed Snivy
Had a very shiny nose
And if you ever saw it
You could even say it glows

All of the other Snivies
Used to laugh and call him names
They never let poor Charu
Join in any Snivy games

(Click the arrow to see the rest)


Quote:
Originally Posted by Vendetta21 View Post
All in all I would say that Charu not only won this game, his play made me reconsider how I play it.
Charu is offline   Reply With Quote
Old 04-8-2014, 03:05 PM   #3
Pseudo Enigma
ごめんなさい (/ω\)
FFR Veteran
 
Pseudo Enigma's Avatar
 
Join Date: Aug 2012
Age: 28
Posts: 2,290
Default Re: Two fun facts about IT

ugh looks like it's time to go get a job and finally grab a computer that doesn't turn into a pile of shit when it has Win7.
Pseudo Enigma is offline   Reply With Quote
Old 04-8-2014, 03:08 PM   #4
dAnceguy117
new hand moves = dab
FFR Simfile AuthorFFR Veteran
 
dAnceguy117's Avatar
 
Join Date: Dec 2002
Location: he/they
Age: 33
Posts: 10,094
Default Re: Two fun facts about IT

Quote:
Originally Posted by Pseudo Enigma View Post
ugh looks like it's time to go get a job and finally grab a computer that doesn't turn into a pile of shit when it has Win7.
maybe switch to a lightweight linux distro for now?
dAnceguy117 is offline   Reply With Quote
Old 04-8-2014, 03:19 PM   #5
reuben_tate
Kawaii Desu Ne?
Retired StaffFFR Veteran
 
reuben_tate's Avatar
 
Join Date: Dec 2007
Location: The Kawaiian Island~
Age: 30
Posts: 4,182
Default Re: Two fun facts about IT

Quote:
Originally Posted by choof View Post
If you work at a place that still uses XP, may god have mercy on your soul.
For anyone that does use XP at the workplace it would probably be best for them to alert their supervisor or superiors; perhaps they are unaware of the situation or the implications of XP no longer getting support.
__________________
AMA: http://ask.fm/benguino

Not happening now! Don't click to join!



Quote:
Originally Posted by Spenner View Post
(^)> peck peck says the heels
Quote:
Originally Posted by Xx{Midnight}xX
And god made ben, and realized he was doomed to miss. And said it was good.
Quote:
Originally Posted by Zakvvv666
awww :< crushing my dreams; was looking foward to you attempting to shoot yourself point blank and missing
reuben_tate is offline   Reply With Quote
Old 04-8-2014, 04:09 PM   #6
igotrhythm
Fractals!
FFR Veteran
 
igotrhythm's Avatar
 
Join Date: Sep 2004
Location: Meesheegan
Age: 38
Posts: 6,534
Send a message via Skype™ to igotrhythm
Default Re: Two fun facts about IT

Quote:
Originally Posted by reuben_tate View Post
For anyone that does use XP at the workplace it would probably be best for them to alert their supervisor or superiors; perhaps they are unaware of the situation or the implications of XP no longer getting support.
Yeah, and since when have managers of cubicle dwellers worried at all about the problems their workers face? Any Dilbert comic will tell you that the answer is "never."

More info about the so-called Heartbleed bug, which is still making stuff vulnerable after the patch: http://arstechnica.com/security/2014...oulette-style/
__________________
Quote:
Originally Posted by thesunfan View Post
I literally spent 10 minutes in the library looking for the TWG forum on Smogon and couldn't find it what the fuck is this witchcraft IGR
igotrhythm is offline   Reply With Quote
Old 04-8-2014, 04:21 PM   #7
Bluearrowll
⊙▃⊙
FFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Bluearrowll's Avatar
 
Join Date: Nov 2007
Location: I live in the last place where you Look.
Age: 31
Posts: 7,376
Send a message via AIM to Bluearrowll Send a message via MSN to Bluearrowll
Default Re: Two fun facts about IT

I work in a test data centre at a bank and a significant chunk of machines are XP run. The UK Government forked out 12 million pounds to Microsoft to continue support for a year. 64KB is a large enough amount of memory that could cause passwords / emails / private keys to be compromised. The timing of the reveal of this bug is very unfortunate.

Useful links on Heartbleed:
http://blog.existentialize.com/diagn...bleed-bug.html

Check to see if a server you care about is affected:
http://filippo.io/Heartbleed
__________________
1st in Kommisar's 2009 SM Tournament
1st in I Love You`s 2009 New Year`s Tournament
3rd in EnR's Mashfest '08 tournament
5th in Phynx's Unofficial FFR Tournament
9th in D3 of the 2008-2009 4th Official FFR Tournament
10th in D5 of the 2010 5th Official FFR Tournament
10th in D6 of the 2011-2012 6th Official FFR Tournament

FMO AAA Count: 71
FGO AAA Count: 10

Bluearrowll = The Canadian player who can not detect awkward patterns. If it's awkward for most people, it's normal for Terry. If the file is difficult but super straight forward, he has issues. If he's AAAing a FGO but then heard that his favorite Hockey team was losing by a point, Hockey > FFR
PS: Cool AAA's Terry
- I Love You


An Alarm Clock's Haiku
beep beep beep beep beep
beep beep beep beep beep beep beep
beep beep beep beep beep
- ieatyourlvllol
Bluearrowll is offline   Reply With Quote
Old 04-8-2014, 04:22 PM   #8
Spenner
Forum User
Retired Staff
 
Spenner's Avatar
 
Join Date: Nov 2006
Location: Canada
Age: 31
Posts: 2,396
Send a message via MSN to Spenner Send a message via Skype™ to Spenner
Default Re: Two fun facts about IT

Got XP on all the store computers where I work too, though it's not used for much. But still... having a POS system become vulnerable, yikes.
__________________

Spenner is offline   Reply With Quote
Old 04-8-2014, 05:53 PM   #9
dAnceguy117
new hand moves = dab
FFR Simfile AuthorFFR Veteran
 
dAnceguy117's Avatar
 
Join Date: Dec 2002
Location: he/they
Age: 33
Posts: 10,094
Default Re: Two fun facts about IT

(from the OpenSSL bug article)

Quote:
"Bugs in single software or library come and go and are fixed by new versions," the researchers who discovered the vulnerability wrote in a blog post published Monday. "However this bug has left a large amount of private keys and other secrets exposed to the Internet. Considering the long exposure, ease of exploitations and attacks leaving no trace this exposure should be taken seriously."
yep, gotcha. so how long has it been?

Quote:
Fully recovering from the two-year-long vulnerability may also require revoking any exposed keys, reissuing new keys, and invalidating all session keys and session cookies.
TWO YEARS

WHAT
dAnceguy117 is offline   Reply With Quote
Old 04-8-2014, 06:03 PM   #10
Pseudo Enigma
ごめんなさい (/ω\)
FFR Veteran
 
Pseudo Enigma's Avatar
 
Join Date: Aug 2012
Age: 28
Posts: 2,290
Default Re: Two fun facts about IT

Quote:
Originally Posted by Bluearrowll View Post
Check to see if a server you care about is affected:
http://filippo.io/Heartbleed
rip
Pseudo Enigma is offline   Reply With Quote
Old 04-8-2014, 06:12 PM   #11
MrGiggles
Senior Member
FFR Veteran
 
MrGiggles's Avatar
 
Join Date: Aug 2005
Location: Skaia
Age: 21
Posts: 2,846
Send a message via AIM to MrGiggles Send a message via MSN to MrGiggles
Default Re: Two fun facts about IT

The heartbleed bug is almost as cool as that CryptoLocker thing that came out a while back

almost
__________________
MrGiggles is offline   Reply With Quote
Old 04-8-2014, 06:13 PM   #12
Bluearrowll
⊙▃⊙
FFR Simfile AuthorD7 Elite KeysmasherFFR Veteran
 
Bluearrowll's Avatar
 
Join Date: Nov 2007
Location: I live in the last place where you Look.
Age: 31
Posts: 7,376
Send a message via AIM to Bluearrowll Send a message via MSN to Bluearrowll
Default Re: Two fun facts about IT

Quote:
Originally Posted by Pseudo Enigma View Post
rip
This bug attacks HTTPS port 443 - flashflashrevolution is using port 80 and as such would not show up as an infected website. seagateshare where my network drive is hosted on however...
__________________
1st in Kommisar's 2009 SM Tournament
1st in I Love You`s 2009 New Year`s Tournament
3rd in EnR's Mashfest '08 tournament
5th in Phynx's Unofficial FFR Tournament
9th in D3 of the 2008-2009 4th Official FFR Tournament
10th in D5 of the 2010 5th Official FFR Tournament
10th in D6 of the 2011-2012 6th Official FFR Tournament

FMO AAA Count: 71
FGO AAA Count: 10

Bluearrowll = The Canadian player who can not detect awkward patterns. If it's awkward for most people, it's normal for Terry. If the file is difficult but super straight forward, he has issues. If he's AAAing a FGO but then heard that his favorite Hockey team was losing by a point, Hockey > FFR
PS: Cool AAA's Terry
- I Love You


An Alarm Clock's Haiku
beep beep beep beep beep
beep beep beep beep beep beep beep
beep beep beep beep beep
- ieatyourlvllol
Bluearrowll is offline   Reply With Quote
Old 04-8-2014, 06:20 PM   #13
dAnceguy117
new hand moves = dab
FFR Simfile AuthorFFR Veteran
 
dAnceguy117's Avatar
 
Join Date: Dec 2002
Location: he/they
Age: 33
Posts: 10,094
Default Re: Two fun facts about IT

Quote:
Originally Posted by Pseudo Enigma View Post
rip
the "uh-oh" message doesn't mean the server is vulnerable, it means something else happened during the test.

http://filippo.io/Heartbleed/faq.html#wentwrong
dAnceguy117 is offline   Reply With Quote
Old 04-8-2014, 06:27 PM   #14
arcnmx
nanodesu~
Retired StaffFFR Veteran
 
arcnmx's Avatar
 
Join Date: Jan 2013
Location: Ontario, Canada
Posts: 503
Send a message via Skype™ to arcnmx
Default Re: Two fun facts about IT

Yeap heartbleed is quite the bug. Stupid simple mistake of passing memcpy the wrong length, huge consequences.

Quote:
Originally Posted by Bluearrowll View Post
64KB is a large enough amount of memory that could cause passwords / emails / private keys to be compromised. The timing of the reveal of this bug is very unfortunate.
Note that you can just repeat the attack over and over to get a new random set of memory from the server each time, so you can obtain a lot more than just 64KB of data with this attack.

And yeah, FFR isn't vulnerable because lolnohttps. Ironically any sites that use no encryption are potentially safer than those that do - at least an attacker needs to be in a privileged position to sniff sensitive data from HTTP.
__________________


FMO AAAs (1): Within Life :: FGO AAAs (1): Einstein-Rosen Bridge
arcnmx is offline   Reply With Quote
Old 04-8-2014, 06:36 PM   #15
Reincarnate
x'); DROP TABLE FFR;--
Retired StaffFFR Veteran
 
Reincarnate's Avatar
 
Join Date: Nov 2010
Posts: 6,332
Default Re: Two fun facts about IT

I don't know shit about encryption so can someone ELI5 for me -- how does this bug get fixed? What should the average person do to protect him/herself in the meantime?
Reincarnate is offline   Reply With Quote
Old 04-8-2014, 06:38 PM   #16
igotrhythm
Fractals!
FFR Veteran
 
igotrhythm's Avatar
 
Join Date: Sep 2004
Location: Meesheegan
Age: 38
Posts: 6,534
Send a message via Skype™ to igotrhythm
Default Re: Two fun facts about IT

Quote:
Originally Posted by Reincarnate View Post
I don't know shit about encryption so can someone ELI5 for me -- how does this bug get fixed? What should the average person do to protect him/herself in the meantime?
Probably change your password--once right away and again when the patch is applied.
__________________
Quote:
Originally Posted by thesunfan View Post
I literally spent 10 minutes in the library looking for the TWG forum on Smogon and couldn't find it what the fuck is this witchcraft IGR
igotrhythm is offline   Reply With Quote
Old 04-8-2014, 06:39 PM   #17
Artic_counter
FFR Veteran
FFR Veteran
 
Artic_counter's Avatar
 
Join Date: Jan 2007
Location: In your anus. Right corner
Age: 30
Posts: 1,002
Default Re: Two fun facts about IT

I have heard that AVs will continue to do a good job protecting your computer even though microsoft have closed their support. However, since I know sweet FA about computers, could you please tell me if any of that is true?
__________________


Artic_counter is offline   Reply With Quote
Old 04-8-2014, 06:42 PM   #18
arcnmx
nanodesu~
Retired StaffFFR Veteran
 
arcnmx's Avatar
 
Join Date: Jan 2013
Location: Ontario, Canada
Posts: 503
Send a message via Skype™ to arcnmx
Default Re: Two fun facts about IT

Quote:
Originally Posted by Reincarnate View Post
I don't know shit about encryption so can someone ELI5 for me -- how does this bug get fixed? What should the average person do to protect him/herself in the meantime?
For most people the bug goes like this: you login to your email on yahoo (lol), use it normally, etc. Then someone random performs the attack on yahoo: the server might randomly send them your password or the contents of your emails or anything, really.

All you can do to protect yourself is to not use a vulnerable service until they fix it, and change your password once they do. It's easily fixed by updating a system, but that's something someone running a server has to do - not something general users have to worry about.

For server administrators it's also worse than just compromising your user's information, as it could leak private encryption keys as well. Anyone who gets a copy of that suddenly can decrypt and sniff all past and future communications as if the connection were never encrypted at all.
__________________


FMO AAAs (1): Within Life :: FGO AAAs (1): Einstein-Rosen Bridge
arcnmx is offline   Reply With Quote
Old 04-8-2014, 06:43 PM   #19
igotrhythm
Fractals!
FFR Veteran
 
igotrhythm's Avatar
 
Join Date: Sep 2004
Location: Meesheegan
Age: 38
Posts: 6,534
Send a message via Skype™ to igotrhythm
Default Re: Two fun facts about IT

there is now a Chrome extension to see if a server you're browsing is affected!

https://chrome.google.com/webstore/d...cafdggilajhpic
__________________
Quote:
Originally Posted by thesunfan View Post
I literally spent 10 minutes in the library looking for the TWG forum on Smogon and couldn't find it what the fuck is this witchcraft IGR
igotrhythm is offline   Reply With Quote
Old 04-8-2014, 07:13 PM   #20
dAnceguy117
new hand moves = dab
FFR Simfile AuthorFFR Veteran
 
dAnceguy117's Avatar
 
Join Date: Dec 2002
Location: he/they
Age: 33
Posts: 10,094
Default Re: Two fun facts about IT

in b4 a vulnerability is found in the chrome extension

-----

Quote:
Originally Posted by Artic_counter View Post
I have heard that AVs will continue to do a good job protecting your computer even though microsoft have closed their support. However, since I know sweet FA about computers, could you please tell me if any of that is true?
antivirus software helps deal with malware after it's already on your system. running Windows XP after Microsoft stops providing updates will theoretically make you much more likely to *get* that malware. I'm sure some antivirus software does what it does pretty well, but when you run an OS with widely known and exploited vulnerabilities, you're asking for trouble.

the bigger question imo: why run XP?

------

oh dear I just found something.
http://www.npr.org/2014/04/08/300462...ouble-for-some
Quote:
Mike Eldridge, 39, of Spring Lake, Mich., says that since his computer is currently on its last legs, he's going to cross his fingers and hope for the best until it finally dies.

"I am worried about security threats, but I'd rather have my identity stolen than put up with Windows 8," he says.
...................................

Last edited by dAnceguy117; 04-8-2014 at 07:23 PM..
dAnceguy117 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -5. The time now is 01:40 PM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright FlashFlashRevolution