nyan
nyanbinary@infosec.exchange
<p>Little goblin with catears.</p><p>Unfinished projects, complaining about computers, reinventing the wheel (badly), has not fully read any docs since 2015. Certified cognitohazard.</p><p>Proud bot parent to many failsons:<br /><span class="h-card" translate="no"><a href="https://infosec.exchange/@enojifier_bot" class="u-url mention">@<span>enojifier_bot</span></a></span> <br /><span class="h-card" translate="no"><a href="https://infosec.exchange/@dreizehnzwoelf_bot" class="u-url mention">@<span>dreizehnzwoelf_bot</span></a></span><br />Infosec related: <a href="https://infosec.exchange/collections/116931760660109009" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/collections/1</span><span class="invisi
Posts
-
Post #4502381
Note to self: Do not abbreviate "Germans" to "Germs"
-
Post #4501814
I guess I am picking a fight with ANOTHER CNA, aren't I?
-
Post #4462871
Sonicwall
-
Post #4442058
tfw some automation breaks because you didn't even consider folx would post attachments without alt text :neobot_giggle:
- Post #4429322
- Post #4422432
-
Post #4414735
F32.2 L :3
-
Post #4395420
RE: https://infosec.exchange/@dotdotslash_bot/117044868305159984 @GossiTheDog@cyberplace.social they seem to be working for me? :dragnconfused:
-
Post #4390933
Fine, I guess I am writing my own suricata rules now
-
Post #4383331
considering writing a quick bot to automate winning the bonking war ... or at least prevent the other side from winning
-
Post #4380453
Multicloud is if your service goes down if AWS or Azure have issues :3
-
Post #4378687
Civic pride 😌
-
Post #4376116
fuck it, need snack, brb
-
Post #4374876
New blogpost: https://blagh.nyanbinary.de/posts/on-those-mitre-sqlite-vulnerabilities/ Some digging on who might be behind the SQLite fake vulnerabilities (a University research team, probably as part of a paper) & how MITRE continues to be not very good at this whole "CNA" thing. Please don't mistake me complaining about stuff as journalism :neodog_gun: Also: Go and look at GCVE. Especially if you are working at a security vendor & are fed up with the issues of CVEs. N...
-
Post #4371970
Happy August 4th to those that celebrate.
-
Post #4371657
spreadsheets? :neofox_drake_dislike: spreading them cheecks! :neofox_drake_like:
-
Post #4363044
Wanting to do a quick Darktide round before bed, already took the meds that make me groggy. First mission was cancelled after a quarter, second one is me backfilling a mission into the game over screen, now game is hanging... ... cmon, I'm on a timer, lol, soon me dodge weaving my psyker ass through hordes of specialists isn't gonna be very ... elegant anymore!!!
-
Post #4361438
ToDo: Check if the usual sysmon configs report on infostealer-typical file accesses
-
Post #4361006
Hire me. Experience: Couple of years Vulnerability Management, Security Consulting/Solution Design, in-house IR, technical ops of security tooling, security testing/finding validation when actual pentesting would have been too expensive to hire. Love the terminal, good at talking to techies & lower management, don't let me near upper management. Would honestly love to pivot to something more technically specialized, but open for pretty much everything (except 100% paper work or daily...
-
Post #4360357
So, for the three people that haven't seen it: MITRE waved through a bunch of bogus vulnerabilities in SQLite and issued CVEs. Primary reporting: https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ SQLite Forum Thread: https://sqlite.org/forum/forumpost/34bdf3b9bd759d4d IFIN thread: https://discourse.ifin.network/t/sqlite-critical-cves-or-llm-slop-jfrog-security-research/ I am very much not surprised that this happens (having seen the bottom-of-the-barrel vulnerabilities th...
-
Post #4360044
OF COURSE IT WAS MITRE
-
Post #4352952
Head hurty :neocat_pensive:
-
Post #4350763
New (short) blogpost: curl | bash > AUR. This is mostly unrelated to the recent attacks. I just think AUR is dangerous as a concept as it creates intransparency around trust. https://blagh.nyanbinary.de/posts/curl-bash-aur/
-
Post #4337615
RE: https://infosec.exchange/@nyanbinary/117027901823593906 normalize sending infostealers to your friends to keep in touch & provide them enrichment
-
Post #4337317
Disocrd scammers, I dont have time for this back and forward, just send me the fucking payload already
-
Post #4322035
meow?
-
Post #4282362
tfw you see something on fedi but you hate "ai" so much you literally trace all the struts of the london eye by hand so you don't have to look at the "ai" thingy...
-
Post #4280242
Sanity check: Does Librewolf seem kinda slow with solving Anubis challenges (recently)?
-
Post #4274976
I should have threaded this entire thing but it was all scattershot posting anything, lets start the thread now. And to make it clear: I'd be appreciating advice here, if there are any wizards around. So, after an update + reboot yesterday my laptop (Arch btw) doesn't want to do decryption for the full disk encryption anymore. Setup: UEFIone nvme drive, gpt, two partitions: /efi and encrypted lvmencryption is LUKS2, aes-xts-plain64, hmac(sha256) for integrityinside are then the actua...
-
Post #4237606
Motherf... I cant clone https://sourceware.org/git/glibc.git because I get a 429... every time, including the first time I visit the site.