/srv/irclogs.ubuntu.com/2017/05/12/#ubuntu-uk.txt

brobostigonmorning boys and girls.05:49
SuperMattmorning06:38
brobostigonmorning06:39
MooDoohowdy all07:23
SuperMattG'ning07:24
foobarryhttp://imgur.com/a/SYs5z what just happened?07:49
foobarrymy email on a spam list overnight?07:49
popeyfoobarry: there's a setting in hangouts which disables unsolicited chat07:55
popeyalso, I have noticed a large uptick in comment spam on G+ this week, maybe related07:56
foobarrystrange that i never needed it before07:57
foobarrybut i got a mail from haveibeenpwned this week07:58
foobarryIn late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the acco07:58
foobarryunt owner had reused their password07:58
czajkowskiAloha11:03
BigRedSAh, goood morning!11:12
=== alan_g is now known as alan_g|lunch
=== alan_g|lunch is now known as alan_g
diplocorebird 1.4.2 from 'diddledan' installed13:15
diploIs that this diddledan ?13:15
* diddledan scurries for cover13:15
diplohah13:16
diploDoesn't work for me, loads if I run from terminal, no desktop icon ( tried logging on and off ) but Request ping/create account doesn't do anything currently. Do I need to reboot for this sort of thing ?13:20
diploThe name com.canonical.SafeLauncher was not provided by any .service files13:21
diddledanthe request pin button won't work unless you have snapd-xdg-open installed on your host system13:21
diddledanthis is a known issue that the snappy devs STILL haven't fixed months after it was reported13:22
diplota fanx, installing now13:22
diddledanit seems the plan is to move the functionality of that apt package into snapd itself13:22
diploJust went on snapcraft but thought I'd prod you too13:23
diploWorks better now13:23
diddledanas to the desktop icon, it seems somewhat flaky - sometimes I get it to install the icon other times I don't13:24
diploWorks ta, will write my own I guess..13:24
diddledanI don't know if I'm packaging the snap wrong, or if it's a snapd issue13:24
* diplo will try and remember where .desktop files go13:24
diddledanfor your own sessions only, not system wide, .desktop files can go in ~/.local/share/applications/13:25
diplota13:26
diddledanthe systemwide path is /usr/share/applications13:27
diddledanor at a pinch I think /usr/local/share/applications will work, too13:27
diddledanmy Winsider is busted13:35
diploCheers, guessing I'll need to logout for it to be available13:35
diddledansomehow Windows' drivers for NVidia believe my discrete GTX960 card is actually in a laptop (it's in a desktop) running in Optimus mode13:36
diddledanwait, is Trumpet saying he's copying Nixon's usage of recording devices? https://twitter.com/sarahjeong/status/86302719237196185613:45
diploI've set /ignore to most things trump14:14
diploBut I do follow sarah14:14
diddledanhttp://www.bbc.co.uk/news/health-3989964614:37
diploBeen following that on twitter, knew it wouldn't be long14:46
diploAlways wondered why they had external access on the machines they keep our records on14:46
diddledan"Trusts and hospitals in London, Blackburn, Nottingham, Cumbria and Hertfordshire have been affected."14:47
diddledanyeah, seems a bit wonky to allow remote access to their systems14:47
diddledanto/from14:47
diddledanif they need the internet then they should use a different PC14:47
diploYup or a tablet or something, whilst I've been at the docs they've googled before :P14:49
diddledanwhen someone says "80% chance of <x> happening" do they mean that in terms of 50% means equal chance of happening as that of not happening, and 0% chance meaning definitely won't happen?14:49
diddledandiplo: I hope they weren't googling your symptoms :-p14:50
diploWell drugs for my symptoms14:50
Laneyoh goddddddddd it's finally raininggggggggggggg15:39
Laneythe allotment is like ":)))))))))))))))))))))))))))))))"15:40
diddledanblind man coding is epic: https://channel9.msdn.com/16:05
m0nkey_You can have our rain.16:50
m0nkey_We've even had a bit of a flood.16:50
zmoylan-pibut we'll never take your jaffa cakes? :-P16:50
m0nkey_No Jaffa cakes :-(16:50
diddledansaid by an australian in an american film about scotland made in canada16:51
zmoylan-pi... no jaffa cakes... what hell have we sunk too...16:51
diddledanok, maybe not made in canada. I donno about that bit16:51
zmoylan-pialso made in ireland16:51
diddledanok, so lets celebrate scotland, by making a film in ireland for an american audience with an australian actor16:52
diddledantotally makes sense16:53
zmoylan-pithe irish army supplied the extras iirc16:53
diddledanwell them lot would probably like to give the scots a good hiding16:54
diddledanever since the giants' causeway incident16:54
diddledanthat scottish giant was a big meanie!16:54
zmoylan-piwell the battle went well and created the isle of man...16:55
diddledanthe land of the three legged folk16:56
zmoylan-piand tailess cats16:58
=== alan_g is now known as alan_g|EOW
ali1234does anyone else think this nhs cyber attack is really fishy?17:30
popeytriggered by someone who wants to show the NHS are failing, rather than some random russian dude?17:31
ali1234i'm not going to speculate about motive17:32
ali1234but it seems odd that all the computers in a national organization would get infected at exactly the same time17:32
ali1234i mean do they have a shared network drive accessible by all the millions of computers in the country?17:33
ali1234okay not millions, more like 50,000 probably17:38
MartijnVdSali1234: Telefonica is also hit -- there are rumours there's some kind of "port 445" based worm going around17:40
MartijnVdSquoting my ISP friends/ex-coworkers here17:40
popeyi dont think they all are infected17:40
ali1234port 445 as in samba?17:40
popeyquite a lot I imagine17:40
popeyand precautionary take them all offline17:40
popeyso no more get infected17:40
MartijnVdSali1234: port 445 as in SMB over IP17:40
ali1234i doubt they have the ability to take all systems offline remotely17:41
ali1234given the way the NHS is structured, and the fact they only centralized the records what, 4 years ago?17:42
ali1234oh, apparently they scrapped it anyway17:43
ali1234so are these systems even connected together at all?17:43
MartijnVdSali1234: check out this: https://twitter.com/search?q=445&src=typd17:45
MartijnVdSpeople are claiming it's a MS17-010 based thing17:45
ali1234is that the thing that was in the news yesterday/this morning?17:45
MartijnVdSwell it's from march, but it's a RCE (system privs, basically "root") in the service that handles port 44517:46
diddledanthere is also the bug that MS patched on Tuesday in Windows Defender17:49
ali1234ah yes thats the one i was thinking about17:49
ali1234isn't that email related?17:50
ali1234and you know how bigs orgs like to CC all...17:50
diddledanthe one that Tavis Ormandy alerted them to - basically anything that can get a file into the realtime scanner (so an email arriving in your mail client counts, even if you don't read it) can exploit it17:51
diddledanyou may find even email that gets into your spam box will get scanned17:51
diddledanjust downloading a file in your browser will probably be a vector, again even if you never open it17:52
ali1234people downloading wouldn't hit a nationwide org in a matter of hours though17:52
diddledantrue17:53
ali1234an email sent to everyone could though17:53
MartijnVdSali1234: it would if it was an image embedded on some website they all use17:53
diddledanit does seem somewhat fishy that so many systems went down together17:53
diddledanpoint, MartijnVdS !17:53
MartijnVdS(some ad even maybe)17:54
diddledaniiiiiits FRIDAY PIZZA time17:54
popeyI've worked at placed where pretty much the entire company was nuked in one day18:06
diddledanpopey: you did a good hack there18:06
popeyi was the only one who could carry on working because i had a debian laptop18:06
popeyeveryone else was on windows18:07
popeythey went and played golf, i was sat there still working :S18:07
popeynot sure who won there :)18:07
diddledanwas it your responsibility to clean up the mess?18:07
popeyno18:08
diddledanphew18:08
popeyi think it was sasser or blaster or something18:08
diddledanaah yeah they were nasty beasts18:08
diddledanI tried reading the code of melissa way back in time18:09
foobarryi'm betting its not a zero day and failure to patch systems effectively18:57
foobarryi recently watched a programme about stuxnet that was amazing18:58
foobarrydid anyone see it?18:58
diddledanapparently the hospital ransomware attack used a CIA tool (released under the vault7 dump)20:05
diddledanhttps://twitter.com/wikileaks/status/86312267782073139320:05
diddledanoh I misread20:05
diddledanNSA tools, not the Vault7 tools20:05
diddledanhttps://arstechnica.com/security/2017/05/an-nsa-derived-ransomware-worm-is-shutting-down-computers-worldwide/20:05
diddledanalso on the intercept: https://theintercept.com/2017/05/12/the-nsas-lost-digital-weapon-is-helping-hijack-computers-around-the-world/20:06
=== Seeker` is now known as Seeker
=== Seeker is now known as Seeker`
ali1234any reliable evidence of that?20:24
ali1234this sure is a huge mess20:26
foobarryhttp://www.cnbc.com/2017/05/12/samsung-galaxy-s8-dex-station-review.html20:27
foobarry"I tried using the latest Samsung smartphone to replace my work computer — now I'm convinced it's the future"20:27
foobarrysome sites are saying its eternalblue.20:28
ali1234yeah but are they basing it on anything more than "because wikileaks said so"20:29
foobarryhttps://www.theregister.co.uk/2017/05/12/spain_ransomware_outbreak/20:30
ali1234"It's understood"20:30
ali1234fake news heh20:30
foobarrydoesn't all quite add up yet20:31
foobarryvariant not detected by antimalware tools?20:31
foobarrypatched or unpatched systems? in NHS maybe unpatchable20:32
ali1234just as likely the attackers made their own exploit for a know bug20:32
BassettsCan someone tell me if I am being dumb here. I have rsnapshot backing up my laptop to my media server. df -h --total reports 6.3G used on the laptop and 230G free. du -h -d 1 tells me the backup folder is at 24G and the backup is still running?!21:49
zmoylan-pii thought the nhs has speant a large sum of money to keep getting patches for the winxp systems?21:56
diddledanthey did22:03
diddledandoesn't mean they're doing anything with them though22:04
zmoylan-piwell that's money well spent then...22:04
diddledanlike installing them or something22:04
zmoylan-piat least we'll see how bad their backup system is out of this...22:08
diddledanaye22:14
daftykins:D22:23
daftykinsgood to know22:23

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!