GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by da_667 (da_667@infosec.exchange)

  1. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 21-May-2025 09:25:24 JST da_667 da_667

    I'm interviewing 3 candidates back to back to back for an internship role. We gave them a screening quiz to test their knowledge.

    I have a sneaking suspicion they all used AI to answer the questions given to them. The mistakes are overall the same. The wording is ever so slightly different.

    I'm kind of insulted.

    In conversation about 18 hours ago from infosec.exchange permalink
  2. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 21-May-2025 08:47:46 JST da_667 da_667
    in reply to
    • Graham Sutherland / Polynomial
    • XSS~1.BUN :blobhaj_hearttrans:

    @gsuberland @xssfox wanna know the best part of this? one of the candidates claims to be a CMU grad.

    In conversation about 19 hours ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/542/775/124/963/199/original/c4bf76f3b0fe2a2c.jpg
  3. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 15-May-2025 03:41:21 JST da_667 da_667

    question for you all. plumber is trying to sell me on a whole house water filtration system to go with some other kinda required plumbing work around the house. Would it be worth it? I'm kinda leaning towards no, because Michigan's water quality in general (not counting northern michigan, because its all well water up there), is generally okay, but I'm looking for opinions.

    In conversation about 7 days ago from infosec.exchange permalink
  4. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 14-May-2025 01:25:53 JST da_667 da_667
    in reply to
    • cR0w :cascadia:
    • B'ad Samurai 🐐

    @cR0w @badsamurai you know what I love the most? knowbe4 re-uses their SSL certs. its just one gigantic SSL cert for a bunch of domains. Congrats, you just doxxed your phishing infra because I can fuckin' read.

    In conversation about 8 days ago from infosec.exchange permalink
  5. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 09-May-2025 02:44:41 JST da_667 da_667
    in reply to
    • Kevin Beaumont
    • NosirrahSec 🏴‍☠️

    @GossiTheDog @NosirrahSec I can't fathom anyone replacing seasoned DFIR staff with a fucking AI. Even with force multiplier gains, it needs to be babysat consistently.

    In conversation about 13 days ago from infosec.exchange permalink
  6. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 09-May-2025 02:42:49 JST da_667 da_667
    in reply to
    • Kevin Beaumont

    @GossiTheDog Imagine taking that big of a bonus after single handedly causing billions in damages over a single day due to gross negligence.

    https://fortune.com/2024/08/03/crowdstrike-outage-fortune-500-companies-5-4-billion-damages-uninsured-losses/

    But sure, fire the people saddled with fixing the incompetence. Let's see how that goes.

    In conversation about 13 days ago from infosec.exchange permalink
  7. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 08-May-2025 15:45:59 JST da_667 da_667
    in reply to

    I might just settle in on one of the 30-odd inch curved monitors, see what I think and if I can deal with it, replace the 27in. 1080p monitor that refuses to die.

    In conversation about 13 days ago from infosec.exchange permalink
  8. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 08-May-2025 15:45:59 JST da_667 da_667

    it's irritating that if you opt to go for a monitor above 27", that the fuckers are all curved. I feel like the curved monitors are a fucking gimmick.

    In conversation about 13 days ago from infosec.exchange permalink
  9. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 07-May-2025 04:28:44 JST da_667 da_667

    One blog post from akamai is turning into multiple rules to cover vulns in IOT devices that I didn't have coverage for.

    https://www.akamai.com/blog/security-research/2025/may/active-exploitation-mirai-geovision-iot-botnet

    My thanks to akamai for a wonderful data source to pivot off of.

    In conversation about 15 days ago from infosec.exchange permalink
  10. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 04-May-2025 11:50:34 JST da_667 da_667

    I wrote a thing. Its political. This is your only warning.

    "Be the heretic that orange nazi gasbag believes you can be"

    https://www.totes-legit-notmalware.site/home/be-the-heretic-that-orange-nazi-gasbag-believes-you-can-be

    In conversation about 18 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.totes-legit-notmalware.site
      Be The Heretic that Orange Nazi Gasbag Believes you can Be | 667's shitpost box
      This website is a personal blog with cybersecurity and technology themes. It also ventures into some nerd culture themes, and there is heavy use of strong lanuage. Generally, this website should be considered not safe for work.
  11. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 04-May-2025 11:50:33 JST da_667 da_667
    in reply to

    This did numbers while I was out today. Thank you for reading. I... didn't originally have a goal when I set out to write this.

    But then the more I thought about it, the more I'm realizing there's no cavalry coming. All we have is each other, and that even the tiniest positive actions towards one another and our community as a whole accumulates.

    But even if you don't have spoons, energy, attention span, or money to do anything, that's fine. those positive actions apply to you as well. Self-care is important. You are your own biggest advocate in that regard.

    I also just wanted to remind everyone, these people in charge unapologizingly, remorselessly fucking awful skinwalkers, and that you have no obligation to make nice with supporters of this administration in any way. If they want a sympathetic ear, tell them to fuck off to any one of the multitudes of conservative hugboxes out there.

    In conversation about 18 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/446/740/151/927/027/original/383028c509f4f9df.png
  12. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 04-May-2025 11:50:32 JST da_667 da_667
    in reply to
    • Viss

    @Viss see also: anyone associated with organizing RSAC. I just don't fucking understand how or why you would want the concentration camp enjoyer to keynote your event, when literally anyone in charge of the CVE program, or from CISA themselves would've been an absolute fucking banger instead.

    In conversation about 18 days ago from infosec.exchange permalink
  13. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 04-May-2025 11:50:31 JST da_667 da_667
    in reply to
    • Viss

    @Viss Literally could have had Jen Easterly come up on stage say "I don't have a job now, good luck" and mic drop.

    In conversation about 18 days ago from infosec.exchange permalink
  14. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 01-May-2025 21:36:03 JST da_667 da_667

    a time-themed bar called the inifinite stratum, and nobody but NTP nerds will get it

    In conversation about 20 days ago from infosec.exchange permalink
  15. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 01-May-2025 02:59:43 JST da_667 da_667
    in reply to

    you should've done it yourself

    I've watched videos on how to do it. and I managed to somewhat successfully sharpen one knife without killing myself. It took me a whole afternoon.

    This dude was done inside of an hour. I've no doubt he was using automatic tools

    In conversation about 21 days ago from infosec.exchange permalink
  16. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 01-May-2025 02:59:43 JST da_667 da_667

    knife sharpening service was worth it. got 19 knives done for 78 bucks. Used one of my knives to butterfly chicken for chicken + riced cauliflower for lunch, and it was effortless.

    They really needed the maintenance.

    In conversation about 21 days ago from infosec.exchange permalink
  17. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 28-Apr-2025 07:11:29 JST da_667 da_667
    • Viss
    • PJ Sliney

    I can't stop fucking laughing.

    https://www.varonis.com/blog/malicious-firewall-rules-in-azure-sql

    TL;DR: if you have access to modify azure firewall rules, you can craft DELETE requests, and depending on the number of ../ in your request, can delete servers, resource groups, etc.

    with thanks to @pjsliney for the heads up.

    Also cc @Viss

    Go to the cloud they said, it'll be fine they said

    In conversation about 24 days ago from infosec.exchange permalink
  18. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 27-Apr-2025 06:25:00 JST da_667 da_667
    in reply to
    • Reasonable Man

    @r000t can't say that I have

    In conversation about a month ago from infosec.exchange permalink
  19. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 27-Apr-2025 06:16:35 JST da_667 da_667

    today I've learned that ethtool doesn't work to check link or duplex speed on virtio devices because the VM and the host are aware its a virtual machine, and just yeets frames between VMs, or out the hypervisor's interface (if bridged) at link speed.

    In conversation about a month ago from infosec.exchange permalink
  20. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 26-Apr-2025 04:25:44 JST da_667 da_667
    in reply to

    @GossiTheDog didn't even consider this. Hope your employer has strict MDM. But even then, who knows what happens.

    In conversation about a month ago from infosec.exchange permalink
  • Before

User actions

    da_667

    da_667

    Senior Security Researcher, Proofpoint Emerging Threats.I've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.Work-Related hashtags:#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetectionHobbies:#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorking #HomeLab

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          30576
          Member since
          18 Nov 2022
          Notices
          146
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.