Remote
0
Followers
0
Following
17
Posts
Joined April 26, 2022
Languages:
Deutsch, English
Family:
Wife, 2 sons and a cat
Profession:
Security Engineer
Hobbies:
My homelab in a rack in the basement
Posts
SaaS companies adding AI to their products seem to be completely clueless on how to fix the security issues that this brings:
https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data
Open post
Replying to
@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social I see a lot where the cause of the incident is the uncontrolled usage of GenAI. Not where GenAI is the adversary or used by the adversary.
1
0
0
0
Open post
Replying to
@tiraniddo@infosec.exchange
0
0
0
0
Open post
Replying to
@vimja@tooting.ch
3
0
0
0
Open post
@campuscodi@mastodon.social All questions and references to the vulns in GitHub discussions and issues get deleted immediately.
Also someone running a honeypot saw scans of a possible RCE:
@heinen@infosec.exchange
Seems to be a real shitshow for a CNCF Landscape project with 25k GitHub Stars. I hope noone is using it.
0
0
0
0
Open post
Replying to
@UnderTheDome@troet.cafe
@UnderTheDome@troet.cafe @CiclistaRubio@norden.social Shift + Alt wechselt zwischen Anzeigesprachen, Ctrl + Shift zwischen Tastaturlayouts.
Falls du die Tastenkombibation nicht explizit deaktiviert hast ("input language hot keys" in den Einstellungen) sind die noch aktiv.
Hat mich auch schon Haare gekostet..
1
0
0
0
Open post
Replying to
@KeyJ@mastodon.gamedev.place
8
0
0
0
Open post
Replying to
@RoganDawes@infosec.exchange
@RoganDawes@infosec.exchange @ifrauding@don.linxx.net @goncalor@infosec.exchange @campuscodi@mastodon.social HDMI also has an Ethernet channel. However Notebooks usually do not implement it.
Also Displayport 1.1 afaik also has a "High" (2MB?) bandwidth back channel, however also not implemented usually and removed from newer DP standards.
So they seem to have a particular threat scenario in mind but I can't imagine what it is.
Also the threat model could be home office where the secure notebook is attached to the unsecure home monitor/tv or doing meetings at outside facilities where you don't particularly trust the beamer/display but still want to show media. But yeah, woud be really interesting what it does.
1
1
0
0
Open post
Open post
Replying to
@SwiftOnSecurity@infosec.exchange
1
0
1
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w I don't know if this is what you want but you can already do this with EDL (External Dynamic Lists) if you have a webservice delivering the IPs for the ASNs:
https://iserv.nl/files/edl/feed.php
Trend Micro replied to a similar Feature Request that they don't have a good enough data source to allow this (I suggested MaxMind ASN).
2
1
0
0
Open post
Replying to
@tschaefer@ipv6.social
@tschaefer amazon.com doesn't have AAAA records, it's only reachable via IPv4 but it redirects to www.amazon.com which has IPv6 connectivity.
1
2
0
0
Open post
Replying to
@davidhuser@swiss.social
@davidhuser@swiss.social You could also have a look at the autodiscover.example.net DNS record to get an idea about where mailclients will be connecting to. This would help to identify the infrastructure of municipalities who use gateways to receive as well as send mail.
1
1
0
0
Open post
Replying to
@davidhuser@swiss.social
@davidhuser@swiss.social A lot of them have spf.protection.outlook.com in their SPF which means that there is a high probability that the mailboxes are actually hosted on M365 but they use a (cloud-hosted) mail security gateway like SEPPMail or cleanmail et al.
I just checked some and the map should be a lot more red IMHO.
0
2
0
0
Open post
Replying to
@faebudo@ioc.exchange
@albrecht@masto.a0s.de @tschaefer@ipv6.social Oh Scheisse, das IPv4 Netz auf das die Source genattet wird ist ein RFC5737 Documentation Address Block.
Das kann sich einfach niemand ausdenken..
1
2
0
0
Open post
Replying to
@albrecht@masto.a0s.de
@albrecht@masto.a0s.de @tschaefer@ipv6.social Ich würde einfach mal ganz frech raten das das Ihre Lösung ist für einen grossen Kunden der einen Grossteil der Infrastruktur bei AWS mit IPv6 hat (IPv4 kostet extra) und für "digitale Souveränität" trotzdem noch einen Dienst bei StackIT im Backend benutzt und diesen erreichen will.
Ganz geil ist ja auch das man nach dem NAT64 gar nicht mehr weiss woher der Traffic kommt und einfach alles an Traffic akzeptieren muss.
Somit hat man als StackIT Kunde keine Chance mehr irgendwelche Angriffe auf Netzwerkebene abzuwehren.
0
2
0
0
Remote instance
ioc.exchange
Open on original server