Member of the EVE Tweet Fleet
Dec 31

Electronic Arts, Nintendo and Sony Still Support SOPA

By Xeross Posted in News, Tech Leave a Comment

Various “news” sites have reported that EA, Nintendo and Sony have dropped their SOPA support, though they’ve never published a press release about it and they weren’t even on the official list of SOPA supporters, Techdirt explains what caused this error.

So they don’t support SOPA? No, they do support it, as they’re all members of the ESA (Entertainment Software Association) which supports SOPA as can be seen in the official list of supporters (Mirror).

If you want to check whether a tech company is supporting SOPA don’t forget to look at the list of members of the ESA and the BSA (Business Software Alliance) who also support SOPA.

Tagged with:
Dec 29

Hash Algorithm Collision Denial-of-Service Vulnerability, Large Number of Websites Vulnerable

By Xeross Posted in News, Security/Hacking, Tech Leave a Comment

A security advisory was released yesterday detailing a denial-of-service vulnerability that most of the web could be affected by.

The vulnerability lies in the hashing algorithms used by a variety of programming languages (including Python, Ruby, PHP and Java). When collisions happens these algorithms will take up large amounts of CPU cycles to deal with them (From what I understand).

To give you an idea of the extent of this problem I’ll quote the PDF linked in the advisory, take for example PHP:

On an i7 core, the 60 seconds take a string of multi-collisions of about 500k. 30 seconds of CPU time can be generated using a string of about 300k. This means that an attacker needs about 70-100kbit/s to keep one i7 core constantly busy. An attacker with a Gigabit connection can keep about 10.000 i7 cores busy.

Or Ruby:

A typical POST size limit in Ruby frameworks is 2 MB, which takes about 6 hours of i7 CPU time to parse. Thus, an attacker with a single 850 bits/s line can keep one i7 core busy. The other way around, an attacker  with a Gigabit connection can keep about 1.000.000 (one million!) i7 cores busy.

This allows someone to take down almost any webserver with (very) limited resources. Possible workarounds are: limiting CPU time, limiting the POST size, or limiting the maximum amount of POST variables.

I’m currently waiting for the first PoCs and exploits to be published and will post an update when I get my hands on one (Which will also confirm if I understand the exploit correctly).

Update: I can see how this will ruin your day

Update 2: Go here for an easy to understand explanation.

Tagged with:
Dec 25

50,000+ Domains Transferred Away From GoDaddy Due To SOPA support

By Xeross Posted in News, Tech Leave a Comment

GoDaddy has seen a massive amount of domains being transferred away from them as customers are moving elsewhere because of their support for SOPA. Among the companies transferring are Wikipedia and the Cheezburger Network (Who own over 1000 domains). It all took off when a GoDaddy boycott was started on Reddit. Various other domain registrars are even offering discount codes for anyone transferring to them.

Just today (The 25th of December) the counter is standing on 28,656 domains transferred out as seen on DailyChanges, and the amount just keeps climbing, day after day more and more domains are being transferred away.

GoDaddy has now retracted their public support for SOPA but the damage has been done, not to forget that they helped write SOPA, not just support it. I have no idea how long this will keep going and how many people will move away but it’s gonna hurt (It’s already hurting actually). GoDaddy is even begging for people to stay.

I’m sure more companies will face the wrath of the public because of their SOPA support, and various companies are already retracting their support for it, some companies never even explicitly supported SOPA “they agreed with Floyd Abrams’ analysis of SOPA. That’s it. They didn’t say their firms supported SOPA”.

Tagged with:
Dec 24

Stratfor Rooted

By Xeross Posted in Anon/Etc., Security/Hacking, Tech Leave a Comment

Merry #LulzXmas to everyone http://imagebin.org/190224 Stratfor rooted. All your base are belong to us. <3 #Anonymous

This tweet just went out from the @AnonymousIRC Twitter account (First occurance of the tweet I could find), a mirror of the defacement can be found on Zone-H. The Stratfor website is down as I write this.

Stratfor is a large private intelligence corporation having fortune 500 companies and international intelligence agencies as their clients (source). A full list of clients can be found here.

Edit: there’s also this:

Over 90,000 Credit cards from LEA, journalists, intelligence community and whitehats leaked and used for over a million dollars in donations

- By @AnonymouSabu

So one million dollars from compromised credit cards, from what I can understand of later tweets they only used corp execs credit cards, who wont feel it that hard in their pockets, but not sure if I’m very fond of this action.

The Video Posted

Tagged with:
Dec 23

Op9GAG: Initial Battle Report

By Xeross Posted in Anon/Etc. Comments (4)

I myself was unfortunately late to the party for the initial battle, this due to it starting at 6AM in the morning and me having to work, but here’s what I’ve been able to gather.

HOIC (High Orbit Ion Cannon) attacks were started on the main site but proved to be unsuccessful, after a while SlowLoris was suggested which was used on the 9GAG store with success, taking it down for an hour.

Joining and voting were turned off shortly after the attack started, so we lost that method of attack.

Note that this was only the initial strike, plans are being forged and executed as we speak, this isn’t a one-shot operation, this is an extended campaign.

Join us on irc://irc.anonops.li/op9gag

Update: The 9GAG store has been taken offline completely, the link is removed from the website and its URL apparently also redirects to their main website.

Tagged with:
Dec 22

WTF is SOPA? (SOPA Explained)

By Xeross Posted in Tech Leave a Comment

TotalBiscuit explaining SOPA in an easy to understand way, big thanks to him for making this.

Tagged with:
Dec 20

Useful Skyrim Mods

By Xeross Posted in Gaming Comments (4)

A list of the Skyrim mods I am currently using, I will periodically update this as mods get added/removed.

Balancing/Tweaks

Faster Horses Makes the horses sprint faster by either 1.5x or 2x. For if the default sprint speed feels too slow.
Essential Horses Make horses essential, so they don’t die when they needlessly rush in to help you in a fight.
Damaging Bolts Doubles damage for Incinerate, Thunderbolt, and Icy Spear.
Improved Magics – Sauron Edition Dual cast tweaks/rebalancing, increased damage, decreased magicka cost.
Recharge Chance on Kill (Not sure if this is actually what it does) Recharges enchanted weapons on kill? I still need to figure out what it does
Longer Duration for Spells

Make certain spells last longer. Light that doesn’t turn off after 30 seconds \o/

Perk Points Requirements: Skyrim Script ExtenderTweakable amount of perk points per level, I have it set to 2 so that leveling feels more rewarding.
Longer Sprinting Reduces the stamina cost of sprinting.
Killable Children Finally you can kill the little fuckers that keep making insulting comments towards you.
Richer Merchants Merchants have more money, so less 48-hour waits when you need to dump large amounts of stuff.

Crafting/Related

More Enchants/Item Allows up to 4 enchantments on an item (Replaces the dual enchantment perk)
Lost Art of the Blacksmith Lots and lots of things now craftable.
Craftable Staves Allows you to craft a variety of staves
More Craftables More craftable stuff.
Val’s Crafting Meltdown Alpha Make it possible to smelt armour, weapons and miscellaneous back to base materials (bars, etc.)
I Put a Spell On You Allow all armour enchantments on all armour pieces, same goes for weapons (If that’s even applicable).

Graphics

Better Beast Races / No More Blocky Faces Fixes the blockiness of the faces caused by the compression that Bethesda applied on the normal maps.
Deadly Spell Impacts Custom (in my opinion better) spell impacts, including a unique impact for lightning spells (Normally they have the same texture as fire spells).
Glowing Ore Veins Makes ore veins more noticeable by making them shine/glow, convenient if you don’t want to meticulously search caves for ore veins.
Realistic Ragdoll Death Force Tweaks the ragdolls to behave more realistically, now you won’t have to chase after a corps because your firebolt propelled it away.

Other

Breezehome Enchanting Table The only thing that was missing in Breezehome.
Container Categorization Requirements: Skyrim Script ExtenderAdds categories to containers, like your inventory has.
QD Inventory Custom UI for inventory optimized for PC gaming.
SkyUI Alternative option to QD Inventory, aims to eventually be a complete UI overhaul/redo
No NPC Greetings NPC greetings don’t trigger at all, or only from a reduced distance.

Update (2012-08-07): Fixed link for More Enchants/Item

Tagged with:
Dec 20

Response to BR1CKSQU4D Dox

By Xeross Posted in Anon/Etc. Comments (1)

Apparently I have become an interesting enough target to be doxed, by some guys calling themselves BR1CKSQU4D, as seen below:

------
Xeross
------
Dox:
    Name: Justin Brunk
    Born: December 2nd 1992
    Location: Noord-Brabant, Netherlands
    E-Mail: trutherton@wehaslinks.com

Computer:
    IP: 94.210.96.100 (5ED26064.cm-7-3b.dynamic.ziggo.nl)
    OS: Fedora

Profiles:

http://twitter.com/Xeross


http://twitpic.com/photos/Xeross


http://stackoverflow.com/users/327687/xeross


http://www.youtube.com/user/Xeross


http://steamcommunity.com/id/xeross155

Sites:

http://theelitist.net/

Notes:
    Gay furry programmer (literally) that wears Guy Fawkes masks to parties
    Still plays pokemon on gameboy
    Writes WoW fanfiction ( http://theelitist.net/the-battle-for-undercity )
    Dox confirmed by reddit, website

- Source

This was posted quite a while ago (1-2 months I think), but I didn’t have the time to write a response.

Now they’ve been moderately accurate, but I can’t help but feel for the poor sod(s) whose name/email address was used in this document. The name Justin Brunk was obtained from the YouTube account Xeross which as you might’ve guessed isn’t me, I’ll help them along a bit by pointing to my Youtube Account.

Next up, the email address I have no idea where they got that from, perhaps they wanted to bother whomever is managing WeHasLinks.com. Also interesting is that they deem Reddit a reliable source for dox.

The last discrepancy there is to point out is that I supposedly wear Guy Fawkes masks to parties, I don’t, the photos they’re talking about were of some guys we ran across at Reverze  2011 who indeed did wear Guy Fawkes masks.

Anyway, thanks for the laugh BR1CKSQU4D, try harder next time ;)

~Xeross the gay furry programmer

Tagged with:
Dec 20

Operation: 9GAG

By Xeross Posted in Anon/Etc. Comments (2)

irc://irc.anonops.li/op9gag

Expect Us

Tagged with:
Dec 16

Displaying the configured 403 error in Symfony 1.4

By Xeross Posted in Developing, How-To's, Tech Comments (1)

Today I had to figure out how to trigger a 403 error and display the appropriate error page. I wanted to use the configured 403 page that the authentication system displays on failure. So after a bit of digging I found that to display this page you call the following (From the controller):

$this->forward(sfConfig::get('sf_secure_module'), sfConfig::get('sf_secure_action'));

To set the HTTP status code to 403 you would use (Again from the controller):

$this->getContext()->getResponse()->setStatusCode(403);

This should give you a 403 response with the configured permission/access denied page.

Note: I haven’t worked with Symfony a lot so there might be a better way, yet I haven’t been able to found one, if there’s a better way, let me know in the comments!

Tagged with: