cda

@CDA

Researcher on Internet infrastructure, state-sponsored hacking, sanctions, human rights, and authoritarianism; 'Blonde guy, talks about Iran a lot.'(ملا لغتی)

Washington, DC
Geregistreerd in januari 2009

Tweets

Je hebt @CDA geblokkeerd

Weet je zeker dat je deze Tweets wilt bekijken? @CDA wordt niet gedeblokkeerd door Tweets te bekijken.

  1. Vastgemaakte Tweet

    Now published through – "Iran’s Cyber Threat: Espionage, Sabotage, and Revenge" – the decade long history of Iranian cyber operations against foreign and domestic targets. By me and .

    Deze collectie tonen
    Ongedaan maken
  2. 6.) Re: 'voter database breach video.' Staged and fake. Attackers obscured details of the sqlmap operation, not to protect PII, but to hide what they are attacking. However, the attackers missed the target IP address in a log file – a VPS currently running SQL server in Moldova.

    Deze collectie tonen
    Ongedaan maken
  3. 5.) Re: this. The breached sites were on shared hosting servers, so naturally this happens. At least one of the emails was posted on VT, as was a COVID 19 scam sent from the same IP, but I think not from the same compromised account. Doesn’t seem related.

    Deze collectie tonen
    Ongedaan maken
  4. 4.) There has been some suggestion that the Proud Boys' inability to maintain hosting (good) contributed to the campaign, or that it was hacked. Both are incorrect. PB's doesn't seem to have DMARC set up so it was more vulnerable to spoofing. But Iran didn't hack the PBs.

    Deze collectie tonen
    Ongedaan maken
  5. 3.) Pretty clear no voter files were breached. Would seem residents of Florida are particularly susceptible to having their mailing and e-mail addresses posted online, including sites that offer 'don't scrape us, download our full dataset instead.' Weird case matches source.

    Deze collectie tonen
    Ongedaan maken
  6. 2.) The threats were sent using mailing scripts hosted on those breached domains; childish stuff, but the mailer probably provides a clue. Also the attacker seems to have used a VPN, looks like Private Internet Access. Sure that rings a bell for some threat intel folks.

    Deze collectie tonen
    Ongedaan maken
  7. 1.) There have been reports that the emails were sent from Estonia and Saudi Arabia. This is imprecise. Those behind the op had breached multiple websites, including Estonian and Saudi sites (using that ccTLD and hosted in, respectively). There are others.

    Deze collectie tonen
    Ongedaan maken
  8. There has been a frustrating dearth of information about these Proud Boy / Iran emails. So I want to take a moment to clarify a few matters. With all appreciation to those who shared samples, and to avoid trampling those who will produce more compelling/comprehensive write-ups.

    Deze collectie tonen
    Ongedaan maken
  9. 𝐼𝓃𝓉𝑒𝓇𝓃𝒶𝓉𝒾𝑜𝓃𝒶𝓁 𝒞𝓎𝒷𝑒𝓇𝓌𝒶𝓇

    Ongedaan maken
  10. Czesław Miłosz –

    Ongedaan maken
  11. New hobby project — coaware, a tracker for COVID-19 exposure notification apps, for watching and mapping their adoption. Built off the simple and inexpensive hardware.

    Deze collectie tonen
    Ongedaan maken
  12. Heh, "khar pedar." These Iranian hackers just don't give a damn.

    Ongedaan maken
  13. Ten thousand retweets and enraged quote tweets in reaction to a "police officer from Texas" calling for civil war – account created May 2020, which only tweets in the dead of night Texas time. We are so easy to game.

    Ongedaan maken
  14. If you’re targeted by harassment by and his clique, please email me at cda@cda.io. Rounding up reports.

    Deze collectie tonen
    Ongedaan maken
  15. I think another story here is buried. Whoever was behind the Telegram monitoring seems to have scraped Instagram for Iranian users using fake accounts and its recommendation system.

    Deze collectie tonen
    Ongedaan maken
  16. In the mystery of the leaked Iranian Telegram data, may I suggest BotSaz – the Telegram bot developer who's Gitlab was adjacent to the exposed Elasticsearch (and taken down at the same time) and doesn't care about security enough to leave PMA open.

    Deze collectie tonen
    Ongedaan maken
  17. Sure enough, when was killed, immediately went silent on Twitter and Telegram

    Ongedaan maken
  18. Ongedaan maken
  19. Apparent cuts to Iran's international internet connections this morning timed with announcement and protests (from ).

    Ongedaan maken
  20. The Clausowitz account has now been removed. I've converted and archived the World War 3 book for researchers. Whoever was trolling the situation decided to make some money from their hate.

    Deze collectie tonen
    Ongedaan maken
  21. Well this is novel (heh): a fake account playing off political divisions on Soleimani is promoting a 616 page, pro-Trump/anti-Iran eBook on Amazon. Looks like someone seeded a machine learning text generator with Iran and published the (incomprehensible) result.

    Deze collectie tonen
    Ongedaan maken

Het laden lijkt wat langer te duren.

Twitter is mogelijk overbelast of ondervindt een tijdelijke onderbreking. Probeer het opnieuw of bekijk de Twitter-status voor meer informatie.

    Je bent misschien ook geïnteresseerd in

    ·