topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Saturday September 19, 2026, 4:19 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Recent Posts

Pages: prev1 ... 223 224 225 226 227 [228] 229 230 231 232 233 ... 404next
5676
Living Room / Re: Apple vs. Samsung Goes NUCLEAR!
« Last post by wraith808 on August 05, 2013, 12:25 PM »
I was at first a bit Skeptical and Cynical about the decision by the Obama Administration to interfere with the process but I did some other reading and found this great break down of the whole dispute

http://appleinsider....n-against-apple-inc- in-pictures

and honestly I think they actually did the right thing. It looks a lot like Samsung is double dipping and not following FRAND terms.

I've been reading this elsewhere too... had to look up what FRAND meant.  So is it possible that this wasn't political... it might have that appearance, but perhaps it's also just the right thing to do?
5677
Living Room / Re: Apple vs. Samsung Goes NUCLEAR!
« Last post by wraith808 on August 05, 2013, 11:58 AM »
I like the first comment... if it happened before, then it's not unprecedented.  :P
5678
Living Room / Re: BREAKING: Half of TOR sites compromised, including TORMail.
« Last post by wraith808 on August 05, 2013, 10:00 AM »
governments will deliberately act stupider than they are in order to encourage such activities and identify those involved in it.

That's been going on for a while.  Back in the 80s, you might have legitimately been able to say that they had not kept up, and weren't effective.  That's what the MO was- to use that perception to hide their proficiency and scout their opposition.  They've become surprisingly blatant and/or lazy as of late.  An operation like this shouldn't have been revealed.  I'm not sure if everyone is catching up, and it's becoming harder, or if it's truly that they think there's no need to hide.  If it's the first, then that's a start.  If it's the latter... well, then I hope that pride is going before the fall.  But it's really looking like they're right... and that they can come in from the cold.
5679
Developer's Corner / Re: Nerdy Data - source code search engine
« Last post by wraith808 on August 05, 2013, 07:56 AM »
Need to search?

http://code.ohloh.net/

Done.

That is the best link that I've been given in a long time.  Thanks Ren!  :-* :Thmbsup:
5680
Living Room / Re: BREAKING: Half of TOR sites compromised, including TORMail.
« Last post by wraith808 on August 05, 2013, 07:55 AM »
Still, it looks like a hosts/clients compromised, and not the protocol itself, which is a consolation, if small.

A chain is only as strong as the weakest link.  So instead of trying to cut the strongest... you go after the weakest.  People are always the weakest link.  It's not even the hosts/clients that they compromised- but the people being stupid mixing secure and non-secure browsing.  All for a bit of javascript.
5681
Living Room / Re: BREAKING: Half of TOR sites compromised, including TORMail.
« Last post by wraith808 on August 05, 2013, 07:53 AM »
They didn't used to. It took them a real long while. Slashdot used to be pretty snarky about "you clueless newbie, set up Tor instead". Well, if they bust the Tor network, then that advice won't work so well!

These are "low tech" actions - "arrest website/node owner, blah blah". So whether the "right people" showed up in the "right departments", all this stuff is accelerating.

I can tell you, with a certainty, when they were being snarky, they were being played.  This isn't a recent development.  It's just a recently known development.
5682
Developer's Corner / Re: Nerdy Data - source code search engine
« Last post by wraith808 on August 04, 2013, 07:50 PM »
The free account on NerdyData will allow the user to search 200 times per month and 10 results per query, with a professional account costing $99 per month, it will allow 1,200 searches and up to 5,000 results per query. Similarly, for enterprise account, it will cost $149/month, and will allow the user to search 3,000 times per month and for every query 100,000 results.

No thanks.
5683
Living Room / Re: BREAKING: Half of TOR sites compromised, including TORMail.
« Last post by wraith808 on August 04, 2013, 07:49 PM »
Oh... I don't think that anyone who knows anything would say that after Stuxnet.  I just wish they'd use their superpowers for good instead of evil.
5684
Living Room / BREAKING: Half of TOR sites compromised, including TORMail.
« Last post by wraith808 on August 04, 2013, 05:42 PM »
(from TwitLonger)

The founder of Freedom Hosting has been arrested in Ireland and is awaiting extradition to USA.

In a crackdown that FBI claims to be about hunting down pedophiles, half of the onion sites in the TOR network has been compromised, including the e-mail counterpart of TOR deep web, TORmail.

http://www.independe...planet-29469402.html

This is undoubtedly a big blow to the TOR community, Crypto Anarchists, and more generally, to Internet anonymity. All of this happening during DEFCON.

If you happen to use and account name and or password combinations that you have re used in the TOR deep web, change them NOW.

Eric Eoin Marques who was arrested runs a company called Host Ultra Limited.

http://www.solocheck...Ultra-Limited-399806
http://www.hostultra.com/

He has an account at WebHosting Talk forums.

http://www.webhostin...wthread.php?t=157698

A few days ago there were mass outages of Tor hidden services that predominantly effected Freedom Hosting websites.

http://postimg.org/image/ltj1j1j6v/

"Down for Maintenance
Sorry, This server is currently offline for maintenance. Please try again in a few hours."

If you saw this while browsing Tor you went to an onion hosted by Freedom Hosting. The javascript exploit was injected into your browser if you had javascript enabled.

What the exploit does:

The JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn't get deleted. Presumably it reports the victim's IP back to the FBI.

An iframe is injected into FH-hosted sites:

TOR/FREEDOM HOST COMPORMISED
By: a guest on Aug 3rd, 2013
http://pastebin.com/pmGEj9bV

Which leads to this obfuscated code:

Javascript Mozilla Pastebin
Posted by Anonymous on Sun 4th Aug 02:52
http://pastebin.mozilla.org/2776374

FH STILL COMPROMISED
By: a guest on Aug 3rd, 2013
http://pastebin.com/K61QZpzb

FBI Hidden Service in connection with the JavaScript exploit:
7ydnpplko5lbgfx5

Who's affected Time scales:

Anyone who accessed an FH site in the past two days with JavaScript enabled. Eric Eoin Marques was arrested on Sunday so that's the earliest possible date.

"In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services
Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization"

http://www.ieee-secu.../papers/4977a080.pdf

The FBI Ran a Child Porn Site for Two Whole Weeks
http://gizmodo.com/w...hole-weeks-510247728

http://postimg.org/image/o4qaep8pz/

On any other day one would say these sick perverts got what they deserved. Unfortunately the Feds are stepping far beyond just pedophiles in this latest issue.

The js inserted at Freedom Hosting? Nothing really, just an iframe inject script with a UUID embedded server-side.

The iframe then delivers an exploit kit that appears to be a JavaScript 0day leading to...something. It only attempts to exploit Firefox (17 and up) on Windows NT. There's definitely some heap spraying and some possible shell code. The suspect shell code block contains some strings that look to formulate an HTTP request, but I haven't been able to collect the final payload yet. The shell code also contains the UUID with which the exploit was delivered. Any UUID will work to get this part of the exploit.

I'm still pulling this little bundle of malware apart. So far, I've got that the attack is split across three separate files, each loaded into an iframe. Calls are made between the frames to further obfuscate the control flow. The 'content_2.html' and 'content_3.html' files are only served up if the request "looks like" Firefox and has a correct Referer header. The 'content_2.html' is loaded from the main exploit iframe and in turn loads 'content_3.html'.

Short version. Preliminary analysis: This little thing probably CAN reach out without going through Tor. It appears to be exploiting the JavaScript runtime in Firefox to download something.

UPDATE: The exploit only affects Firefox 17 and involves several JS heap-sprays. Note that the current Extended Support Release is Firefox 17, so this may also affect some large organizations using Firefox ESR.

http://pastebin.mozilla.org/2777139

The script will only attempt the exploit on Firefox 17, so I'm no longer worried about it being some new 0day. Enough of the "Critical" MFSAs are for various sorts of memory corruption that I don't have the time to find out if this is actually a new exploit or something seen before.

http://postimg.org/image/mb66vvjsh/

Logical outcomes from this?

1. FBI/NSA just shut down the #1 biggest hosting site and #1 most wanted person on Tor

2. Silkroad is next on their list, being the #2 most wanted (#1 was Child Porn, #2 is drugs)

3. Bitcoin and all crypto currenecies set to absolutely CRASH as a result since the feds can not completely control this currency as they please.

I don't always call the Feds agenda transparent, but when i do, I say they can be trying harder.
5685
Living Room / Re: PLease help superboyac build a server (2013 edition).
« Last post by wraith808 on August 04, 2013, 05:29 PM »
It has a drain valve yes, but it hasn't produced a single drop in 3 months.

Thanks for that... I've been looking at this for my man cave, but it has no windows, and I was worried about that so didn't get it.  So what do you do with the hose?  Do you just have it going out of the window?
5686
Living Room / Re: Sci-fi novel now available from DC member kyrathaba!
« Last post by wraith808 on August 04, 2013, 02:56 PM »
Thanks for the test. I notice even in your test, the closing braces aren't indented correctly. I wound up just linking to two separate listings of the code snippet.

Yeah... it just highlights... not indents.  You have to do the indents yourself, although I think there are settings for that.  For example:

Code: C# [Select]
  1. using System;
  2. using System.Runtime.InteropServices;
  3. using System.Windows.Forms;
  4.  
  5. namespace MoveFormWithoutTitlebar {
  6. public partial class Form1 : Form {
  7.  
  8. public const int WM_NCLBUTTONDOWN = 0xA1;
  9. public const int HT_CAPTION = 0x2;
  10.  
  11. [DllImportAttribute("user32.dll")]
  12. public static extern int SendMessage(IntPtr hWnd,
  13. int Msg, int wParam, int lParam);
  14.  
  15. [DllImportAttribute("user32.dll")]
  16. public static extern bool ReleaseCapture();
  17.  
  18. public Form1() {
  19. InitializeComponent();
  20. }
  21.  
  22. private void Form1_MouseDown(object sender, MouseEventArgs e) {
  23. if (e.Button == MouseButtons.Left) {
  24. ReleaseCapture();
  25. SendMessage(Handle, WM_NCLBUTTONDOWN, HT_CAPTION, 0);
  26. }
  27. }
  28. }
  29. }

The DC code highlighter uses GeSHi also, so it doesn't indent either.
5687
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 02:25 PM »
But what I don't get is his cast.  Everyone knows who Uwe Boll is and what kind of movies he makes.  But they still sign up for it... do they need the paycheck that bad?!?

And I'm not talking the bit people... he gets some pretty big names, and drags them along with him.
5688
Living Room / Re: Sci-fi novel now available from DC member kyrathaba!
« Last post by wraith808 on August 04, 2013, 02:21 PM »
Hmmm... It does appear to be something with your installation- I took your code and pasted it on my blog:

http://thinkshui.net...sting-crayon-plugin/

I used the crayon plugin window to paste the code into with the default options if that helps.
5689
Living Room / Re: Sci-fi novel now available from DC member kyrathaba!
« Last post by wraith808 on August 04, 2013, 01:32 PM »
Hmmm... try to copy the code to a plain text editor, then copy it back.  What you're trying to do is remove any extraneous characters that might be affecting the output. 

If that doesn't work, I'm not sure.  I've not seen that before... :(

I'll try it on my blog...
5690
That's why no comment :(
5691
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 12:47 PM »
What the hell. Why not Uwe Boll. He can turn any movie into a horror story.

Sorry, I forgot that's horrible not horror. My mistake.

OMG... I'm just hoping that Uwe Boll never gets another cent to make a movie.  I swear, he must have some really good dirt on someone to get the names and the money and the rights to continue to slaughter movies.
5692
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 12:46 PM »
Yeah he definitely had some humor and I wouldn't put anything past Whedon. He just tends to remind me more of 40's Cary Grant, cute rapid-fire repartee but I guess Firefly's humor had a more serious edge.

Jayne, your mouth's talkin. You should see to that.

One of my favorite quotes.  But one of my favorite dark episodes was War Stories.  The part while they were getting tortured?  There was some comedy gold there... but you felt bad for laughing.
5694
Living Room / Re: Sci-fi novel now available from DC member kyrathaba!
« Last post by wraith808 on August 04, 2013, 12:12 PM »
Hmmm... not sure past that.  Your syntax looks right...

My suggestion: life's too short to try to debug an extension when you're doing things right, and there are several options out there.

I'd try http://wordpress.org...-syntax-highlighter/ :)
5695
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 12:08 PM »
I have an original Deities & Demigods with all that in it. Though I bought it well after it came out - found it in a store one day and snatched it up real quick.

I bought mine new from the store. :P  I was like 10 or so at the time... but still.

The funnier thing... I worked at that same store 8 years later... and the person I bought it from was still working there.  And he wasn't the owner.  Flash forward 20 or so years with me working part time there sometimes (for credit, natch)... and that guy was still working there when the store closed down.
5696
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 12:02 PM »
If Joss Whedon was writing I'd rather it died in pre-production. Don't get me wrong, I love his glib dialog, but for Lovecraft? Might as well make it a romantic comedy.

I totally agree.  I love Whedon, but some things just weren't meant to mix.
5697
Living Room / Re: Movies or films you've seen lately
« Last post by wraith808 on August 04, 2013, 12:01 PM »
And I'd like to see At the Mountains of Madness get made so badly that I don't think I really care who (within reason) makes it at this point.

Michael Bay?  How about Cameron?  Or Ridley Scott!

Sorry for that visual :P
5698
FWIW, the most useful setting in Tomato that I think every router firmware should have is the one that lets you set it to reboot itself in the middle of the night every day. For me, that completely solved the problem of having to pull the power on the router when it started having  problems after a couple weeks of constant uptime.

That *does* sound useful.  Though I really only get those problems after the cable goes down for some reason.  I wonder if it could sense that and reboot...
5699
Living Room / Re: Facebook 15 second auto-play ads
« Last post by wraith808 on August 04, 2013, 08:11 AM »
yeah... but I can use adblock on youtube.  On facebook, I've been dealing with ads because of Words with Friends, that keeps changing to get around my custom adblock rules and make the game unusable.

Eh.. I spend too much time on those stupid games anyway...  :-[
5700
Living Room / Re: Sci-fi novel now available from DC member kyrathaba!
« Last post by wraith808 on August 04, 2013, 08:06 AM »
@wraith: closing tag is there, but won't show within DC quote blocks. It's the closing "pre": left angle bracket,  slash, "pre", right angle bracket.

So I guess the next question is... which WP Plugin for Geshi do you have installed?  There are several...

A good list: http://www.wpsquare....r-wordpress-plugins/
Pages: prev1 ... 223 224 225 226 227 [228] 229 230 231 232 233 ... 404next