dawn

Discord ID: 185438378378919936


134 total messages. Viewing 100 per page.
Page 1/2 | Next

2016-06-18 14:25:53 UTC [/csg/ #chink-shit-general]  

hi

2016-06-18 14:28:37 UTC [/csg/ #chink-shit-general]  

Thanks good to be here

2016-06-18 14:29:09 UTC [/csg/ #chink-shit-general]  

is there a /g/ discord? for non chink shit related things

2016-06-18 14:29:38 UTC [/csg/ #chink-shit-general]  

That sucks

2016-06-18 14:30:58 UTC [/csg/ #chink-shit-general]  

Who cares

2016-06-18 14:31:12 UTC [/csg/ #chink-shit-general]  

I kinda wanna start a /g/ CTF team

2016-06-18 14:33:30 UTC [/csg/ #chink-shit-general]  
2016-06-18 14:37:13 UTC [/csg/ #chink-shit-general]  

i feel like im gonna get a whole bunch of elitists replying to this

2016-06-18 14:37:18 UTC [/csg/ #chink-shit-general]  

yay for /g/

2016-06-18 14:37:52 UTC [/csg/ #chink-shit-general]  

> Not using windows 10 for anything related to security

2016-06-18 14:37:58 UTC [/csg/ #chink-shit-general]  

> Not having control flow guard

2016-06-18 14:40:55 UTC [/csg/ #chink-shit-general]  

uh...

2016-06-18 14:40:59 UTC [/csg/ #chink-shit-general]  

is that bot written in py?

2016-06-18 14:41:21 UTC [/csg/ #chink-shit-general]  

that's.. probably not a great idea to give anyone access to the urllib/requests package

2016-06-18 14:41:26 UTC [/csg/ #chink-shit-general]  

there's a HTTP response splitting bug

2016-06-18 14:41:36 UTC [/csg/ #chink-shit-general]  

can in theory result in pwning of the bot

2016-06-18 14:42:10 UTC [/csg/ #chink-shit-general]  

i mean idfk if it's vuln

2016-06-18 14:42:58 UTC [/csg/ #chink-shit-general]  

well depends what ver of urllib it uses

2016-06-18 14:43:43 UTC [/csg/ #chink-shit-general]  

!play google.cum

2016-06-18 14:43:48 UTC [/csg/ #chink-shit-general]  

eh

2016-06-18 14:43:55 UTC [/csg/ #chink-shit-general]  

can someone try requesting an invalid url

2016-06-18 14:44:09 UTC [/csg/ #chink-shit-general]  

i'm good

2016-06-18 14:44:21 UTC [/csg/ #chink-shit-general]  

can someone do !play google.cum

2016-06-18 14:44:31 UTC [/csg/ #chink-shit-general]  

uhm.

2016-06-18 14:45:08 UTC [/csg/ #chink-shit-general]  

i mean

2016-06-18 14:45:12 UTC [/csg/ #chink-shit-general]  

someone could in theory exploit your box

2016-06-18 14:45:13 UTC [/csg/ #chink-shit-general]  

via that bot

2016-06-18 14:45:50 UTC [/csg/ #chink-shit-general]  

I don't have a non work box I can use to hit it with

2016-06-18 14:45:52 UTC [/csg/ #chink-shit-general]  

so I can't test it

2016-06-18 14:45:59 UTC [/csg/ #chink-shit-general]  

You got me.

2016-06-18 14:46:22 UTC [/csg/ #chink-shit-general]  

I mean try injecting another header into the URL

2016-06-18 14:46:27 UTC [/csg/ #chink-shit-general]  

then look at the response

2016-06-18 14:47:44 UTC [/csg/ #chink-shit-general]  

Uh you can use it to hit internal resources/send requests to any site with any data you want

2016-06-18 14:48:16 UTC [/csg/ #chink-shit-general]  

Yeah but someone here is hosting it

2016-06-18 14:48:27 UTC [/csg/ #chink-shit-general]  

all I'm saying is it's worth checking so they don't get abuse complaints for someone using their shit in a bad way

2016-06-18 14:48:56 UTC [/csg/ #chink-shit-general]  

What the fuck

2016-06-18 14:49:08 UTC [/csg/ #chink-shit-general]  

All I did was suggest that your bot might be vuln to a public CVE

2016-06-18 14:50:11 UTC [/csg/ #chink-shit-general]  

... I already said I don't have a box I can tail -f logs for

2016-06-18 14:50:43 UTC [/csg/ #chink-shit-general]  

lol

2016-06-18 14:50:57 UTC [/csg/ #chink-shit-general]  

I don't have a box that isn't work related

2016-06-18 14:51:35 UTC [/csg/ #chink-shit-general]  

Make a request to my http server

2016-06-18 14:51:58 UTC [/csg/ #chink-shit-general]  

Where I can see if it's actually working, it's HTTP header injection

2016-06-18 14:52:16 UTC [/csg/ #chink-shit-general]  

It's an issue even if you just have private services running on your box

2016-06-18 14:52:20 UTC [/csg/ #chink-shit-general]  

because smeone can use that to pivot to them

2016-06-18 14:52:48 UTC [/csg/ #chink-shit-general]  

Like i'm only telling you because I like it here already. I'm not trying to make a big deal out of it

2016-06-18 14:53:11 UTC [/csg/ #chink-shit-general]  

I mean it's a potential security bug

2016-06-18 14:53:34 UTC [/csg/ #chink-shit-general]  

I really don't know what's the correct way to handle it now, I thought you'dw ant to at least be informed

2016-06-18 14:54:13 UTC [/csg/ #chink-shit-general]  

I don't know what that means.

2016-06-18 14:54:20 UTC [/csg/ #chink-shit-general]  

I'm just trying to help..

2016-06-18 14:54:33 UTC [/csg/ #chink-shit-general]  

There's a POC

2016-06-18 14:55:01 UTC [/csg/ #chink-shit-general]  

I thought you said /g/ chats in here

2016-06-18 14:55:16 UTC [/csg/ #chink-shit-general]  

Have I upset people?

2016-06-18 14:55:32 UTC [/csg/ #chink-shit-general]  

Wasn't my intention.

2016-06-18 14:57:25 UTC [/csg/ #chink-shit-general]  

i appologize then @Deleted User i just noticed something and thought out loud.

2016-06-18 14:57:50 UTC [/csg/ #chink-shit-general]  

@cathy I said, can be used to send requests filled with custom data, and pivot through your network

2016-06-18 14:57:55 UTC [/csg/ #chink-shit-general]  

there is.

2016-06-18 14:58:00 UTC [/csg/ #chink-shit-general]  

Mind if I pm you?

2016-06-18 14:58:39 UTC [/csg/ #chink-shit-general]  

Okay I get it.

2016-06-18 15:09:12 UTC [/csg/ #chink-shit-general]  

can we talk about csg tablets?

2016-06-18 15:11:03 UTC [/csg/ #chink-shit-general]  

tablets are great

2016-06-18 15:11:21 UTC [/csg/ #chink-shit-general]  

book reading, mangos reading, movie watching

2016-06-18 15:11:25 UTC [/csg/ #chink-shit-general]  

^

2016-06-18 15:11:41 UTC [/csg/ #chink-shit-general]  

phones are too small

2016-06-18 15:12:22 UTC [/csg/ #chink-shit-general]  

awh

2016-06-18 15:13:07 UTC [/csg/ #chink-shit-general]  

even 6" phones

2016-06-18 15:13:08 UTC [/csg/ #chink-shit-general]  

are toos mall

2016-06-18 15:13:12 UTC [/csg/ #chink-shit-general]  

for tablet related usage

2016-06-18 15:15:01 UTC [/csg/ #chink-shit-general]  

why can't we get cheap programs from China ๐Ÿ˜ฆ

2016-06-18 15:16:24 UTC [/csg/ #chink-shit-general]  

The browser?!

2016-06-18 15:16:31 UTC [/csg/ #chink-shit-general]  

Oh dear god.

2016-06-18 15:16:39 UTC [/csg/ #chink-shit-general]  

If you're serious, ditch it. Get chromium for security

2016-06-18 15:17:01 UTC [/csg/ #chink-shit-general]  

Early access? .-.

2016-06-18 15:17:22 UTC [/csg/ #chink-shit-general]  

wat

2016-06-18 15:17:27 UTC [/csg/ #chink-shit-general]  

Maxthon is public?

2016-06-18 15:17:36 UTC [/csg/ #chink-shit-general]  

._.

2016-06-18 15:17:43 UTC [/csg/ #chink-shit-general]  

Can I have a copy

2016-06-18 15:17:53 UTC [/csg/ #chink-shit-general]  

Edge is making me want to kill myself

2016-06-18 15:18:10 UTC [/csg/ #chink-shit-general]  

What's it based on?

2016-06-18 15:18:36 UTC [/csg/ #chink-shit-general]  

What engine is it using?

2016-06-18 15:18:38 UTC [/csg/ #chink-shit-general]  

oho. fun ๐Ÿ˜„

2016-06-18 15:18:46 UTC [/csg/ #chink-shit-general]  

Secure

2016-06-18 15:18:47 UTC [/csg/ #chink-shit-general]  

and terrible

2016-06-18 15:19:35 UTC [/csg/ #chink-shit-general]  

Edge is like

2016-06-18 15:19:40 UTC [/csg/ #chink-shit-general]  

Windows 10 + Edge

2016-06-18 15:19:43 UTC [/csg/ #chink-shit-general]  

is borderline unhackable

2016-06-18 15:20:28 UTC [/csg/ #chink-shit-general]  

Eh.

2016-06-18 15:20:36 UTC [/csg/ #chink-shit-general]  

pwn2own already owned Edge

2016-06-18 15:20:44 UTC [/csg/ #chink-shit-general]  

but they've added the patches and getting a reliable exploit now

2016-06-18 15:20:50 UTC [/csg/ #chink-shit-general]  

is beyond annoying

2016-06-18 15:21:17 UTC [/csg/ #chink-shit-general]  

not saying it's impossible, but borderline

2016-06-18 15:27:23 UTC [/csg/ #chink-shit-general]  

@cathy load it into IDA

2016-06-18 15:27:33 UTC [/csg/ #chink-shit-general]  

well dump the firmware first ofc

2016-06-18 15:28:07 UTC [/csg/ #chink-shit-general]  

if it's hex you can convert that to a bin

2016-06-18 15:28:35 UTC [/csg/ #chink-shit-general]  

I might be

2016-06-18 15:34:25 UTC [/csg/ #chink-shit-general]  

SURE IS!

2016-06-18 15:34:45 UTC [/csg/ #chink-shit-general]  

laame

2016-06-18 15:35:01 UTC [/csg/ #chink-shit-general]  

did you set the processor flavour as arm/avr ?

2016-06-18 15:35:17 UTC [/csg/ #chink-shit-general]  

Yeah but I mean did you set it to avr

2016-06-18 15:35:22 UTC [/csg/ #chink-shit-general]  

because if you didn't IDA wont recognize it

134 total messages. Viewing 100 per page.
Page 1/2 | Next