log☇︎
100500+ entries in 0.022s
asciilifeform: iirc mircea_popescu at the time said that the thing really oughta eat a programmable set of checkpoint ☟︎
asciilifeform: i never cut the old ones out, but introduced flag 'verifyall'
asciilifeform: ah
asciilifeform: snip of 'checkpoints'
asciilifeform: trinque: what was this in re
asciilifeform: ( the last time i mentioned him on the air -- he actually showed up! in pm! to whine re how cruelly he is libelled, how he was Never A Stooge, etc. snoar. )
asciilifeform: decimation.
asciilifeform: or the other d00d, which one was he,
asciilifeform: and lol, infiltrate, sooo 2013!111 what'll he do, bore folx to death, like ninjashotgun
asciilifeform: mircea_popescu: he didn't show up under the default lamer nick (e.g., 'fromphuctor') so probably not this
asciilifeform: shinohai: i still dun get why cia stooge needs a handle. can read the l0gz on www, like anybody
asciilifeform: !!up onlooker
asciilifeform: in other strange, '4-year-old male white rhino who was slaughtered this week inside his enclosure at a zoo outside Paris. The rhino — discovered by his keeper at the Thoiry Zoological Park on Tuesday — now holds the ominous distinction of likely being the first rhino to be killed by poachers inside a zoo, experts said.'
asciilifeform: conflicting data re seekrit heathen pits, noose at 11
asciilifeform: fuckable, even
asciilifeform: dunno, per my informant there were gurls there,
asciilifeform: 'they're exempt from equalism!11 , think!'
asciilifeform: the funny bit is, that was when i formed picture of nsa as 'serious org'
asciilifeform: or maybe this is only at cia.
asciilifeform: they suure luvv anime bois tho. apparently.
asciilifeform: and , years later, ended up briefly labouring in a butugychag full of ex-nsa folx, who confirmed, they dun like ethnic untermenschen there
asciilifeform: briefly upstack: as i once described, many years ago asciilifeform actually tried to sign up for nsa! was , unsurprisingly, turned down ( you get a ream of paper even if turned down! )
asciilifeform: trinque: wassat?
asciilifeform: mircea_popescu: sweeping a floor for beloved comendante hasta y por la siempre, as gurl does, is quite different from sweeping floor for salary from hitler. even if same broom and same floor somehow.
asciilifeform: mircea_popescu: that's rather like to say that fucking same gurl vs fucking hole in a muddy tree trunk, 'is the same'
asciilifeform: commuting to and sitting in butugychag is a mega-difference
asciilifeform: in asciilifeform's mental calculus, it sure does
asciilifeform: megabux / ~0 is pretty sum
asciilifeform: gotta divide by amt of honestwork, mircea_popescu
asciilifeform: no, but the fact-of.
asciilifeform: i suspect that , e.g., gavin's pay stubs, would entertain plenty.
asciilifeform: mircea_popescu: and somebody gives a shit re junk routers etc?
asciilifeform: ( recall, in mircea_popescu's recent case, answer was the -- very usual -- 'nope' )
asciilifeform: trinque: first q to ask in a wedge: 'has it SEEN the block?'
asciilifeform: ( incidentally, trb doesn't validate scripts in blocks. at. all. )
asciilifeform: shinohai: no mention of the db, the actual bottleneck..
asciilifeform: but i'll be the first to admit that this heuristic is very much a 'blind man and the elephant'.
asciilifeform: and who embed anime gif into their project docs (several examples in the linked dump)
asciilifeform: thus far i suspect that 'leakage' is roughly proportional to a directorate's population of folx who know what is 'twerk'
asciilifeform: not even the directorate which runs the gavins, the hearns, ever seems to leak so much as a drop.
asciilifeform: BingoBoingo: we did have a thread back in... 2013? re 'they will copy su approach and make 2-in-a-box kgb/gru duet'
asciilifeform: ( just as crypto directorate is )
asciilifeform: ~that~ compartment, apparently, leakproof.
asciilifeform: and srsly, 0 directly bitcoin-related anything. in motherfucking 2015-16. asciilifeform is disappoint.
asciilifeform: this rounds out today's lulzfest, i think.
asciilifeform: ^ apparently they use own auditor directorate for beta testing, and consistently fail
asciilifeform: h had consistent packet sizes.'
asciilifeform: 'IOC/ECG's Advanced Forensic Division (AFD) performed an analysis of Hive version 2.5 network communications to assess its likelihood of detection.The results of this analysis are found in document AFD-2012-0973-2. In summary, AFD was able to create signatures for DNS, ICMP, and TFTP triggers; found that the TCP and UDP triggers did not adhere to their respective protocol standards; and further found that the TCP and UDP triggers eac
asciilifeform: document also of slight interest in re discussion of ntp, and issues of time synchronization in general. apparently unsolved problem for usg just as well as for victims.
asciilifeform: or any matches. If a match is found the packet is assumed to be a TCP replay and is dropped.'
asciilifeform: sl/include/polarssl/ssl.h is extended to include the session _checksum, tool_id, use_custom, and xor_key. The data contained within this packet is constant with the exception of a time stamp taken from the real-time clock and a few bytes of random data. A CRC checksum is computed from the entire packet and is included with the HELLO packet. When Blot receives this packet, it checks the CRC searches a list of previously seen packets f
asciilifeform: 'Hive beacons were designed to work with the Blot proxy (developed by Xetron). Blot looks for a tool ID embedded in the HELLO packet of an SSL session initiation. If the ID is found, then it forwards the packet to the tool-handler, otherwise it is sent to the cover server. The tool ID is embedded in the HELLO packet using the embedData function defined in …/polarssl/library/loki_utils.c. The SSL data structure defined in …/polars
asciilifeform: https://wikileaks.org/ciav7p1/cms/files/DevelopersGuide.pdf << for aficionados strictly -- details of implant protocol, where gibblets are disguised as tcp replay packets. apparently standardized across this particular directorate.
asciilifeform ate the whole thing.
asciilifeform: largely sums to snoar.
asciilifeform: loox like they censored the ~only ~useful bits, e.g. the active av holes.
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_4849785.html >> 'I strongly suggest that you name your missing vector for DanceFloor "Twerk". '
asciilifeform: srsly?
asciilifeform: hile she is listening to music, the tool will execute the survey and a prioritized file collection. All collected data will be stored to the root of the removable media it is executing from. When the asset next meets with the case officer, the thumbdrive is retrieved and the collection is processed. '
asciilifeform: 'RainMaker v1.0 is a survey and file collection tool built for a FINO QRC operation. IOC/FINO is looking to expand asset-assisted operations. The intended CONOPS involves using an asset to gain access to a target network. The asset has the ability to plug in a personal thumbdrive to the network. In this scenario, the asset will have "downloaded" the portable version of VLC player (2.1.5) and will listen to music during work hours. W
asciilifeform: actually nearing the bottom of this barrel
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_9535630.html << their version of mircea_popescu's 'uci'.
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_22642800.html << plunder of lulz from the italian 'hackteam' dump of '15
asciilifeform can almost picture this scene
asciilifeform: 'hey lemme borrow this'
asciilifeform: '...initial plan for concealment host is as a day planner.'
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_1179686.html << lulzy, pocket gadget for theft of seeekrits from... floppies
asciilifeform: (0 details, but stated to exist.)
asciilifeform: aaaand https://wikileaks.org/ciav7p1/cms/page_9535850.html << hald (dbus component, poetteringism) local root.
asciilifeform: ^ siemens voip gear, pwned
asciilifeform: and oh hey, http://btcbase.org/log/2015-08-02#1222312 <<<>>> https://wikileaks.org/ciav7p1/cms/page_2621481.html ☝︎
asciilifeform: pretty heavy.
asciilifeform: lel, i was wrong re their 'gossipd', it was written, by unknown commercial contractor: https://wikileaks.org/ciav7p1/cms/files/Fluxwire_manual-3.5.0.pdf << docs.
asciilifeform: (and, bonus: builds only on winblowz, heavy on -- yes -- masm)
asciilifeform: trinque: the move to intel, killed it, intel iron wants megatonne of initialization crapolade
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_36405256.html << re the 'internal gossipd', at the time of the writing appears to be entirely hypothetical
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_14588150.html << crapple firmware infector
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_3375460.html << usbdrive-shaped hardware raper for crapple desktops
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_18382968.html << winblowz code-signing bypass, courtesy of microshit
asciilifeform: 'Worked as head of Software Engineering at Mediatech Inc. from 2004-2006' << who will be the first to name this illustrious fella.
asciilifeform: https://wikileaks.org/ciav7p1/cms/page_5341225.html << him, apparently
asciilifeform: 'Development of a tool to burst out a binary using udp packets with forward error correction at 100MB/s' << somebody reads the l0gz
asciilifeform: nope
asciilifeform: which is why you'll often find trb-related tcp pipes randomly RST'd, and the like.
asciilifeform: Framedragger: don't forget huawei.
asciilifeform: buncha konsoomer junk also (linksys et al)
asciilifeform: various cisco rootkits, also, but these i regard as a snore
asciilifeform: 'VOIP - Huawei VOIP Collection' << direct phuctor lel
asciilifeform: BingoBoingo: neato
asciilifeform: ( more re same, https://wikileaks.org/ciav7p1/cms/page_13205587.html )
asciilifeform: ( from the docs of the active ios9+ browser driveby-with-arbitrary-payload. which hopefully surprises nobody )
asciilifeform: so added a couple of new members and changed some sizes in the struct scheme.These are fairly trivial to reverse but comparing each function in a disassembler with the Tiny Scheme source version. Apple uses Tiny Scheme to create a vector of sandbox rules that it then converts to a compiled sandbox profile....'
asciilifeform: 'Apple seems to have taken version 1.38 of the Tiny Scheme project (available online, google it or check workshop output) and modified it a little. Most modifications are fixes for the most obvious bugs in the program: changing sprintf to snprintf and adding some more size checks but they have not fixed everything. In fact, they haven't even bothered keeping up with the Tiny Scheme project, which is now on version 1.41. Apple have al
asciilifeform: lel, ipnoje uses 'tinyscheme' internally.
asciilifeform: ( ads, e.g., https://www.techexpousa.com/jobdetails.cfm/450840/Software-Engineer )
asciilifeform: in-house mega-seekrit javaturd.
asciilifeform: now how would i know.
asciilifeform: and it is not even first-revealed in today's dump, has figured in... help-wanted ads, for eons.
asciilifeform: java turd.
asciilifeform: in other lulz, nsa has internal clone of ida, 'ghidra' ☟︎