topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Saturday December 20, 2025, 1:14 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Recent Posts

Pages: prev1 ... 89 90 91 92 93 [94] 95 96 97 98 99 ... 364next
2326
Find And Run Robot / Re: What hotkey(s) do *you* use to trigger FARR?
« Last post by f0dder on June 22, 2010, 03:48 AM »
Win+F12. Can't remember why I switched from the pause key - perhaps it interfered with Win+Pause, which brings up system properties?
2327
Afaik that still requires you to run in test-signing mode, 4wd.
2328
Living Room / Re: Recommend some music videos to me!
« Last post by f0dder on June 20, 2010, 01:34 PM »
Blockhead - The Music Scene

Really trippy video, I liked it immensely
eeww I'm unraveling  :-*
- definitely dont need any drugs for that one!
The guy who drew it probably did heavy doses of LSD, though :)
2329
Living Room / Re: 20 years later, the movie "Total Recall" still kicks butt
« Last post by f0dder on June 17, 2010, 06:35 AM »
Oh - DEXTER. Great show.
:Thmbsup:
2330
DC Gamer Club / Re: Dinosaurs Didn't Have Keyboards
« Last post by f0dder on June 16, 2010, 05:48 PM »
Too bad it requires some plugin I've never heard of... and I'm pretty conservative on those, haven't even bowed under the pressure of silverlight yet.

You've never heard of the Unity game engine?
Nope :)
2331
DC Gamer Club / Re: Dinosaurs Didn't Have Keyboards
« Last post by f0dder on June 16, 2010, 04:24 PM »
Downloaded, spent ~50 seconds with it, deleted it in frustration :)
2332
DC Gamer Club / Re: Dinosaurs Didn't Have Keyboards
« Last post by f0dder on June 16, 2010, 04:01 PM »
Too bad it requires some plugin I've never heard of... and I'm pretty conservative on those, haven't even bowed under the pressure of silverlight yet.
2333
Five Three Days.  Now that we're to the "it's MS's bug and he made an error in judgement" phase, how is 3 days slowly?
+1

Let's not forget what happened when MS put out a faulty patch recently which had people screaming for blood over the inconvenience it caused. Patching holes is not necessarily a simple matter, I imagine testing a patch is enormously complicated.

Rushing out a patch for an exploit not already in the wild would have been irresponsible on MS's part.
+1. Btw, was that the problematic patch that turned out not to be MS's fault, but a piece of nasty malware causing the BSODs? Or was that another incident? :)
2334
First of all: if he's been in contact with MS and choose to release exploit code within a week... then he really deserves to be slapped around. Releasing exploit details is something you do either
1) after patches have been made public and have had time to be rolled out, or
2) if the organization has been ignoring you for "long enough" (which is definitely more than a couple of weeks).

When an exploit is reported, the company needs to investigate it, which includes being able to reproduce it reliably and finding a bugfix. Then that bugfix has to be tested thoroughly before a patch can be rolled out. Going public with exploit details within a week? Christ.
2335
Hi, btw - FYI

My NOD32 (Heuristic Scanner Option) interpret both Hooks DcKeyHk.dll + DcMouseHk.dll
as Win32/KeyLogger.BitLogic.AA application  :huh:
Long live overzealous antivirus heuristics :-* :-* :-*
2336
How does KeePass insert the encrypted passwords into the other apps? It would be trivial to add a clipboard watcher to a keylogger...

And Dominik would like to see his methods challenged. Note that this is for KeePass 2.x, KeePass 1.x lacks any kind of protection against keyloggers if you rely on AutoType.
Thanks for that link - it's a decent system he's implemented, I had been thinking of something similar. While it will fool a bog-standard keylogger, there's still some ways to target it. You could (probably) log the clipboard entries when Ctrl+V is sent to the target app (that way you don't have to be part of the clipboard listener chain, nor poll the clipboard constantly). Or API-level hooks could be thrown into the mix...
2337
Living Room / Re: 20 years later, the movie "Total Recall" still kicks butt
« Last post by f0dder on June 15, 2010, 08:43 AM »
Great bits of Eisenhower-era societal standards are found everywhere. Note how the women are doing 'girl's work' serving coffee? Apparently back in the 50s, her being an astronaut with two PhDs couldn't keep Janey from finding a way make herself useful. And the crew members smoke too! They're in an oxygen enriched closed environment and smoking... but no worries about fire or explosions, right? Must be because they're puffing American cigarettes.
Fun :-*
2338
Developer's Corner / Re: I guess I'm not using a static variable then
« Last post by f0dder on June 14, 2010, 06:53 PM »
Heh, what?! Static variables experimental? :P - what language is that from?
2339
Oh, I wasn't worried about the hash-checking program intentionally having it's checking functionality disabled - but along the lines of the program getting infected on one machine, and when running on the next spreading the infection. If the infection was with a nasty piece of self-hiding code, the hash-checking would be ineffective without having been explicitly targeted.
2340
mouser: I had the same idea, but you have to keep in mind, though, that the really nasty malware is capable of hiding itself, so it's not going to be 100% foolproof... you'd have to run a guaranteed clean version of the hash-checker, not the copy from the usb stick.
2341
Is the usb drive big enough to hold two copies of what you need? If so keep a fully archived passworded copy and each time you sit down to a new PC extract the contents of that archive. That way you can be sure the programs themselves remain uninfected.
Not if there's an active virus on the system :) - but at least the file in the source archive should be safe.
2342
How does KeePass insert the encrypted passwords into the other apps? It would be trivial to add a clipboard watcher to a keylogger...
2343
i suspect that the logic of these devices is that they look for a counter within the first 8 characters of a name - as the counter beyond the 8 character limit doesn't list correctly. it just seems odd that they do this whilst also being able to display long file names.
Long file names are handled pretty specially on FAT partitions... an 8.3 short filename is generated for each file (with the last few chars changed to make the names unique), and a number of additional FAT filename entries marked with special attributes are created for the long/unicode name. It's all very hairy and messy.
2344
General Software Discussion / Re: theremin hero...
« Last post by f0dder on June 14, 2010, 12:14 PM »
Awesome!
2345
...and ontop of keyloggers, there's the risk of getting your usb drive infected by malware from an infected public computer.
2346
Living Room / Re: Second Wind - beautiful student animation
« Last post by f0dder on June 14, 2010, 10:47 AM »
I really liked the style of this animation, everything went very well together - colors, texture, animation style, music...  :up:
2347
Well said, Eóin.
2348
Living Room / Re: 20 years later, the movie "Total Recall" still kicks butt
« Last post by f0dder on June 13, 2010, 07:45 PM »
Three words...Howard the Duck
Saw it as a kiddo, found it again a few months ago, been meaning to revisit it... wonder if it'll spoil my (fond) memories of it.

PS: linking to external images don't work, at least not the way you tried doing it :)
2349
Living Room / Re: 20 years later, the movie "Total Recall" still kicks butt
« Last post by f0dder on June 13, 2010, 07:32 PM »
On the topic of hot movies babes, and sticking in the retro theme, how about a Cherry 2000 (pic)? Great flick! Not sure if anyone will know it though. 1987 movie with Melanie Griffith in it.
Might be a B-movie, but I kinda like it :)
2350
Gotta be +3 here, one plus for each of the above points by Eóin, Renegade and Stoic Joker.

I'm all for making exploits details + proof-of-concept code public, but only after the software vendor has had a reasonable amount of time to fix the bug. Microsoft have been pretty damn bad in the past, but they've measured up - and are pretty open about security these days.
Pages: prev1 ... 89 90 91 92 93 [94] 95 96 97 98 99 ... 364next