[00:47:54] *** Joins: ngomez (~nsgomez@2001:19f0:5c00:8965:22f2:77ed:e053:d8be) [00:48:00] *** Joins: arirawr (~arirawr@40.76.77.146) [00:49:36] *** Quits: arirawr- (~arirawr@40.76.77.146) (*.net *.split) [00:49:39] *** Quits: nsgomez (~nsgomez@2001:19f0:5c00:8965:22f2:77ed:e053:d8be) (*.net *.split) [00:49:43] *** Quits: skasturi (skasturi@april-fools/2014/runnerup/skasturi) (*.net *.split) [01:01:51] *** Joins: skasturi (skasturi@april-fools/2014/runnerup/skasturi) [03:45:47] *** Quits: vishwin_ (~alliek@wikimedia/O) (Ping timeout: 264 seconds) [03:51:59] *** Joins: vishwin_ (~alliek@wikimedia/O) [14:49:57] ian_znc: http://www.openwall.com/lists/oss-security/2016/02/01/4 [14:49:58] Title: oss-security - Socat security advisory 7 - Created new 2048bit DH modulus [14:50:06] first of all: lmao [14:50:21] secondly, do you want to exploit that with me? [14:53:53] iangcarroll: ^ [14:54:07] one sec, gotta talk about my PSAT scores with someone [15:29:58] *** Quits: vishwin_ (~alliek@wikimedia/O) (Ping timeout: 256 seconds) [15:35:56] *** Joins: vishwin_ (~alliek@wikimedia/O) [16:20:52] iangcarroll: ping [16:20:58] that's one long talk [16:21:01] did you fail? [16:22:09] yes, i failed so badly the test broke [16:22:26] they had to make the scores a signed int, just for you [16:22:32] lolol [16:22:35] wow that's a clever one [16:22:44] i came up with that on the spot [16:22:50] * gsingh93 pats himself on the back [16:22:59] as it turns out I have to help with a play until 8PM [16:23:27] kk [16:23:39] let me know if you want to work on in sometime this week [16:23:50] it seems like a nice and simple n-day to exploit [16:24:15] this*, not in [16:26:42] will do [18:13:18] iangcarroll: https://www.facebook.com/groups/wearehx/permalink/1725755264335658/ [18:13:18] Title: Log into Facebook | Facebook [18:13:22] i'm curious [18:13:24] i don't know the answer [18:17:41] possible, I guess [18:17:53] DO should be rate limiting how many domains can be added though [18:28:39] it seems to simple [18:30:42] i mean, it is simple [18:31:09] but it can only be exploited when nameservers stop serving records for a domain and allow others to claim the domain [18:31:33] so [18:31:44] let's say you own the domain [18:31:54] there's an A record for the domain pointing to your server [18:32:04] this CNAME thing will or won't work? [18:32:39] wait, what? [18:32:51] isn't that what the question is saying? [18:32:53] i thought the attack was a domain is pointed to DO but hasn't been added to an account [18:33:07] how do you know it isn't added to an account? [18:33:19] i thought this guy hijacked his own domain [18:33:23] you can narrow it down by seeing if it returns any records; otherwise it's just brute force [18:33:39] i don't think he has done this attack successfully (?) [18:33:46] let me read the post again [18:34:18] " I just tested it on one of my domain names. No restrictions. Pretty cool hack if you ask me." [18:34:40] he keeps using A/CNAME which is confusing because how I read it relies on the domain not having been enrolled at all [18:35:07] i can't add ian.sh to two different accounts so idk [18:39:29] lol http://elections.ap.org/ [18:39:31] Title: U.S. ELECTIONS | [18:39:33] they didn't really finish their footer [18:45:17] iangcarroll, lol [18:45:22] is this from fuzzy search [18:45:41] iangcarroll, how were the PSATs for you [18:46:16] what's fuzzy search? [18:46:33] well, I know what fuzzy searching is, but in this context [18:47:00] I did okay for a sophomore [18:47:06] apparently I'm on track for college [18:54:01] with a little luck, you just might graduate [18:54:22] have you thought about what colleges you want to go to? [18:55:10] no [18:55:20] because then I'd have to look up their avg minimum GPAs [18:55:24] and then I'd have to calculate mine [18:55:24] oh god [18:55:28] don't talk about GPAs [18:55:32] my GPA is going downhill [18:55:32] gg [18:55:33] gg [18:55:42] mine is roughly 0 [18:55:47] my math grade [18:55:48] went from an A [18:55:49] to [18:55:54] something I don't even want to mention [18:55:55] though to my credit I have never failed a class [18:55:57] midterm == death [18:56:08] oh god my time management on the midterm [18:56:09] oh go [18:56:10] d [18:56:12] lol [18:56:17] just no [18:56:21] got 71% as my final grade for geometry last year [18:56:23] barely made it [18:56:24] i only had 5 mins [18:56:30] for what I was supposed dto take 40 mins on [18:56:30] lol [18:56:31] GG [18:56:59] life protip learn when the test ends before it starts [18:57:23] just gonna like, self-accredit ian's tech school and get a PhD in dank memes [18:58:09] msft gave ian's tech school 300 codes to give out to students [18:58:14] for dreamspark [19:02:10] iangcarroll: go to UM [19:02:27] then you can play the CTFs I run there [19:02:43] but then I wouldn't have an excuse to not go see my parents [19:02:56] yea, that was the worst part about UM [19:03:10] i could get away with it for a while though [19:03:22] lol [19:03:24] busy studying or group project excuses [19:05:09] got another CTF coming up? [19:05:13] not too far of a drive [19:09:15] iangcarroll, microsoft's azure is terrible [19:09:15] af [19:09:29] gsingh93, trust me if um accepted me i would be happy af [19:10:26] meh, it's not awful [19:10:38] it's the worst among {AWS,Google,Rackspace,Azure} [19:11:44] better than trying to use like DO in production though lol [19:12:55] iangcarroll: we'll probably have one before the semester ends [19:13:09] you probably won't be eligible for prizes, but you can still play [19:13:47] oh well [19:14:02] let me know when it gets scheduled [19:19:35] will do [19:19:40] i have some new problems coming up [19:19:47] one was based off of a recent problem i solved at work [19:20:17] kinda want to write a CTF, maybe under certly's name [19:20:21] but I have like [19:20:28] -3 units of time [19:20:29] so [19:21:58] iangcarroll: i can help you out [19:24:01] cool; i'll have to do it april-may range though, as I've got to sort some other stuff out first [19:26:08] i act on too many ideas of mine :p [19:31:12] iangcarroll, certly is pretty cool [19:31:41] can you describe what certly actually does? [19:31:47] is it like the middle man for getting a cert? [19:32:08] and then managing all of them? [19:32:48] it was, at one point [19:33:25] in 2014 when you wanted to buy a cert you either paid digicert $250 or used a god awful interface to try and order it [19:33:30] so ian_znc [19:33:37] wrong ian :p [19:33:37] does this actually give me a certificate [19:33:41] or does it just manage them [19:33:51] or you could use startssl, like me [19:34:07] that does not really contradict "or used a god awful interface" :P [19:34:22] ah, good point [19:34:51] what about letsencrypt now [19:35:13] LE, imo, only adds to the problem when you need wildcards or EV certs, etc [19:35:22] you end up with multiple places to manage and renew all of your certs [19:35:49] however, I'm going to pivot certly because at this point a CA or a major player needs to adopt ACME, and we don't have enough leverage to really make any technical changes to how CAs operate [19:36:08] adopt and fork ACME, that is, or at least modify it before it becomes a standard [19:36:42] ACME doesn't solve payment or validation, both critical things for CAs that need to make money [19:37:00] well, both critical things for CAs, the former for those who need to make money [19:37:10] how much money have you made? [19:37:23] we never really launched [19:37:36] lolol [19:37:41] but we've probably processed ~$600 in manual orders via email [19:37:47] which is not really much [19:38:33] one of the problems I've run into is that I cannot build a usable interface for a dashboard lol [19:38:53] your problem is really just that it's written in PHP [19:39:13] obviously :p [19:41:10] i have a break in two weeks so we'll see if I learn python [19:41:26] it might be worth it to build stuff in PHP just to annoy people though [19:41:51] :p [19:48:52] iangcarroll: you'll have the benefit of no one ever wanting to mess with your code [19:49:15] like that one guy who puts "THIS FILE WAS GENERATED, DO NOT MODIFY" at the top of all his code [19:50:24] lol [22:03:55] lol double taxes [22:04:05] will be paying double taxes next summer [22:04:21] cat $ >> /dev/null [22:05:15] canada though [22:05:32] does canada have bad taxes? [22:08:20] lol, someone skipped their highschool government class [22:09:54] i can't take it yet :p [22:09:56] too young [22:10:59] lol. [22:11:11] s/lol/lawl/ [22:11:12] vishwin probably meant: lawl. [23:29:31] *** Joins: majora (~majora@205.204.23.189)