@kajer @Epic_Null @cR0w the package was still out of date at the time
Conversation
Notices
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:08:21 JST
Ryan Castellucci (they/them) :nonbinary_flag:
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:09:23 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@kajer @Epic_Null @cR0w Also, someone from CorpSec messaged me about that machine a while ago when I set up policies allowing 0.0.0.0/1 and 128.0.0.0/1 to access port 22.
-
Embed this notice
../kajer/. (kajer@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:10:32 JST
../kajer/.
clearly allowing 0/0 is bad
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:11:17 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@kajer @Epic_Null @cR0w I asked if it was okay to allow 0.0.0.0/1, 128.0.0.0/2, and 192.0.0.0/3 and they didn't think that was funny.
-
Embed this notice
Ryan Castellucci (they/them) :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:12:13 JST
Ryan Castellucci (they/them) :nonbinary_flag:
@kajer @Epic_Null @cR0w Someone did bullshit like this to me when I worked CorpSec, now it's my turn to ensure a new generation is learning!
-
Embed this notice
../kajer/. (kajer@infosec.exchange)'s status on Thursday, 27-Aug-2026 06:14:15 JST
../kajer/.
@ryanc @Epic_Null @cR0w Sadly, it's the only way.
-
Embed this notice