chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

If you’re on #Discord be careful but this is in part a large reason why I force the invite link to be a 301 I did on Cloudflare to discord.chiefgyk3d.com and disabled invite creation. It’s not only more convenient but to me a bit more secure #infosec
https://krebsonsecurity.com/2023/05/discord-admins-hacked-by-malicious-bookmarks/

cybercareersblog, to infosec
cybercareersblog, to infosec
cybercareersblog, to infosec
0x58, to infosec

Loving the new @substackinc dashbaord. Much more clear and with lots more of relevant information one wants to see about their publication :dance_cool_doge:​

Mine here's btw 👇 :flan_wink:​ #infosec

https://0x58.substack.com

michael, to infosec
@michael@thms.uk avatar
moira, to infosec
@moira@mastodon.murkworks.net avatar

Holy shit did we dodge a bullet. When I upgraded our mastodon server last December I originally ordered a Gigabyte motherboard as part of the upgrade, ended up sending it back as defective.

Turns out it was much, much more defective than I knew.

#InfoSec #gigabyte #backdoor #HolyShit #NoMoreGigaByteForMeThanks

https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/

chikorita157, to infosec
@chikorita157@sakurajima.moe avatar

This is probably worse than the Asus motherboard warrenty debacle over AMD Ryzen 7000 3D cpus exploding cpus and killing Asus mother boards.

https://arstechnica.com/security/2023/06/millions-of-pc-motherboards-were-sold-with-a-firmware-backdoor/

Not that many good selections of motherboards since Asus, Gigabyte, and MSI are apparently bad brands.

#gigabyte #infosec

odr_k4tana, to infosec

#Infosec and #socialengineering mastonauts: Do you have any experience with using masterprints for fingerprint sensors? Interested in looking into that for teaching purposes....

taeluralexis, to infosec

I’m officially 2 weeks into my PNPT journey. The main course has so far gone over enumeration & OSINT, finding & utilizing exploits against systems & crafting our own buffer overflow attacks, & using tools such as Burp Suite, Metasploit & Nessus.

Now we’re focusing heavy on Active Directory. I did an LLMNR poisoning attack to grab domain user credentials & used Hashcat to crack the hash last week.

But I was STUCK on SMB relay attacks lol but I was able to get it lol #infosec #cybersecurity

0xor0ne, to infosec
9to5linux, to opensource
@9to5linux@floss.social avatar

#OpenSSL 3.1.1, 3.0.9, and 1.1.1u are out now and include bug and security fixes!

#OpenSource #Linux #infosec

0xor0ne, to infosec

Intersting reading about the Go-based DDoS-focused botnet HinataBot targeting Linux devices

https://akamai.com/blog/security-research/hinatabot-uncovering-new-golang-ddos-botnet

#botnet #infosec #cybersecurity

image/jpeg
image/jpeg

avoidthehack, to infosec

More malicious extensions in #Chrome Web Store

At least 18 different malicious extensions (as of 30 MAY and this post) identified by @WPalant

Remember extensions have privileged access to the browser (and data in the browser). Choose your extensions wisely... they could be #spyware or #malware in disguise.

#cybersecurity #infosec #security #opsec #privacy

https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/

9to5linux, (edited ) to linux
@9to5linux@floss.social avatar
AstraKernel, to php

🪲 PHP developers and other developers, can you identify what is the issue in this code?

(No comment like "PHP". Save it for some other time 😀. This can happen in any language)

#php #CodeIgniter #programming #development #developers #laravel #infosec

CharlieMcHenry, to infosec
@CharlieMcHenry@connectop.us avatar

A popular Android app, iRecorder, began secretly spying on its users months after it was listed on Google Play https://techcrunch.com/2023/05/29/popular-android-app-microphone-spying-google-play/ #infosec #Malware #Android #smartphone #SmartPhones #iRecorder

0xor0ne, to linux
0xor0ne, to infosec

A must read for anyone interested in Wi-Fi security
Exploit power safe features for leaking clear text frames and more

GitHub: https://github.com/vanhoefm/macstealer
Paper: https://papers.mathyvanhoef.com/usenix2023-wifi.pdf

#infosec #cybersecurity #wifi #wireless #security

image/jpeg
image/jpeg

marcchehab, to infosec

Dear #infosec community. How come we use Mastodon and not Nostr? I find it a little odd because, technically speaking, Nostr is way more interesting, don't you agree? User experience is great on Mastodon (talking elk.zone) though - and the crowd is better (in my bubble anyway). What's your take on Mastodon v Nostr? Genuinely interested in your opinions

SecureOwl, to infosec

Why should you aspire to be an information security librarian rather than an information security rockstar?

When you should build a security tool versus buy it?

What physical security risk does a Honda Civic pose to your business?

Which area of information security was I surprised to find out was the most time consuming but important area to work on?

Find answers to all these questions, and more, in Security Operations in Practice, available from all good bookstores, and various online/digital marketplaces.

https://shop.bcs.org/store/221/detail/workgroup?id=3-221-9781780175065

taeluralexis, to infosec

#100DaysOfHacking Officially started the next round of my journey learning infosec & it’s my birthday month sooo lol I gotta start off big.

I started this morning with learning crackmapexec which took the first set of credentials I found after compromising a system on Active Directory & found other machines on the network where I can use those creds. It also dumped the SAM hashes!

Last night I used Bloodhound to perform enumeration of an AD domain, it was so cool lol #infosec #cybersecurity

JimGuckin, to infosec

Maybe I've been in #infosec too long, but this sign makes me trust the coffee machine less. It makes me feel like it's an in person #phishing test.

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Things I may be working on in my upcoming #twitch streams spinning up a @matrix instance, Umbrel Bitcoin node with Electrum on a @Raspberry_Pi, Arduino tinkering with my Inventr.io kit, diving more into @GrapheneOS, and redoing my @QubesOS setup on my @purism Librem 14 laptop. #infosec #streamer

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

I'm running #pihole in recursive #DNS mode and having everything in my home and my public /29 use it as the main DNS server.

The good things? Ad/tracker blocking on things that don't have built in ad/tracker blocking like certain phone apps, less spam (I host my main mail server locally), reduced monitoring from my Internet provider.

The bad things? Single point of failure. If pihole is down, everything else is as well.

#FirstWorldProblems #ItsAlwaysDNS #infosec #homelab

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • thenastyranch
  • magazineikmin
  • mdbf
  • GTA5RPClips
  • everett
  • rosin
  • Youngstown
  • tacticalgear
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • khanakhh
  • megavids
  • tester
  • ethstaker
  • cubers
  • osvaldo12
  • cisconetworking
  • Durango
  • InstantRegret
  • normalnudes
  • Leos
  • modclub
  • anitta
  • provamag3
  • lostlight
  • All magazines