CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^
Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though!
How can I help?
(posts searchable via tootfinder)
Posts
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
Alright I'm speeding up my review of the phishing kits that my project, Phossil, collected. My current estimate is that over the last 5 years I've collected about 1,200 kits. I'm going to review these in two passes - first, just to identify whether they're legit phishing kits (not other malware, webshells, etc.). Later I'll review them for contents - leaked info, trends, targeted companies, etc. I'll be shitposting in this thread with anything funny that I see.
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
Ah man someone accidentally zipped up their Git repo in a phishing kit and I think their actual personal, professional info is in there. I'm looking at a GitHub and LinkedIn rn and I'm suspicious.
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
[clickbait] Check out this ONE WEIRD TRICK to make your credentials UNPHISHABLE!
Just add "fuck" ANYWHERE in your password, and when you get phished, the phishing kit will DISCARD your credentials as invalid WITHOUT sending them to the operator!!
Stay safe and don't forget to SMASH that follow button!! 🕵️ 🔒 ✨ 💪 🥰
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
Hmm. Phishing kits are putting more and more effort into blocking automatic security scanners. This is a relatively short set of evasion rules - I'm seeing some kits with eight *entire files* worth of rules of what IPs, hostnames, user agents, etc. to block.
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
A friend sent this to me and y'all might enjoy
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^ Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though! How can I help? (posts searchable via tootfinder)
Did a little explainer on what the request amplification problem is with Mastodon's link previews, what I observed in a small-scale test (traffic amplification of 36,000:1!), what website operators should know, etc. It's here for those curious: https://chris.partridge.tech/2022/request-amplification-in-mastodon/