ax0n

@ax0n

Buy it. Use it. Break it. Fix it. Husband. Tabby Wrangler. Bot Hunter. SecOps. DFIR. SysAdmin. When in doubt, use BSD. Hard NOCs Class of '06. Tweets my own.

Kansas
Joined April 2008

Tweets

You blocked @ax0n

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @ax0n

  1. Undo
  2. Feb 23
    Undo
  3. Retweeted
    Feb 11

    Today, the Cole County prosecutor declined to file charges against me over my discovery of a flaw in a public website. This decision is a relief. But it does not repair the harm done to me and my family. Here is my personal statement on these matters:

    Show this thread
    Undo
  4. Retweeted

    It's time for all of us in , to stop blaming and take responsibility. To look at hiring differently. To take risks on people. To focus on growing grassroots talent. And ultimately to . I am so thankful every day for all the leaders in my past /11

    Show this thread
    Undo
  5. Jan 23

    Last night, the "K2 Stresser" control panel had thousands of infected systems shown.

    Show this thread
    Undo
  6. Jan 23

    C2/Payloads: 107[.]189.12.110 Payloads: http port 80 C2: TCP port 6969 Panel: http port 666 C2 check-in text: "educatia e ca erectia, de o ai se vede" I posted many related file hashes in this "Discussion" on VirusTotal:

    Show this thread
    Undo
  7. Jan 23

    The remaining 3 are part of a "Stresser" style DDoS toolchain. The downloader, C2 and binaries are all hosted on the same machine. I found the (unauthenticated) "K2 Stresser" HTTP control panel running on an alternate port on the C2 system. Anyhow here are some IOCs 3/?

    Show this thread
    Undo
  8. Jan 23

    Each platform (Targeting amd64 FreeBSD, amd64, i386, i686, mips, arm and arm64 Linux) downloads 4 binaries: "main" "TCP-HTTP", "HTTP-Basic" and "UDP-Basic". All four appear to have been written in Go. The "main" binary checks in to c2 by sending some humorous Romanian text. 2/?

    Show this thread
    Undo
  9. Jan 23

    Last week, my honeypot snagged a mundane "Downloader" that does the old "detect platform, download binaries" dance. I've caught 3 iterations of the loader, they're only detected by a few on . The dozens of bins? All of them reporting clean. 1/?

    Show this thread
    Undo
  10. Retweeted
    Jan 21

    I get asked about 10 times a week about blocking traffic based on geolocation in our various tools that can do it. Let me say this again for those in the back: Blocking by geo will not save you. It’s just as easy for them to attack you from a compromised host in your country or

    Show this thread
    Undo
  11. Retweeted
    Jan 17

    Spent my weekend busting my butt to get new folks into our industry, and come back to more gatekeeping. Know this: You can succeed in and enjoy cybersecurity. Regardless of gender, race, background... Society and life may throw hurdles, but lots of us want to help you succeed.

    Show this thread
    Undo
  12. Retweeted

    As a high school dropout my unpopular opinion is... Any route a person manages to take to get to the place they are at is valid. So those able to attend college for the specialization they are passionate about is beneficial and does not take away or devalue all other routes! 🧐

    Undo
  13. Retweeted
    Jan 17

    I've found this on VT

    Undo
  14. Retweeted
    31 Dec 2021

    Sometimes I notice people trying for hours to evade one of my signatures and finally succeed for a moment - until they notice that their evasion triggers a different signature 😂 Oh boy, I love my job.

    Undo
  15. 28 Dec 2021

    Axon's corollary to The Third Law: Any sufficiently antiquated technology is indistinguishable from magic.

    Undo
  16. Retweeted

    Restored a TRS-80 CoCo model 2. Was in pretty bad shape with multiple cable burns and yellowing Interesting fact is that this this computer ran at 880kz which was the same frequency as our home town AM radio station KWIP Fond memories of playing games with my friend Mike on it

    Undo
  17. Retweeted
    9 Dec 2021

    Good news! Thanks to everyone’s support Dan Kaminski will be inducted into the Internet Hall of Fame during a December 14th ceremony. The livestream will happen 06:00-08:00 Pacific Time Zone (14:00-16:00 UTC):

    Undo
  18. 1 Dec 2021
    Undo
  19. 25 Nov 2021

    Adjective Noun Adjective Club. 🤡

    Undo
  20. 17 Nov 2021

    Do you know how to use the ed(1) line editor in a pinch? I reformatted a shared Windows 11 and partition from FAT32 to ExFAT but forgot to edit my fstab entry. Whoops. (cc )

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·