https://www.wired.com/story/plant-spy-chips-hardware-supermicro-cheap-proof…
U tih $200 je uračunata i lemilica od $150 i mikroskop od $40. Za čip kaže da je platio $2. :) Ne znam koliko košta Cisco ASA 5505 firewall koji je hakovao. Ispade da je jeftinije hakovati ozbiljan fajervol nego napraviti kontroler za bojler. ;)
Za ponedeljak.
Pozdrav,
On Oct 12, 2019, 16:09, at 16:09, nebojsa.raskovic(a)unitedcommunications.rs wrote:
>Pozdrav Ksenija,
>
>
>možeš li ovo da okačiš u ponedeljak?
>
>
>S poštovanjem,
>
>Nebojša Rašković
Jesmo li pisali o ovome? Dobih malopre SMS:
Zelimo da Vas obavestimo da je Telenor banka, 10. oktobra 2019, promenila
poslovno ime u Mobi Banka ad Beograd. Vasi brojevi racuna, platne kartice i
svi drugi proizvodi i usluge koje koristite ostaju nepromenjeni. Novi nazivi
mobilne i veb aplikacije banke bice Mobi Banka. Uskoro mozete ocekivati da
ce biti potrebno da azurirate Vasu mobilnu aplikaciju. I dalje nas mozete
pronaci u svim Telenor prodavnicama. Za detaljne informacije posetite nas na
www.mobibanka.rs <http://www.mobibanka.rs> .
Pre par godina je na nekom backup-u nađen stari etc/password fajl iz prve verzije BSD 3 Unix-a, i tu su lozinke ljudi koji su ga pravili, između ostalih i velikih imena kao što su Brian W. Kernighan, Dennis Ritchie, Ken Thompson, Bill Joy (osnivač SUN-a), Steve Bourne (tvorac bourne shell-a)...
I od tad razni hakeri pokušavaju da grubom silom nađu koje su password-e dotični koristili. Danas je "pao" Ken Thompson, čiji je password bio p/q2-q4! što je u nekoj opskurnoj šahovskoj notaciji oznaka za "kraljičin pion dva polja unapred", što bismo mi rekli d2d4, uvod u damin gambit i neka druga otvaranja... Što ima logike jer se Thompson bavio i šahovskim programima.
Evo svih password-a, za sada se još "drži" Bill Joy čija lozinka nije provaljena.
root:OVCPatZ8RFmFY:Ernie Co-vax --> cowperso
daemon:*:The devil himself --> (login not allowed)
bill:.2xvLVqGHJm8M:Bill Joy --> (password still unknown)
ozalp:m5syt3.lB5LAE:Ozalp Babaoglu --> 12ucdort
sklower:8PYh/dUBQT9Ss:Keith Sklower --> theik!!!
kridle:4BkcEieEtjWXI:Bob Kridle --> jilland1
kurt:olqH1vDqH38aw:Kurt Shoens --> sacristy
schmidt:FH83PFo4z55cU:Eric Schmidt --> wendy!!!
hpk:9ycwM8mmmcp4Q:Howard Katseff --> graduat;
tbl:cBWEbG59spEmM:Tom London --> ..pnn521
jfr:X.ZNnZrciWauE:John Reiser --> 5%ghj
mark:Pb1AmSpsVPG0Y:Mark Horton --> uio
dmr:gfVwhuAMF0Trw:Dennis Ritchie --> dmac
ken:ZghOT0eRm4U9s:Ken Thompson --> p/q2-q4!
sif:IIVxQSvq1V9R2:Stuart Feldman --> axolotl
scj:IL2bmGECQJgbk:Steve Johnson --> pdq;dq
pjw:N33.MCNcTh5Qw:Peter J. Weinberger --> uucpuucp
bwk:ymVglQZjbWYDE:Brian W. Kernighan --> /.,/.,
uucp:P0CHBwE/mB51k:UNIX-to-UNIX Copy --> whatnot
srb:c8UdIntIZCUIA:Steve Bourne --> bourne
finger::The Finger Program --> (no pw but runs a program, not a login shell)
who::The Who Program --> (no password but runs a program, not a login shell)
w::The W Program --> (no password but runs a program, not a login shell)
mckusick:AAZk9Aj5/Ue0E:Kirk McKusick --> foobar
peter:Nc3IkFJyW2u7E:Peter Kessler -- ...hello
henry:lj1vXnxTAPnDc:Robert Henry --> sn74193n
jkf:9ULn5cWTc0b9E:John Foderaro --> sherril.
fateman:E9i8fWghn1p/I:Richard Fateman --> apr1744
fabry:d9B17PTU2RTlM:Bob Fabry --> 561cml..
network:9EZLtSYjeEABE:(no name listed) --> network (runs a program, not a login shell)
tty:: --> (no password but runs a program, not a login shell)
Najgori od sve dece :) je Steve Bourne koji je za lozinku izabrao... bourne. Nije mnogo bolji ni Brian Kernighan koji je koristio /.,/., radi lakšeg kucanja. Ili Dennis Ritchie, koji je stavio dmac. Neki su koristili datum rođenja (Fateman), imena žena/devojaka (jilland1, wendy!!!, sherril.), neku običnu reč tipa whatnot, foobar, hello)... Od boljih pokušaja, Robert Henry je koristi sn74193n što je binarni counter na 7400 familiji čipova, Stuart Feldman je stavio axolotl što je nekakva meksička amfibija koju zovu "hodajuća riba", a Ozalp Babaoglu - ko god da je to, ali očito Turčin - je koristio 12ucdort što je 1, 2, 3, 4 na turskom jeziku :)
Pa sad vi vidite koji password koristite, možda će - kad postanete slavni - kroz 50 godina neko naći backup vašeg kompjutera pa tadašnjim daleko bržim mašinama krekovati vaš hash...
Pozdrav, Dejan
https://leahneukirchen.org/blog/archive/2019/10/ken-thompson-s-unix-passwor…
09oct2019 · Ken Thompson's Unix password
Somewhere around 2014 I found an <https://github.com/dspinellis/unix-history-repo/blob/BSD-3-Snapshot-Develop…> /etc/passwd file in some dumps of the BSD 3 source tree, containing passwords of all the old timers such as Dennis Ritchie, Ken Thompson, Brian W. Kernighan, Steve Bourne and Bill Joy.
Since the DES-based <https://minnie.tuhs.org/cgi-bin/utree.pl?file=V7/usr/man/man3/crypt.3> crypt(3) algorithm used for these hashes is well known to be weak (and limited to at most 8 characters), I thought it would be an easy target to just crack these passwords for fun.
Well known tools for this are <https://www.openwall.com/john/> john and <https://hashcat.net/wiki/> hashcat.
Quickly, I had cracked a fair deal of these passwords, many of which were very weak. (Curiously, bwk used /.,/.,, which is easy to type on a QWERTY keyboard.)
However, kens password eluded my cracking endeavor. Even an exhaustive search over all lower-case letters and digits took several days (back in 2014) and yielded no result. Since the algorithm was developed by Ken Thompson and Robert Morris, I wondered what’s up there. I also realized, that, compared to other password hashing schemes (such as NTLM), crypt(3) turns out to be quite a bit slower to crack (and perhaps was also less optimized).
Did he really use uppercase letters or even special chars? (A 7-bit exhaustive search would still take over 2 years on a modern GPU.)
The topic <https://inbox.vuxu.org/tuhs/tqkjt9nn7p9zgkk9cm9d@localhost/T/#m160f0016894e…> came up again earlier this month on <https://www.tuhs.org/> The Unix Heritage Society mailing list, and I <https://inbox.vuxu.org/tuhs/87bluxpqy0.fsf@vuxu.org/> shared my results and frustration of not being able to break kens password.
Finally, today this secret <https://inbox.vuxu.org/tuhs/CACCFpdx_6oeyNkgH_5jgfxbxWbZ6VtOXQNKOsonHPF2=74…> was resolved by Nigel Williams:
From: Nigel Williams <nw(a)retrocomputingtasmania.com <mailto:nw@retrocomputingtasmania.com> >
Subject: Re: [TUHS] Recovered /etc/passwd files
ken is done:
ZghOT0eRm4U9s:p/q2-q4!
took 4+ days on an AMD Radeon Vega64 running hashcat at about 930MH/s
during that time (those familiar know the hash-rate fluctuates and
slows down towards the end).
This is a chess move in <https://en.wikipedia.org/wiki/Descriptive_notation> descriptive notation, and the beginning of <https://en.wikibooks.org/wiki/Chess_Opening_Theory/1._d4> many common openings. It fits very well to Ken Thompson’s <https://www.chessprogramming.org/index.php?title=Ken_Thompson> background in computer chess.
I’m very happy that this mystery has been solved now and I’m pleased of the answer.
[Update 16:29: fix comment on chess.]
NP: Mel Stone—By Now
Sent from my iPad 2018
Ja bih objavila nešto o ovome, Forbsova lista nije šala.
Šta misle urednici?
Vesna Čarknajev
CEO
PC Press | Osmana Đikića 4 | 11000 Beograd | Srbija
Tel: +381 11 2765-533 | Mob: +381 63 234-801
E-mail: vesna(a)pcpress.rs <mailto:vesna@pcpress.rs>
From: CarGo [mailto:no-reply@appcargo.com]
Sent: Tuesday, October 8, 2019 12:33 PM
To: vesna(a)pcpress.rs
Subject: Dostignuća do kojih smo došli zahvaljujući tebi
Hvala na podršci i poverenju!
<https://marketing-image-production.s3.amazonaws.com/uploads/90bf396104cda11…>
Šta smo sve postigli uz tvoju podršku u proteklom periodu
CarGo uvršten na Forbsovu listu top 10 najinovativnijih kompanija na svetu koje menjaju industriju iz korena
Sa ponosom možemo da kažemo da smo u ovoj godini uvršteni u top 10 najinovativnijih kompanija koje menjaju industriju iz korena po čuvenom magazinu Forbes.
Više na linku - CarGo Forbes
<https://marketing-image-production.s3.amazonaws.com/uploads/86d6c1a8473ba5f…>
Donacija muzičkog festivala klasične muzike ''Leteći muzički ključevi''
🎼🎻
Prepoznali smo značaj saradnje između Srbije i Nemačke, ali i razvoja kulture u Srbiji, te smo zato rešili da podržimo ovaj sjajan festival klasične muzike. Ovo je prvi, ali svakako ne i poslednji angažman udruženja u oblasti kulture.
<https://marketing-image-production.s3.amazonaws.com/uploads/d967c4b3c692288…>
CarGo ponudio rešenje umesto protesta: Osnovati novo udruženje za poštene taksiste
CarGo je ponudio poštenim taksistima da se učlane u novo Udruženje čime će biti oslobođeni harača taksi donova, gde će im biti zagarantovana neto zarada od 150.000 dinara, kao i pomoć u izmirivanju poreskog duga, kupovini novih automobila, najsavremenije plaćanje usluge i pomoć oko vođenja knjiga.
Više o ponudi za sve poštene taksiste na sledećem linku
<https://marketing-image-production.s3.amazonaws.com/uploads/c058342523dd48b…>
CarGo za izgradnju roditeljske kuće
💚🏡
Udruženje CarGo je doniralo milion dinara za izgradnju roditeljske kuće u Beogradu.
Zaposleni u kompaniji CarGo Technologies pridružili su se finalnom „Maršu solidarnosti” u Beogradu, kojim je uspešno završena šetnja Tamare i Bogdana iz Udruženja NURDOR.
<https://marketing-image-production.s3.amazonaws.com/uploads/cf527678aa865c4…>
CarGo osniva Fondaciju: Od svake CarGo usluge novac u humanitarne svrhe
Aleksandar Vučić, predsednik udruženja „CarGo“, najavio je osnivanje CarGo humanitarne fondacije koja će nastaviti da pomaže svim ljudima koji se obrate za pomoć, a finansiraće se tako što će kompanija CarGo Technologies od svake pružene usluge deo novca direktno uplaćivati na račun Fondacije.
<https://marketing-image-production.s3.amazonaws.com/uploads/362de8a50487ffb…>
CarGo kupio elektromotorna kolica Radovanu Samardžiću, donirao odlazak u banju kao i obezbedio posao
<https://marketing-image-production.s3.amazonaws.com/uploads/7f438bd5d64ab3a…>
<https://marketing-image-production.s3.amazonaws.com/uploads/d8f39d7f0350304…>
Iguman Hilandara posetio CarGo: Hvala za pomoć „kampu prijateljstva” i humanitarne akcije
Iguman manastira Hilandar arhimandrit Metodije posetio sedište Udruženja građana „CarGo” i tom prilikom u znak zahvalnosti za pruženu podršku „Kampu prijateljstva” uručio je „Hilandarsku spomenicu” i kopiju ikone Bogorodice Trojeručice sa posebnim pečatom Hilandara.
Više na linku - Iguman posetio CarGo
<https://marketing-image-production.s3.amazonaws.com/uploads/2f8039285be16cb…>
Otvoreno pismo Aleksandra Vučića, predsednika Udruženja „CarGo“: CarGo odgovor na protest taksista
U ponedeljak 30.09 predsednik Udruženja građana CarGo Aleksandar Vučić se obratio javnosti povodom protesta taksista.
Celo otvoreno pismo na sledećem linku - Otvoreno pismo Aleksandra Vučića
CarGo završio prvi investicioni ciklus u vrednosti od dva miliona evra kupovinom 50 novih Tojota
U proteklom mesecu sa ponosom smo zatvorili prvi investicioni ciklus kupovinom 50 novih Toyota čime smo ponudili još kvalitetniju uslugu svim našim članovima Udruženja.
<https://marketing-image-production.s3.amazonaws.com/uploads/a9410082b07b55e…>
Video sa novim Tojotama
U septembru kupljeno 50 novih Renoa - Talismani i Megani
Nabavkom 50 novih Reno automobila, više od 100 ljudi je uposleno u ovom delu investicionog ciklusa. Sva vozila su deo naše ECO klase čime je ponuda za sve članove Udruženja dodatno obogaćena.
<https://marketing-image-production.s3.amazonaws.com/uploads/2c112fdd4725511…>
Video sa novim Renoima
CarGo se otvara u Francuskoj: Prvi gradovi Nica, Kan i Sen Trope
<https://emojipedia-us.s3.dualstack.us-west-1.amazonaws.com/thumbs/120/whats…>
U proteklom mesecu smo otvorili i još jedno tržište - Francusku. Sa ponosom ističemo da će CarGo funkcionisati u Nici, Kanu i Sen Tropeu, a potom će se proširiti i na ostale francuske gradove. Time je srpski softver postao izvozni proizvod za evropsko tržište.
<https://marketing-image-production.s3.amazonaws.com/uploads/18d93ddc0f24411…>
CarGo nabavio 50 novih Folksvagen vozila
Početkom septembra smo nabavili 50 novih Folksvagena čime smo omogućili svim članovima Udruženja da imaju bezbedniju, kvalitetniju i bogatiju ponudu naše usluge na ulicama Beograda.
<https://marketing-image-production.s3.amazonaws.com/uploads/25252bb11d4ade1…>
Video sa novim Folksvagenima
BEZ TVOJE PODRŠKE NE BISMO NIŠTA OD OVOGA USPELI I ZATO HVALA TI ŠTO NAS PODRŽAVAŠ I ŠTO SI UZ NAS!
Srdačno,
<https://marketing-image-production.s3.amazonaws.com/uploads/87ce9d32f34be2d…>
CarGo
Dr. Milutina Ivkovića 2a, Belgrade, 11000
Unsubscribe - Unsubscribe Preferences
---
This email has been checked for viruses by Avast antivirus software.
https://www.avast.com/antivirus
https://www.theregister.co.uk/2019/10/02/apple_hong_kong/
Here's that hippie, pro-privacy, pro-freedom Apple y'all so love: Hong Kong protest safety app banned from iOS store
Trying to avoid cops, live rounds, tear gas? Oh no, you don't, say Cook & Co
By <https://www.theregister.co.uk/Author/Kieren-McCarthy> Kieren McCarthy in San Francisco 2 Oct 2019 at 21:47
Apple has banned an app that allows people in Hong Kong to keep track of protests and police activity in the city state, claiming such information is illegal.
“Your app contains content - or facilitates, enables, and encourages an activity - that is not legal ... specifically, the app allowed users to evade law enforcement," the American tech giant <https://twitter.com/hkmaplive/status/1179108329240424448> told makers of the HKmap Live on Tuesday before pulling it.
Advertisement
The makers, and many others, have taken exception to that argument, by pointing out that the app only allows people to note locations - as many countless thousands of other apps do - and so under the same logic, apps such as driving app Waze should also be banned.
That argument is obtuse of course given that the sole purpose of HKmap Live is to track police activity on the streets of Hong Kong and not to help people navigate to other locations. For example, at the time of writing – 0300 Hong Kong time – there are only a few messages live but they are clearly intended to provide ongoing intelligence on police movements.
“After the tear gas was applied, the police officer immediately returned to the police station,” reads one. “Four flashing lights parked at the police station door,” says another. Another simply reads: “Riot.” It is extremely easy to see at a glance where police activity is concentrated given the combination of messages and precise GPS locations.
But local Hong Kong citizens have highlighted a quirk of local laws that provide a strong counter-argument: under the law, the Hong Kong police are obliged to wave a blue flag at the spot in which they wish to declare that an illegal gathering is taking place.
Legal review?
The intent is to give citizens sufficient notice and time to move away from the area before any police action is taken. The HKmap Live app simply takes that official approach and extends it to citizens, allowing them to notify others of action that will be taken in specific locations.
It is far from clear whether Apple has undertaken that kind of legal review, or whether it is choosing to follow local law or US law in declaring the app illegal. Apple has also, so far, refused to say whether it took the decision to ban the app in response to a request from the Chinese authorities, but in the past has show a <https://www.theregister.co.uk/2017/08/02/apple_chief_on_chinese_vpn_app_ban/> remarkable willingness to kowtow to Middle Kingdom mandarins.
Regardless, the ban has left a bad taste in the mouths of many, given the background to events in Hong Kong, especially the <https://www.cbsnews.com/news/hong-kong-protester-shot-by-police-arrested-ch…> recent shooting of a protester at point-blank range with live ammunition by a police officer.
Apple has made defense of citizens’ rights a key differentiator in its technology and painted itself as a business that will stand up to unreasonable requests by the authorities who wish to use its technology to bypass current laws - in the US at least. That Cupertino chose to ban the app without discussing the issue with the app’s developers and has given a very limited, and quite possibly incorrect, explanation as to why, has infuriated many.
In a follow-up to its announcement that Apple has banned its app, the makers <https://twitter.com/hkmaplive/status/1179419820078575621> said they were optimistic that the issue could still be resolved in their favor. “To make it clear, I still believe this is more a bureaucratic f up than censorship,” said one on Twitter. “Everything can be used for illegal purpose on the wrong hand. Our App is for info, and we do not encourage illegal activity.”
Given escalating tensions in Hong Kong and growing levels of violence, particularly this week’s use of live ammunition by the police, there is an additional reason to question Apple’s decision: many Hong Kong citizens claim they had started using the app in order to carry out their legal right to protest while at the same time avoiding dangerous hotspots of violence.
Assumptions
“Apple assume our users are lawbreakers and therefore evading law enforcement, which is clearly not the case,” the makers complained.
The situation itself in Hong Kong is growing increasingly worrying. Protests are now in their fifth month, with neither side seemingly willing to back down. The Chinese government is determined to clamp down on the unrest in its semi-autonomous province but so far has been careful not to intervene militarily, out of fear it could result in the world turning its back on the country, as it did following the Tiananmen Square massacre in 1989.
The protesters in the meantime are furious at China’s growing influence over the province. The protests began when the Hong Kong legislature proposed a new bill that would make it easier to extradite people to China from the city. But they then exploded when the legislature refused to withdraw the bill and instead used harsh police tactics in an effort to stamp out the protests; a tactic that backfired drastically.
In that sense, some Hong Kongers feel they are fighting for their very right to exist autonomously from the Chinese mainland; while China is increasingly unhappy at what it sees as a questioning of its authority. The lengthy and often violent stand-off has encompassed all facets of life in the famous city, from a storming of its international airport to business leaders being pressured to lend their support to Beijing.
Demands
The protesters have five broad demands that must be met before they say they will step down: the withdrawal of the extradition bill, which has happened; legislature leader Carrie Lam to step down, which Beijing is very resistant to; an inquiry into police brutality; those who have been arrested to be released; and – perhaps the hardest hurdle – greater democratic freedoms.
<https://www.theregister.co.uk/2019/08/29/hong_kong_isps_great_firewall_prot…>
<https://www.theregister.co.uk/2019/08/29/hong_kong_isps_great_firewall_prot…> Hong Kong ISPs beg Chinese govt not to impose Great Firewall on them
<https://www.theregister.co.uk/2019/08/29/hong_kong_isps_great_firewall_prot…> READ MORE
It is unclear whether China will ultimately find a way to accept those demands and defuse the tension or whether it will decide to try to impose its will forcibly. In the meantime, protests continues and there are daily clashes between protesters and police.
While Apple, for obvious reasons, will not want to take any part in all this, its decision to ban an app that could make the lives of Hong Kong citizens safer and perhaps even support the authorities by calling it illegal does put the company in a position of taking sides.
Advertisement
If there is any good news, it’s that the HKmap Live service is <https://hkmap.live/> also available on the Web so it isn’t reliant on a iPhone app and Apple users in Hong Kong will still be able to access the service for as long as it stays live. ®
Sponsored: <https://go.theregister.co.uk/tl/1862/shttps:/serverlesscomputing.london/> Serverless Computing London - 6-8 Nov 2019
Sent from my iPad 2018