AstraKernel, to infosec

Password generation

#infosec #jazz #guitar #music

juliewebgirl, to infosec
@juliewebgirl@mstdn.social avatar

WAIT! WTF??

When did it become law to require #2FA if customer info is on a server??

Alternately, what companies are making that shit up so that they can force 2FA??

And stop this madness convincing people to use 2FA when they don't even know what it's called or how it actually works other than "they send a code to your phone"!!

HEADDESK
HEADDESK
HEADDESK

#infosec @elfin

alis, to infosec

A collection of some of the worst password “rules” from around the web.

Most of these are here for having length maximums and/or restrictions on special characters which, given we live in Ye Moderne Times and best practice password advice is to use pass phrases, is, uh. Yeah.

#infosec #tech

0xor0ne, to infosec
cybercareersblog, to infosec
carlypage, to random

NextGen Healthcare, a US-based provider of EHR software, says hackers breached its systems and stole the personal data of more than 1 million patients https://techcrunch.com/2023/05/08/nextgen-healthcare-data-breach/

EpiphanicSynchronicity,
@EpiphanicSynchronicity@pkm.social avatar

@carlypage Maybe it’s overly draconian, but my first impulse when I see things like this is to legally forbid vendors that lose control of patient data like that from calling their products and services HIPAA-compliant. Because they no longer are, and the stakes are just so high.
#uspolitics
#healthcare
#InfoSec

SecureOwl, to infosec

You can download the complete Pen Test Diaries series on Kindle for FREE today: https://www.amazon.com/dp/B095J4KX4F

The Pen Test Diaries allow you to follow penetration tester Laura Knight through the technical, and non-technical processes involved in testing an organisations information security measures.

Based on the author's real world experiences, the diaries tell fictionalised versions of penetration testing discoveries.

#infosec #pentest #pentesting #cybersecurity

abrignoni, to infosec

Sometimes the things you don't want to hear are the things you need to hear the most.

0x58, to infosec

Another week, another bunch of cool #infosec events :)

🇸🇬 May 9-12 #BlackHatAsia
🇫🇷 May 12 @sth4ck
🇺🇸 May 12 @sleuthcon
🇺🇸 May 12 @bsidesknoxville

More here 👇

https://github.com/xsa/infosec-events

0xor0ne, to infosec

Excellent analysis, explanation and exploitation of CVE-2019-5736: vulnerability in runC (Docker) that allow to gain root privileges
(credits Yuval Avrahami)

https://unit42.paloaltonetworks.com/breaking-docker-via-runc-explaining-cve-2019-5736/

#docker #infosec #cybersecurity

image/jpeg
image/jpeg
image/jpeg

alevsk, to opensource

Two weeks ago I had the chance to learn new recon techniques from the great Jason Haddix at #RSAC2023 and now I have more domains than I can handle. I built a tool to organize and sort the data called Recon MindMap.

It's #opensource and it's available at https://github.com/Alevsk/rmm

Recon MindMap (RMM) can receive data from pipe or read from a file, it will automatically organize the data in a hierarchy and sort it alphabetically, it generates output in json, markdown or plain text compatible with mind map tools like Obsidian or Xmind

#infosec #opensource

image/png
image/png

fedops, to infosec
@fedops@fosstodon.org avatar

Read this and weep if you're tasked with protecting windows systems:

https://www.fo-sec.com/articles/compromising-mdatp-endpoint

It's 2023 and yet password hashes can be trivially dumped from memory and decoded since they use known-broken algorithms. And information exfiltration can defeat so-called endpoint protection by being fast enough. What?!

Running any kind of business-critical process on windows systems is nothing but gross negligence. If you have a ransomware attack you're the problem, not the victim. #infosec

0xor0ne, to infosec
cybercareersblog, to infosec
PogoWasRight, to infosec

Murfreesboro Medical Clinic reopens some, but not all, services after April ransomware attack. Attack appears to be work of BianLian:

https://www.databreaches.net/murfreesboro-medical-clinic-reopens-some-but-not-all-services-attack-appears-to-be-work-of-bianlian/

#databreach #ransomware #infosec #cybersecurity #incidentresponse #HealthSec

@serghei @allan

0xor0ne, to infosec

Tigress is a nice little piece of software for obfuscating software written in C

https://tigress.wtf/introduction.html

It can apply a lot of different transformations:

https://tigress.wtf/introduction.html

#infosec #cybersecurity #obfuscation #tigress

image/jpeg
image/png

bodomenke, to infosec
@bodomenke@hessen.social avatar

Does anybody of the #InfoSec-bubble work with #KnowBe4 security awareness trainings?

https://www.knowbe4.de/de/produkte

alex_02, to infosec

For anyone with a youtube channel specifically for hacking/infosec... did you guys start out with a set path?

I'm going to be working off of some very budget setup, but my idea is to start out small with 15 to 20 minute videos. I want to cover several topics specifically hacking on a budget (I have a lot to share on this), hardware, osint, talk about recent news possibly, talk about recent hacks by gangs, apts, hacking groups, etc.

I'm kind of going off into the unknown with this and not expecting to become big anytime soon, but I want to at least try.

I am also trying to figure out what to do with a Patreon and at the moment I don't even have a phone plan so not even sure if the content I will make will be any good.

Any input would be appreciated.

#infosec #infosecurity #hacking #youtuber #youtube #osint

zaibatsu, to infosec
@zaibatsu@masto.ai avatar

Changes to Twitter's verification system make it easier to spoof accounts reporting election results https://bit.ly/3NLqepC?utm_source=dlvr.it&utm_medium=mastodon #infosec #disinformation #security

monkeyninja, to infosec
@monkeyninja@mastodon.cloud avatar

Just witnessed this guy trying to explain ARP Poisoning (incorrectly) to a female network admin/#redteam #infosec friend and I admit, I was torn between calling him on it or checking to see if anyone had invented the term LAN-splaining yet.

0xor0ne, to infosec

Interesting reading about call stack spoofing on Windows for EDR evasion
(credtis @joehowwolf )

https://labs.withsecure.com/publications/spoofing-call-stacks-to-confuse-edrs

#redteam #offsec #infosec #cybersecurity

image/jpeg
image/jpeg

PogoWasRight, to infosec

Two class action lawsuits against home healthcare providers get preliminary settlement approval;
https://www.databreaches.net/two-class-action-lawsuits-against-home-healthcare-providers-get-preliminary-settlement-approval/

Maxim Healthcare and SuperCare lawsuits.

DataBreaches looks for provisions in settlements that require improved data security. Some settlements do not seem to include much provision for that. And some keep those provisions confidential. In these two cases, one kept it confidential but the other one spelled out changes.

Would love to see some lawyers go through all the settlements involving patient data and see how much improvement in data protection is being written into settlements to reduce risk of future attacks.

#databreach #dataprotection #infosec #cybersecurity #datasecurity #lawsuit #settlement #transparency

oci3o, to infosec
yuliyan, to SmallWeb
@yuliyan@nahe.social avatar

Digital wellbeing move of the week: I set up an e-mail address for the sole purpose of signing up to newsletters. From idea to action in just 3 years, wow.

What are some rad newsletters to sign up for?

Topics:

'preshy8)

kpwn, to javascript

Pentesting web applications thoroughly requires you to analyze their #JavaScript.

I've summarized my knowledge from 5 years of pentests into a series of threads.

Part 3: O̸b̸f̵u̷s̸c̶a̵t̶i̶o̸n̵ & Deobfuscation

➡️ Minification, beautification, obfuscation and deobfuscation

#Infosec #CyberSecurity #BugBounty #Pentesting

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines