Scott Miller is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Scott Miller @Miller_Geek@infosec.exchange

So, do the and vulns create avenues for container or VM escape?

Thanks for the help everyone! Ultimately I'm pretty sure I'd need to use ARP poisoning, which is definitely out of scope as this isn't a sanctioned exercise. Alternately from an insider threat perspective I could capture traffic on the insecure servers, but I'm gonna call that out of scope for now as well.

Pleasantly surprised to find the problem isn't quite as bad as I expected, but still not great.

Hey guys, what tools would you recommend for capturing credentials sent over http on a local network? I need to make a point at work

Scott Miller boosted

@tinker - has threatened to sue security researchers in the past, including Fox-IT.

Wonder what other security vulnerabilities are in Keeper products that they wish to hide through litigation?

Scott Miller boosted

Bad idea! , a password manager bundled with Windows has a security flaw. Security journalists reported on it. What did Keeper do? Sued the journalists.

Fuck Keeper.

zdnet.com/google-amp/article/s

Scott Miller boosted

DO NOT USE ETHERDELTA RIGHT NOW!!!!

twitter.com/etherdelta

SOMEONE REDIRECTED THEIR DNS

(please signal boost)

c/ @Miller_Geek

Scott Miller boosted
Scott Miller boosted

An "NSA backdoor" proposed TLS extension finally turns up inthe wild: in random Canon printers that fail to work with TLS 1.3...
blog.cryptographyengineering.c
As the blog post points out at length, gee this spy stuff can be super mundane.

Scott Miller boosted

I'm always amazed at when I discover (through other people's research or my own) vulnerabilities in core aspects of networking that harken back to the earliest days of networking.

Back then, we just needed things to work. Didn't realize how much we would depend upon the net and web for our daily lives.

If it works, that was enough. No mind for security built in.

Scott Miller boosted

Had a chance to talk to high schoolers and early vocational school students (information security tracks) about hacking and pentesting. Spoke to two groups and walked them through a tabletop of breaching a company.

A lot of enthusiastic folks. A lot of great back and forth! That was a blast.

Scott Miller boosted

@Miller_Geek @icefox there's a huge environmental component imo - it's one of the reasons that I try to be more vocal about how sparse my knowledge is on some of the things I work on, to try and help destigmatize not knowing now kinda

Scott Miller boosted

Baby Boomers being awful at the post office again (and racist!) Show more

Scott Miller boosted
Please boost this. If you’re trying to start a co-op ISP don’t be like these fuckbags

https://www.fuckingrestech.com/

Public records can be creepy. I found the home phone number for the guy that owns the LLC that pays the taxes on an abandoned property near me.

Scott Miller boosted

death penalty, punishment, justice Show more

Scott Miller boosted

Oh Eris. Wow. Mudge posted a link to this. This is intense. I can’t download the python script linked in the post yet. If anyone grabs it, let me know:

archive.is/PQAnU

So...I might be getting Gigabit internet. Any ideas for what to do with that much bandwidth?

Scott Miller boosted

Ive had a friend in NC loose their job today. It looks very likely they were fired so that their employer could stop carrying their autistic three year old on the corporate health insurance. A child who lost an eye to cancer and is now recovering from said cancer. Their shopping for legal advice. If anyone has resources please let me know.

Scott Miller boosted

pol, FCC, lawsuit Show more