Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Caint logo. It's just text.
da_667D

da_667@infosec.exchange

@da_667@infosec.exchange
Welcome to Caint!

Issues? Post in Comments & Feedback
You can now view, reply, and favourite posts from the Fediverse. You can click here or click on the on the navigation bar on the left.
About
Posts
9
Topics
6
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Yeah, I think I'm just going to take this Patch Tuesday off.
    da_667D da_667

    @cR0w yeah

    Uncategorized

  • google: hey, go grab the push notification to log in to your account.me: clicks the button, button clickergoogle: "WHO THE FUCK IS THIS?
    da_667D da_667

    google: hey, go grab the push notification to log in to your account.

    me: clicks the button, button clicker

    google: "WHO THE FUCK IS THIS? YO, SOME DUDE LOGGED INTO MY ACCOUNT."

    Uncategorized

  • @xssfox hahaha what the fuck
    da_667D da_667

    @xssfox hahaha what the fuck

    Uncategorized

  • anyway, I'm ready to fuck my life up today.
    da_667D da_667

    anyway, I'm ready to fuck my life up today.

    Uncategorized

  • @xssfox I remember way back when, I ran some server 2003 VMs on vmware server, and I got negative round trip times for ping, but I've never seen anything like that.
    da_667D da_667

    @xssfox I remember way back when, I ran some server 2003 VMs on vmware server, and I got negative round trip times for ping, but I've never seen anything like that.

    Uncategorized

  • If video games have taught me anything, if I just eat enough cheese wheels it can heal me #Gaming
    da_667D da_667

    @JenMsft cheese heals everyone! Except for the lactose intolerant 😞

    Uncategorized gaming

  • what is it about this time of year that makes yellow jackets go apeshit
    da_667D da_667

    @cR0w that explains most of it. I've just noticed that they've been out and about way more than usual around this time.

    I'm deathly afraid of them. If I hear them nearby, I lose my shit. I understand from the article that most the time they don't mean any harm still doesn't stop me from freaking the fuck out. I got stung one too many times as a kid.

    Uncategorized

  • what is it about this time of year that makes yellow jackets go apeshit
    da_667D da_667

    what is it about this time of year that makes yellow jackets go apeshit

    Uncategorized

  • today I've learned that GET requests can technically have a request body.
    da_667D da_667

    today I've learned that GET requests can technically have a request body. In most normal cases, the server ignores the client body on the get request.

    Additionally if a content-length header is specified and you include a body on a GET request, that Snort2.9 and Suricata5+ will inspect the client body.

    why do I bring this up?

    This is a great write-up by ESET on GhostRedirectory and their Rungan backdoor:

    https://www.welivesecurity.com/en/eset-research/ghostredirector-poisons-windows-servers-backdoors-side-potatoes/

    I forged this pcap, and got my rule to fire:

    alert http any any -> $HOME_NET any (msg:"ET MALWARE GhostRedirector Rungan Backdoor Access M1"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"action|3d|cmd"; fast_pattern; http.request_body; content:"cmdpath|3d|"; content:"ming1|3d|"; reference:url,www.welivesecurity.com/en/eset-research/ghostredirector-poisons-windows-servers-backdoors-side-potatoes/; classtype:trojan-activity; sid:1; rev:1;)
    Uncategorized
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups