HNHacker News
TopNewBestAskShowJobs

snowy

1,314 karma · joined September 22, 2014

submissionscomments
snowy··on FBI Is Wrong: All Routers Need to Be Reset, What to Do
This article is wrong. It states: "MicroTik Cloud Core routers, mainly used by enterprises, may be affected if they run versions 1016, 1036 or 1072 of the MicroTik RouterOS.

Those are model numbers, not firmware versions. He lifted that from this Krebs artical (https://krebsonsecurity.com/2018/05/fbi-kindly-reboot-your-r...) which is also wrong.

All Mikrotik products running less than version 6.38.5 are vulnerable: https://forum.mikrotik.com/viewtopic.php?t=134776

It makes me wonder what else is wrong....

snowy··on Linode Turns 14
If they don't have an ASN. It also means they don't have their own IP address space and could not build a transit network.
snowy··on Theresa May to launch sweeping internet regulation despite not winning majority
WARNING!! Loud auto playing video!
snowy··on Early paper money from British Colonial America
Thirty Shillings

To counterfeit is DEATH

How prevalent were counterfeit notes in this period vs now?

snowy··on I had a health crisis in France
If doctors and nurses are at breaking point, its down to them been underfunded and under resourced. Blaming this on immigration is unhelpful and wrong!!
snowy··on Dyn Analysis Summary of Friday October 21 Attack
Can any one explain why they keep referring to this as a complex attack? From the article it seems to be a simple volumetric attack. They mention that it uses UDP port and TCP port 53, nothing complex about that...

Am I missing something here. It wasn't an L7 attack (or was it?) Why keep referring to it as complex?

snowy··on Akamai takes Brian Krebs’ site off its servers after ‘record’ cyberattack
krebsonsecurity.com is now resolving to localhost. I guess he doesn't want to give the DDoSers a target.....
snowy··on OpenSSL Security Advisory
I'm a huge fan of freeradius. I have tried multiple propiortary radius servers and I can honestly say freeradius is the most flexible most reliable radius server in the world. Thanks so much for your effort.
snowy··on US student declared dead reportedly 'kidnapped to teach English to Kim Jong-un'
Point taken. I have updated the title.
snowy··on Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
> what you can do with the bits of information you named when this vulnerability is not present?

If you have SNMP write access you can effectively control the ASA. You could for example get the ASA to fetch a new configuration from your own TFTP server.

For example: http://www.cisco.com/c/en/us/support/docs/ip/simple-network-...

Hence why SNMP is always protected by an ACL. If you have SNMP exposed then you already have big problems.

snowy··on Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability
You would have to have the ASA configured to accept SNMP packets from the IP your sending them from (or maybe spoof the source address if you knew it as it would be a UDP packet) and you would also have to know the SNMP community string.

Chances are if you had all of this info you could cause all sorts of damage even without the vulnerability.

snowy··on My Raspberry Pi cluster
I also got an odroid XU4. As a replacement for a sheeva plug I was using as a home server. I was hoping to use the HDMI out into my TV and use it for browsing and streaming media. Unfortunately none of the distros produced by hardkernel fully work. There is always something broken in each distro. It's a complete pain. I don't know why they cant just produce a distro that has all of the hardware working at install time.
snowy··on BT fault hits broadband users and banks
From my point of view if you end up with mission critical equipment connected only to A or B power then its engineered wrong.
snowy··on BT fault hits broadband users and banks
True. But Data centers usually have an A and B power systems independent of each other for redundancy . Equipment is usually connected to both. The failure of either should not cause an outage. (Unless some one is stupid enough to connect core network equipment to only A or B power)
snowy··on Nepal's Ban on Production and Use of Plastic Bags Comes into Effect
In Ireland we have a levy (I.e. addiontal tax) on plastic bags. It's been in place since 2002: https://en.wikipedia.org/wiki/Recycling_in_the_Republic_of_I...

From link: One noticeable success in Ireland's environmental track record was the introduction of a plastic bag levy in 2002, the first country in the world to do so. All consumers were required to pay 15c for a plastic bag; this led to an immediate decrease of over 90% in the amount of plastic bags in circulation. From 328 bags per inhabitant per year when the levy was introduced, usage fell to 21 bags per capita.

snowy··on How I Could Steal Money from Instagram, Google and Microsoft
Any one else think that the bug bounty rewards were quite low?
snowy··on Airtel is sniffing and censoring CloudFlare’s traffic in India
So is it reasonable to say?: piratebays fault for not enforcing SSL between their origin servers and cloud flare?
snowy··on Worm going through unpatched Ubiquiti routers
Of relevance: http://krebsonsecurity.com/2015/11/the-lingering-mess-from-d...
snowy··on How Fastly coded their own routing layer for scaling CDN
You mean proxy ARP?
snowy··on NTP Pool Bad Actors: The Rising Sophistication of Network Scanning
At least most IPv4 addresses on a LAN are behind NAT. It's not a firewall but probably has saved some people.
snowy··on People Call Me Aaron
These cases are unrelated in anyway.

How can you compare the death of a man shot by police on the underground because of been confused with a terrorist, with a person driven to suicide because they are facing a jail sentence?

snowy··on The TTY demystified
Down votes? Anyone care to elaborate?

Seriously, I don't understand. If I find an article that I find interesting I can just post it multiple times under different URL's?

Is that now acceptable on HN?

snowy··on The TTY demystified
So are those the rules now? If we consider some thing to be worthy we can post it again and again and again?
snowy··on The TTY demystified
Great article. However I don't under stand how it has managed to be posted 12 times: https://hn.algolia.com/?query=%09The%20TTY%20demystified&sor...
snowy··on ProtonMail pays $6k ransom, gets taken out by DDoS anyway
Does any one know the technical details of the attack? The article simply refers to it as 'highly advanced denial-of-service attacks'.

From the fact that it knocked off their upstream providers also means it was probably just a simple volumetric attack like an NTP or DNS reflection attack. These are relatively easy to defend against.

I work for an ISP that gets hit with 5 or 6 of these a week, but because of the mitigation strategies we have in place our customers don't even notice...

snowy··on Someone bought 'Google.com' from Google for one minute
Thank you.
snowy··on Someone bought 'Google.com' from Google for one minute
In Ireland some one managed to redirect google.ie (The irish google search domain):

http://technology.ie/google-ie-hijacked/

The ccTLD register (The IEDR) had a vulnerability in their management portal that was exploited (I believe it was an SQL injection if I recall correctly).

The attacker changed the DNS servers to their own and then put an A name record pointing google.ie to their own server.

The server just displayed a hijacked by page.

It was probably just some kid. If it was a criminal they would have done some thing far more malicious.

yahoo.ie also got hijacked.

It was an absolute pain, for months after the IEDR's portal was disabled, you had to call them to make any changes to any .ie domain.

snowy··on A first look at the OS the Chinese government wants to replace Windows
Nope. I use apparmor. Interesting though. I didn't know that about SELinux.
snowy··on A first look at the OS the Chinese government wants to replace Windows
I wonder what spyware they have embedded in it?

A distro brought to you by the Chinese government. I would trust that as much as a distro brought to you by the NSA.

snowy··on To hack an Android phone, just type in a really long password
I have a galaxy S6 running android 5.1.1 with device encryption.

The lock screen only accepts a password of 16 digits long.

So.... Only some devices effected?

EDIT:

On further research its fixed on 5.1.1.

Kind of a stupid fix? Just limiting the size on the input password field?

Also I notice that you can no longer copy paste from the emergency call screen.

Page 1 of 2Next →