HN user

snowy

1,314 karma
Posts124
Comments51
View on HN
krebsonsecurity.com 6y ago

Interview with the Guy Who Tried to Frame Me for Heroin Possession

snowy
374pts87
news.ycombinator.com 6y ago

NY Payroll Company Vanishes With $35 Million

snowy
1pts1
krebsonsecurity.com 7y ago

The World’s Biggest ‘Bulletproof’ Hoster

snowy
3pts1
krebsonsecurity.com 7y ago

Feds Bust Up Dark Web Hub Wall Street Market

snowy
2pts0
krebsonsecurity.com 7y ago

A Year Later, Cybercrime Groups Still Rampant on Facebook

snowy
65pts11
krebsonsecurity.com 7y ago

Crypto Mining Service Coinhive to Call It Quits

snowy
2pts0
krebsonsecurity.com 7y ago

Former Russian Cybersecurity Chief Sentenced to 22 Years in Prison

snowy
2pts0
krebsonsecurity.com 7y ago

Courts Hand Down Hard Jail Time for DDoS

snowy
1pts0
krebsonsecurity.com 7y ago

A Chief Security Concern for Executive Teams

snowy
1pts0
krebsonsecurity.com 7y ago

Half of All Phishing Sites Now Have the Padlock

snowy
166pts73
krebsonsecurity.com 7y ago

Calif. Man Pleads Guilty in Fatal Swatting Case, Faces 20+ Years in Prison

snowy
1pts0
krebsonsecurity.com 8y ago

Deleted Facebook Cybercrime Groups Had 300,000 Members

snowy
1pts0
www.scmp.com 8y ago

Woman offered refund after iPhone X facial recognition fails

snowy
5pts0
krebsonsecurity.com 8y ago

Tech Firms Team Up to Take Down ‘WireX’ Android DDoS Botnet

snowy
1pts0
krebsonsecurity.com 9y ago

Why So Many Top Hackers Hail from Russia

snowy
142pts79
krebsonsecurity.com 9y ago

OneLogin: Breach Exposed Ability to Decrypt Data

snowy
3pts0
krebsonsecurity.com 9y ago

Blind Trust in Email Could Cost You Your Home

snowy
1pts0
krebsonsecurity.com 9y ago

Shopping for W2s, Tax Data on the Dark Web

snowy
2pts0
krebsonsecurity.com 9y ago

A Shakeup in Russia’s Top Cybercrime Unit

snowy
4pts0
krebsonsecurity.com 9y ago

Extortionists Wipe Thousands of Databases, Victims Who Pay Up Get Stiffed

snowy
3pts0
www.bbc.com 9y ago

China clamps down on Kim Jong-un 'fatty' jokes

snowy
2pts0
krebsonsecurity.com 9y ago

Computer Virus Cripples UK Hospital System

snowy
3pts0
krebsonsecurity.com 9y ago

Hackers Hit U.S. Senate GOP Committe

snowy
2pts0
www.businessinsider.com 9y ago

Republicans: We don't want SpaceX investigating its own rocket accidents

snowy
15pts9
sputniknews.com 9y ago

Iraqis Use 9/11 Bill to Demand Compensation from US for 2003 Invasion

snowy
3pts0
www.thedailybeast.com 9y ago

Pentagon Paid for Fake ‘Al Qaeda’ Videos

snowy
65pts16
www.cam.ac.uk 9y ago

Body cameras sees complaints against police ‘virtually vanish’, study finds

snowy
5pts2
www.reuters.com 9y ago

Samsung slammed by Chinese state TV over Note 7 recall 'discrimination'

snowy
1pts0
www.theverge.com 9y ago

Spacecom seeking $50M or free flight from SpaceX after Falcon 9 explosion

snowy
2pts0
www.independent.co.uk 9y ago

US student declared dead reportedly 'kidnapped to teach English to Kim Jong-un'

snowy
26pts13

This article is wrong. It states: "MicroTik Cloud Core routers, mainly used by enterprises, may be affected if they run versions 1016, 1036 or 1072 of the MicroTik RouterOS.

Those are model numbers, not firmware versions. He lifted that from this Krebs artical (https://krebsonsecurity.com/2018/05/fbi-kindly-reboot-your-r...) which is also wrong.

All Mikrotik products running less than version 6.38.5 are vulnerable: https://forum.mikrotik.com/viewtopic.php?t=134776

It makes me wonder what else is wrong....

Linode Turns 14 9 years ago

If they don't have an ASN. It also means they don't have their own IP address space and could not build a transit network.

If doctors and nurses are at breaking point, its down to them been underfunded and under resourced. Blaming this on immigration is unhelpful and wrong!!

Can any one explain why they keep referring to this as a complex attack? From the article it seems to be a simple volumetric attack. They mention that it uses UDP port and TCP port 53, nothing complex about that...

Am I missing something here. It wasn't an L7 attack (or was it?) Why keep referring to it as complex?

I'm a huge fan of freeradius. I have tried multiple propiortary radius servers and I can honestly say freeradius is the most flexible most reliable radius server in the world. Thanks so much for your effort.

what you can do with the bits of information you named when this vulnerability is not present?

If you have SNMP write access you can effectively control the ASA. You could for example get the ASA to fetch a new configuration from your own TFTP server.

For example: http://www.cisco.com/c/en/us/support/docs/ip/simple-network-...

Hence why SNMP is always protected by an ACL. If you have SNMP exposed then you already have big problems.

You would have to have the ASA configured to accept SNMP packets from the IP your sending them from (or maybe spoof the source address if you knew it as it would be a UDP packet) and you would also have to know the SNMP community string.

Chances are if you had all of this info you could cause all sorts of damage even without the vulnerability.

I also got an odroid XU4. As a replacement for a sheeva plug I was using as a home server. I was hoping to use the HDMI out into my TV and use it for browsing and streaming media. Unfortunately none of the distros produced by hardkernel fully work. There is always something broken in each distro. It's a complete pain. I don't know why they cant just produce a distro that has all of the hardware working at install time.

True. But Data centers usually have an A and B power systems independent of each other for redundancy . Equipment is usually connected to both. The failure of either should not cause an outage. (Unless some one is stupid enough to connect core network equipment to only A or B power)

In Ireland we have a levy (I.e. addiontal tax) on plastic bags. It's been in place since 2002: https://en.wikipedia.org/wiki/Recycling_in_the_Republic_of_I...

From link: One noticeable success in Ireland's environmental track record was the introduction of a plastic bag levy in 2002, the first country in the world to do so. All consumers were required to pay 15c for a plastic bag; this led to an immediate decrease of over 90% in the amount of plastic bags in circulation. From 328 bags per inhabitant per year when the levy was introduced, usage fell to 21 bags per capita.

These cases are unrelated in anyway.

How can you compare the death of a man shot by police on the underground because of been confused with a terrorist, with a person driven to suicide because they are facing a jail sentence?

The TTY demystified 11 years ago

Down votes? Anyone care to elaborate?

Seriously, I don't understand. If I find an article that I find interesting I can just post it multiple times under different URL's?

Is that now acceptable on HN?

The TTY demystified 11 years ago

So are those the rules now? If we consider some thing to be worthy we can post it again and again and again?

Does any one know the technical details of the attack? The article simply refers to it as 'highly advanced denial-of-service attacks'.

From the fact that it knocked off their upstream providers also means it was probably just a simple volumetric attack like an NTP or DNS reflection attack. These are relatively easy to defend against.

I work for an ISP that gets hit with 5 or 6 of these a week, but because of the mitigation strategies we have in place our customers don't even notice...

In Ireland some one managed to redirect google.ie (The irish google search domain):

http://technology.ie/google-ie-hijacked/

The ccTLD register (The IEDR) had a vulnerability in their management portal that was exploited (I believe it was an SQL injection if I recall correctly).

The attacker changed the DNS servers to their own and then put an A name record pointing google.ie to their own server.

The server just displayed a hijacked by page.

It was probably just some kid. If it was a criminal they would have done some thing far more malicious.

yahoo.ie also got hijacked.

It was an absolute pain, for months after the IEDR's portal was disabled, you had to call them to make any changes to any .ie domain.

I have a galaxy S6 running android 5.1.1 with device encryption.

The lock screen only accepts a password of 16 digits long.

So.... Only some devices effected?

EDIT:

On further research its fixed on 5.1.1.

Kind of a stupid fix? Just limiting the size on the input password field?

Also I notice that you can no longer copy paste from the emergency call screen.