sten0✅ is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

sten0✅ @sten0_SE@infosec.exchange

sten0✅ boosted

Schrödinger's Ops... production is in a constant superposition of states between "duct-taped together" and "everything's on fire"

😂 mastodon.social/media/HRjJa6Ax

KFC to start taking/storing facial image scans because how could that POSSIBLY go wrong?

"KFC ensures they will be secure" lmao ok, and I'm a Nigerian Prince who just needs to transfer some funds for an upcoming trip.

See enclosed a check for $5,000 USD. Please cash, take $500 for troubles, and wire the rest to my offshore acct. infosec.exchange/media/bNrh2yY

Re:

If you didn't know about the "hidden" printer dots that get added I have a few others for you. The general idea is called "canary trapping" and takes many forms ranging from differeing stories, font spacing, scene markers (film industry), high-pitched frequencies beyond human hearing range (music industry) etc.

nbcnews.com/news/us-news/feds-

infosec.exchange/media/ItzyGp-

ICYMI: ~600 pg monster covering damn-near everything about VM/homelabs. Last day to get it for free... buy it anyway!

courtesy of @da_667 (same handle on tweeter)

blindseeker.com/AVATAR/AVATAR-

Good roadmap to learning exploitation.

"From 0x90 to 0x4c454554, a journey into exploitation"

myne-us.com/2010/08/from-0x90-

Bypass security on any AT&T wireless by logging onto ufix.att.com

Start checking all those wifi's near you... infosec.exchange/media/u3vUrUw

sten0✅ boosted

Did you know? Clouds are formed from the evaporated tears of many thousands of network and systems admins mastodon.social/media/g3ikKTz9

Edit: 1 high vuln was found, since patched.. led to server shutdown.

The audits yield a mixed bag.

Low-medium vulns but nothing considered "high" - crypto solid.

Possible problems with implementation (par for course really).

threatpost.com/openvpn-audits-

Great lesson applies to tech debt and pretty well. Focus on making, not securing will cause large amount of pain in [probable near] future. infosec.exchange/media/S3svVwW

LIN bus often bridged to CAN bus and can be connected to via cd changer connector in trunk.

Watch out for malicious junk in your trunk... here's hoping that "car's will be an iPhone on wheels" quote guy get's a serious life lesson soon...

hackaday.com/2017/05/26/embed-

RSA 2048 private master key for offline AES-NI keys.

sendspace.com/file/fz133k

pass: 85W0vhRkPbqcvaTafHknhMRP

sten0✅ boosted

@sten0_SE 4. Iterate to next model/version and sunset previous version.

sten0✅ boosted

@sten0_SE security adds no marginal sales value.

So many [recent] examples of no validation/verification/authentication. Pathetic. Negligence, pure and simple. Not like SQLi is ~20 years old...

¯\_(ツ)_/¯ 💩 🔥

Pacemakers, TrendMicro AV, automated email, SQLi for years,

t.co/wDI39Kzi6Y

blog.whitescope.io/2017/05/und

coresecurity.com/advisories/tr

main()
{
printf("Hello World");

}

May as well join you fine folks over here as well (pref local > fed timelines).

Interests: OSINT, SE, locksport, Red Team, general abuse of systems

blog:

sten0.ghost.io

birdsite:

twitter.com/sten0_SE

.social:

mastodon.social/@sten0_SE

sec masto:

securitymastod.one/@sten0_SE