Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ret2kw
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ret2kw
-
Jessey Bullock proslijedio/la je Tweet
Over the past few years I've spent 100s (1000s?) of hours studying how companies have scaled their security. Here are my
@AppSecCali slides that distill what I've learned- the big, scalable, systematic wins that measurably improve your security posture.https://docs.google.com/presentation/d/1zbj9XBiv6r6zla0KHNfs63Ux45QZAfRut2zlK7o-dRw/edit#slide=id.g6555b225cd_0_1069 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
I'm excited to share my post about discovering & exploiting multiple critical vulnerabilities in Cisco's DCNM. Busting Cisco's Beans :: Hardcoding Your Way to Hell https://srcincite.io/blog/2020/01/14/busting-ciscos-beans-hardcoding-your-way-to-hell.html … PoC exploit code: https://srcincite.io/pocs/cve-2019-15975.py.txt … https://srcincite.io/pocs/cve-2019-15976.py.txt … https://srcincite.io/pocs/cve-2019-15977.py.txt …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Anticheats such as BattlEye have been trying to detect generic hypervisors, in particular those prevalent in the cheating community (DdiMon and hvpp), by using time-based detections. Here's some advice on that for the developers. https://vmcall.blog/battleye-hypervisor-detection/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
CVE-2019-19781 post-exploitation notes: If you are seeing attackers reading your /flash/nsconfig/ns.conf file then you need to change all passwords. The SHA512 passwords are easily crackable with hashcat.pic.twitter.com/mNMaTT1oCE
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Announcing BLAKE3!
* Faster than MD5, SHA-1, SHA-2, SHA-3, and BLAKE2
* Merkle tree: unlimited parallelism, verified streaming
* Builtin MAC, KDF, XOF
* One algorithm, no variants
* Rust crate: https://crates.io/crates/blake3
Try it: cargo install b3sum
http://blake3.io pic.twitter.com/QJWIwi44go
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
First #wasm security blogpost of 2020
Some people ask me, so here is how to start fuzzing #WebAssembly APIs of#browser JavaScript engines like Chrome/V8. In this blogpost, I'm using:
Dharma/Domato
Chrome/v8 ASan pre-built
Honggfuzz ;)https://webassembly-security.com/fuzzing-wasm-javascript-dharma-chrome-v8/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
WireGuard has been merged to net-next, which means it will be in mainline Linux for 5.6. Exciting day!https://twitter.com/davem_dokebi/status/1203855208599576576 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
New blog post. ARM hardware bug. In the specification. https://siguza.github.io/PAN/
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
BattlEye has for the past year been detecting unknown cheats using memory heuristics combined with a method known as stack walking: https://vmcall.blog/battleye-stack-walking/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
AWS Nitro Enclaves are little "sidecar" isolated VMs with no network access or storage that you can create and communicate to only from an EC2 VM to eg store secrets and keys in, do crypto. https://aws.amazon.com/ec2/nitro/nitro-enclaves/ … they also have attestation. Currently in preview.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Ever wanted to inject a shared library into an already-running linux process, without using ptrace? Well, now you can... https://github.com/DavidBuchanan314/dlinject …https://asciinema.org/a/290906
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
endlessh : SSH tarpit that slowly sends an endless banner : https://github.com/skeeto/endlessh More : https://nullprogram.com/blog/2019/03/22/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
An Android app to read and write MIFARE Ultralight EV1 tags https://github.com/grspy/ulev1plus
#NFC#AndroidHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Easy UNIX piping! No config options! Modern crypto! No keyrings! Public keys that fit in a tweet! No more looking up how to encrypt a file on StackOverflow.
age1t7r9prsqc3w3x4auqq7y8zplrfsddmf8z97hct68gmhea2l34f9q63h2kp
Try it out and send feedback
https://age-encryption.org pic.twitter.com/3pBSwKdRnc
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
New blogpost: Sanitized Emulation with QEMU-AddressSanitizer https://andreafioraldi.github.io/articles/2019/12/20/sanitized-emulation-with-qasan.html … I just open-sourced my QEMU patches to fuzz binaries with ASan, QASan. You can also use it with ARM targets on Linux, a thing that you can't do with LLVM ASan!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
I just published a massive guide for
@bellingcat on using reverse image search engines for digital investigation. I test out the Big Three services, ranking them with a running scorecard, and detail some creative search strategies at the end of the guide.https://www.bellingcat.com/resources/how-tos/2019/12/26/guide-to-using-reverse-image-search-for-investigations/ …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
icymi (I did!) here's the
@falco_org security audit results: https://falco.org/blog/falco-security-audit/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Looking for an exceptional candidate to join my exceptional team at Apple :) Deets below if you’re interested https://jobs.apple.com/en-us/details/200115837/vulnerability-management-engineer?team=CORSV …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
#IPv6adventcalendar (20): IPv6 Security Strategy, via@insinuator Baseline https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/ … Routing Layer https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-2-network-isolation-on-the-routing-layer/ … Filtering (I) https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-3-traffic-filtering-in-ipv6-networks-i/ … Filtering (II) https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-4-traffic-filtering-in-ipv6-networks-ii/ … First Hop Securityhttps://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-5-first-hop-security-features/ …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jessey Bullock proslijedio/la je Tweet
Signal Technology Preview for secure value recovery https://lobste.rs/s/6eufwt
#crypto#privacy#securityhttps://signal.org/blog/secure-value-recovery/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.