You can call me a sensationalist, or that I don't know what I'm talking about. That's fine. I don't care. still fucking hate cloudflare. still doesn't feel right.
consider everything that cloudflare has done with their position of power so far:
-protected nazis -forwarded abuse claims to nazis for them to hunt the ones making the claims -hatespeech? more like freeze peach. (Re: kiwi farms bullshit) -DNS over HTTPS having no garuntees of privacy anywhere -DoH being used for massive malware campaigns, and no commitments to actually hunt down malicious infrastructure -cloudflare workers, tunnels and various other services often hosting malware, but then doing fuck-all about it because "Hey, we don't actually host malware"
So, would mishandling passwords really surpise anyone? but don't worry, "we're quirky because lava lamps, lol."
@GossiTheDog Honest to god, this is still the most chill social network out of the options available.
If the worst I have to complain about is "Mastodon HOA" that is considerably better than the feeling of dread and self-loathing that is watching people cut into you and one another for their 15 minutes of fame constantly.
all I hear on my server is REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE as I make two out of the twenty cores lose their shit compiling software in a VM.
and here I am installing 2GB of updates to kali, installing docker-compose, and installing dtale to throw and capture pcaps. This monday is moving already.
@GossiTheDog Not quite sure how I missed your POC the first time around, but I just added coverage in the ET ruleset for both Snort and Suricata. Rules will be out this evening in our daily rule release. Cheers and thank you.
Suricata:
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco ASA/FTD Memory Leak Attempt (CVE-2020-3259)"; flow:established,to_server; http.method; content:"GET"; http.uri; bsize:>800; content:"|2b|CSCOE|2b|/sdesktop/webstart.xml|3f|"; fast_pattern; content:"|25|p"; endswith; reference:url,github.com/GossiTheDog/Exploits/blob/main/Cisco-CVE-2020-3259.sh; reference:cve,2020-3259; classtype:attempted-admin; sid:1; rev:1;)
@GossiTheDog Been beating this drum for years. Infostealers are a huge threat because of crossing the streams. whether its byod, or wfh with a company asset, and your kid decides that downloading and running free_robux.toteslegit.exe on your work laptop with saved passwords in the browser is totally fine.
Tik-Tok ban upheld? Good, now do X for election interference and facebook reels because its just as shit as tik-tok ever was.
Oh, you won't do that because Mark and Elon are puppeteering the government so hard, their hands are literally up the president's ass? who would've guessed.
Senior Security Researcher, Proofpoint Emerging Threats.I've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.Work-Related hashtags:#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetectionHobbies:#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorking #HomeLab