log☇︎
198900+ entries in 0.121s
mod6: naw, I gave up on gentoo for the time being, and just used a old deb build machine i've got laying around.
asciilifeform: ( i must point out, if it doesn't , you may not get any warning, other than idiot linux kernel silently dropping bytes, e.g. 0x03 )
asciilifeform: mod6: stty thing worked without problems ?
mod6: on to the advanced tests.
mod6: nice. all of the basic tests passed.
a111: Logged on 2017-04-13 17:19 Framedragger: asciilifeform: btw udp_recvmsg() is the kernel-internal function which is vulnerable. need to check callstack of recvfrom() vs recv(), possibly only recvfrom() is vulnerable (thereby reducing set of exposed programs greatly). otherwise even more funtimes.
Framedragger: http://btcbase.org/log/2017-04-13#1642997 << lulzy: http://www.ecsl.cs.sunysb.edu/elibrary/linux/network/udprecv.pdf diligently follows path of recvfrom() and the likes, *quotes the lines around the bug*, but fails to notice anything bad. if you didn't know, it'd be a very nuanced thing showing that the monk is not actually a good monk ☝︎
asciilifeform: mircea_popescu: sorta the whole point in even having pediwikia -- so that they can have this.
mircea_popescu: o look at that -- wikipedia page re "orange revolution" includes no verbiage of usg involvement ; mentions vaguely "russian nationalist groups".
mircea_popescu: dumb bitch, kept trying to push "orange revolution" angle and whatnot, 30 years out of date.
mircea_popescu: oh what the fuck was her name.
asciilifeform: 'Also on #bitcoin-assets, but that place is very toxic. People on #bitcoin-assets probably have info about bitbet.us, but they aren't quite sane, so be careful.' << lolx2
asciilifeform: '...for all the bad rep Mircea Popescu gets (trolling, narcissist and an asshole in general), his websites are trustworthy, never been hacked and works.' << lel
mircea_popescu: o btw, no more visa free travel in eu for ustards.
asciilifeform: in other lulz, bitbet.us '...is no more, for what he thought was h2o, was h2so4'
mircea_popescu: i confess i have trouble retaioning the names of all these c list starlets
mircea_popescu: who was the anodyne condolezza rice clone that was doing "revolutionizing" ukraina and failed so spectacularily ?
asciilifeform: they're the intended victim, much of the time.
asciilifeform: ( the various 'buried in cement' routers, modems, etc. exhibited in phuctor , say . )
mircea_popescu: end up with the same three herbivores on iphone.
mircea_popescu: except teh terrorists don't upgrade.
asciilifeform: the almost forcible induction of gendercommitters, wimminzintech, etc. mushminds into open sores -- tops off the supply of deniable, 'free-range, organically grown' liquishit
asciilifeform: the lulzy bit re pwnholes is that they are a renewable resource: every major version of ~everything introduces a few dozen new ones.
mircea_popescu: no, but they ~obsoleted~ it. the trick is that in physical engineering you are allowed backsies.
mircea_popescu: o, you mean like they obsoleted the only remaining useful us plane without having as much as a proper paper replacement for it ?
asciilifeform: pretty sure that they earnestly see it like this.
asciilifeform: mircea_popescu: per the tards' internal logic -- 'we burned the vuln -- we own the tendrils'
mircea_popescu: perhaps it'll be stanford or mit or "another" meaningless head of the same turd of agglomerated stupidity though. for flavour.
mircea_popescu: in any event i am looking forward to the princeton paper providing the original research of "shit we read on #trilema that we came up with ourselves shut up terrorist!!1"
asciilifeform: mircea_popescu: you'll also love how it is done because... prngs sometimes PASS when you do this (how ? idk)
mircea_popescu: http://btcbase.org/log/2017-04-13#1642982 << such lulz that thing. really, looping over the entropy ? ☝︎
a111: Logged on 2017-04-13 16:56 asciilifeform: https://news.ycombinator.com/item?id=14105718 ( https://archive.is/nmX2h ) << witness the unsurprising chorus : 'nobody used it! NOBODY! shuddup terrorist'
mircea_popescu: http://btcbase.org/log/2017-04-13#1642960 <<< yeah, it's quite evidently usg burning one of their few remaining good exploits once they finally figured out it was leaked and used by republican interest. ☝︎
asciilifeform: ( also note, rarely is anyone interested in ALL possible branches in ALL of ram -- typically you want some particular set. )
asciilifeform: it's as reliable as the box it was slaved to, signalled when the bucked filled, to go and empty.
a111: Logged on 2017-04-13 16:11 trinque: crypto/bio/bss_dgram.c has several invocations with recvmsg
mircea_popescu: well so then what use it is ? as per alfism, not reliable, worse than useless!!1
mircea_popescu: which works for fixed length tree ? ookayt.
asciilifeform: (and to store whatever else that dun fit in the standard debug regs)
asciilifeform: mircea_popescu: iirc it worked by cordoning off a portion of l0/1 caches to use as trace record
mircea_popescu: it is a more difficult taks than immediately apparent.
mircea_popescu: yeah, that's not actually available. i doubt even intewl thing ever worked as advertised (which is the true explanation of the rarity)
Framedragger: mircea_popescu: asciilifeform: ty
mircea_popescu: you are running this in gdb yes ?
mircea_popescu: but basically ctrl-c bt will print out the whole strack, one line per frame. if that's what you wanted ?
mircea_popescu: or could do backtrace full n to limit to n frames.
mircea_popescu: ah i guess oh. turns out ~i~ was doing some creative reading.
Framedragger: mircea_popescu: function call history for c proggy? i prolly am doing sth horribly wrong, tho
asciilifeform: mircea_popescu: he wasn't trying for ordinary trace
asciilifeform: Framedragger: nope and nope, intel's thing only works with their shitware
Framedragger: asciilifeform: would gdb be able to run on it, tho? with `record btrace`? just curious
mircea_popescu: dude what are you talking about i/we use gdb all the time to trace
asciilifeform: so of 0 use, unless somebody gets hold of the magic proggy.
asciilifeform: lulzily enough, asciilifeform ~has the box~ -- but 0 software for it, it never leaked. box turned out to contain empty fpga.
Framedragger retires to pig farm
asciilifeform: other than with intel's magic probe box.
mircea_popescu: i would be authorized to give you a sandwich.
mircea_popescu: now if you were poor and "from a needy family" or however "two idiots had kids" is doublespoken today...
asciilifeform: mircea_popescu: asciilifeform can't possibly be the first to ever try to search inside a dir of tarballs. srsly, 0 support?!
Framedragger: (meanwhile gdb is "Target does not support branch tracing." (cpu doesn't support one way to do this; it's an i5; omg)
mircea_popescu: oh tar. doh.
asciilifeform: and of course it thinks 'single file', it's presently the only known way to grep in a tar.gz.
mircea_popescu: tar xvfz cmake-2.8.10.2.tar.gz --to-stdout | grep -H "MSG_PEEK" /dev/null > liquishit.txt
asciilifeform: mircea_popescu: it dun do any good for searching in tars.
mircea_popescu: nfi why it thinks deluge from pile is single file, but anyway.
mircea_popescu: http://btcbase.org/log/2017-04-13#1642916 << actually can coax grep to properly recognize "multifile" by adding a /dev/null at end ☝︎
mircea_popescu: how is this supporting "Sinus flushing" as opposed to, i dunno, "used to wash up pre anal sex" ? ☟︎
mircea_popescu: trinque that's accurate, actually. "shit improved by the radical communist branch of usg". a sort of "Bitcoin foundation" avant la lettre, "GNu the african antelope".
mircea_popescu: tremble, bitches, because you will end up floating on the fucking river. all of youze.
a111: Logged on 2016-07-10 01:40 mircea_popescu: http://btcbase.org/log/2016-07-10#1500575 << let me guess, this is really the washington-thinktank-gendarmerie plan getting rid of those pesky washington-local-thinktanks ? plan proceeding according to plan ?
a111: Logged on 2017-04-13 15:30 asciilifeform: in yet-other lulz, https://archive.is/mcaLO >> 'NEW YORK -- Sheila Abdus-Salaam, an associate judge on New York state's highest court and the first African-American woman to serve on that bench, was found dead Wednesday in the Hudson River, authorities said. ... became the first Muslim judge in the United States when she started serving on the state Supreme Court in 1994 ... On the court, Abdus-Salaam was among the most reliable and
mircea_popescu: http://btcbase.org/log/2017-04-13#1642888 <<->> http://btcbase.org/log/2016-07-10#1500604 in which vein, let me guess, this is because black, yes ? not because pantsuited, middle aged woman ? ☝︎☝︎
trinque: by now I assume the g prepended means "shit bolted to side"
asciilifeform had nfi that any awktron knew how to open sockets.
ben_vulpes: did we ever do the "brain parasite from flushing sinuses with not-entirely-clean-water" thread?
ben_vulpes: mircea_popescu: it is a thing ben_vulpes is baseline familiar with, believe it or not!
asciilifeform: mircea_popescu: not on running disk, they live on cd somewhere
mircea_popescu: ben_vulpes they're not plumbing lines. there is such a thing as brain-blood barrier.
mircea_popescu: do you not have the rest of the 3.* tree asciilifeform ?
ben_vulpes: length of plumbing lines from gums and nasal membranes to brain ispretty short
mircea_popescu: and then every gcc subsequent.
mircea_popescu: ben_vulpes nothing's "wired directly to brain" wtf are you on about.
a111: Logged on 2017-04-12 21:58 danielpbarron: http://btcbase.org/log/2017-04-12#1642660 << i don't use mouthwash, brush and floss once a day (with regular non vibrating brush, and i reuse the floss untill it splits apart or breaks) -- hadn't been to the dentist in over 8 years; went in last year and they tell me my teeth are in great shape considering, although i did have to get some cavities fixed (mostly in wisdom teeth which is expected. and yes i still have my wisdom teeth
ben_vulpes: http://btcbase.org/log/2017-04-12#1642721 << you mean to tell me that you're culturing some weird population on your floss and then rubbing that all over delicate, highly permeable mucous membranes wired directly to your brain? ☝︎
Framedragger: i'm hangover af after $party, everything is black currently (doesn't happen often, tbh)
mircea_popescu: who knows these things.
Framedragger: only to an extent, and as BingoBoingo said, circulation. tide goes in, tide goes out
mircea_popescu: is that so ? hm.
Framedragger: "custom shitty udp program" probably fits the bill
a111: Logged on 2017-04-13 13:52 Framedragger: i'll grant you that i'm this overly naive kid as regards these matters. but i fear the psychological alternative :) (becoming an angry man full of bile; principle of charity has a psychological function to me, too). and eh, 'empire'. very binary
Framedragger: huh gdb's `bt` is not giving me backtrace. i put a breakpoint on recvfrom(), it got called and everything, and `bt` gives me squat. compiled with debug symbols. go back to school framedragger
mircea_popescu run highschool would have pillory for inept mothers, with topless zebra'd milfs there present almost every day.
a111: Logged on 2017-04-13 13:36 asciilifeform: also for some reason silence re authorship of the overflow..
mircea_popescu: http://btcbase.org/log/2017-04-13#1642845 << that is misunderstood esprit de corps. it's visible when child does something stupid, gets punished for it, and mother shows up at school to protest ~the punishment~. the fact her son does stupid shit does not bother her -- on the contrary, she knows where he got that from, which knowledge fills her of joy and hope for the future. perhaps if she insists the dumb will inherit the ea ☝︎
Framedragger: asciilifeform: btw udp_recvmsg() is the kernel-internal function which is vulnerable. need to check callstack of recvfrom() vs recv(), possibly only recvfrom() is vulnerable (thereby reducing set of exposed programs greatly). otherwise even more funtimes. ☟︎
asciilifeform: mircea_popescu: see continuation of thread
a111: Logged on 2017-04-13 13:33 asciilifeform: could say the truth, in theory, 'only used in socat, inserted by wrecker'
mircea_popescu: http://btcbase.org/log/2017-04-13#1642842 << they misperceive the cost of not saying so ; as well as the cost of saying so. why's girl in highschool not say "i hate these dumbass girls who claim they're my friends and absolutely like you" ? because human nature. ☝︎
Framedragger: (it's possible that bug isn't triggered if you only recv(), not recvfrom(), but i didn't look into it to confirm)
Framedragger: asciilifeform: ah, only glibc etc if "recvfrom" in keywords, you're right. but if only "recv" (https://codesearch.debian.net/search?q=recv+.*+MSG_PEEK&page=1), then lots of results