Posts
2716
Following
681
Followers
1506
"I'm interested in all kinds of astronomy."
repeated

A companion blog to my Bluehat 2024 presentation on OleView.NET is up now. https://googleprojectzero.blogspot.com/2024/12/windows-tooling-updates-oleviewnet.html

0
5
1
repeated

Ever wanted to know what data or other programs send to AMSI. I wrote a C# COM server implementation that logs this data as a JSON string. Had some fun learning more about COM and .NET AOT with this little project https://github.com/jborean93/AmsiProvider

0
5
1
repeated


has just released a PANOS update, 10.2.13, which includes this interesting little fix. Looking at the portal logs from the management console or CLI I can't see any cleartext passwords being logged in regular or debug mode.

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-13-known-and-addressed-issues/pan-os-10-2-13-addressed-issues

1
3
0
repeated

Here's the slides to my PoC 2024 keynote "An insider perspective on the offensive industry": https://webdl.nso.group/OffIndustry-PDF.pdf

My apologies for the delay in publishing these.

2
9
0
repeated

Astalavista.com - Security Community - Relaunch 2024 https://forum.astalavista.com

0
3
0
To understand the reality of today both in tech and society as a whole it is important to realize the *adult people can't fucking read*

https://www.oecd.org/en/publications/survey-of-adults-skills-2023-country-notes_ab4f6b8c-en/hungary_c8c395ed-en.html

(Check below for more countries)
1
0
3
repeated
repeated

❄️☃️Merry Jerry🎄🌲

Hear ye hear ye

The following instances will be offline briefly on Saturday, December 14 from 9am ET / 2pm UTC for approxmately 10 minutes:
infosec.exchange
infosec.town
infosec.pub
pixel.infosec.exchange
books.infosec.exchange
matrix/element.infosec.exchange
relay.infosec.exchange
meetup.infosec.exchange
video.infosec.exchange
infosec.press
infosec.place
fedia.io
fedia.social
elk,.infosec.exchange
infosec.space
convo.casa

The servers supporting these instances require a reboot. The Dell servers these instances run on take a very long time to boot, so I am estimating 10 minutes of downtime. It could be more, could be less.

We use live patches to minimize reboots needed for patching, however Ubuntu only provides livepatch support for a year, which is how long most of these systems have been running for.

5
3
0
repeated

In his latest blog, ZDI researcher Piotr Bazydło covers a pre-auth Arbitrary File Deletion vulnerability he discovered in the SolarWinds Access Rights Manager (ARM). It may not sound exciting, but it can lead to a local privilege escalation on domain-joined Windows machines. Read the details at https://www.zerodayinitiative.com/blog/2024/12/11/solarwinds-access-rights-manager-one-vulnerability-to-lpe-them-all

0
4
0
@mttaggart "Security is a Specialization" <- this 1000x
0
0
2
repeated

It's time for everybody's favorite: unsolicited advice!

In which I discuss the reality of the cybersecurity jobs market, and what you really should be doing to improve your chances.

https://taggart-tech.com/20241212-2025-jobs-guide/

4
5
0
@mainframed767 @racingmars "business-y sounding report" -> I'm sorry but I'm triggered by this... "business-y" content is wasting my time, and IMO if someone prefers that instead of an on-point, although stylisticly imperfect report, it's the reader's problem not the writer's.
0
0
0
repeated
@cR0w Yeah I wonder if anyone tracks the frequency and impact of its bugs when doing supply chain analysis...
0
0
1
Apache incubator projects have always been gold mines, but Solr stands out based on the traffic it generates on Full-Disclosure...
0
0
2
repeated

Fixed the OpenGraph image on Shazzer it was bugging me. Then did a normalization vector to test it!

https://shazzer.co.uk/vectors/675add23a8574986b36cc848

0
2
0
repeated

I can't seem to get WebView2 working in a Visual Studio extension, so I'm dropping that effort for now.

If anyone knows how to do this, or actually wants Function-Graph-Overview in Visual Studio, let me know!

0
1
0
Show older