note.md (44)

←← 掲示板一覧に戻る ← スレッド一覧に戻る

1 野に咲く名無し@転載禁止 (0e286) 2023/10/15 01:52:17.875 ID:HfkwgyeK

!NO
!noid

2 野に咲く名無し@転載禁止 2023/10/15 01:52:53.658

Google, Cloudflare, and AWS Disclose Largest DDoS Attack in History
https://www.hackread.com/google-cloudflare-aws-largest-ddos-attack/

Google, Cloudflare, and AWS Disclosed Digital History’s Largest Ever DDoS Attack- Courtesy HTTP/2 Zero-day

3 野に咲く名無し@転載禁止 2023/10/15 01:53:19.969

Dubbed HTTP/2 Rapid Reset, the vulnerability lets attacker send specially designed HTTP/2 requests to their target server and trigger a large-scale response. They can further amplify this response by sending the same request to as many vulnerable IoT devices and misconfigured servers as they want. The vulnerability is tracked as CVE-2023-44487 and has been assigned a CVSS score of 7.5 out of 10, rated High Severity.

4 野に咲く名無し@転載禁止 2023/10/15 01:55:16.238

Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication

https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html

Microsoft has announced that it plans to eliminate NT LAN Manager (NTLM) in Windows 11 in the future, as it pivots to alternative methods for authentication and bolster security.

5 野に咲く名無し@転載禁止 2023/10/15 01:57:45.664

KerberosはmacOSだとHeimdalという名称の互換性を持たせたプロトコルになっているのが古い良きハッカー文化とかjargonを思い出させる

6 野に咲く名無し@転載禁止 2023/10/15 02:01:12.265

ここ1月くらいで色んなことがあったcurlのやつとか
でも1番はCISAのKnown Exploited Vulnerabilities Catalogじゃないかな
https://www.cisa.gov/known-exploited-vulnerabilities-catalog

7 野に咲く名無し@転載禁止 2023/10/15 02:02:49.160

>>6
CISAとNISTから日本でもNISCを中心に監査が入ってる...という話を聞いた気がするし気のせいかもしれない

8 野に咲く名無し@転載禁止 2023/10/15 02:06:49.304

D-Link WiFi range extender vulnerable to command injection attacks
https://www.bleepingcomputer.com/news/security/d-link-wifi-range-extender-vulnerable-to-command-injection-attacks/

9 野に咲く名無し@転載禁止 2023/10/15 02:07:18.797

Cisco urges admins to fix IOS software zero-day exploited in attacks
https://www.bleepingcomputer.com/news/security/cisco-urges-admins-to-fix-ios-software-zero-day-exploited-in-attacks/

10 野に咲く名無し@転載禁止 2023/10/15 02:07:24.776

謎定期

11 野に咲く名無し@転載禁止 2023/10/15 02:08:54.336

セキュリティエンジニアでもやってるんですかね🤔

12 野に咲く名無し@転載禁止 2023/10/15 02:08:56.645

US and Japan warn of Chinese hackers backdooring Cisco routers
https://www.bleepingcomputer.com/news/security/us-and-japan-warn-of-chinese-hackers-backdooring-cisco-routers/

13 野に咲く名無し@転載禁止 2023/10/15 02:11:56.110

とはいえ国内にある怪しげなVPSやASを除き5chのIP🐜の荒らし見る限りYAMAHAの古いのとか古いCE踏み台にしてる傾向

14 野に咲く名無し@転載禁止 2023/10/15 02:13:11.550

Thousands of Juniper devices vulnerable to unauthenticated RCE flaw
https://www.bleepingcomputer.com/news/security/thousands-of-juniper-devices-vulnerable-to-unauthenticated-rce-flaw/

15 野に咲く名無し@転載禁止 2023/10/15 02:14:08.729

tracertかけるとifの名前でJUNOS経由してるなあってわかるから面白い

16 野に咲く名無し@転載禁止 2023/10/15 02:16:39.019

curlのやつ

Two High-Risk Security Flaws Discovered in Curl Library - New Patches Released
https://thehackernews.com/2023/10/two-high-risk-security-flaws-discovered.html

17 野に咲く名無し@転載禁止 2023/10/15 07:11:14.884

NPM Typosquatting Attack Deploys r77 Rootkit via Legitimate Package
https://www.hackread.com/npm-typosquatting-attack-deliver-r77-rootkit/

18 野に咲く名無し@転載禁止 2023/10/15 07:12:51.494

FortiGuard Labs Uncovers Series of Malicious NPM Packages Stealing Data

https://www.hackread.com/fortiguard-labs-malicious-npm-packages-steal-data/

19 野に咲く名無し@転載禁止 2023/10/15 07:14:31.193

New Magecart Attack Uses 404 Errors to Steal Your Card Data
https://www.hackread.com/magecart-attack-404-errors-steal-card-data/

1. Akamai has discovered a new Magecart campaign in which scammers manipulate the default 404 error messages to inject malicious code.
2. The malicious code is injected as bogus Meta Pixel code or an inline script.

これなかなかよく考えられてる

20 野に咲く名無し@転載禁止 2023/10/15 07:19:42.680

【PR】

Wing Disrupts the Market by Introducing Affordable SaaS Security
https://thehackernews.com/2023/10/wing-disrupts-market-by-introducing.html

Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new approach has emerged that can be launched for $1,500 a year.

21 野に咲く名無し@転載禁止 2023/10/15 07:21:28.182

そうなのよね、現実問題セキュリティというのはリスクに対して事前も事後もコストが高すぎる
他方国や業界団体からは一方的にやれと言われる

22 野に咲く名無し@転載禁止 2023/10/15 07:24:10.881

でもまあ、そのガイドライン自体発行日若いのに内容が時代錯誤なものだったりするから国主導のWGで意見を求めてますからツッコんであげる必要があるし、よく知らない業界団体ならレスバする羽目になる

23 野に咲く名無し@転載禁止 2023/10/15 07:25:57.236

The Anti-AntiAdblocker uBlock Origin filter to get rid of the annoying YouTube message. It turns off the JavaScript anti-adblock payload:
https://files.enderman.ch/scripts/yt-antiadblocker.txt

24 野に咲く名無し@転載禁止 2023/10/15 07:29:37.257

Universal Acceptance Issues with .TUBE, ASCII and IDN Domains https://circleid.com/posts/20231014-universal-acceptance-issues-with-.tube-ascii-and-idn-domains

In 2022, we developed a specialized short link creator for videos under the .TUBE TLD, to provide added value for our clients. However, we encountered a very significant problem. When .TUBE URLs were sent via WhatsApp, they were not linkifying. This issue persisted despite the TLD being delegated by ICANN almost eight years ago.

25 野に咲く名無し@転載禁止 2023/10/15 07:30:12.818

Moreover, many serious issues still persist with many other platforms. For example, Apple simply does not appear to linkify any nTLD except for .XYZ and .ONLINE, and even for those, the linkification is dependent upon the version of WhatsApp being used. Apple ought to be encouraged by ICANN to update the list of TLDs that they recognize in Apple applications, and to regularly update that list in the future. We also know that X (fka Twitter) is not linkifying .KIDS nor .MUSIC gTLDs delegated in 2021. We are researching whether Microsoft has similar issues, but all of these efforts are draining our corporate executive time and resources, to do a job that should have been done by ICANN years ago. We have collected evidence and reference materials for ICANN and the community’s consideration and posted them on our drive. Despite its knowledge of this linkification problem, and despite the significant ICANN resources already allocated to deal with so-called “Universal Acceptance,” almost a decade into the new TLD program, the two operating systems used by 98% of all the telephones in the world are not fully UA compliant.

26 野に咲く名無し@転載禁止 2023/10/15 07:31:53.517

😙
test.天主教

https://icannwiki.org/.天主教

27 野に咲く名無し@転載禁止 2023/10/15 07:33:40.401

Pirate Sites Exploit ‘Interplanetary File System’ Gateways, Publishers Warn

https://torrentfreak.com/pirate-sites-exploit-interplanetary-file-system-gateways-publishers-warn-231013/

The InterPlanetary File System, more broadly known as IPFS, has been around for the past eight years.

While the name may sound otherworldly to the public at large, the peer-to-peer file storage network has a growing user base among the tech-savvy.

In short, IPFS is a decentralized network where users make files available to each other. The system makes websites censorship resistant and not vulnerable to regular hosting outages.

28 野に咲く名無し@転載禁止 2023/10/15 07:35:24.402

torrentの頃と同じ論調を展開してるわけだけど音楽業界がそこまで過敏にならなくなったのはsubscriptionっていう対抗可能な商業形態を作ったからなんじゃないですかね

29 野に咲く名無し@転載禁止 2023/10/15 07:39:31.505

Genshin Impact: Major Private Server Dev Faces DMCA Subpoenas
https://torrentfreak.com/genshin-impact-major-private-server-dev-faces-dmca-subpoenas-231010/

30 野に咲く名無し@転載禁止 2023/10/15 07:41:05.799

Encrypted Client Hello (ECH) Effectively Defeats Pirate Site Blocking
https://torrentfreak.com/encrypted-client-hello-ech-effectively-defeats-pirate-site-blocking-231006/

The actual blocking is done by Internet providers, often following a court order. These measures can range from simple DNS blocks to more elaborate schemes involving Server Name Indication (SNI) eavesdropping, or a combination of both.

Thus far, the more thorough blocking efforts have worked relatively well. However, as privacy concerns grew, new interfering technologies have emerged. Encrypted DNS and SNI, for example, made blocking efforts much harder, although not impossible.

GFWかな?

31 野に咲く名無し@転載禁止 2023/10/15 07:42:53.404

Russia Prepares RuStore VPN Ban After Declaring RuStore Installation Mandatory
https://torrentfreak.com/russia-prepares-rustore-vpn-ban-after-declaring-rustore-installation-mandatory-231004/

sideloadになるかは別にしてロシアってどこかの法改正の段階で「新規のVPNクライアント」の配布自体を違法化してた記憶あるんだが

32 野に咲く名無し@転載禁止 2023/10/15 07:47:55.666

エッヂの今後の運営方針議論スレ
https://git.3chan.cc/edginer/eddiner/issues/42

極性辞書によるネガポジ判定でもすりゃいいんじゃないですかね
faxcntやredditのkarmaみたいに忍法帖にスコア組み込めば

33 野に咲く名無し@転載禁止 2023/10/15 07:52:28.117

The SUN👈🤭

UP IN THE SKY US warns Starlink satellites will start killing people and reveals chance of hitting a human will soon be 61% each year
https://www.the-sun.com/tech/9321207/us-warning-starlink-satellites-kill-people/

THE Federal Aviation Administration has spoken out on the dangers of Starlink satellites potentially injuring humans on Earth.

By 2035, debris from low-earth orbit (LEO) objects, like Starlink satellites, could fall and injure or kill someone, the FAA said in report to Congress.

34 野に咲く名無し@転載禁止 2023/10/15 07:52:36.856

>>33
凄い煽り記事

35 野に咲く名無し@転載禁止 2023/10/15 07:59:40.415

Comcast starts squeezing 2 Gbps symmetrical internet speeds through decades-old coaxial cables
https://www.engadget.com/comcast-starts-squeezing-2-gbps-symmetrical-internet-speeds-through-decades-old-coaxial-cables-143657830.html

Comcast is upgrading its residential cable internet service to offer upload and download speeds of up to 2 Gbps through decades-old coaxial cables.

36 野に咲く名無し@転載禁止 2023/10/15 08:01:51.784

>>35
"residential cable internet service"
アメリカだなぁ、あの国は未だにT1の回線存在するからビックリする
だからLEOに投資出来たんだろうけど

37 野に咲く名無し@転載禁止 2023/10/15 08:04:13.515

Across U.S., Chinese Bitcoin Mines Draw National Security Scrutiny
https://www.nytimes.com/2023/10/13/us/bitcoin-mines-china-united-states.html

Microsoft reported one site in Wyoming because of its proximity to a data center and nuclear missile base. Records show other cryptocurrency facilities have ties to the Chinese state.

38 野に咲く名無し@転載禁止 2023/10/15 08:07:22.219

talkもそうだけどハワイにペーパーLLC作るの安いし簡単なんよね
それでAS申請してIPレンジ割当してもらってIXとpeerはれば色々悪いことできるし中国系グループが日本でもやってる

39 野に咲く名無し@転載禁止 2023/10/15 08:10:08.511

tips

An unscientific benchmark of SQLite vs the file system (btrfs) https://golangexample.com/an-unscientific-benchmark-of-sqlite-vs-the-file-system-btrfs/

40 野に咲く名無し@転載禁止 2023/10/15 08:12:48.842

【PR】

PROFESSIONAL EMAIL SHOULDN’T COST SO MUCH

Unlimited domains. Unlimited users. All at $1 a month.
https://mymangomail.com/

41 野に咲く名無し@転載禁止 2023/10/15 08:53:56.047

なるほど、なるほど
うーん、せやな
わかる

42 野に咲く名無し@転載禁止 2023/10/15 08:55:37.859

なるほどね

43 野に咲く名無し@転載禁止 2023/10/15 11:14:16.939

https://bot.sannysoft.com/

44 野に咲く名無し@転載禁止 2023/10/15 11:20:59.449

なるほどな
海外クラスのワイなら分かるわ