Stefan Schmidt

12.8K posts

Stefan Schmidt banner
Stefan Schmidt

Stefan Schmidt

@Zap42

🎧 🛀 🌌 👽☁ full stack begins at layer 1 | high speed copy&paste | only DNS is truly web-scale | his password ¯ \ _ (ツ) _ / ¯ @[email protected]

Berlin, Germany Katılım Kasım 2007
2.3K Takip Edilen627 Takipçiler
Stefan Schmidt retweetledi
lcamtuf
lcamtuf@lcamtuf·
Techies: with IPv6, we'll never run out of addresses! Also techies:
lcamtuf tweet media
English
30
36
1.1K
76.3K
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
32
458
6.7K
75K
Stefan Schmidt retweetledi
TracketPacer
TracketPacer@TracketPacer·
TracketPacer tweet media
ZXX
12
12
289
6.7K
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
64
53
859
16.4K
TracketPacer
TracketPacer@TracketPacer·
it’s taken me my entire career up until today to not touch SNMP with my dirty little mitts. i hadn’t so much as blinked at an SNMP trap. but then… i purchased a switched PDU
TracketPacer tweet media
English
42
6
356
12.2K
Stefan Schmidt retweetledi
Lukasz Olejnik
Lukasz Olejnik@lukOlejnik·
Ex-BND (German Foreign Intelligence Service) deputy chief Arndt Freytag von Loringhoven received a message from fake Signal “support” asking for his PIN. He typed it in. His contacts then got a malicious link through his hijacked account. He’s a former NATO intelligence chief, and the author of a book called Putin’s Attack on Germany, where he apparently covers Russian cyberattacks. He fell for a fake customer service message.
Lukasz Olejnik tweet media
English
149
1.7K
6.8K
1M
Stefan Schmidt retweetledi
MG
MG@_MG_·
If you use a personal phone/laptop for your work, pay very close attention to this little detail. Iran attackers wipe 200k devices at a company called Stryker. Within those devices appears to be employees PERSONAL devices. The attackers used the company’s MDM software, which is basically IT management software running on everything. It’s an incredibly attractive backdoor to an attacker. I successfully targeted MDM software for several Red Team engagements. It’s… lots of fun :) Anyway, a lot of companies require you to install their MDM software on your personal devices before you can access resources like Corp email. It’s used to keep devices updated, lock things down if they get stolen, etc. The company often promises that they won’t access personal data, erase any personal data, etc. But this is often ONLY POLICY. If a bad actor gains access to the MDM tool, as was the case here, then anything can happen. People should be aware of these risks. I refused to run MDM software on any of my personal devices. The company needs to provide me with hardware if they want that. I personally isolate all corp devices to their own network too. If an adversary can get into the corp laptop, then can then get inside my network… there have been cases of it happening in the past.
MG tweet media
Kim Zetter@KimZetter

I've published more details about the cyberattack in this piece: zetter-zeroday.com/iranian-hackti…

English
88
654
3.3K
561.1K
stacksmashing
stacksmashing@ghidraninja·
Simple age check for Linux: Just have the shell ask the user to check the host IP on first boot. If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇
English
132
146
2.4K
116.8K
Stefan Schmidt
Stefan Schmidt@Zap42·
@TheIcelandGuy Open recursive server is not much of an issue in my experience (29670) but of course it depends on size of the customer base. If you can limit access to the fabric even better. I'd put a dnsdist in front for rate limits or blocks on a whim. 1-2GB of RAM is usually enough.
English
1
0
0
18
Martin Hannigan
Martin Hannigan@TheIcelandGuy·
@Zap42 I’d like to offer faster local recursion available to anyone connected to a switch fabric/ixp. Google isn’t sending a resolver anytime soon so “self help”. Plenty of CPU+RAM to put to work. Abuse is the challenge. Or is it?
English
1
0
0
32
Martin Hannigan
Martin Hannigan@TheIcelandGuy·
If you can’t get access to a localized dns resolver like 1.1.1.1/8.8.8.8/etc is there a roll your own alternative that makes sense? #dns #networkperformance
English
4
0
7
1.2K
spencer
spencer@techspence·
True or false, cybersecurity skills are necessary for IT admins?
English
139
9
315
26.6K
Stefan Schmidt
Stefan Schmidt@Zap42·
@quelltexten An der Theorie mit zu gross zum scannen koennte was dran sein. Mein aktuelles fail2ban log sagt fuer IPv6 keine Eintraege bei ssh aber welche fuer exim.
Deutsch
0
0
0
99
quelltexten
quelltexten@quelltexten·
es ist so absurd wie seit ich ipv6 only server habe ich praktisch keine ssh login versuche mehr bekomme. mein f2b war vorher permanent auf 50+ entries bei sehr geringer ban time, jetzt leer
Deutsch
10
1
68
7.8K
Stefan Schmidt retweetledi
Flightradar24
Flightradar24@flightradar24·
Airspace clearing after strikes by the United States and Israel in Iran.
English
161
3.3K
18.9K
4.4M
Cloudflare
Cloudflare@Cloudflare·
Let's talk ports. Aside from 80 and 443 what is your favorite networking port and why? #CloudflareChat
English
174
4
216
65K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
WHAT THE FUCK
mRr3b00t tweet media
English
124
35
741
134.5K