Jump to content

A really dumb 18 year old exploit in Windows was never patched

SIGSEGV

Its sent hashed, but there are rainbow tables for pretty much any hashing algorithm used, so... tough luck

Bitch please Brute-Force is the way too go.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Bitch please Brute-Force is the way too go.

If youre doing it on a large scale (which you probably are, if youre doing it at all) then its a stupid waste of time, when it was already done, and all you need is to search the rainbow tables

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to comment
Share on other sites

Link to post
Share on other sites

That's some strange exploit there. So I guess maybe Microsoft will acknowledge this internally and do something about it for Windows 10?

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

 

 

So, an attacker only needs to intercept this HTTP request, which can be easily done using Man-in-the-Middle (MITM) attack, and then redirect the victim to a malicious SMB server controlled by the attacker.

 

Who the hell would be using SMB over a WAN not encrypted anyway?

If its just talking about local sharing and you get things stolen from you via MITM then you have a more serious issue in your network than this.

 

I cant help but think things like this are so over hyped. The likelihood of this happening in the real world is very small and if it does its likely your own fault for not having the proper security precautions in place.

Intel I9-9900k (5Ghz) Asus ROG Maximus XI Formula | Corsair Vengeance 16GB DDR4-4133mhz | ASUS ROG Strix 2080Ti | EVGA Supernova G2 1050w 80+Gold | Samsung 950 Pro M.2 (512GB) + (1TB) | Full EK custom water loop |IN-WIN S-Frame (No. 263/500)

Link to comment
Share on other sites

Link to post
Share on other sites

Who the hell would be using SMB over a WAN not encrypted anyway?

If its just talking about local sharing and you get things stolen from you via MITM then you have a more serious issue in your network than this.

 

I cant help but think things like this are so over hyped. The likelihood of this happening in the real world is very small and if it does its likely your own fault for not having the proper security precautions in place.

At least 966,190 devices globally that have been indexed by SHODAN at the time of posting.

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

At least 966,190 devices globally that have been indexed by SHODAN at the time of posting.

 

Yep so that proves my second point. 

'if it does its likely your own fault for not having the proper security precautions in place.'

Intel I9-9900k (5Ghz) Asus ROG Maximus XI Formula | Corsair Vengeance 16GB DDR4-4133mhz | ASUS ROG Strix 2080Ti | EVGA Supernova G2 1050w 80+Gold | Samsung 950 Pro M.2 (512GB) + (1TB) | Full EK custom water loop |IN-WIN S-Frame (No. 263/500)

Link to comment
Share on other sites

Link to post
Share on other sites

Mostly adobe software. I mostly use indesign and photoshop. Unless I'm mistaken, I can't use those on Linux. There are few programs that I use that are cross platform, but I kind of need photoshop and indesign for work.

https://www.playonlinux.com/en/supported_apps-6-0.html

Older versions of InDesign work https://appdb.winehq.org/objectManager.php?sClass=application&iId=755Major features don't tend to change with new versions. 

Interested in Linux, SteamOS and Open-source applications? Go here

Gaming Rig - CPU: i5 3570k @ Stock | GPU: EVGA Geforce 560Ti 448 Core Classified Ultra | RAM: Mushkin Enhanced Blackline 8GB DDR3 1600 | SSD: Crucial M4 128GB | HDD: 3TB Seagate Barracuda, 1TB WD Caviar Black, 1TB Seagate Barracuda | Case: Antec Lanboy Air | KB: Corsair Vengeance K70 Cherry MX Blue | Mouse: Corsair Vengeance M95 | Headset: Steelseries Siberia V2

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Here at linux there is no drivers support and few software for you,and on windows you can get security breach by a 12 year old.

Isnt the world just wonderfull,imagine if we all worked towards a common goal 1 Best OS that can adapt and run on everything.

Link to comment
Share on other sites

Link to post
Share on other sites

SMB Supports encryption anyway...

Additionally, SMB is stupid and shouldn't be used. 

Link to comment
Share on other sites

Link to post
Share on other sites

Here at linux there is no drivers support and few software for you,and on windows you can get security breach by a 12 year old.

Isnt the world just wonderfull,imagine if we all worked towards a common goal 1 Best OS that can adapt and run on everything.

No driver support? I've got every single pience of hardware from my ISA sound cards to my GTX 970 working under Linux.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

https://www.playonlinux.com/en/supported_apps-6-0.html

Older versions of InDesign work https://appdb.winehq.org/objectManager.php?sClass=application&iId=755Major features don't tend to change with new versions. 

Well, even if older versions of InDesign work... that doesn't really help me if I own the newest version. I don't pirate, and I don't feel like spending another chunk of change purchasing old software. Unless adobe wants to exchange my key for the older versions.

Fractal Design Define R4 | MSI x79a-GD45 | 3960X @ 4.6Ghz | Lots of EK Blocks | EVGA GTX780Ti 3GB | Corsair Dominator Platinum 16GB (4x4) DDR3 1866 | Samsung 840 Pro 512GB SSD | Western Digital Red 2TB x4 (Raid 10) | Corsair AX760 | Windows 7 Professional 64-bit

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

the people behind wine reverse engineered most of the windows .dll libraries and compiled them for linux.

That sounds like a shit load of work. I'll look into it. Been wanting to get off windows for a while.

Fractal Design Define R4 | MSI x79a-GD45 | 3960X @ 4.6Ghz | Lots of EK Blocks | EVGA GTX780Ti 3GB | Corsair Dominator Platinum 16GB (4x4) DDR3 1866 | Samsung 840 Pro 512GB SSD | Western Digital Red 2TB x4 (Raid 10) | Corsair AX760 | Windows 7 Professional 64-bit

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Now on the issue of Windows 8 and newer, does windows 8 use your microsoft account credentials for SMB? Wouldn't it pop up asking for credentials to use? Does it happen on any SMB share or only ones that respond they are password protected? Are open shares being given this info even without requesting it?

 

Is this a very specific case being brushed over a very large population?

Link to comment
Share on other sites

Link to post
Share on other sites

I don't even use an MS account.

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

No driver support? I've got every single pience of hardware from my ISA sound cards to my GTX 970 working under Linux.

Yea well my asus xonar and my mouse says otherwise while they work by default without installing anything, they have no options/control panels,i cant set any settings or equalizer on my soundcard,i cant set any macros on my mouse or custom config buttons,nvidia control panel has very few options there.

Software options are quite limited,while you got good browsers choice theres almost no good video player like potplayer/mpc-hc + madvr just VLC basic stuff.

As for games most of what i play is online games,best games are online nowdays,very few to no online games are supported on linux.

Id love linux to have more support and everyone should build apps for windows/linux/mac but if only it were that easy :|

Link to comment
Share on other sites

Link to post
Share on other sites

Yea well my asus xonar and my mouse says otherwise while they work by default without installing anything, they have no options/control panels,i cant set any settings or equalizer on my soundcard,i cant set any macros on my mouse or custom config buttons,nvidia control panel has very few options there.

Software options are quite limited,while you got good browsers choice theres almost no good video player like potplayer/mpc-hc + madvr just VLC basic stuff.

As for games most of what i play is online games,best games are online nowdays,very few to no online games are supported on linux.

Id love linux to have more support and everyone should build apps for windows/linux/mac but if only it were that easy :|

Don't forget that Linux isn't as dumbed down as Windows, getting the most out of it actually requires you to learn how to use it. Just like in the late 80's/ early 90's when computers needed a lot of tweaking to run properly.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×