Glen Arrowsmith

3.1K posts

Glen Arrowsmith banner
Glen Arrowsmith

Glen Arrowsmith

@garrows

InfoSec/CyberSecurity, Javascript/Node.js dev, system architect, roboticist, father.

Brisbane انضم Ekim 2007
634 يتبع1.1K المتابعون
Ryan Hickman
Ryan Hickman@ryanmhickman·
🤣 @GeminiApp just started spitting out it's internal monologue and it's gone mental 🤪
Ryan Hickman tweet mediaRyan Hickman tweet mediaRyan Hickman tweet media
English
1
0
0
101
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
On one hand, I want to name my home ssid to something extremely common like "Guest" so things like @wiglenet can't easily find me. But on the other hand if my devices are all looking for the "Guest" ssid, it will likely see those in the wild and be handing out my password to each one it sees.
English
17
1
93
18.7K
Glen Arrowsmith
Glen Arrowsmith@garrows·
Slack is down. Productivity improves 10x
English
1
0
2
174
vx-underground
vx-underground@vxunderground·
Regarding the BlackBasta leaks: we haven't reviewed them in totality yet. It's quite a bit of messages in JSON format. It also has some Russian slang which makes it difficult to translate accurately. Thankfully there are some native Russian speakers who have made some interesting highlights. 1. Somewhere in the conversation BlackBasta members discuss Lockbit ransomware group. They believe he cannot be trusted. 2. In the conversation Dispossessor ransomware group is discussed. Dispossessor wants to join BlackBasta. One of the members "Hshsi Jdidi" says they believe Dispossessor has a "good resume" but think they only want to work with them because of their "fame". They also express concern that Dispossessor may be a law enforcement officer. They express concern with the takedowns from Lockbit, Conti, and others. 3. One of the BlackBasta affiliates is a minor. They are 17 years old. 4. They are EXTREMELY interested in VPN exploits. They go to great lengths to acquire, purchase, or find people, capable of delivering VPN exploits. 5. Someone is wanting to grant them access (or sell them access) to their private loader for the cost of $84,000/month 6. Following the success of Scattered Spider, BlackBasta has begun incorperating social engineering into their operations. They have a person named "Nur" who is responsible for identifying key personnel at organizations they want to target. Once a person of influence is identified (manager, HR, etc) they contact them via telephone call. 7. BlackBasta maintains a spreadsheet of victims they're trying to target. It is shared between members and they collaborate on it together. It has the person of interest, if they've tried social engineering them, and general strategy notes. They often identify multiple targets at companies. 8. The caller who contacts victims is tasked with having the employee install "Remote Monitoring and Management" from level-dot-io. Once the application is installed they begin work (eventually). 9. Targets are not selected randomly. BlackBasta has immense interest in Electrical companies, Industrial supply chain companies (Steel, wood, recycling, general supplies), and Tax and/or Financial management companies (companies which manage finances for other companies). 10. Their workflow is documented fairly well. However, because these leaks are from 2023 - 2024, they may be outdated. Here is the general idea: Step 1: Get victim to execute malicious .HTA file. The .HTA file is delivered from either a masqueraded malicious download link, social engineering, or a masqueraded malicious e-mail Step 2: The .HTA file drops a .BAT or .EXE file which contains commands to connect to their C2 server. Step 3: The C2 server has a .JS file which can then deliver an actual payload file allowing either ransomware deployment, or tooling for remote access.
English
9
64
353
56.1K
Glen Arrowsmith
Glen Arrowsmith@garrows·
How dare you! My code is artisanal, single origin, micro-brewed in traditional heirloom graymatter.
English
0
0
2
57
vx-underground
vx-underground@vxunderground·
Hello, this is now an ultra-rare-limited-edition-last-second-speedrun-giveaway. Our friend @_MG_ thought it would be funny to gift us 4 @Hak5 OMG. hacker cables right before my vacation begins. This is a speedrun. I've got 4 cables to giveaway (via voucher, you still have to pay for shipping) before 11PM EST. (approx. 6 hours from now). Leave a comment below, I'll pick 4 random people. If you live in a different timezone and miss this — I'm sorry. Blame MG, not us, because he wanted to do this the very last second (he's a troll). See subsequent post for details on OMG cables (if you live under a rock).
vx-underground tweet media
English
1.3K
60
982
74.1K
Glen Arrowsmith
Glen Arrowsmith@garrows·
AI can't generate ASCII art thumbs up. Prove me wrong.
Glen Arrowsmith tweet mediaGlen Arrowsmith tweet media
English
0
0
0
68
Glen Arrowsmith
Glen Arrowsmith@garrows·
Conspiracies were invented by big foil to sell more tinfoil hats. It's true. Do your own research.
Glen Arrowsmith tweet media
English
1
0
3
71
Glen Arrowsmith
Glen Arrowsmith@garrows·
I made a WebCam pixelation tool last night. A bit of fun especially if you want to do something interesting with OBS streaming or zoom meetings. garrows.com/pixelcam/ #pixelart
English
0
0
0
131
Peter Laurie
Peter Laurie@pjlaurie·
@garrows Now sit still while I tell you how to format your SQL correctly.
GIF
English
1
0
1
27
Peter Laurie
Peter Laurie@pjlaurie·
Commas are the new line terminators.
English
1
0
0
159
Glen Arrowsmith
Glen Arrowsmith@garrows·
@pjlaurie Whatever tabs/spaces as long as it's set in .editorconfig. But commas before the value is unholy.
English
1
0
1
41
Peter Laurie
Peter Laurie@pjlaurie·
@garrows Only if you're one of those tab people... or the chaotic-evil 4 (or 8) spaces people.
English
1
0
0
28
Peter Laurie
Peter Laurie@pjlaurie·
Who'd have thought they were a dot away from being more correct. Mind you, I've died on this hill a lot of times instead.
Peter Laurie tweet media
English
1
0
0
91
Glen Arrowsmith
Glen Arrowsmith@garrows·
UltraTune (Aussie car servicing company) was reportedly ransomwared last night. Data is unverified.
Glen Arrowsmith tweet mediaGlen Arrowsmith tweet media
English
0
0
1
201
Glen Arrowsmith
Glen Arrowsmith@garrows·
@LitMoose He was wise to report it to the companies using zendesk instead. We had a report for one of our vendors recently because they failed to fix it. They took action once customers were being exploited. We won't be renewing.
English
1
0
1
132