caspa is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

caspa @caspa@infosec.exchange

caspa boosted

#MastoAdmins If you're using Nginx and haven't updated your config in a few weeks, you should check out the latest recommended config: github.com/tootsuite/documenta Lots of new stuff in there!

- Immutable caching (faster reloads)
- HTTP2 (faster everything)
- Default CSP (scores A+ on Mozilla Observatory)
- Gzip compression
- Better SSL settings
- Probably some more stuff I forgot!

caspa boosted

If abusing Google search operators is sometimes called "dorking" can abusing Twitter's sometimes be called "twerking" ? 🤔

caspa boosted
mastodon v1.3.3 no longer does a DDoS to refresh feeds!
caspa boosted

We're looking for a new Comms Director! 😀 Know anyone who is qualified and wants to help tell the world about Tor? 🤓 Please help us spread the word. 👍

torproject.org/about/jobs-comm

caspa boosted
caspa boosted

For those of you interested in sending toots from command line. github.com/glynnbird/toot

caspa boosted

@sten0_SE there was yet another issue why this particular type of phishing technique was so effective: users are primed (especially Android users) to automatically grant any permission to any app regardless of whatever it might request. It's basically as automatic as clicking through an EULA.

caspa boosted
No, seriously, It's really cute how these out of order mastodon toots show up in my feed all at once at midnight each day.
caspa boosted
caspa boosted
caspa boosted

"It's not safe to run an internet facing Windows box right now," a hacker who used to work in the US Department of Defense said to Motherboard.

I'm thinking this could be a good time to introduce your friends to #Linux.

I wrote a bit on why over on Reddit: reddit.com/r/linux/comments/65

#ShadowBrokers

caspa boosted

Even though #Microsoft has patched most of the #Shadowbrokers exploits, it is going to be years until the patches get pushed to enterprise systems. This is especially true for the older 2003 Servers still running.

Businesses are reluctant to #patch old systems for fear of breaking them or the hosted software.

caspa boosted

"If you're a hacker, hack back." : Excellent read from flexidie about their FlexiSpy/Vervata hack : pastebin.com/raw/Y1yf8kq0

caspa boosted

I wish motivation came as nicely packaged as caffeine

caspa boosted

Mastodon
where you will learn French, Japanese and at least three programming languages through osmosis

caspa boosted

@tallpanicgrass

99 bugs in the code, 99 bugs in the code! Take one down, patch it out, 126 bugs in the code!
- Ancient Developer Chant

caspa boosted
caspa boosted

Are you a fan of the Red Team Field Manual (RTFM)? Check out the new Blue Team Field Manual (a.co/0nEjco2). All that stuff you normally have to go look up? Yeah, it's in there.

caspa boosted
caspa boosted

n00b question, do I need to follow people or can I just use the federated timeline to show me everyone here? what makes sense?