2 野に咲く名無し@転載禁止 2023/10/15 01:52:53.658
Google, Cloudflare, and AWS Disclose Largest DDoS Attack in History
https://www.hackread.com/google-cloudflare-aws-largest-ddos-attack/
Google, Cloudflare, and AWS Disclosed Digital History’s Largest Ever DDoS Attack- Courtesy HTTP/2 Zero-day
3 野に咲く名無し@転載禁止 2023/10/15 01:53:19.969
Dubbed HTTP/2 Rapid Reset, the vulnerability lets attacker send specially designed HTTP/2 requests to their target server and trigger a large-scale response. They can further amplify this response by sending the same request to as many vulnerable IoT devices and misconfigured servers as they want. The vulnerability is tracked as CVE-2023-44487 and has been assigned a CVSS score of 7.5 out of 10, rated High Severity.
4 野に咲く名無し@転載禁止 2023/10/15 01:55:16.238
Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication
https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html
Microsoft has announced that it plans to eliminate NT LAN Manager (NTLM) in Windows 11 in the future, as it pivots to alternative methods for authentication and bolster security.
5 野に咲く名無し@転載禁止 2023/10/15 01:57:45.664
KerberosはmacOSだとHeimdalという名称の互換性を持たせたプロトコルになっているのが古い良きハッカー文化とかjargonを思い出させる
6 野に咲く名無し@転載禁止 2023/10/15 02:01:12.265
ここ1月くらいで色んなことがあったcurlのやつとか
でも1番はCISAのKnown Exploited Vulnerabilities Catalogじゃないかな
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
8 野に咲く名無し@転載禁止 2023/10/15 02:06:49.304
D-Link WiFi range extender vulnerable to command injection attacks
https://www.bleepingcomputer.com/news/security/d-link-wifi-range-extender-vulnerable-to-command-injection-attacks/
9 野に咲く名無し@転載禁止 2023/10/15 02:07:18.797
Cisco urges admins to fix IOS software zero-day exploited in attacks
https://www.bleepingcomputer.com/news/security/cisco-urges-admins-to-fix-ios-software-zero-day-exploited-in-attacks/
10 野に咲く名無し@転載禁止 2023/10/15 02:07:24.776
謎定期
11 野に咲く名無し@転載禁止 2023/10/15 02:08:54.336
セキュリティエンジニアでもやってるんですかね🤔
12 野に咲く名無し@転載禁止 2023/10/15 02:08:56.645
US and Japan warn of Chinese hackers backdooring Cisco routers
https://www.bleepingcomputer.com/news/security/us-and-japan-warn-of-chinese-hackers-backdooring-cisco-routers/
13 野に咲く名無し@転載禁止 2023/10/15 02:11:56.110
とはいえ国内にある怪しげなVPSやASを除き5chのIP🐜の荒らし見る限りYAMAHAの古いのとか古いCE踏み台にしてる傾向
14 野に咲く名無し@転載禁止 2023/10/15 02:13:11.550
Thousands of Juniper devices vulnerable to unauthenticated RCE flaw
https://www.bleepingcomputer.com/news/security/thousands-of-juniper-devices-vulnerable-to-unauthenticated-rce-flaw/
15 野に咲く名無し@転載禁止 2023/10/15 02:14:08.729
tracertかけるとifの名前でJUNOS経由してるなあってわかるから面白い
16 野に咲く名無し@転載禁止 2023/10/15 02:16:39.019
curlのやつ
Two High-Risk Security Flaws Discovered in Curl Library - New Patches Released
https://thehackernews.com/2023/10/two-high-risk-security-flaws-discovered.html
17 野に咲く名無し@転載禁止 2023/10/15 07:11:14.884
NPM Typosquatting Attack Deploys r77 Rootkit via Legitimate Package
https://www.hackread.com/npm-typosquatting-attack-deliver-r77-rootkit/
18 野に咲く名無し@転載禁止 2023/10/15 07:12:51.494
FortiGuard Labs Uncovers Series of Malicious NPM Packages Stealing Data
https://www.hackread.com/fortiguard-labs-malicious-npm-packages-steal-data/
19 野に咲く名無し@転載禁止 2023/10/15 07:14:31.193
New Magecart Attack Uses 404 Errors to Steal Your Card Data
https://www.hackread.com/magecart-attack-404-errors-steal-card-data/
1. Akamai has discovered a new Magecart campaign in which scammers manipulate the default 404 error messages to inject malicious code.
2. The malicious code is injected as bogus Meta Pixel code or an inline script.
これなかなかよく考えられてる
20 野に咲く名無し@転載禁止 2023/10/15 07:19:42.680
【PR】
Wing Disrupts the Market by Introducing Affordable SaaS Security
https://thehackernews.com/2023/10/wing-disrupts-market-by-introducing.html
Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new approach has emerged that can be launched for $1,500 a year.
21 野に咲く名無し@転載禁止 2023/10/15 07:21:28.182
そうなのよね、現実問題セキュリティというのはリスクに対して事前も事後もコストが高すぎる
他方国や業界団体からは一方的にやれと言われる
22 野に咲く名無し@転載禁止 2023/10/15 07:24:10.881
でもまあ、そのガイドライン自体発行日若いのに内容が時代錯誤なものだったりするから国主導のWGで意見を求めてますからツッコんであげる必要があるし、よく知らない業界団体ならレスバする羽目になる
23 野に咲く名無し@転載禁止 2023/10/15 07:25:57.236
The Anti-AntiAdblocker uBlock Origin filter to get rid of the annoying YouTube message. It turns off the JavaScript anti-adblock payload:
https://files.enderman.ch/scripts/yt-antiadblocker.txt
24 野に咲く名無し@転載禁止 2023/10/15 07:29:37.257
Universal Acceptance Issues with .TUBE, ASCII and IDN Domains https://circleid.com/posts/20231014-universal-acceptance-issues-with-.tube-ascii-and-idn-domains
In 2022, we developed a specialized short link creator for videos under the .TUBE TLD, to provide added value for our clients. However, we encountered a very significant problem. When .TUBE URLs were sent via WhatsApp, they were not linkifying. This issue persisted despite the TLD being delegated by ICANN almost eight years ago.
25 野に咲く名無し@転載禁止 2023/10/15 07:30:12.818
Moreover, many serious issues still persist with many other platforms. For example, Apple simply does not appear to linkify any nTLD except for .XYZ and .ONLINE, and even for those, the linkification is dependent upon the version of WhatsApp being used. Apple ought to be encouraged by ICANN to update the list of TLDs that they recognize in Apple applications, and to regularly update that list in the future. We also know that X (fka Twitter) is not linkifying .KIDS nor .MUSIC gTLDs delegated in 2021. We are researching whether Microsoft has similar issues, but all of these efforts are draining our corporate executive time and resources, to do a job that should have been done by ICANN years ago. We have collected evidence and reference materials for ICANN and the community’s consideration and posted them on our drive. Despite its knowledge of this linkification problem, and despite the significant ICANN resources already allocated to deal with so-called “Universal Acceptance,” almost a decade into the new TLD program, the two operating systems used by 98% of all the telephones in the world are not fully UA compliant.
26 野に咲く名無し@転載禁止 2023/10/15 07:31:53.517
😙
test.天主教
https://icannwiki.org/.天主教
27 野に咲く名無し@転載禁止 2023/10/15 07:33:40.401
Pirate Sites Exploit ‘Interplanetary File System’ Gateways, Publishers Warn
https://torrentfreak.com/pirate-sites-exploit-interplanetary-file-system-gateways-publishers-warn-231013/
The InterPlanetary File System, more broadly known as IPFS, has been around for the past eight years.
While the name may sound otherworldly to the public at large, the peer-to-peer file storage network has a growing user base among the tech-savvy.
In short, IPFS is a decentralized network where users make files available to each other. The system makes websites censorship resistant and not vulnerable to regular hosting outages.
28 野に咲く名無し@転載禁止 2023/10/15 07:35:24.402
torrentの頃と同じ論調を展開してるわけだけど音楽業界がそこまで過敏にならなくなったのはsubscriptionっていう対抗可能な商業形態を作ったからなんじゃないですかね
29 野に咲く名無し@転載禁止 2023/10/15 07:39:31.505
Genshin Impact: Major Private Server Dev Faces DMCA Subpoenas
https://torrentfreak.com/genshin-impact-major-private-server-dev-faces-dmca-subpoenas-231010/
30 野に咲く名無し@転載禁止 2023/10/15 07:41:05.799
Encrypted Client Hello (ECH) Effectively Defeats Pirate Site Blocking
https://torrentfreak.com/encrypted-client-hello-ech-effectively-defeats-pirate-site-blocking-231006/
The actual blocking is done by Internet providers, often following a court order. These measures can range from simple DNS blocks to more elaborate schemes involving Server Name Indication (SNI) eavesdropping, or a combination of both.
Thus far, the more thorough blocking efforts have worked relatively well. However, as privacy concerns grew, new interfering technologies have emerged. Encrypted DNS and SNI, for example, made blocking efforts much harder, although not impossible.
GFWかな?
31 野に咲く名無し@転載禁止 2023/10/15 07:42:53.404
Russia Prepares RuStore VPN Ban After Declaring RuStore Installation Mandatory
https://torrentfreak.com/russia-prepares-rustore-vpn-ban-after-declaring-rustore-installation-mandatory-231004/
sideloadになるかは別にしてロシアってどこかの法改正の段階で「新規のVPNクライアント」の配布自体を違法化してた記憶あるんだが
32 野に咲く名無し@転載禁止 2023/10/15 07:47:55.666
エッヂの今後の運営方針議論スレ
https://git.3chan.cc/edginer/eddiner/issues/42
極性辞書によるネガポジ判定でもすりゃいいんじゃないですかね
faxcntやredditのkarmaみたいに忍法帖にスコア組み込めば
33 野に咲く名無し@転載禁止 2023/10/15 07:52:28.117
The SUN👈🤭
UP IN THE SKY US warns Starlink satellites will start killing people and reveals chance of hitting a human will soon be 61% each year
https://www.the-sun.com/tech/9321207/us-warning-starlink-satellites-kill-people/
THE Federal Aviation Administration has spoken out on the dangers of Starlink satellites potentially injuring humans on Earth.
By 2035, debris from low-earth orbit (LEO) objects, like Starlink satellites, could fall and injure or kill someone, the FAA said in report to Congress.
35 野に咲く名無し@転載禁止 2023/10/15 07:59:40.415
Comcast starts squeezing 2 Gbps symmetrical internet speeds through decades-old coaxial cables
https://www.engadget.com/comcast-starts-squeezing-2-gbps-symmetrical-internet-speeds-through-decades-old-coaxial-cables-143657830.html
Comcast is upgrading its residential cable internet service to offer upload and download speeds of up to 2 Gbps through decades-old coaxial cables.
36 野に咲く名無し@転載禁止 2023/10/15 08:01:51.784
>>35
"residential cable internet service"
アメリカだなぁ、あの国は未だにT1の回線存在するからビックリする
だからLEOに投資出来たんだろうけど
37 野に咲く名無し@転載禁止 2023/10/15 08:04:13.515
Across U.S., Chinese Bitcoin Mines Draw National Security Scrutiny
https://www.nytimes.com/2023/10/13/us/bitcoin-mines-china-united-states.html
Microsoft reported one site in Wyoming because of its proximity to a data center and nuclear missile base. Records show other cryptocurrency facilities have ties to the Chinese state.
38 野に咲く名無し@転載禁止 2023/10/15 08:07:22.219
talkもそうだけどハワイにペーパーLLC作るの安いし簡単なんよね
それでAS申請してIPレンジ割当してもらってIXとpeerはれば色々悪いことできるし中国系グループが日本でもやってる
39 野に咲く名無し@転載禁止 2023/10/15 08:10:08.511
tips
An unscientific benchmark of SQLite vs the file system (btrfs) https://golangexample.com/an-unscientific-benchmark-of-sqlite-vs-the-file-system-btrfs/
40 野に咲く名無し@転載禁止 2023/10/15 08:12:48.842
【PR】
PROFESSIONAL EMAIL SHOULDN’T COST SO MUCH
Unlimited domains. Unlimited users. All at $1 a month.
https://mymangomail.com/
41 野に咲く名無し@転載禁止 2023/10/15 08:53:56.047
なるほど、なるほど
うーん、せやな
わかる
42 野に咲く名無し@転載禁止 2023/10/15 08:55:37.859
なるほどね
43 野に咲く名無し@転載禁止 2023/10/15 11:14:16.939
44 野に咲く名無し@転載禁止 2023/10/15 11:20:59.449
なるほどな
海外クラスのワイなら分かるわ