GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by da_667 (da_667@infosec.exchange), page 2

  1. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 01-May-2025 02:59:43 JST da_667 da_667

    knife sharpening service was worth it. got 19 knives done for 78 bucks. Used one of my knives to butterfly chicken for chicken + riced cauliflower for lunch, and it was effortless.

    They really needed the maintenance.

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 28-Apr-2025 07:11:29 JST da_667 da_667
    • Viss
    • PJ Sliney

    I can't stop fucking laughing.

    https://www.varonis.com/blog/malicious-firewall-rules-in-azure-sql

    TL;DR: if you have access to modify azure firewall rules, you can craft DELETE requests, and depending on the number of ../ in your request, can delete servers, resource groups, etc.

    with thanks to @pjsliney for the heads up.

    Also cc @Viss

    Go to the cloud they said, it'll be fine they said

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 27-Apr-2025 06:25:00 JST da_667 da_667
    in reply to
    • Nietzschean Ekko Enjoyer

    @r000t can't say that I have

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 27-Apr-2025 06:16:35 JST da_667 da_667

    today I've learned that ethtool doesn't work to check link or duplex speed on virtio devices because the VM and the host are aware its a virtual machine, and just yeets frames between VMs, or out the hypervisor's interface (if bridged) at link speed.

    In conversation about 2 months ago from infosec.exchange permalink
  5. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 26-Apr-2025 04:25:44 JST da_667 da_667
    in reply to

    @GossiTheDog didn't even consider this. Hope your employer has strict MDM. But even then, who knows what happens.

    In conversation about 2 months ago from infosec.exchange permalink
  6. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 25-Apr-2025 10:23:51 JST da_667 da_667

    I don't know if its bias or not, but the number of really stupid webapp vulnerabilities seems to be on the rise. There seems to be a lot of endpoints that just. require zero auth. A lot of webapps that just blindly trust the user if certain http headers are there. A lot of webapps seem to just completely lose their shit when they hit that (?:\x3b|\x60|\x0a|\x26{2}).

    In conversation about 2 months ago from infosec.exchange permalink
  7. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 24-Apr-2025 04:59:10 JST da_667 da_667
    • Kevin Beaumont

    @GossiTheDog your character looks like they've seen some shit.

    In conversation about 2 months ago from infosec.exchange permalink
  8. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 22-Apr-2025 04:31:57 JST da_667 da_667

    only thing I wanna know is if they hit the dead pope with the pope hammer three times like they were supposed to.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/377/116/971/085/193/original/92f5633e2156fdad.jpg
  9. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 19-Apr-2025 05:15:45 JST da_667 da_667
    in reply to
    • Kevin Beaumont

    @GossiTheDog ..which means that its recoverable by bad guys, which means that this is just as much an infostealer now as it was before.

    In conversation about 3 months ago from infosec.exchange permalink
  10. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 19-Apr-2025 05:04:22 JST da_667 da_667
    in reply to
    • Kevin Beaumont

    @GossiTheDog 1.2gb of ram. holy shit, lmao.

    In conversation about 3 months ago from infosec.exchange permalink
  11. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 18-Apr-2025 15:12:43 JST da_667 da_667
    in reply to
    • Viss
    • Taggart :donor:

    @mttaggart @Viss what happens when you hide your dead man's switch service into shit like service accounts with non-printable ascii characters? What happens when you store the dead man's switch into an alternate data stream?

    In conversation about 3 months ago from infosec.exchange permalink
  12. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 18-Apr-2025 15:12:43 JST da_667 da_667
    in reply to
    • Viss
    • Taggart :donor:

    @mttaggart @Viss I've very interested in this. I like the idea of active countermeasures, but turned up to 11.

    It wasn't that long ago that some were theorycrafting that by just installing VMware Tools, or by installing a host of forensic, malware analysis, or reverse engineering tools, that whole hosts of automated malware will just throw shitfits and refuse to run.

    What happens when you develop defense tools that randomize the name of the executable and/or the service or drivers required to run each time they are run?

    What happens when you install a dead man's switch service when the AV/EDR executable/service/driver are otherwise disabled or removed entirely?

    In conversation about 3 months ago from gnusocial.jp permalink

    Attachments


  13. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 18-Apr-2025 15:12:42 JST da_667 da_667
    in reply to
    • Viss
    • Taggart :donor:

    @mttaggart @Viss any of you around long enough to remember defense tools for the blind?

    https://sourceforge.net/p/dtftb/code/HEAD/tree/

    tl;dr: "nobody gets shells, now that this daemon is running. I'm not locked in here with you, you're locked in here with me"

    In conversation about 3 months ago from infosec.exchange permalink
  14. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 12-Apr-2025 03:10:17 JST da_667 da_667

    For the record, the 2020 Election wasn't stolen. Fuck the current administration.

    In conversation about 3 months ago from infosec.exchange permalink
  15. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 07-Apr-2025 22:34:31 JST da_667 da_667
    in reply to
    • Kevin Beaumont

    @GossiTheDog that was incredibly awful, not gonna lie. Wonder which rainforest had to burn down to render that demo.

    In conversation about 3 months ago from infosec.exchange permalink
  16. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 04-Apr-2025 22:26:12 JST da_667 da_667
    in reply to
    • silverwizard

    @silverwizard if you're looking for minaturized hardware, the minisforum ms01 is REALLY good. Otherwise... I'm not sure about full-size server hardware

    In conversation about 3 months ago from infosec.exchange permalink
  17. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 29-Mar-2025 18:42:36 JST da_667 da_667

    I don't want AI models taking all of my favorite media and movies from growing up, enshittifying them, and devaluing the effort and care it took to make.

    I'm sick of AI taking my hobbies and my recreation, and telling us all that its a fucking revolution. Motherfucker, its theft.

    AI should be doing my fucking chores, not devaluing the things I want to do in my free time.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      For Sale Page
  18. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 29-Mar-2025 16:20:44 JST da_667 da_667

    never do when you can overdo: A guide to excess, and anticipating software developers stuffing shit into javascript that should never be there.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/244/412/136/546/763/original/63a8a46ad0dd4f19.jpg
  19. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:00:48 JST da_667 da_667

    Never thought I'd be able to work in Heisenberg Uncertainty Priciple, Hawthorn Effect, and Freeman's Mind into the same chapter of a book.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/242/721/077/676/264/original/5f4972010994d4e2.png
  20. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 27-Mar-2025 06:56:19 JST da_667 da_667

    this microservice could have been a sql query

    In conversation about 3 months ago from infosec.exchange permalink
  • After
  • Before

User actions

    da_667

    da_667

    Senior Security Researcher, Proofpoint Emerging Threats.I've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.Work-Related hashtags:#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetectionHobbies:#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorking #HomeLab

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          30576
          Member since
          18 Nov 2022
          Notices
          151
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.