topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Wednesday April 24, 2024, 9:52 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - Deozaan [ switch to compact view ]

Pages: prev1 2 3 4 [5] 6 7 8 9 10 ... 19next
101
I recently discovered Etcher, which is a nice utility you can use to easily write disc images to USB drives and SD cards. It's great for things such as bootable Linux Live OSes or flashing an SD card for an IoT/SBC device.

Some notable features:

  • It prevents you from overwriting your internal drives.
  • It verifies that the media was flashed correctly.
  • It's cross platform, working on Linux, Windows, and MacOS.
  • It's portable. No need to install.



Check it out at etcher.io

102
Discovered by Joern Schneeweisz, a security researcher for Recurity Labs, the flaw relies on tricking users into cloning (copying) a source code project via an "ssh://" link.

Social engineering not necessary to exploit the flaw

Schneeweisz says that a URL in the form of "ssh://-oProxyCommand=some-command" allows an attacker to execute commands on the computer of the user performing the clone operation.

"While it might be tricky to convince a user to clone a repository with a rather shady looking ssh:// URL, this attack vector is exploitable in a more sneaky way when it comes to Git submodules," Schneeweisz explains.

"It is possible to create a Git repository that contains a crafted ssh:// submodule URL. When such a repository is cloned recursively, or the submodule is updated, the ssh:// payload will trigger," the researcher added.

Patches to fix the vulnerability should already have been released, so be sure to update your version control to protect yourself from this vulnerability.

Read more about it here: https://www.bleeping...evere-vulnerability/

103
An interesting article on how trivial it is to link "anonymized" data to real people, and how Web of Trust probably shouldn't be trusted.

In August 2016, a data broker received a phone call from a woman named Anna Rosenberg, who worked for a small startup in Tel Aviv. Rosenberg claimed she was training a neural network, a type of computing architecture inspired by the human brain, and needed a large set of browsing data to do so. The startup she was working for was well-funded and purchasing the data wouldn't be a problem. But given the number of brokers out there, Rosenberg wasn't going to purchase the browsing data from just anyone. She wanted a free trial.

[...]

After receiving her free trial data [...] Eckert's first task with the data was to find out if her browsing data was included in the dataset. To do this, she queried the data for the URL linked with her company's login page, which generates a unique ID for each employee.

[...]

Although it turned out her browser history wasn't in the data set, by querying the data for her company's login page Eckert discovered that a number of her colleagues were in the data by matching the unique login IDs from the company's page to the individuals.

With this information, Eckert would've been able to see her colleagues' entire browsing history for the last month. One of the colleagues included in the dataset was a close friend of hers, and she reached out to him to let him know that she had his browsing history. The question she had was which browser plugin was collecting and selling this data.

To answer this question, Eckert had her colleague delete one browser plugin every hour until he disappeared from the live data. On the seventh plugin, he disappeared. This suggested that the plugin collecting and selling his browser data was, ironically enough, called Web of Trust, which offers "free tools for safe search and web browsing."

Read the rest of the article here:

https://motherboard....t-actually-anonymous

104
DC Gamer Club / Jotun: Valhalla Edition free on Steam & GOG
« on: July 14, 2017, 03:36 PM »
For a limited time you can claim Jotun to your Steam account or to your GOG account.

I've never played it so I can't attest to whether or not it's any good. But at this price, it's worth looking into (or just claiming "just in case").


105
You can now download the Ubuntu command-line interface (AKA shell) from the Windows Store, with some caveats.

The store listing appears, but it says it's only compatible with Windows 10 version 16190.0 or higher, which is only available as part of the Windows Insiders program at the moment.

Even still. This is an interesting and useful development for anyone who ever fired up a VM just to run a few Linux commands.

107
DC Gamer Club / Steam Summer Sale 2017 - June 22 through July 5
« on: June 24, 2017, 08:54 PM »
It's summer, and that means another Steam summer sale!

Aside from the nice discounts on many games, Steam is also running a promotion where you can do a few "quests" each days to earn sticker packs. I don't really see the point of the stickers or sticker packs, but I guess they know all about how driven people are by worthless digital collections.

Speaking of worthless digital collections, you can also earn Steam Summer Sale Trading Cards through various activities on your Steam account during the sale.

But anyway, I've been using Steam less and less over the past few years, mostly because of the glut of crap that has gotten on the storefront through Greenlight (which has recently been discontinued), and also because I've begun to appreciate the value in DRM-free games more and more (hooray for GOG!). That said, it might be fun if people use this thread as an opportunity to recommend good games to each other that are worth picking up during the sale.

108
DC Gamer Club / Extra Copy Giveaway: Wasted
« on: June 13, 2017, 01:57 PM »
DC member p3lb0x has an extra game key for Wasted and is willing to give it away to someone who would make use of it.

I have the key to hand out to the first person to ask for it, under the following conditions:

  • You must be an established member of DonationCoder.

That's it, really.

It's a humble bundle key, which I believe is redeemable on Steam.

109
DC Gamer Club / Payday 2 - Steam giveaway
« on: June 08, 2017, 02:51 PM »
You can claim Payday 2 to your Steam account right now, for free. It includes all the DLC.

PAYDAY 2: We're giving away 5 million copies of PAYDAY 2 for a limited time only!



110
Living Room / RESOLVED: Please help me figure out this CD
« on: June 07, 2017, 10:38 PM »
UPDATE: I've come to the conclusion that the CD is corrupt (Cyclic Redundancy Check errors), and have told the owner to try to get a new copy from the original source. Original message below.



Someone handed me a CD, telling me it contains photos of her 5-year old daughter's ballet class. She says her computer won't read it and asked if I could get the photos off of it for her.

When I put it in my computer it tries to read it for several seconds but then gives up. It doesn't show up as having anything inserted in it.  Here's the mystery: I opened up the Disk manager to see what it would reveal, and it's showing this:

Big CD.png

Media: CD-ROM Disc
Size: 1.1GB (1,073,741,312 bytes)
Volumes: 1.1 GB Unknown

The CD itself is labeled as a Philips 700 MB/80 min 52x speed CD-R. I'm sure most of those details about the CD itself are unimportant, but I included them just in case.

So... how can a 700 MB CD have a 1.1 GB partition on it? Is there any way I can salvage the data from the disc, or is it a lost cause? Any suggestions or troubleshooting steps I should take to try to get the disc to read properly?

Thanks!

111
The man was ordered to give his iPhone password to police. He insists that he did. But the password he gave them doesn't work. So the judge is holding him in criminal contempt.

A Hollywood man must serve 180 days in jail for refusing to give up his iPhone password to police, a Broward judge ruled Tuesday — the latest salvo in intensifying legal battles over law-enforcement access to smart phones.

Christopher Wheeler, 41, was taken into custody in a Broward Circuit Court, insisting he had already provided the pass code to police investigating him for child abuse, although the number did not work.

“I swear, under oath, I’ve given them the password,” a distraught Wheeler, his hands handcuffed behind his back, told Circuit Judge Michael Rothschild, who earlier in May found the man guilty of contempt of court.

While the headline does sound scary, maybe it's a technicality. Maybe the case is that since he provided a password that didn't work, the judge thinks he's lying and holds him in contempt. Perhaps if he had simply refused to provide any password at all, citing the 5th amendmentw, the judge would not have held him in contempt of court.

112
DC Gamer Club / Starpoint Gemini 2 - 48 hour giveaway on Steam
« on: May 22, 2017, 12:54 PM »
Starpoint Gemini 2 is free (to keep) for the next ~48 hours.

If you're thinking What are you guys smoking? the answer is Not a thing, amigo.. Our next game in the Starpoint series, Starpoint Gemini Warlords is coming out on May 23rd, 2017 and what better way is there to celebrate this (and to spread the word *wink* *wink*) than to offer Starpoint Gemini 2 for free?

We hope you like the game. And if you do, maybe you'd be interested in that Warlords thingie I mentioned above ;).

113
DC Gamer Club / Mount & Blade - 48 hour giveaway on GOG
« on: May 19, 2017, 11:43 AM »
For the next ~44 hours from the time of this post, you can get Mount & Blade for free (and DRM free!) on GOG. And all the other Mount & Blade games are 75% off as well.

Supposedly M&B: Warband is the best of the bunch.

I've played quite a bit of M&B (the original) but haven't really played any of the expansions/sequels.



And here's a roundup of some mods for the game which should give you plenty to do:

http://www.moddb.com...00-free-limited-time

114

Dungeons 2 is free on the Humble Store for the next 2 days as part of their Spring Sale. Note that this purchase has to be redeemed to a Steam account within a couple of weeks. I don't remember the exact timeframe.



Eador: Genesis is free on GOG for the next 2 days to celebrate the launch of Gremlins, Inc from the same company.

115
I think this is a pretty clever new email service.

First of all, Lemon features end-to-end encryption so that no one--not even Lemon engineers--can read the content of your emails, except of course you and the intended recipient. No scraping the content of your emails to better advertise to you or gather personal/private information. In fact, there are no ads in your email period. "The way it works is that the passphrase you use to unlock your emails is not saved anywhere / on our server and therefore even our engineers cannot read your emails. (Don't forget your passphrase!)"

Secondly, Lemon is powered via IPFS[1] and Ethereum's blockchain technology. This allows Lemon to be decentralized. Meaning there is no central server to be hacked. No single point of failure that can prevent you from being able to access your email. In fact, there is no server at all. "Your emails are safe in pretty much any scenario you can imagine, from natural disaster to alien invasion."

Thirdly, you can still use it to email your mom. Lemon will translate your email from the IPFS version and communicate with the recipient's SMTP server (or vice versa for incoming email from non-Lemon accounts). "When emailing people that are outside of Lemon Email service, we have [an] additional security layer so that third party email services cannot read or decrypt your emails."

The future of the internet, using P2P/distributed technologies such as IPFS and Ethereum, is developing into something really amazing. :Thmbsup:

More info about Lemon:
https://lemon.email/

The one thing that puzzles me is they claim it's all "at the price of one cappuccino a month" but the pricing plans page says it's $20/mo. That sounds like one expensive cappuccino to me!


1. See my post "IPFS - Is this the future of the internet?"

116
DC Gamer Club / Alien Swarm: Reactive Drop
« on: April 26, 2017, 03:32 PM »
Alien Swarm just got a big upgrade. It has been re-released as Alien Swarm: Reactive Drop with more campaigns, more multiplayer options (including co-op bots to help fill out your party), Steam Workshop support for community-made campaigns and mods, and more.

Alien Swarm: Reactive Drop extends Alien Swarm, bringing more of everything: maps, aliens, game modes, guns... And most importantly Steam Workshop support.

  • Tactical co-op for up to 8 players with a top-down perspective
  • Steam Workshop support for community maps and challenges
  • New co-operative campaigns
  • Challenges: Modifications of the game, just like Mutations in Left 4 Dead 2
  • PvP: Deathmatch, Gun Game, Instagib, and Team Deathmatch
  • Singleplayer: Play with improved bots on all our official maps
  • New Aliens: HL2 antlion guards and more
  • New Weapons: Desert Eagle, Devastator, and Combat Rifle, with more to come

And it's still completely free!

I had a lot of fun playing Alien Swarm with other DC members, but it always seemed unfairly hard if you couldn't get a full party of 4 players. But now with the addition of bots, it's very doable to complete the original campaign with even just two competent players.

I haven't tried any of the new campaigns yet, but I'm looking forward to doing so. Hopefully with folks from DC again. :Thmbsup:

117
DC Gamer Club / StarCraft + Brood War expansion now free
« on: April 19, 2017, 01:32 PM »
Blizzard is gearing up to release a remastered edition of the original StarCraft. And in preparation for that big release later this year, they've released the original for free.



StarCraft®: Remastered upgrades the essential sci-fi strategy experience from beginning to end. Welcome back to the original game and its award-winning expansion, StarCraft: Brood War.

We’ve remastered our units, buildings, and environments, improved game audio, and broadened our supported resolutions. Illustrated interludes bring the struggles and victories of heroes like Artanis, Fenix, Tassadar, Raynor and Kerrigan to life like never before. Most importantly, the strategy gameplay that StarCraft perfected years ago remains unchanged.

Get ready for Remastered. The original StarCraft is free to download right now!

119
Have I Been Pwned is a website/service that allows you to check to see if your email address (or other info) can be found within the database(s) of various sites that have had data breaches over the years. It was mentioned earlier on this site in this thread.

But consider this a friendly reminder/suggestion to occasionally check and see which sites have mishandled your data.

https://haveibeenpwned.com/

120
So, I've tried repeatedly to get this update to install. But it just keeps failing, reverting the changes, and then immediately when I get back into Windows 10 it downloads the update again and tells me I need to restart to finish installing it.

I even tried manually downloading the update and installing it. It, too, told me I needed to reboot to finish installing it. When I did that, it did the usual thing and after a while it said it failed to install and reverted the changes.

I've searched and found other people asking around how to get this update to install, many times without a response. But even in the cases where I did see a response, nowhere have I found anyone saying they were able to resolve the situation.

Anyone here have any experience getting stubborn updates to take? Normally I'd just let a failed update sit there and not install, but this results in Windows 10 nagging me to restart my computer and threatening to do it for me "outside of active hours" if I don't take care of it myself. Halp!

KB4013429 Failure.png

121
I (mostly) stopped using LastPass a couple years ago for reasons unrelated to this, but it seems multiple password-leaking vulnerabilities (and other dangerous exploits) have been discovered recently:

LastPass works by storing your passwords in the cloud. It provides browser extensions that connect to your LastPass account and automatically fill out your saved login details when you surf to your favorite sites.

However, due to the discovered vulnerabilities, simply browsing a malicious website would be enough to hand over all your LastPass passphrases to strangers. The weak LastPass script uncovered by Ormandy could be exploited by tricking it into granting access to the manager's internal data. It can also be potentially abused to execute commands on the victim's computer – Ormandy demonstrated this by running calc.exe simply by opening a webpage.

Even though I no longer use LastPass for new passwords, my account still has many old passwords I haven't updated in a while, and I have kept the extension installed because of that, since it seems to work more reliably than the extension for the password manager I switched to. So maybe it's time for me to fully ditch LastPass.

122
General Software Discussion / XYplorer is not responding.
« on: March 14, 2017, 09:20 PM »
NOTE: This thread was originally a reply in the Windows now has banner ads thread, and was moved here in an attempt to keep that other thread on topic. The original conversation is below:



But maybe it's time to re-evaluate XYplorer and see what all the hubbub is about.

Nope. I still can't do XYplorer. It frequently locks up on me for several seconds at a time.

123
General Software Discussion / Windows Explorer now has banner ads
« on: March 11, 2017, 02:27 PM »
I opened up Windows Explorer just now and was greeted by this:

Windows Explorer Ad.png

124
Cloudflare released an incident report detailing a recent discovery and patching of a bug which leaked data in rare instances. This leaked data includes passwords and other sensitive information.

Virtually every site that uses Cloudflare was possibly affected, meaning that basically you should change your passwords everywhere and make sure you have 2FA enabled where possible. EDIT: See further replies to this thread for clarification on potentially affected sites.

I'm on mobile so it's too much work for me to make things pretty right now, but here are pertinent links:

Cloudflare incident report: https://blog.cloudfl...oudflare-parser-bug/

List of sites (possibly) affected: https://github.com/p...tes-using-cloudflare

125
Living Room / SHA1 is dead - First known collision exploit discovered
« on: February 23, 2017, 06:53 PM »
Cryptographers refer to the attack disclosed Thursday as an "identical-prefix" collision, meaning it allows the attacker to create two distinct messages that have the same hash value. This variety is less powerful than the "chosen-prefix" MD5 collision carried out by Flame. In the latter case, attackers can target one or more existing files, such as the digital certificate that a company uses to authenticate its update mechanism. Despite the collision against SHA1 being less powerful, cryptography experts said any real-world identical-prefix attack represented a game-over event for a hashing function.

"In crypto we have the idea that hash function collisions should be really hard to find, even if they're 'useless,'" said Johns Hopkins University professor Matt Green, speaking generally about collisions before he learned the specifics of the new SHA1 attack. A real-world collision attack "is the equivalent of finding out that your scalpel wasn't sterilized properly. It may not verifiably have germs on it, but the whole instrument is considered unsafe."

Read more here:
https://arstechnica....unction-is-now-dead/

Pages: prev1 2 3 4 [5] 6 7 8 9 10 ... 19next