Skip to content
0
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
da_667@infosec.exchangeundefined

da_667

@da_667@infosec.exchange
About
Posts
49
Topics
14
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • This post did not contain any content.
    da_667@infosec.exchangeundefined da_667@infosec.exchange
    This post did not contain any content.
    Uncategorized

  • "AI is giving attackers a huge advantage!"
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Viss @iagox86 @cR0w @darthnull sometimes, it can be pretty helpful. If for no other reason, the references sometimes point to an actual write-up instead of nuclei's meta-request template bullshit.

    Uncategorized

  • "AI is giving attackers a huge advantage!"
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @iagox86 @cR0w @darthnull what's incredibly fun is looking at nuclei-templates repo, thinking you've found something that can serve as a proof of concept for some thing you really needed, and its a GET request that they parse with regex for version strings.

    Thanks for that, I guess.

    Uncategorized

  • "AI is giving attackers a huge advantage!"
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @iagox86 @cR0w @darthnull If I had a dollar for every time I was looking up PoC/exploits for a given CVE, and its some slop report from a website that just seems to scrape cve.org and regurgitate it along with very generic remediation recommendations, I probably wouldn't be rich, but like, I could have a fairly nice lunch.

    Uncategorized

  • "AI is giving attackers a huge advantage!"
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @FuturisticRobert @cR0w @krypt3ia @Viss no shit. My hourly rate starts at 400 an hour, minimum of 4 hours.

    Uncategorized

  • No time to explain.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @catsalad Clavicus Vile, at it again.

    Uncategorized

  • It's been extremely hard to keep this one under wraps.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Dio9sys sorry to keep badgering you, and if you're under NDA or just don't want to right now, that's fine, but can you tell me if it was an actually cookie header value?

    Uncategorized

  • It's been extremely hard to keep this one under wraps.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Dio9sys Quick question- the initial payload string -- were you all seeing that in GET requests? POST requests? Attached to particular exploit attempts? Would love to sig it. I'll have Suricata rules for the C2 tomorrow (We just finished up QA release for today, unfortunately)

    Uncategorized

  • It's been extremely hard to keep this one under wraps.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Dio9sys Oh I live for unraveling stuff like this. I love your write-up. Extremely well-done, and thank you for sharing with us.

    Uncategorized

  • It's been extremely hard to keep this one under wraps.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Dio9sys every damn time I see something interesting, its either mirai or a crypto miner, lmao.

    Uncategorized

  • It's been extremely hard to keep this one under wraps.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @Dio9sys good to know I'm among the like-minded. Second I saw this I was like... "That's URL-encoded base64 with the double equal at the start, so... in reverse. Good times.

    Uncategorized

  • Tag your favorite application that has added an LLM agent nobody wants, babes
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @hacks4pancakes #firefox

    Uncategorized

  • This post did not contain any content.
    da_667@infosec.exchangeundefined da_667@infosec.exchange
    This post did not contain any content.
    Uncategorized

  • Theory: Security mindset is a curse added to another job
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @silverwizard oh yeah, definitely. I can't look at most computer things I touch without wondering how easy it would be to compromise the shit out of it.

    Uncategorized

  • I made a 1200 page book.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    and I say that without a hint of arrogance, I promise. I am my own worse critic, and I agonized over every detail.

    Uncategorized

  • I made a 1200 page book.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    I did this shit with draw.io. Free software. I produce diagrams that are better than those of a multi-billion dollar company.

    Uncategorized

  • I made a 1200 page book.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    Entire pages of this. Along with paragraphs of text to describe it in multiple ways -- for visual learners, as well as learners who just like to read to find their answers.

    Uncategorized

  • I made a 1200 page book.
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    RE: https://hachyderm.io/@thomasfuchs/116083589029041168

    I made a 1200 page book. Half of the pages were MASSIVE charts and diagrams meant to guide them along and make sure they didn't get lost.

    That one of the world's most valuable companies can produce slop and get away with it is an insult.

    Uncategorized

  • Today in InfoSec Job Security News:
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @GossiTheDog ladies and gentlemen, it's this stupid shit (tm) that we are paying up the ass for new SSDs and RAM for.

    Uncategorized

  • Today in InfoSec Job Security News:
    da_667@infosec.exchangeundefined da_667@infosec.exchange

    @GossiTheDog what's funny to me, is that there were influencers on linkedin a few days ago claiming claudecode could find vulnerabilities in code faster than humans, and they're like "look at all these openssl vulns it found!" now I'm like. "well no shit its finding vulnerabilities, when its the one introducing them."

    Uncategorized
  • 1
  • 2
  • 3
  • 1 / 3
  • Login

  • Login or register to search.
  • First post
    Last post