Notices by Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange), page 22
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 01-Oct-2023 18:41:56 JST Jake Hildreth (acorn) :blacker_heart_outline: -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 01-Oct-2023 18:41:40 JST Jake Hildreth (acorn) :blacker_heart_outline: @catsalad @jerry https://apps.apple.com/bg/app/icq-video-calls-chat-rooms/id302707408
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 01-Oct-2023 18:41:25 JST Jake Hildreth (acorn) :blacker_heart_outline: @catsalad @jerry Uh... I'm participating in the Winamp re-release beta right now and just deleted ICQ from my phone last week. (I am not joking about either.)
In conversation from gnusocial.jp permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 30-Sep-2023 23:23:22 JST Jake Hildreth (acorn) :blacker_heart_outline: @catsalad @jerry The fact that WS_FTP still exists at all gives me the warm & fuzzies.
In conversation from gnusocial.jp permalink -
Embed this notice
Merry Jerry 🎄🎅🕎⛄️❄️ (jerry@infosec.exchange)'s status on Saturday, 30-Sep-2023 23:22:19 JST Merry Jerry 🎄🎅🕎⛄️❄️ @catsalad this is the way
In conversation from infosec.exchange permalink Repeated by horse -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 30-Sep-2023 06:34:31 JST Jake Hildreth (acorn) :blacker_heart_outline: @zak Why use Launchpad when Spotlight exists? And why use Spotlight when Alfred exists?
In conversation from infosec.exchange permalink -
Embed this notice
Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 29-Sep-2023 05:37:20 JST Tinker ☀️ Hackers / Pentests - Wanna sniff out canary tokens?
Ya worried the blue team seeded fake credentials throughout their environment? Put them in LSASS, LSA, or even that suspicious "too good to be true" passwords.txt file?
Ya worried that if you use those creds, blue team will get alerted that you used them because no one ever uses those creds and any login attempt triggers massive alarms?!?!?!
Just dump Active Directory (with other valid creds) via LDAP and go through the resulting LDIF.
Look up the sus account and look for the parameter "lastLogon:" : Was it a while back? Has anyone used the account in a while?
Now look for the parameter "pwdLastSet:" - Is it close to the lastLogon? Did blue team set the password, set the alert, and then leave it to sit?
If they are recent dates, maybe it's a new hire. So maybe it's fine.
But if its older... thats a little suspicious.
Look for other parameters and paint a picture. Look at passwordExpirationTime. Is it 0? Look for accountExpires, is it set for near forever? (or a long way off).
Big thing is, compare it to other accounts, especially accounts you know are good. Look at normal and then conduct anomaly analysis and see how well your sus account stacks against known good or known normal.
Active Directory gives a lot of information. Dive into it.
In conversation from infosec.exchange permalink Repeated by horse -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Thursday, 28-Sep-2023 19:10:19 JST Jake Hildreth (acorn) :blacker_heart_outline: @TheGibson Toot! is the best I’ve found so far. It the elk.zone web app is great too.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 23-Sep-2023 19:38:25 JST Jake Hildreth (acorn) :blacker_heart_outline: @Sempf Example: "A photo of a squat rack with an empty bar. The bar is very rusty because it hasn’t been used in four months. The photographer is rusty for the same reason."
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 23-Sep-2023 04:34:15 JST Jake Hildreth (acorn) :blacker_heart_outline: @Sempf I love writing humorous shit in my alt text!
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Friday, 22-Sep-2023 19:02:51 JST Jake Hildreth (acorn) :blacker_heart_outline: Hello, old friend.
In conversation from infosec.exchange permalink Attachments
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Thursday, 21-Sep-2023 18:56:21 JST Jake Hildreth (acorn) :blacker_heart_outline: @DataDrivenMD @com Did you happen to install a beta version on those 3 devices?
In conversation from gnusocial.jp permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Thursday, 21-Sep-2023 10:17:30 JST Jake Hildreth (acorn) :blacker_heart_outline: @tinker @wendynather Oh em gee, what did you use to create this?
In conversation from infosec.exchange permalink -
Embed this notice
Ian Coldwater 📦💥 (ian@hachyderm.io)'s status on Thursday, 21-Sep-2023 01:44:45 JST Ian Coldwater 📦💥 I am feverish in bed post-vaccine, please tell me a cool fact about something
In conversation from hachyderm.io permalink Repeated by horse -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Tuesday, 19-Sep-2023 22:31:32 JST Jake Hildreth (acorn) :blacker_heart_outline: @frainfostudent @GossiTheDog @malwaretech *besterest hacker
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Monday, 18-Sep-2023 04:53:48 JST Jake Hildreth (acorn) :blacker_heart_outline: @rand0h yakkety yak
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 17-Sep-2023 23:12:08 JST Jake Hildreth (acorn) :blacker_heart_outline: @rand0h Bluesky can feel dead if you aren’t following many people and/or not using custom feeds. Custom feeds are cool.
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 17-Sep-2023 22:09:10 JST Jake Hildreth (acorn) :blacker_heart_outline: Refactoring is oddly satisfying.
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 16-Sep-2023 03:00:03 JST Jake Hildreth (acorn) :blacker_heart_outline: @bandrel LIVE NOW!
In conversation from infosec.exchange permalink -
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Saturday, 16-Sep-2023 02:14:21 JST Jake Hildreth (acorn) :blacker_heart_outline: TODAY!!! 2pm ET on the Twitch Happy Hour we wrangle @bandrel and let him host the entire thing by himself. https://Twitch.tv/TrimarcSecurity
In conversation from infosec.exchange permalink Attachments