IRC log for #buglabs on 20120224

00:02.47*** join/#buglabs VishMac (~VishMac@cpe-74-73-151-138.nyc.res.rr.com)
00:58.04*** join/#buglabs jedahan (~jedahan@subtle/user/jedahan)
01:15.30*** join/#buglabs jedahan (~jedahan@subtle/user/jedahan)
01:39.18*** join/#buglabs haveahennessy (~openpeak@c-76-110-76-214.hsd1.fl.comcast.net)
04:06.38*** join/#buglabs c4milo (~c4milo@207-38-137-125.c3-0.avec-ubr2.nyr-avec.ny.cable.rcn.com)
04:24.47*** join/#buglabs jedahan (~jedahan@subtle/user/jedahan)
04:26.49*** join/#buglabs c4milo (~c4milo@207-38-137-125.c3-0.avec-ubr2.nyr-avec.ny.cable.rcn.com)
06:10.40*** join/#buglabs Marrs (~marrs@planetmarrs.xs4all.nl)
07:06.13*** join/#buglabs Marrs (~marrs@planetmarrs.xs4all.nl)
07:54.29*** join/#buglabs Marrs (~marrs@095-097-179-234.static.chello.nl)
08:38.03*** join/#buglabs jkridner___ (~jason@pdpc/supporter/active/jkridner)
12:54.15*** join/#buglabs GNUtoo|laptop (~gnutoo@host29-81-dynamic.48-82-r.retail.telecomitalia.it)
13:55.59*** join/#buglabs guillaum1 (~gl@AMontsouris-153-1-39-200.w90-2.abo.wanadoo.fr)
14:19.21*** join/#buglabs barberdt (~barberdt@66.43.64.66)
14:33.20*** join/#buglabs c4milo (~c4milo@66.43.64.66)
15:44.50*** join/#buglabs jedahan (~textual@subtle/user/jedahan)
15:45.05jedahanhttp://www.leggetter.co.uk/real-time-web-technologies-guide << get on that list!
15:48.09theterg_nyahhah, pusher
15:49.33thetergjedahan: i've passed the link along, thanks!
15:51.06*** join/#buglabs VishMac (~VishMac@66.43.64.66)
15:53.13jedahancool did you Yam it?
15:54.19thetergnahbro, there's this awesome new rfc we're using as a social media platform
15:54.22thetergit's rfc1149
15:54.52thetergwe're also going to be using it for the next generation of BUGswarm
15:55.12jedahanI heard AVIAN is going to be wrapped in a REST api for the next release of nodesocketjsio
15:55.22thetergTOTALLY ASYNCHRONOUS bro
15:55.33thetergpacket order isn't even *ENFORCED*
15:58.52jedahansounds like http://artoffailure.free.fr/index.php?/projects/laps/ theterg
15:59.16jedahanor rather http://artoffailure.free.fr/index.php?/projects/internet-erosion/
15:59.17jedahanso close
16:00.54thetergneato
16:01.02haveahennessyyou divas dont live together no more?
16:01.50thetergthereheis
16:02.13haveahennessywatching.. like an eagle
16:02.37thetergnahbro, we're still in park slope
16:03.05haveahennessyromance supercaliente
16:03.16haveahennessyamirite c4milo?
16:03.24theterghey, thats *bromance* good sir
16:03.27thetergI mean, wait
16:03.47thetergdamn.
16:03.54haveahennessyha
16:04.47c4miloohboy
16:05.06c4milohaveahennessy: you should play the Stripe capture the flag war game
16:05.19haveahennessyshould I?
16:05.22haveahennessyconvince me..
16:05.25c4milohehe
16:05.27VishMacshouldnt you
16:05.29haveahennessydo i have to purchase anything?
16:05.36c4milohaveahennessy: nah
16:05.43haveahennessylink?
16:05.44c4milohttps://stripe.com/blog/capture-the-flag
16:05.54haveahennessygracias
16:06.03VishMaci couldnt even ssh in properly
16:06.15VishMacso if you get past that…you're well on your way to dominance
16:06.21jedahanchallenge: decode ==^^^bbeimmmovv
16:06.32jedahani have guesses where to start but I know nothing about ciphers
16:06.36jedahanhints on how to learn ciphers?
16:06.37haveahennessyha.. this looks interesting
16:07.18c4milohuh?
16:07.30c4milohaveahennessy: I got third level last night, then I got stuck
16:07.43c4milothen I had  to go to sleep
16:08.12c4milowaiting for lunch time to continue trying
16:09.18haveahennessyha
16:09.40c4miloit's fairly easy to get to the third level
16:10.09jedahannice c4milo
16:10.14c4milothird level I think is a buffer overflow or stack overflow
16:10.45c4miloI don't have experience exploiting those
16:10.47c4milo:/
16:10.58haveahennessyd-:
16:11.04haveahennessyfirst time for everything
16:12.16c4milohas to read Smashing the stack for fun and profit
16:37.28jconnollyheh, I sent that link out earlier too jedahan
16:37.33jconnollyscrolls back
16:38.17jconnollyc4milo: davidbalbert got to level4 with some help
16:38.49jedahanc4milo that paper seems like a great read
16:38.57jedahanITS NOT MUNGing THE STACK
16:38.59jedahanNO MUNG
16:39.01jedahan, mang
16:40.35jedahanman who is this Clay Shirky guy he is everywhere
16:45.05c4milojconnolly: nice
16:45.38c4milojconnolly: is level04 a stack overflow right?
16:46.42jconnolly[11:46] <jconnolly> is level04 a stack overflow exploit?
16:46.42jconnolly[11:46] <davidbalbert> yeah
16:46.43jconnollyindeed
16:46.58c4milocool
16:47.11c4milojconnolly: in what level are you?
16:47.24jconnollyI'm not, I didn't get to it last night
16:48.12jconnollydavidbalbert irl: well it's a buffer overflow, but you overflow the stack so that you execute the code in the overflowed buffer, so it's both a buffer overflow that is exploited via a stack overflow
16:50.44GNUtoo|laptophi, I think tslib is broken in core-based oe for the bug2.0
16:51.24c4milojconnolly: interesting. I identified the stack overflow but I haven't identify the buffer overflow.
16:51.47c4milojconnolly: my first attempt was using gdb. lol
16:52.58c4milojconnolly: then I realized gdb doesn't run the binary with suid for security purposes.
16:53.05c4milo^.^
16:53.48jconnolly;D
16:54.00GNUtoo|laptopwho should I talk to ? stefen is not there currently
16:54.16GNUtoo|laptopbasically the problem is that angstrom uses more recent kernel headers
16:55.25haveahennessyjconnolly: has dalbert finished it?
16:56.40jconnollyI don't think so, I think he stopped at 4
16:56.56jconnollyGNUtoo|laptop: stefan schmidt is no longer employed by buglabs.
16:57.15GNUtoo|laptopahh that's why I don't see him anymore here
16:57.19jconnollyindeed
16:57.24GNUtoo|laptopwho does the oe part then?
16:57.48jconnollyif you can describe the problem I can take a stab at it.
16:58.17GNUtoo|laptopyes but the solution requires a more recent kernel
16:58.34c4miloor we kindly accept pull requests :)
16:58.34GNUtoo|laptoptslib: Selected device uses a different version of the event protocol than tslib was compiled for
16:59.17GNUtoo|laptopthe thing is that angstrom woulnd't allow to use another kernel headers version
16:59.34GNUtoo|laptopwouldn't allow means that you get insulted if you send a patch for it or something like that
16:59.56GNUtoo|laptopI must look
17:00.02GNUtoo|laptopI should ask how palmpre handle that
17:00.13GNUtoo|laptopmaybe there is another way than upgrading the kernel
17:00.26taylor|s1riesi'm not sure palmpre is a good example for much these days.
17:00.40GNUtoo|laptop* it uses tslib
17:00.47GNUtoo|laptop* it's a very old 2.6.24 kernel
17:00.49jconnollyor support for bug hardware is only for angstrom 2008 or 03/2011
17:01.03GNUtoo|laptopyes but I work only with core-based oe
17:01.13GNUtoo|laptopuntil now I used the xfce46-image
17:01.26GNUtoo|laptopso that didn't need a tslib driver
17:02.33GNUtoo|laptopbyw I still must test the kernel patch for fixing the i2c
17:02.38GNUtoo|laptops/i2c/spi
17:03.10GNUtoo|laptopso you have no one working on oe anymore?
17:03.22GNUtoo|laptopwhy did stefen leave?
17:04.20taylor|s1riesGNUtoo|laptop: we don't have a lot of work for him right now.
17:04.34GNUtoo|laptopah ok
17:04.52GNUtoo|laptopyou're busy with java stuff I guess
17:05.00taylor|s1riessomething like that, yes.
17:14.15c4miloGNUtoo|laptop: Javascript stuff ^.^
17:14.48GNUtoo|laptopok
17:14.55GNUtoo|laptopthe thing for the automotive
17:15.04c4milohaveahennessy: where are you?
17:15.24c4milohaveahennessy: level03?
17:17.21GNUtoo|laptopand there is the boss at the end of the level( ambigious)
17:17.50haveahennessycamilo.. dont have much time to play now..
17:17.59haveahennessyi did the first one quick
17:18.14haveahennessyi'll try the next one later tonight maybe
17:18.26haveahennessyi dont know anything about web exploits
17:42.36*** join/#buglabs Marrs (~marrs@planetmarrs.xs4all.nl)
18:48.56*** join/#buglabs guillaum1 (~gl@AMontsouris-153-1-38-234.w90-2.abo.wanadoo.fr)
19:10.55*** join/#buglabs c4milo_ (~c4milo@66.43.64.66)
20:38.09*** join/#buglabs jkridner (~jason@pdpc/supporter/active/jkridner)
21:15.09*** join/#buglabs c4milo (~c4milo@66.43.64.66)
23:10.45*** join/#buglabs c4milo (~c4milo@66.43.64.66)
23:37.04*** join/#buglabs jedahan (~jedahan@subtle/user/jedahan)

Generated by irclog2html.pl Modified by Tim Riker to work with infobot.