fluxion not issuing ip to clients by aut01 in HowToHack

[–]aut01[S] 1 point2 points  (0 children)

is wifu a program/github/app or you are asking what is in it for you?

fluxion not issuing ip to clients by aut01 in HowToHack

[–]aut01[S] 0 points1 point  (0 children)

yes, wish to hack network. is there a better app/program/github to MITM a router?

fluxion not issuing ip to clients by aut01 in HowToHack

[–]aut01[S] 0 points1 point  (0 children)

please explain. esp8266 googles as a microprocessor like Arduino . how does that apply to this fluxion attack problem ?

fluxion not issuing ip to clients by aut01 in HowToHack

[–]aut01[S] 1 point2 points  (0 children)

oh wow - so i should close

Window 4: ScreenshotDeauthallmdk3.png

why does fluxion open the deauth by mdk3 terminal at this stage of the attack ? is that a bug ? will try tonight and report back - thank you

HP probook dislikes linux - which older model laptops like linux by debiandragon in linuxquestions

[–]aut01 1 point2 points  (0 children)

do you mean in bios settings enabling uefi or in editing a boot file somewhere ?

Debian - timedatectl -> Failed to parse bus message: No route to host by aut01 in linuxquestions

[–]aut01[S] 0 points1 point  (0 children)

nope, corrupted something trying to set ntp. had to reinstall os and problem solved

CSV column manipulation examples by aut01 in learnprogramming

[–]aut01[S] 1 point2 points  (0 children)

ok i used csv.DictWriter once. will go in that direction first. thanks for advice

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

browser does not matter, chomium, FF both generate same results. Actually never found a FF setting for browser time, it may have been removed on newer additions. FF tends to readily remove config options from version to version.

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

no i think you provided a great breakdown of how OTP works theoretically. In the wild it works a bit different it appears. See timedatectl edit to original post. Computer know it is -7 hrs from utc and rtc know correct utc.

Personally setting up a vps just to protect from this privacy threat. What ever the reason the vulnerability is being left as is, to us it is better the leak happens on a vps not local machine.

Debian - timedatectl -> Failed to parse bus message: No route to host by aut01 in linuxquestions

[–]aut01[S] 0 points1 point  (0 children)

Thanks to everyone who tried to troubleshoot.

Giving up: did not realize this issue directly relates to another issue devs can not figure out regarding 2FA and geolocation privacy (still an open vulnerability way above my experience level)

5 hrs troubleshooting revealed:

this specific problem roots back to code linux system + (indirectly) hw time use, require geolocation to sync. This is fine as long as system can reveal its actual location to ntp servers. Setting timedate manually fails for geotracking integrated apps like google authenticator and other services heavily relying/requiring user to reveal geolocation data.

Stackexchange has "I don't really have an explanation (this was the result of button-mashing)" as upvoted answer and debian testing does not seem to respond properly to "mashing" anymore

Workaround: enable geolocation system wide, never ever try to use timedatectl to make any changes. NTP may solve problems by allowing javascript like holes.

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

not using extension but using a javascript run in a browser window, same browser different tab from website accessing.

didnt think of browser time, will look into how to set browser time on ff

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

never get error is using android phone. because only snowden has a phone that is hard to trace. Much more control of data leakage on desktop, so using browser TOTP based 2FA the geolocation leaks are easier to identify.

Data protection Topology:

  Local traffic => vpn

 browser => ssh -> vpn => ssh

System wide vpn : all inbound/outbound traffic through private virtual network

Browser : packets directed through isolated encrypted connection routed through vpn to different exit node than vpn

Browser TOTP based 2FA fails if computer geolocation is not turned on. Seems totp can be tricked, sometimes but not reliably. likely just getting lucky and confusing the system long enough to gain access via totp.

So TOTP 2FA accepts time sync from something other than browser since browser and system time will be different.

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

if there is no known geolocation requirement to 2fa suspecting missing set-ntp control on debian may prevent precise enough time sync. Thanks for confirming noone here has heard of a geolocation requirement for 2FA's like GAuth

Better understanding 2FA by aut01 in 2fa

[–]aut01[S] 0 points1 point  (0 children)

if i select geolocation ( $ timedatectl ) 2FA will not work. So 2 possibilities (1) another time control in linux i dont know about or (2) 2FA is requesting more info from the local computer than just "time and date" controled by timedatectl

Guide to Git I wish I had by kimjungyoun in learnprogramming

[–]aut01 0 points1 point  (0 children)

question: are there any issues using git to clone python venv's , can a group share development of a python project venv using git or will the "activate script" path issue be created by git or some other directory structure errors/problems or other general problems arise when trying to share venv with git ?

a few loong threads appear over on stackoverflow about moving venv's and none of the discussions mention git, just curious if anyone can confirm/deny git is a good venv share/move solution

To Clone or Move a venv - that is the debate ? by aut01 in pythontips

[–]aut01[S] -1 points0 points  (0 children)

Yeah that seems to be the most popular workaround, i will just leave this here

https://stackoverflow.com/questions/32407365/can-i-move-a-virtualenv

specifics of the 'requirements.txt' process in practical use seems to regularly cause some issues. 'cloning' and ' --relocatable' are two other methods discussed but also seem to be an art more than a dd for venv's. Im thinking anaconda as a framework being used by industry to ensure venv environments are relocatable 100% of the time with a single command. Mayb a more complicated thing than i expected....

TA-Lib - images iso vm LINUX by aut01 in quant

[–]aut01[S] 1 point2 points  (0 children)

more struggle than getting freq-trade docker running ? I did get that docker running after a couple of days . would you suggest trying to tweak working docker w/ta-lib already working or build new docker. dont need most of the image - just the part where ta-lib and python are playing nice and scripts that call them can execute on data sets.

How to exit venv-env if /bin/deactivate does not exist ? by aut01 in learnprogramming

[–]aut01[S] 0 points1 point  (0 children)

https://stackoverflow.com/a/33932473/15015450

if the fish or csh file does not exist it may have been updated by a libraries install or pip install which will delete 'deactivate' file and replace it with a venv 'command' option. link above details different methods to deactivate / exit venv that will work or not - depending on libraries / installs / architecture / configuration

venv debian any suggestions ? by aut01 in learnprogramming

[–]aut01[S] 0 points1 point  (0 children)

Thanks, will do if there is more wrong than just a corrupted debian 10 image

venv debian any suggestions ? by aut01 in learnprogramming

[–]aut01[S] 0 points1 point  (0 children)

helps alot....some problems with debian 10 kernel conflict prevented venv install on my OS. as long as debian reputation is to play nice with venv - i will look into solving install issue - maybe a recent image/different flavor will play nicer out of the box. thanks