Announcement

Collapse
No announcement yet.

PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

    I just got word from lil_freak that she is planning to bring back the Defcon Forum Meet. The [forum=505]Forum[/forum] for it has been opened and is available for posting.

    Good luck lil_freak!

    Comment


    • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

      New info from Nikita, new for Defcon 18 is [forum=506] Be The Match Foundation - Bone Marrow Drive @ DC 18[/forum]. Forum is open and thread is included for discussion.

      Comment


      • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

        The [forum=507]Open CTF[/forum] forum is now open for service. 2 old threads with questions about the status and the announcement of the new owners have been moved to the new forum, retitled, and closed, so there is less confusion. A new URL has been added to the description of the Open CTF forum to point to the new web site.

        [forum=508]Forum for Goon Band -- Recognize[/forum] has been added, because I can. Thread and discussion for it moved to this new forum with a permanent redirection left where the thread once was.

        Myrcurial provided us a new link for the [forum=498]10,000ยข Hacker Pyramid[/forum], and the description of that forum has been altered to provide the new link instead of the old for Defcon 18.


        Sent out tweets for all 3 updates.
        Last edited by TheCotMan; March 25, 2010, 01:34.

        Comment


        • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

          Accounts set to be forum leader(s)/organizer(s) for forums containing events they run from previous years copied forward to contest/event forums for this year. If I forgot to copy one forward from previous years to this year please let me know. If permissions seem broken now, please let me know.

          Comment


          • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

            Bascule and Overdose added as Forum Leader(s)/Organizers for the forum [forum=501]Hacker Karaoke[/forum].

            Comment


            • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

              I just spoke with Nikita and we have a new contest:

              A new contest for the time leading up to Defcon 18 has been added: [forum=511]What's in Neil's Pants?[/forum]

              Originally posted by Description
              A Trivia game, where prizes include, but not limited to, Items from Neil's pants. Held online & may contain hints & secrets to win Leetness. Prizes to be claimed at Defcon or mailed to via snail mail. Good Luck!
              Good luck!

              Nikita to be set as Forum Leader/Organizer in this forum.
              Last edited by TheCotMan; April 22, 2010, 15:14.

              Comment


              • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                HighWiz has announced the return of [forum=512]DC101[/forum] to Defcon. He promises more information will be provided soon. A new forum has been created for this event. You can find his announcement in the forum.

                HighWiz has been set to Forum Leader/Organizer of this forum.

                Comment


                • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                  Hackajar has just notified me that [forum=513]The Summit[/forum] will be returning to Defcon 18 this year. The forum has been created and an announcement sent out with twitter.

                  Forum is active. Description may change as new information is provided by Hackajar.

                  Comment


                  • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                    Talked with Pyr0 recently, and he said [forum=514]Skytalks[/forum] will return to Defcon this year for Defcon 18. The forum has been activated, and he has been set as Forum Leader/Organizer for that forum.

                    Comment


                    • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                      The Purge:

                      Based on the published thread in the "Rules" section on account use a new round of purging has been completed:

                      400 users-account with a "zero post-count" and no activity in over 2 years, accounts purged.

                      70 user-accounts with unconfirmed email addresses and "zero post-count" have been purged.

                      Relevant content from thread on purging accounts:
                      Originally posted by purge
                      Account deletion:
                      If an account has a ZERO postcount, and has been UNUSED for 2 YEARS, that account may be deleted without warning.

                      If an account has a ZERO postcount AND appears to be a "one-time-use" account AND has been UNUSED for over 1 YEAR , that account may be deleted without warning.

                      If an account has a ZERO postcount, and is configured to include an UNCONFIRMED EMAIL ADDRESS, that account may be deleted without warning.

                      If an account has a ZERO postcount, and is configured to include an UNCONFIRMED EMAIL ADDRESS, and the confirmation e-mail message to the email address associated with the account bounces, that account may be deleted without warning.
                      A majority of these are failed attempts by spam-bots to register with the forums and post spam.

                      Comment


                      • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                        Forums, test-forums, pics, and main (www) site unavailable earlier today for network device upgrade. Web servers remained up during maintenance but access to them was lost during upgrade and diagnostics of network device(s).

                        Expect intermittent access to forums and pics over the next few hours as a problem with this network device upgrade is diagnosed.

                        Also, DT may have an announcement on a minor change to some services to improve security, soon for applications that can take advantage of these new features.

                        Comment


                        • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                          First, I think DT has finished the diagnostics with the network device upgrade for making sure users can talk to the forums, pics and main site.

                          Access should be restored.

                          Now for the 2 new features...

                          Originally posted by TheCotMan View Post
                          ... Also, DT may have an announcement on a minor change to some services to improve security, soon for applications that can take advantage of these new features.
                          I talked with DT, and he said I should type about it.

                          There are 2 header values that can be added to web servers and presented to web clients/browsers to help them help protect their users.

                          The first, and most useful is Strict-Transport-Security.

                          It is described here in an article "Security in Depth: New Security Features" (Tuesday, January 26, 2010). It is Strict-Transport-Security. You can read the details on that page and others, but a quick summary is:

                          Strict-Transport-Security Provides direction to your web browsers( that support it) which have previously visited your "https-based" services that sent this to your web browser (that support it) to upgrade all your requests from http to https before you transmit them and a time period for which that auto-upgrade-http-to-https should be valid. It is supposed to start working after your first https visit from a web browser that support it..

                          More detail about it can be found here.

                          There are claims for it being supported by NoScript (the firefox plugin). It works for me, so it should work for you. After the web server started transmitting this header item, and it was no longer being filtered, I pointed my web browser at http://forum.defcon.org/ which gave me the old "http is no longer supported web page." Then I clicked the link to https://forum.defcon.org/index.php and I was browsing with https. Just that one visit to https from Firefox with the NoScript plugin installed was enough. My next attempt to visit http://forum.defcon.org/ lead to my keystroke and then request being intercepted by NoScript, and changed to https://forum.defcon.org/

                          The next header item added was also mentioned
                          here in an article "Security in Depth: New Security Features" (Tuesday, January 26, 2010). It is X-Frame-Options: deny. You can read the details on that page and others, but its quick summary is: try to help users at risk for frame-captured content from suffering from frame-captured content and risks associated with it.

                          Both of these were ideas pushed forward by Jeff, and he did all the hard work to make it possible for these header items to make their way to your web browsers.
                          Me? I only added 4 lines to a configuration file, copied and pasted them to other web server configs, and then restarted the web servers.He had to do quite a bit more work to diagnose the earlier problems with the network device that was upgraded, and then provide rules to permit those new header items access to leave the Defcon network.

                          Why take so long to implement something posted about in January? Eh. While we both had time discussing the problems with the upgrade, he brought this up and said we should do it. He did the work. It's done. See how he spends his Friday night? You should thank him.

                          These are all live on forums, test-forums, and pics. These same header items will eventually be made available to the main-site and probably the media server too.

                          Questions or comments are welcome.
                          Last edited by TheCotMan; April 30, 2010, 22:46.

                          Comment


                          • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                            SmittyHalibut got an OK from DT to run a new contest for Defcon 18 called [forum=517]Crash and Compile[/forum]. The forum has been activated while SmittyHalibut works out getting a location to run the contest/event. Details on the contest are available in t a thread inside the forum.

                            Comment


                            • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                              This is either the second or third time I've brought down the forums as a mistake. Sorry about this.

                              I ran a report on the server, and through resource exhaustion, killed it. I spoke with Jeff, and he was not able to login to the server at all. Console messages suggest I used too much memory. Whoops! Sorry about that.

                              Database was mostly recoverable. It looks like someone was in the middle of a post when the server was reset. That post was lost as the transaction was empty. No other posts appear to be damaged or lost.

                              Forums should be returning to service in a few minutes.

                              Comment


                              • Re: PUBLIC-NOTICES: Forum Changes/Fixes. Any Questions?

                                Rides and Room Sharing is open.

                                Comment

                                Working...
                                X