Infosec Press

Reader

Read the latest posts from Infosec Press.

from what

In the wake of his purchase, far-right billionaire Elon Musk has made many awful changes at Twitter. Kneecapping capabilities for viewing, researching, and archiving materials posted on the forum is certainly less immediately harmful than, say, stochastic terrorism against schools & childrens' hospitals, but it's still no good, and requires some stopgaps.

Twitter frequently now seems to block archive.org altogether; and even when it is possible to archive a tweet by other means, it is generally only viewable as a single post, devoid of any surrounding context in the form of threads or replies.

One intermittent way to currently get around this limitation is to use the open-source, alternative Twitter front-endNitter”, and specifically Chris McCormick's redirect proxy Twiiit.

The steps I've found useful are as follow:

  • For example, let's say I need to preserve this post along with some of its immediate context: https://twitter.com/dril/status/1707911269033148925
  • I replace the url's “twitter” domain with “twiiit” – e.g. https://twiiit.com/dril/status/1707911269033148925
  • Before I hit “enter”, I COPY that modified URL. This is because Nitter instances themselves are regularly being blocked by Twitter, or are otherwise unable to dredge up a copy of the post. The “twiiit” re-direct will try various Nitter instances, though; so if the first couple don't function, I simply paste the URL and try again. It only saves a couple of seconds, but they can add up.
  • I find myself redirected to a functional Nitter front-end of the tweet, which includes replies and context, in this case it's this one: https://nitter.nohost.network/dril/status/1707911269033148925
  • I create an archive of that Nitter front-end by using archive.org and/or archive.today.

If I'm trying to preserve a longer thread, I will sometimes archive every fourth or fifth post to ensure that the data is complete via overlapping captures.

As Musk continues to use his fortune in an apparent quest to singlehandedly reinvigorate the embers of the alt-right, it'll remain important to be able to document & preserve some of what is posted on his platform — this will likely require a continual stream of kludgy workarounds by diligent researchers who are much more clever than I am. So, thanks in advance.


P.S. – Nitter instances render timestamps as UTC, which is generally more reliable than the local timestamp which appears when I view the original tweet from the US West coast.

 
Read more...

from CatSalad🐈🥗 (D.Burch)

(Updated:2023-09-26)

This list only contains accounts for security bsides, events, and conferences found in the fediverse / Mastodon with some post history. I will regular update this post as more events migrate here. For hacker meet-ups and local DEFCON / 2600 groups, please refer to the link below.

📌⁠InfoSec Events by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hacker Meet-ups by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hackerspaces by Region (ᵃˡˢᵒ🦣ⷨ)

🐈🥗

⸻ Event Info

@cfp_time@infosec.exchange – Call for Papers (#CFP) @InfoCon@defcon.social – #InfoCon @InfoconDB@infosec.exchange – #InfoconDB archive @SecurityBSidesGlobal@infosec.exchange – Security BSides Global

⸻ Online 🌐

@ComfyConAU@infosec.exchange – #ComfyCon @Digit4lOverdose@infosec.exchange – D.O. Conference @pancakescon@infosec.exchange – #PancakesCon

⸻ Canada 🇨🇦

@BSidesCalgary – #BSidesCalgary, AB @BSidesEdmonton – #BSidesEdmonton, AB @BSidesFredericton – BSidesFredericton, NB @BSidesMTL – #BSidesMTL Montreal, QC @BSidesOttawa – #BSidesOttawa, ON @BSidesRegina – #BSidesRegina, SK @BSidesStJohns– #BSidesStJohns, NL @BSidesTO – #BSidesTO Toronto, ON @BSidesVancouver – #BSidesVancouver, BC @BSidesVI@infosec.exchange – #BSidesVI Vancouver Island, BC @hackfest@infosec.exchange – #Hackfest Québec City, QC @halifaxbsides@infosec.exchange – #BSidesHalifax, NS @NorthSec@infosec.exchange – #NorthSec Montréal, QC @polar@infosec.exchange – #PolQc POLAR Conf, QC @seqcure@infosec.exchange – #SeQCure Québec, QC @thelongcon@infosec.exchange – #TheLongCon Winnipeg, MB

⸻ US – Northeast

@bsidesboston@infosec.exchange – #BSidesBoston, MA @BSidesBuffalo@infosec.exchange – #BSidesBuffalo, NY @BSidesCambridgeMA@infosec.exchange – #BSidesCambridge, MA @BSidesCharm@infosec.exchange – #BSidesCharm Towson, MD @BSidesCT – #BSidesCT Hamden, CT @BSidesFloodCity – #BSidesFloodCity Johnstown, PA @BSidesHBG – #BSidesHBG Harrisburg, PA @BSidesNJ@infosec.exchange – #BSidesNJ ? NJ @BSidesNYC@infosec.exchange – #BSidesNYC New York City, NY @bsidesphilly@infosec.exchange – #BSidesPhilly Philadelphia, PA @bsidespgh@infosec.exchange – #BSidesPGH Pittsburgh, PA @bsidesroc@infosec.exchange – #BSidesROC Rochester, NY @hushcon@infosec.exchange – #HushCon New York City, NY @jawncon@infosec.exchange – #JawnCon Philadelphia, PA @pumpcon@infosec.exchange – #PumpCon Philadelphia, PA @ShmooCon@infosec.exchange – #ShmooCon Washington, DC @SummerC0n@infosec.exchange – #SummerCon Brooklyn, NY

⸻ US – Midwest

@BlueTeamCon@infosec.exchange – #BlueTeamCon Chicago, IL @bsides312@infosec.exchange – #BSides312 Chicago, IL @BSidesBloomington – #BSidesBloomington, IN @BSides_BTown@infosec.exchange – #BSides_BTown Bloomington, IN @bsidesboulder@infosec.exchange – #BSidesBoulder, CO @bsideschicago@infosec.exchange – #BSidesChicago, IL @BSidesColoradoSprings – #BSidesColoradoSprings, CO @BSidesColumbus – #BSidesColumbus, OH @bsidesdayton@infosec.exchange – #BSidesDayton, OH @bsidesdenver@infosec.exchange – #BSidesDenver, CO @BSidesFtWayne – #BSidesFtWayne, IN @bsideskc@infosec.exchange – #BSidesKC Kansas City, MO @BSidesMilwaukee – #BSidesMilwaukee, WI @BSidesPeoria – #BSidesPeoria, IL @bsidesspfd@infosec.exchange – #BSidesSpfd Springfield, MO @CircleCityCon@infosec.exchange – #CircleCityCon Indianapolis, IN @CypherCon@infosec.exchange – #CypherCon Milwaukee, WI @thotcon@infosec.exchange – #THOTCON Chicago, IL @WWHackinFest@infosec.exchange – #WWHackinFest Deadwood, SD

⸻ US – West

@bsidescv@infosec.exchange – #BSidesCV Central Valley, CA @BSidesHawaii – #BSidesHawaii Honolulu, HI @bsidesla@infosec.exchange – #BSidesLA Los Angeles, CA @BSidesPDX@pdx.social – #BSidesPDX Portland, OR @BsidesSD@infosec.exchange – #BSidesSD San Diego, CA @bsidesseattle@infosec.exchange – #BSidesSeattle, WA @bsidessf@infosec.exchange – #BSidesSF San Francisco, CA @soups@hci.social – #SOUPS Symposium on Usable Privacy and Security, Anaheim, CA

⸻ US – Southwest

@BSidesAlbuquerque – #BSidesAlbuquerque, NM @bsidesaustin@infosec.exchange – #BSidesAustin, TX @BSidesDFW@infosec.exchange – #BSidesDFW Dallas-Fort Worth, TX @BSidesLV@infosec.exchange – #BSidesLV Las Vegas, NV @BSidesRGV@infosec.exchange – #BSidesRGV Rio Grande Valley, McAllen, TX @BSidesSATX@infosec.exchange – #BSidesSATX San Antonio, TX @BSidesSantaFe – #BSidesSantaFe, NM @BSidesTucson – #BSidesTucson, AZ @cactuscon@infosec.exchange – #CactusCon Mesa, AZ @defcon@defcon.social – #DEFCON Las Vegas, NV @DianaInitiative@defcon.social – #DianaInitiative Las Vegas, NV

⸻ US – Southeast

@bsidesatl@infosec.exchange – #BSidesATL Atlanta, GA @BSidesAugusta@infosec.exchange – #BSidesAugusta, GA @BSidesBirmingham – #BSidesBirmingham, AL @BSidesCharleston@infosec.exchange – #BSidesCharleston, SC @BSidesCLT@infosec.exchange – #BSidesCLT Charlotte, NC @BSidesCHS – #BSidesCHS Charleston, SC @BSidesCharlotte@infosec.exchange – #BSidesCharlotte, NC @BSidesGVL – #BSidesGVL Greenville, SC @BSidesHSV – #BSidesHSV Hunstville, AL @BSidesJAX – #BSidesJAX, Jacksonville, FL @BSidesKC – #BSidesKC Kansas City, MO @bsidesknoxville@infosec.exchange – #BSidesKnoxville, TN @BSidesNOLA – BSidesNOLA New Orleans, LA @BSidesNoVA – #BSidesNoVA Arlington, VA @bsidesorlando@infosec.exchange – #BSidesOrlando, FL @BSidesRoanoke – #BSidesRoanoke, VA @BSidesRDU@infosec.exchange – #BSidesRDU Raleigh/Durham, NC @BSidesSPFD@infosec.exchange – #BSidesSPFD Springfield, MO @bsidesSTL@infosec.exchange – #BSidesSTL St. Louis, MO @BSidesStPete – #BSidesStPete St. Petersburg, FL @BSidesTampa – #BSidesTampa, FL @CackalackyCon@infosec.exchange – #Cackalacky Con, Raleigh, NC @CYBERWARCON@infosec.exchange – #CyberwarCon Arlington, VA @securityonion@infosec.exchange – #SecurityOnion Con, Augusta, GA

⸻ US – Territories

@BSidesPR – #BSidesPR San Juan, PR 🇵🇷

⸻ Caribbean

@BSidesCaymanIslands – #BSidesCaymanIslands, KY 🇰🇾

⸻ Latin America

@BSidesArgentina – #BSidesArgentina Jujuy, Argentina 🇦🇷 @bsidescdmx@infosec.exchange – #BSidesCDMX Mexico City, Mexico 🇲🇽 @BSidesCO – #BSidesCO Bogotá, Colombia 🇨🇴 @bsidesjp@infosec.exchange – #BSidesJoãoPessoa, Brazil 🇧🇷 @BSidesPeru – #BSidesPeru Lima, Peru 🇵🇪 @BSidesPanama – #BSidesPanama Panama City, Panama 🇵🇦 @BSidesSP@infosec.exchange – #BSidesSP Sao Paulo, Brazil 🇧🇷 @BSidesVitória – #BSidesVitória, Brazil 🇧🇷

⸻ Europe 🇪🇺

@botconf@infosec.exchange – #Botconf Nice, FR 🇫🇷 @brucon@infosec.exchange – #BruCON Mechelen, BE 🇧🇪 @BSidesAthens – #BSidesAthens, GR 🇬🇷 @BSidesBUD – #BSidesBUD Budapest, HU 🇭🇺 @BSidesCyprus – #BSidesCyprus Limassol, CY 🇨🇾 @BSidesDublin – #BSidesDublin, IE 🇮🇪 @BSidesKraków~~ – #BSidesKraków, PL 🇵🇱 @bsideskbh@infosec.exchange – #BSidesKbh København, DK 🇩🇰 @bsideslisbon@infosec.exchange – #BSidesLisbon, PT 🇵🇹 @bsidesljubljana@infosec.exchange – #BSidesLjubljana, SI 🇸🇮 @BSidesMilano – #BSidesMilano, IT 🇮🇹 @BSidesOsijek – #BSidesOsijek, HR 🇭🇷 @bsidesoslo@infosec.exchange – #BSidesOslo, NO 🇳🇴 @BSidesPrishtina – #BSidesPrishtina, XK 🇽🇰 @BSidesRoma – #BSidesRoma, IT 🇮🇹 @bsidesrvk@infosec.exchange – #BSidesReykjavik, IS 🇮🇸 @BSidesSOF@infosec.exchange – #BSidesSOF Sofia, BG 🇧🇬 @BSidesTallinn – #BSidesTallinn, EE 🇪🇪 @BSidesTirana – #BSidesTirana, AL 🇦🇱 @BSidesTransylvania – #BSidesTransylvania Cluj-Napoca, RO 🇷🇴 @BSidesUmeå – #BSidesUmeå, SE 🇸🇪 @bsidesvienna@infosec.exchange – #BSidesVienna, AT 🇦🇹 @BSidesZurich@infosec.exchange – #BSidesZurich, CH 🇨🇭 @deepsec@social.tchncs.de – #DeepSec Con, Vienna, AT 🇦🇹 @hack_lu@infosec.exchange – #HackLu, LU 🇱🇺 @passthesaltcon@infosec.exchange – Pass the SALT Con, Lille, FR 🇫🇷 @securitybsidesitalia@infosec.exchange – #BSidesItalia IT 🇮🇹 @TumpiConIT@infosec.exchange – #TumpiCon Turin area, IT 🇮🇹

⸻ Germany 🇩🇪

@BSidesBerlin – #BSidesBerlin @BSidesFrankfurt – #BSidesFrankfurt am Main @BSidesMunich@infosec.exchange – #BSidesMunich @BSidesStuttgart – #BSidesStuttgart @elbsides@infosec.exchange – #Elbsides BSides Hamburg @WEareTROOPERS@infosec.exchange – TROOPERS Conference, Heidelberg

⸻ United Kingdom 🇬🇧

@44CON@infosec.exchange – #44CON London 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @AbertayHackers@infosec.exchange – #SecuriTay Abertay, Dundee, 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @BSidesBasingstoke – #BSidesBasingstoke @BSidesBelfast – #BSidesBelfast @BSidesBHAM@infosec.exchange – #BSidesBham Birmingham 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @BSidesBristol – #BSidesBristol @BSidesCambridge – #BSidesCambridge @BSidesCheltenham@infosec.exchange – #BSidesCheltenham 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @BSidesDundee – #BSidesDundee 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @BSidesExeter – #BSidesExeter @BSidesLancashire – #BSidesLancashire @bsidesleeds@infosec.exchange – #BSidesLeeds 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @BSidesNewcastle – #BSidesNewcastle @VirusBulletin@infosec.exchange – #VB2024 VirusBulletin, London 🏴󠁧󠁢󠁥󠁮󠁧󠁿

⸻ Africa

@BSidesCapeTown – #BSidesCapeTown, South Africa 🇿🇦 @BSidesNairobi – #BSidesNairobi, Kenya 🇰🇪

⸻ India 🇮🇳

@BSidesAhmedabad – #BSidesAhmedabad @BSidesBangalore@infosec.exchange – #BSidesBangalore @BSidesChennai – #BSidesChennai @BSidesIndore – #BSidesIndore @BSidesJaipur – #BSidesJaipur @BSidesOdisha@infosec.exchange – #BSidesOdisha

⸻ Asia

@BSidesMyanmar – #BSidesMyanmar, Myanmar 🇲🇲 @BSidesSG – #BSidesSG Singapore, China 🇨🇳 @BSidesTokyo – #BSidesTokyo, Japan 🇯🇵 @BSidesYerevan – #BSidesYerevan, Armenia 🇦🇲

⸻ Australasia

@bsides_bne@infosec.exchange – #BSides_Bne Brisbane, AU 🇦🇺 @bsidescbr@infosec.exchange – #BSidesCanberra, AU 🇦🇺 @bsidesmelbourne@infosec.exchange – #BSidesMelbourne, AU 🇦🇺 @bsidesperth@infosec.exchange – #BSidesPerth, AU 🇦🇺 @bsidessydney@infosec.exchange – #BSidesSydney, AU 🇦🇺 @crikeycon@infosec.exchange – #CrikeyConAU Brisbane, AU 🇦🇺

⸻ For other events not in the fediverse try: ➡️⁠https://securitybsides.com ➡️⁠https://github.com/xsa/infosec-events by Xavier Santolaria @0x58@infosec.exchange

Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want. :cc_cc:​𝟶 “No Rights Reserved”

⸻ #InfoSec #CyberSecurity #BSides #CatSalad #cc0

 
Read more...

from CatSalad🐈🥗 (D.Burch)

(Updated:2023-09-26)

This list only contains local 2600, DEFCON, CCC, OWASP, LUG, and InfoSec groups with active fediverse / Mastodon accounts, including languages other than English. As more are created or discovered, I will update this message. For hackerspaces, see the link below.

📌⁠InfoSec Events by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hacker Meet-ups by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hackerspaces by Region (ᵃˡˢᵒ🦣ⷨ)

🐈🥗

⸻ InfoSec Groups

@2600@lemmy.world – 2600 Community (Lemmy) @blackhoodie@infosec.exchange – #BHRE (women only) @CCC@social.bau-ha.us – Chaos Computer Club @ccc@anonsys.net – #CCC (friendica) @guide@chaos.social – CCC events #cccRegio @womenincybersecurity@mastodon.social – Women In Cybersecurity (#WiCyS)

⸻ Canada 🇨🇦

@dc902@defcon.social – #DC902 Halifax, NS @OWASP_Ottawa@infosec.exchange – OWASP Ottawa

⸻ US – Northeast

@2600_new_hampshire@eventos.hispagatos.org – 2600, NH @blacksincyber@defcon.social – Blacks In Cybersecurity™ (BIC), Washington, DC @blacksincyber@infosec.exchange – #BIC DMV Metro Area, DC @dc215@defcon.social – #DC215, Philadelphia, PA @defcon201@diode.zone – #DC201 North New Jersey @dc201@diode.zone – DC201 North NJ @defcon201@hostux.social – DC201 North NJ @defcon610@defcon.social – #DC610 Easton, PA @hacdc@fosstodon.org – #HackDC Washington, DC @NYC2600@infosec.exchange – #NYC2600 NY @NYC2600@mastodon.social – NYC 2600, NY @owaspboston@infosec.exchange – OWASP Boston, MA @philly2600@jawns.club – #Philly2600 Philadelphia, PA @Phillysec@infosec.exchange – #Phillysec Philadelphia, PA

⸻ US – Midwest

@defcon402@infosec.exchange – #DC402 Nebraska @DC608Madison@defcon.social – #DC608 Madison, WI @DC608Madison@infosec.exchange – DC608 Madison, WI @defcon937@infosec.exchange – #DC937 Dayton, OH @DenverSec@infosec.exchange – #DenverSec Denver, CO @lansing2600@mastodon.praxis.red – #Lansing2600 Lansing, MI @RockyMtnLUG@fosstodon.org – Rocky Mountain LUG, CO

⸻ US – West

@dc503@defcon.social – #DC503 Portland, OR @dc510@defcon.social – #DC510 Oakland, CA @DCG858@defcon.social – #DC858 / #DC619 San Diego, CA @pdx2600@mastodon.online – #PDX2600 Portland, OR @rainsec@infosec.exchange – #RainSec PDX, Portland, OR

⸻ US – Southwest

@ASULUG@fosstodon.org – #ASULUG ASU, AZ @dallas_hackers@infosec.exchange – Dallas Hackers Dallas, TX @DC512@defcon.social – #DC512, Austin, TX @PLUG@fosstodon.org – #PLUG, Phoenix, AZ

⸻ US – Southeast

@dc404@defcon.social – #DC404 Atlanta, GA @DC443@defcon.social – #DC443 Baltimore, MD @dc540@defcon.social – #DC540 Nova regional, VA @dc540@infosec.exchange – DC540 Nova regional, VA @RTP2600@kolektiva.social – #RTP2600 Raleigh, NC

⸻ Europe 🇪🇺

@2600Malmo@mastodon.online – #2600Malmo 2600 Malmö, SE 🇸🇪 @2600stockholm@mastodon.social – #2600stockholm Stockholm, SE 🇸🇪 @2600_madrid@eventos.hispagatos.org – 2600 Madrid, ES 🇪🇸 @amsterdam@chaos.social – Chaos Amsterdam, NL 🇳🇱 @c3wien@chaos.social – CCC Wien, Vienna, AT 🇦🇹 @CCCBasel@chaos.social – CCC Basel, Muttenz, CH 🇨🇭 @dc4822@infosec.exchange – #DC4822 Warsaw, PL 🇵🇱 @dc9723@defcon.social – #DC9723, Tel-Aviv, IL 🇮🇱 @lugos@floss.social – #LUGOS SI 🇸🇮 @lugv@troet.cafe – #LUGV Vorarlberg, AT 🇦🇹 @ulug@social.linux.pizza – #ULUG Uppsala, SE 🇸🇪

⸻ Germany 🇩🇪

@amborg_sulzbyte@chaos.social – Chaostreff Amberg Sulzbach @c3d2@c3d2.social – CCC Dresden @cccac@chaos.social – CCC Aachen @cccda@chaos.social – CCC Darmstadt @cccffm@chaos.social – CCC Frankfurt @cccfr@chaos.social – CCC Freiburg @ccchh@chaos.social – CCC Hamburg @cccp@chaos.social – CCC Potsdam @cccs@chaos.social – CCC Stuttgart @cccwi@cccwi.social – CCC Wiesbaden @cciz@chaos.social – Computer Club Itzehoe @chaospott@chaos.social – CCC Essen @clubdiscordia@chaos.social – CCC Berlin @ctaz@rheinhessen.social – Chaostreff Alzey @ctbk@chaos.social – Chaostreff Backnang @erlug@social.anoxinon.de – #ErLUG Erlangen @flipdot@social.flipdot.org – #Flipdot CCC Erfa-Kreis, Kassel @haecksen@chaos.social – #Haecksen (Stuttgart, Hamburg, Hannover, Karlsruhe, Leibzig, Göttingen and Berlin) @geekfem@chaos.social – #Geekfem Hamburg @KiLUG@mastodon.social – #KiLUG Haslach im Kinzigtal @LUG_MYK@chaos.social – LUG Mayen-Koblenz @lug_nuernberg@mastodon.online – LUG Nürnberg @lughannover@norden.social – LUG Hannover @lugor@dynlinux.io – #LUGOR Oberhausen Rheinland @muccc@chaos.social – CCC Munich @owasp_de@infosec.exchange – OWASP DE @owasp_ka@chaos.social – OWASP Karlsruhe

⸻ India 🇮🇳

@dc_9111@ioc.exchange – #DC9111, Delhi

⸻ United Kingdom 🇬🇧

@2600@glasgow.social – 2600 Glasgow 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @AbertayHackers@infosec.exchange – Abertay Hackers, Dundee 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @DC44131@infosec.exchange – #DC44131 Edinburgh 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @OWASPLondon@infosec.exchange – OWASP London 🏴󠁧󠁢󠁥󠁮󠁧󠁿

⸻ Australasia

@flinderscybersoc@infosec.exchange – Flinders Cybersecurity Society, Adelaide, AU 🇦🇺 @linuxaustralia@fosstodon.org – Linux Australia 🇦🇺 @owaspmelb@infosec.exchange – OWASP Melbourne, AU 🇦🇺 @PalmyLUG@mastodon.nzoss.nz – #PalmyLUG Palmerston North, NZ 🇳🇿

For other groups & meetups not in the fediverse: ➡️⁠https://forum.defcon.org/social-groups ➡️⁠https://events.ccc.de/ ➡️⁠https://owasp.org/www-community/meetings/ ➡️⁠https://www.2600.com/meetings

Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want. cc​𝟶 “No Rights Reserved”

#InfoSec #CyberSecurity #DEFCON #2600 #CCC #OWASP #WomenInCybersecurity #LUG #LinuxUserGroup #CatSalad #cc0

 
Read more...

from CatSalad🐈🥗 (D.Burch)

(Updated:2023-09-26)

This list contains hackspaces and hacklabs with active fediverse / Mastodon accounts. For monthly group meets, see the post link below. This list will be update as more workshops in the fediverse are discovered.

📌⁠InfoSec Events by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hacker Meet-ups by Region (ᵃˡˢᵒ🦣ⷨ) 📌⁠Hackerspaces by Region (ᵃˡˢᵒ🦣ⷨ)

🐈🥗

⸻ United States 🇺🇸

@hacdc@fosstodon.org – #HackDC Washington, DC @iffybooks@post.lurk.org – Iffy Books – Philadelphia, PA @Noisebridge@sfba.social – #Noisebridge Hackerspace – San Francisco, CA

⸻ Latin America

@lhc@mastodon.com.br – Laboratório Hacker de Campinas, Brazil 🇧🇷

⸻ Europe 🇪🇺

@coredump@chaos.social – #Coredump Hack- & Makerspace, Rapperswil-Jona, CH 🇨🇭 @fhl@mastodon.cisti.org – F-HackLab, Rome, IT 🇮🇹 @hackeriet@chaos.social – #Hackeriet Oslo, NO 🇳🇴 @hackstub@kolektiva.social – #Hackstub Strasbourg, FR 🇫🇷 @hspsh@0x3c.pl – #HsPsh Hackerspace Pomorze, PL 🇵🇱 @hswaw@hackerspace.pl – #HsWaw Warsaw, PL 🇵🇱 @KaouennNoz@diaspodon.fr – #KaouennNoz Rennes, FR 🇫🇷 @lebib@social.bim.land – #LeBIB Montpellier, FR 🇫🇷 @hslodz@mas.to – #HSLodz Hakierspejs Łódź, PL 🇵🇱 @tamperehacklab@qoto.org – #TampereHacklab FI 🇫🇮

⸻ Austria 🇦🇹

@devlol@chaos.social – #DevLol Linz @itsyndikat@chaos.social – #Itsyndikat Innsbrucks @metalab@chaos.social – #Metalab Vienna @realraum@chaos.social – #Realraum Graz @usrspace@chaos.social – /usr/space, Leobersdorf

⸻ Germany 🇩🇪

@acmelabs@chaos.social – #ACMELabs Bielefeld @backspace@chaos.social – #Backspace CCC-Erfa, Bamberg @binhacken@chaos.social – #BinHacken Hacker- & Makerspace, Bingen @bytespeicher@social.bau-ha.us – #Bytespeicher Erfurt @bytewerk@chaos.social – #bytewerk Ingolstadt @c4@chaos.social – CCC Cologne @cbase@chaos.social – c-base, Berlin @cccac@chaos.social – CCC Aachen @cccda@chaos.social – CCC Darmstadt @cccffm@chaos.social – CCC Frankfurt @cccfr@chaos.social – CCC Freiburg @ccchh@chaos.social – CCC Hamburg @cccwi@cccwi.social – CCC Wiesbaden @chaos_fl@chaos.social – Chaostreff Flensburg @chaosdorf@chaos.social – #Chaosdorf Hackspace & CCC Erfa, Düsseldorf @chaostreff_osnabrueck@chaos.social – Chaostreff Osnabrück @chaotikumev@social.chaotikum.org – #Chaotikum Lübeck @chch@chaos.social – Chaostreff Chemnitz @clubdiscordia@chaos.social – #ClubDiscordia CCC Berlin @daslabor@chaos.social – #DasLabor Bochum @datenburg@bonn.social – #Datenburg Bonner @dezentrale@chaos.social – Dezentrale Leipzig @eigenbaukombinat@chaos.social – #Eigenbaukombinat Halle, Saale @entropia@chaos.social – #Entropia Karlsruhe @flipdot@social.flipdot.org – #Flipdot Kassel @hacklabor@chaos.social – #Hacklabor Schwerin @hackershell@social.anoxinon.de – #Hackershell 🌐 @hacksaar@social.saarland #Hacksaar Saarbrücken @Hackzogtum@chaos.social – #Hackzo Coburg @Hasi@chaos.social – Hackspace Siegen @haxko@chaos.social – #Haxko Mayen-Koblenz @HSB@chaos.social – Hackerspace Bielefeld @k4cg@chaos.social – K4 Computergruppe, Nuremberg @krautspace@chaos.social – #Krautspace Jena @leinelab@chaos.social – #LeineLab Hannover @maglab@chaos.social – #MagLab Magrathea Laboratories, Fulda @maschinenraum@social.bau-ha.us – #Maschinenraum m18, Weimar @muccc@chaos.social – CCC Munich @neanderfunk@nrw.social – Freifunk Neanderland, Wülfrath @neotopia@chaos.social – #Neotopia Göttingen @Nerdberg@chaos.social – #Nerdberg Nuernberg @netz39@machteburch.social – #Netz39 Magdeburg @OpenLabAugsburg@chaos.social – OpenLab, Augsburg @OWN@chaos.social – Offene Werkstatt Norderstedt @Port39@chaos.social – #Port39 Stralsund @raumfahrtagentur@chaos.social – Raumfahrt, Berlin @schaffenburg@social.schaffenburg.org – #Schaffenburg @space47@ruhr.social – #Space47 Duisburg @spline@chaos.social – #Spline Berlin @stratum0@chaos.social – #Stratum0 Braunschweig @RaumZeitLabor@chaos.social – #RaumZeitLabor Mannheim @temporaerhaus@chaos.social – Temporärhaus, Ulm @toppoint@chaos.social – Toppoint Hackspace, Kiel @Turmlabor@chaos.social – nachtsnochlicht@Turmlabor, Dresden @UN_Hack_Bar@chaos.social – UN-Hack-Bar, Unna @warpzone@social.bau-ha.us – warpzone, Münster @welcomewerkstatt@norden.social – #WelcomeWerkstatt Hamburg @werkraum@chaos.social – #Werkraum Zittau @westwoodlabs@chaos.social – #Westwoodlabs Westerwald @xHain_hackspace@chaos.social – xHain Hack- Makerspace, Berlin @zLabor@chaos.social – #zLabor Zwickau @ztl@rheinneckar.social – Zentrum für Technikkultur Landau

⸻ Netherlands 🇳🇱

@amsterdam@chaos.social – Chaos Amsterdam @bitlair@hsnl.social – #Bitlair Amersfoort @hack42@chaos.social – #Hack42 Arnhem @hackalot@hsnl.social – #Hackalot Eindhoven @pixelbar@hsnl.social – #Pixelbar Rotterdam @revspace@hsnl.social – #RevSpace Hague @TDvenlo@hsnl.social – #TDvenlo Venlo @TechInc@mastodon.social – Technologia Incognita, Amsterdam @tkkrlab@hsnl.social – #TrrkLab Enschede

⸻ United Kingdom 🇬🇧

@57n@abdn.social – #57n Hacklab, Aberdeen 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @57n@hostux.social – #57North Hacklab, Aberdeen 🏴󠁧󠁢󠁳󠁣󠁴󠁿 @cheltenham_hackspace@mastodonapp.uk – Cheltenham Hackspace 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @EEHackSpace@mstdn.social – #EEHackSpace East Essex 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @hackhitchin@techhub.social – #HackHitchin Hitchin 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @leigh_hackspace@mastodon.social – Leigh Hackspace, Manchester 🏴󠁧󠁢󠁥󠁮󠁧󠁿 @nottinghack@hachyderm.io – #NottingHack Nottingham 🏴󠁧󠁢󠁥󠁮󠁧󠁿

⸻ Australasia

@ballarat@hackerspace.au – Ballarat Hackerspace, AU 🇦🇺

For other hackerspaces not in the fediverse try: ➡️⁠https://wiki.hackerspaces.org/List_of_Hacker_Spaces

Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want. :cc_cc:​𝟶 “No Rights Reserved”

#CCC #ChaosComputerClub #Hacker #Hackspace #Hackerspace #CatSalad #cc0

 
Read more...

from CatSalad🐈🥗 (D.Burch)

List of some useful links, news sites, and open web search engines that also provide .Onion service access through Tor :tor:. Each searx site varies on their up time, so it pays to visit the 🗂️⁠SearXNG Index to find alternatives.

📌⁠List of torified fedi instances (ᵃˡˢᵒ🦣ⷨ) 📌⁠List of useful torified sites (ᵃˡˢᵒ🦣ⷨ)

🗃️⁠Archive.Today⁠〰️→🧅⁠archivei… 💻⁠DEFCON Forums⁠→🧅⁠ezdhgsy… 💻⁠DEFCON Home⁠〰️→🧅⁠g7ejphhu… 💻⁠DEFCON Media⁠〰️→🧅⁠m6rqq6k… 🔐⁠Key.OpenPGP.org⁠→🧅⁠zkaan2x… 🔖⁠Reddit.com⁠〰️〰️→🧅⁠redditorj…★ 📚⁠zLibrary Articles⁠→🧅⁠articles2… 📚⁠zLibrary Books⁠→🧅⁠bookszlib…

⸻News🗞️⁠⸻

🗞️⁠BBC News⁠〰️〰️→🧅⁠bbcnewsd…★ 🗞️⁠DeutscheWelle⁠→🧅⁠dwnewsg…★ 🗞️⁠ProPublica⁠〰️〰️→🧅⁠p53lf57… 🗞️⁠The Guardian⁠〰️→🧅⁠guardian2…

🗂️⁠SearXNG Index⁠→🧅⁠searxspb… 🔍⁠divided-by-zero⁠→🧅⁠f4qfqajs… 🔍⁠nicfab.eu⁠〰️〰️→🧅⁠lgmekfn…★ 🔍⁠northboot.xyz⁠→🧅⁠4n53nafyi… 🔍⁠ononoki.org⁠〰️→🧅⁠searchvrz… 🔍⁠priv.au⁠〰️〰️〰️→🧅⁠privateoz… 🔍⁠prvcy.eu⁠〰️〰️→🧅⁠rq2w52k… 🔍⁠sapti.me⁠〰️〰️→🧅⁠gbat2pb… 🔍⁠stinpriza.org⁠→🧅⁠z5vawdo… 🔍⁠thefloatinglab⁠→🧅⁠iziatwmt… 🔍⁠tiekoetter⁠〰️〰️→🧅⁠searx3ao…

⸻ (★ = Supports HTTPS-over-Onion) 🐈🥗

#TorProject #OnionService #OnionServices #Tor #Onion #Privacy #CatSalad

 
Read more...

from CatSalad🐈🥗 (D.Burch)

(Updated:2023-09-26)

List of fediverse instances that also provide access through .Onion servers using Tor Hidden Services. I will add more as I find them... Well, most of them anyway.

📌⁠List of torified fedi instances (ᵃˡˢᵒ🦣ⷨ) 📌⁠List of useful torified sites (ᵃˡˢᵒ🦣ⷨ)

⸻FediTor🔖⁠⸻

⁠⛔⁠Alive.bar⁠〰️〰️〰️→🧅⁠alivebrntm… 💻⁠Defcon.social〰️→🧅⁠zpj4sjt4a…★ 💻⁠Ieji.de⁠〰️〰️〰️〰️→🧅⁠iejideks5z…★ 💻⁠Infosec.exchange⁠→🧅⁠7jaxqg6… ⛔⁠⁠Kolektiva.social⁠〰️→🧅⁠klktvbm… ⛔⁠⁠Masto.ai⁠〰️〰️〰️→🧅⁠yiynyc2ly…★ 💻⁠Mstdn.social⁠〰️→🧅⁠c6usaa6… 💻⁠Octodon.social⁠→🧅⁠octodonic… ⛔⁠⁠Partyon.xyz⁠〰️→🧅⁠partyonl2… ⛔⁠⁠Qdon.space⁠〰️→🧅⁠nqt42rzz5… 💻⁠Slippy.xyz〰️〰️→🧅⁠irvqsc5bb… 💻⁠Vern.cc⁠〰️〰️〰️→🧅⁠ak.vernccv… 💻⁠Wetdry.world⁠〰️→🧅⁠qm7a3tu…

⸻ (★ = Supports HTTPS-over-Onion) (⛔⁠ = Cloudflared)

🐈🥗

#FediTor #TorProject #OnionService #OnionServices #Fedi #Tor #Onion #Privacy #CatSalad

 
Read more...

from acrypthash

Incident Response: Scam Attack Against Retail Stores

Yesterday our stores experienced a scam attack via phone call claiming to be from the IT department and wanting to test refunds on high value items in order to get free money. Later in the campaign, they change story to claim they were from a VoIP provider. Unfortunately, one or two stores fell victim, but many others remained vigilant.

As a response, our security team deployed the following: – Created a war room for the few members involved. – Sent out communications to all employees involved (we have internal tools for this) – Used OSINT to investigate the phone number being used (the threat actor was dumb enough to use the same number for all attempts). – Blocked the number through our provider (though changing number is obviously very easy. This was done because it was the only number being used at the time.) – Did EDR scans on all store PCs from people that called in. Side Note – This is where communication with non tech savvy people can be difficult. During the social engineering process, the person at the register is instructed to reach a point in the process where you have to enter a credit card number. Reports from one end user claimed the that cc number was entered in automatically by the threat actor on the phone. They claimed no other assistance was given to access the PC, no mouse movement was performed, just the number entry. This does not make any sense to me. I did the following to investigate, but found zero IoCs: – full EDR scan on the endpoint – PCAP review for any malicious connections – RMM software installations – ELK log review – folder review – confirmed scheduled tasks Nothing substantial was found to show that a threat actor had accessed the PC and entered in the cc number. Personally, I think the end user reporting this claimed it happened this way to protect themselves. Regardless, nothing was found.

Through good communication and best security practices we were able to get this incident under control relatively fast. A big take away from this is going to be ACL build out for the feature that allows for the access of refunds through manual entry. Too many people seem to have access to this feature by default.

There is an obvious pattern that must be brought up so we as analysts and blue teamers can remain vigilant. Threat actors are starting to realize how easy social engineering truly is and the power that comes with it. We must keep our end users aware of these threats and train them to question the true intentions of people when something doesn't feel right. Typically when your gut questions something, you're usually right. For our team, we are going to be working closely with our help desk team over the next few weeks to improve their verification process and social skills to learn when something malicious is happening. Happy Hacking!

 
Read more...

from Amy’s tech stuff

start by drawing a n by n grid of points

  ╭─────── n ───────╮
╭ o  o  o  o  o  o  o
│ o  o  o  o  o  o  o
│ o  o  o  o  o  o  o
n o  o  o  o  o  o  o
│ o  o  o  o  o  o  o
│ o  o  o  o  o  o  o
╰ o  o  o  o  o  o  o

take the dots on the main diagonal and move them over to the side

  ╭─────── n ───────╮             1
╭    o  o  o  o  o  o             • ╮
│ o     o  o  o  o  o             • │
│ o  o     o  o  o  o             • │
n o  o  o     o  o  o     ==>     • n
│ o  o  o  o     o  o             • │
│ o  o  o  o  o     o             • │
╰ o  o  o  o  o  o                • ╯ 

we can see the points in the diagonal can be arranged into a line of 1 by n points, thus the main square without the diagonal is n²-n

we can also see that the remaining dots are divided up into two mirror images of each other, mirrored along the main diagonal. Since it can be evenly divided into two, it the remainder must be even

  ╭─────── n ───────╮
╭    •  •  •  •  •  •
│ o     •  •  •  •  •
│ o  o     •  •  •  •
n o  o  o     •  •  •
│ o  o  o  o     •  •
│ o  o  o  o  o     •
╰ o  o  o  o  o  o   

We can also slide all the point of one halve towards the other, creating a rectangle

  ╭───── n-1 ────╮
╭ •  •  •  •  •  •
│ o  •  •  •  •  •
│ o  o  •  •  •  •
n o  o  o  •  •  •
│ o  o  o  o  •  •
│ o  o  o  o  o  •
╰ o  o  o  o  o  o

This gives us the factored form of the expression n (n-1)
From this expression we can see that it must always produce an even result as it takes the product of two consecutive numbers, one of them must be even, and the product of two numbers is even if either number is even

#math

 
Read more...

from Amy’s tech stuff

I recently came across Veilid, a new network focused on secure communication, similar to TOR, but mixed in with distributed storage and a promise of true decentralization without any blockchains or coins.

Both the website and DefCon talk are a bit lacking in explanation at this moment, with a promise of more documentation coming soon. Looking at the repository however gives slightly more insights.

This guide seems to be the most complete introduction at this point.

Also looking through the slides might also give some more crumbs of detail.

TL:DR; Distributed storage

The network provides two kinds of storage:

Block storage allows to store medium sized chunks of data (up to 1MB) onto the network. These are accessed by their hash and are immutable. Nodes can choose to actively become a provider of a block, and nodes will cash retrieved blocks based on demand
(Note: at this point the block store is not implemented yet but is firmly on the roadmap)

Distributed hash table (Key/Value store) is for smaller chunks of (mostly text) data that can be modified by it's owner. These, as the name implies, are accessed via a key. Nodes can register to be informed of changes.

TL:DR; Networking

Everyone participating in the Network is a node, and all nodes are treated equally. Nodes can choose how much or little traffic they are willing to relay, and how much data to store.

At the start a node reaches out to a bootstrap server with a known address, which tells the nodes what other nodes in the network it can contact. From there the new node asks them for information on more peer in the network. This bootstrap server will usually be the main veilid bootstrap server, but can be your own, especially if you want to create a smaller, isolated network for some reason.
Once the node has info on it's peers it will not need to bootstrap again, unless all known peers stop existing the next time it attempts to join.

Since nodes can change, user identity is given by a public/private keypair which identifies a user and allows them to modify their data.

Routing your traffic by relaying it through other nodes is optional. Every user has a list of routes they can be reached by, which change frequently. These routes can just be the user's node itself it they don't want to receive traffic anonymously or a chain of nodes that lead to the user's node. The same thing applies to sending data. You can either send your data though a route of relays of your choosing to hide where it is coming from, or just send your traffic to the receivers route directly.

Up next: Setting up a node and playing with it

#veilid

 
Read more...

from z0ds3c

Nuclei is a tool that allows you to scan web targets for various vulnerabilities and misconfigurations using predefined templates¹. Here are 10 powerful one-liners that you can use with Nuclei to find interesting and potentially exploitable issues:

  • Scan for all CVEs in a target list: cat targets.txt | nuclei -t cves/ -o results.txt

  • Scan for all exposed panels in a target list: cat targets.txt | nuclei -t exposed-panels/ -o results.txt

  • Scan for all subdomain takeovers in a target list: cat targets.txt | nuclei -t subdomain-takeover/ -o results.txt

  • Scan for all XSS vulnerabilities in a target list: cat targets.txt | nuclei -t xss/ -o results.txt

  • Scan for all SSRF vulnerabilities in a target list: cat targets.txt | nuclei -t ssrf/ -o results.txt

  • Scan for all SQL injection vulnerabilities in a target list: cat targets.txt | nuclei -t sqli/ -o results.txt

  • Scan for all open redirects in a target list: cat targets.txt | nuclei -t redirects/ -o results.txt

  • Scan for all misconfigured CORS policies in a target list: cat targets.txt | nuclei -t cors/ -o results.txt

  • Scan for all prototype pollution vulnerabilities in a target list: cat targets.txt | nuclei -t prototype-pollution/ -o results.txt

  • Scan for all RCE vulnerabilities in a target list: cat targets.txt | nuclei -t rce/ -o results.txt

 
Read more...

from z0ds3c

Top 5 Tools for CTFs

Capture the Flag (CTF) competitions are a great way to test and improve your cybersecurity skills. They involve solving a variety of challenges, such as hacking into websites, cracking passwords, and reverse engineering malware.

To be successful in CTFs, it's important to have a good understanding of a variety of cybersecurity topics, as well as the right tools. Here are our top 5 picks for the best CTF tools:

  1. Burp Suite

Burp Suite is a powerful web application security testing tool. It can be used to perform a variety of tasks, including intercepting and modifying HTTP requests and responses, scanning for vulnerabilities, and fuzzing.

  1. Ghidra

Ghidra is a free and open-source reverse engineering tool developed by the National Security Agency (NSA). It can be used to disassemble and analyze machine code, as well as to debug and create software exploits.

  1. Nmap

Nmap is a network mapping and security scanning tool. It can be used to identify all of the devices on a network, as well as the services they are running and the ports they are open on.

  1. SQLMap

SQLMap is an automated SQL injection and database takeover tool. It can be used to exploit SQL injection vulnerabilities in web applications and gain access to underlying databases.

  1. Python

Python is a general-purpose programming language that is widely used in the cybersecurity community. It is a good language for learning and scripting, and it can be used to solve a variety of CTF challenges.

In addition to these tools, it is also important to have a good understanding of the Linux command line and basic networking concepts.

Here are some additional tips for success in CTFs:

Practice regularly. The more CTF challenges you solve, the better you will become at it. Work with a team. CTFs are often more fun and successful when you work with others. Don't be afraid to ask for help. There are many people who are willing to help beginners learn about CTFs and cybersecurity. With the right tools and skills, you can be successful in your next CTF competition!

 
Read more...

from JR DePriest

My eyes are open. My eyes are open so I must be awake. What is that sound? What is that clicking sound? A black stick is falling toward my eyes. I see it. But I'm not blinking. My eyes aren't closing. My eyes can't close. The stick moves past. It's alive. Without moving my head. I can't move my head. I see my wife beside me in bed. Reading. “Please help me,” I say. She ignores me. I see the black sticks again. Legs. They are legs. Weaving. Spider legs. I lift my hand to brush them away. My hand doesn't lift. My arm doesn't move. My arms are made of stone, concrete. They will not move. I feel something on my sternum. Heavy. Round. Like a living bowling ball. Directing the spiders on my face. I can hear them. I know their language. But they are whispering. I ask them, “Why are you doing this?” “What are you doing?” The spider on my sternum shifts. The spiders on my face say “Hush.” Spiders don’t have the concept of a “tone of voice”. But. These two spiders spinning the web to cocoon my head. They seem very patronizing. I haven't earned the right to know what they are doing. My eyes close. I am lost in time. It's almost silly when I find out. The spiders are aware of the popularity of Spider-Man. They think that sounds like a good idea. A spider-human hybrid would be wonders for their reputation. I was chosen as one of the test beds for the brightest spider minds. I would not be their final achievement. No. But I would be experimented on. Techniques would be perfected. I was adrift in time. My eyes open and I am free. I stand and see a well-lit living room. I see an indoor swimming pool, in ground. Not large, but exceptionally clean and inviting. I walk forward and feel my body. The limbs are lanky. Extra tissue has been removed or replaced. My skin seems paper thin on my hands. I step into the water of the pool. It's warm. I expected it to be cool, but it's warm. I lower my head into the water and breathe. I can breathe underwater. I feel the water on my head. My hair is short. I see my golden silk house clothes billow in the water. I exit the pool on the other side, using the concrete steps. A little girl, perhaps 10 years old runs up and smiles at me. “I hate it when you go in the water,” she says. “Sometimes you stay down there for 15 minutes!” She's so young that 15 minutes must seem like eternity. “You'll understand when you're older,” I say. I don’t recognize my own voice. I half-remember a lifetime of experience. Decades. It's breakfast time. One of my daughters is cooking breakfast. I can smell the sizzling meat. I feel a warm surge down my legs. I look down and see hundreds of small brown and gray spiders spread out from my pants. I can hear them. Each of them. I know them. Every one of them. Not by name. They don't have names. But we are connected. They know me and I know them. I know what they know and see what they see. But I don’t see it. I just know it. They are going on patrol. They will keep out the vermin. They will be the barrier at the edge of our domain. They will die to protect us. My body sways and my legs carry me to the table. There are other family members already sitting, all female. Women and girls. I am a grandmother, perhaps a great-grandmother. In this house, I am the Mother of All Spiders. I remember for the spiders. They have short lives. To them my mind is vast. My lifespan nigh immortality. I am their computer. I am their incubator. !!!!!!!!!!!!!!!!! The children! My face turns toward the front room. Before I can form a coherent thought. My hands reach down in front of me and grip the floor. My legs bend and crack. My legs reach up behind me and grab the ceiling. My arms bend and crack . My arms reach up above me and grab the ceiling. My throat aches. My mouth opens wide. I rush along the ceiling. Faster than I imagined possible. I burst through the doorway. I see a man. I know him. He has his hand inside his jacket. He's reaching for something. I snarl and a glob of webbing is projected out of my throat at high velocity. It hits the man in the chest. He's knocked backwards and onto the floor. “No need for that,” he says. He pulls out an envelope. He waves it in the air. My legs reach down to the floor. My legs crack and bend. My arms let go of the ceiling. My arms crack and bend. The spinnerets in my throat retract. The two halves of my jaw reconnect themselves. “You didn't knock,” I say. He stands up. He shakes his head. “When the day comes, you will never see me coming.” He hates us. We know. He knows we know. He doesn't care. He waggles the envelope. “Just take it.” I take the envelope. It is addressed to our family. “Mayor thought it'd be funny to have me deliver your invitation.” I open the envelope and start reading. My spiders will keep their eyes on our guest. And my mind is connected to their minds. My mind is connected to their eyes. I read the invitation: cordially invited… demonstration of advances in science and medicine… honored guests… I remember now. We, the spiders and I, decided to collaborate with other scientists. The best spider minds are very young and naïve compared to the best human minds. It made sense. “I hear they're planning to show off something with centipedes,” he says. My children shift uneasily. The man straightens his jacket and makes a sinister finger gun gesture. “Be seeing you,” he says, before leaving of his own accord.


#WhenIDream #Dreams #Dreaming #Dreamlands #Writer #Writing #Writers #WritingCommunity #ShortFiction #Fiction #Paranormal #Spiders #NightTerrors #SleepParaylsis


CC BY-NC-SA 4.0 This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License

 
Read more...

from beverageNotes

I've been enjoying some Eagle Rare 10 year. At 90 proof, it's not enough to warrant some ice and I've been enjoying it neat. It smells sweet with hints of cinnamon, leather, and a wee bit of cardamom. The first sip of the night is a bit hot, but it drops off and there's a lingering warmth in subsequent sips.

The flavors have been harder to pin down. It's been different on different night. Sometimes caramel. Sometimes leather. Some food may go well with this.

Adding in snacking on sharp cheddar and Triscuits doesn't affect the tasting much.

I've got more, so I'll have to revisit this. Maybe with some chocolate or something sweet.

 
Read more...

from acrypthash

Status Report

It feels good to be where I am. Over the past few months, I have been running a cybersecurity internship program. Last week that finally came to an end. It was a great learning experience for both the interns and myself. We got to see a lot of cool things and I think everyone grew. Now that there aren't interns to take up my time, I have been able to dive back into my projects and research and I feel so happy again. I am really starting to wrap up some outstanding projects.

Defcon: I attend Defcon 31 this year and learned a lot! It was a great experience and I am very happy to have gone. I created a presentation for work after cleaning up all my notes and had a really learned a lot. Now, I have a list of action items that came from the conference and my talk! Things like detection engineering and actually utilizing some of the tools that I was exposed to. I think my favorite talk was the Electron app TCC vuln that was disclosed.

Some other bits and bobs:

  • Tomorrow will be one year at my company and I AM SO HAPPY. Being a security analyst is something I've come to enjoy very much.
  • I managed to break my OpenVAS install after upgrading PostgreSQL. I ended up needing to update /etc/postgresql/14/main/postgresql.conf back to my originally configured port and restart the daemon. I also had to reassign the versioning that PostgreSQL was running in, because that failed to change properly after the upgrade as well.
  • I've gotten more into detection engineering as of late. We utilize Elastalert to send detection alerts to a Slack channel that has been built. This is a nice tool that can provide me information Sentinel One can't easily notify us of.
  • While it's nothing new, I've also been doing research into the Zerologon vuln for DCs. I am going to be downloading copies of some of our DCs and testing to confirm if we our patch is actually working as it should.
  • Our web app pen test is going to be wrapping up soon, where I will get a good look at where we stand from a security perspective on our app.
  • I've gained more forensics experience with analyzing PDFs and malicious word docs that have come in via email. It hasn't been anything too flashy just yet, but still a great experience.

For the rest of year, I have some goals set that I plan on achieving: – GCP training – GREP Cert – Better detections and more coding – BSides Philadelphia – One more good write up in 2023 about something valuable I learned. – My idea is a write up on how to efficiently exploit something like PDQ after post compromise.

 
Read more...

from JR DePriest

The cemetery asphalt is cool in the afternoon shade, identical tombstones, some hundreds of years old stretch as far as I can see. The wrought-iron gate to the inner sanctum, separated by a tall brick wall opens as I approach. I slip in and it closes silently as I navigate through the entrance maze. A right, a left, two rights, and left, and another left. I step into the courtyard and see a few of the workers pruning apple trees or working the garden. Some wave, some ignore me, some don't even notice my passage. I look up at the sanctum, a structure of stone expanded with wood, steel, and siding, ancient and modern gripping each other but never quite merging. I see a young-looking man in the massive arched doorway, thinning brown hair, slightly overweight. “Misty!” Dan calls out. “Misty Meaner!” he says with a wink and a smirk. I roll my eyes and shake my head. His grey-blue eyes invite you to fall into them, fly away, forever. His smile tethers itself to your heart and reels you in. “How old are you, again?” I ask, breaking eye contact. “That's—you know it—it's different.” he stammers. “Point taken, though.” I can feel his magnetism settling, simmering instead of boiling over. As we head inside, I can hear loud dialogue, likely from the theater. “It is,” he says, responding to my thoughts. “I've made some real progress on the 'magitech',” he gushes. “The 3D effect is next level now, with actual depth. “Only works for black and white films right now, but I'll get there.” He takes my hand. “You'll have to come by after your shift,” he offers. I shrug and bight my tongue behind a thin smile. “Be polite,” I think. He steps in front of me, using a tender gesture to raise my head. “Hey, wait.” he says squinting, hiding his charms, probing gently past my surface thoughts. “Are you okay?” I chuckle, “Actually, I feel like shit, but I've got responsibilities so here I am.” I do feel like shit. Brain fog, tight emotions, unexpected bouts of rage and crying. He sniffs the air lightly, “I didn't want to say anything last week.” “About what?” I ask. “Well—I'm not trying to be rude, but I think your hormones are off.” I nod slowly, “That would make sense.” “I haven't had bloodwork in over a year and my endo was talking about switching to injections.” He pats my shoulder, “Please take care of yourself. If it's money, you know she will cover it.” I shrug, “It's time. I have no time.” “Oh,” I start, “will the elders be upset by it?” Dan takes a deep breath and slowly releases it, “I doubt it; it's still closer to what they prefer than any cissy could manage.” “Anyway, I'll let you get to it.” He heads back to his movie theater and his experiments. I assume that's where most of the younger members are.

I remember the ad that brought me here almost two years ago: “Seeking Part-time Caregiver for multiple elderly residents. Must be well-read and have a strong voice. Services will be limited to reading and light teaching. Medical training not required.” And the part that really got my attention, “Transgender women on full HRT only.” I had to see what it was all about. I replied to the ad and met Melinda at an outdoor cafe downtown for coffee. I had water. Melinda was a fount of radiant 'house mom' energy, carefully put together comfortable but elegant outfit, expertly styled red hair, subtle 'no makeup' look makeup. Her eyes were a strange mixture of green and gold. I'd never seen gold in someone's eyes before. And her easy smile lulled me into complacency. I was spilling my deepest secrets and weird hobbies before I even noticed what I was saying. She told me about the job, about my charges, about the fact that they are mostly non-verbal and mobility impaired, but they like to be read to. I was moved to compassion. When she said the job was at an estate in the middle of a national cemetery in the oldest part of town, I was intrigued. I was taken to meet 'The Elders' and was led through a cavernous house, almost a castle, down stone steps lined with torches, to a large room filled with ancient armors, mounted weapons, and two walls of books stretching a full story high. At one end was the largest fireplace I'd ever seen. You could drive a car through it. And it was fully ablaze. I couldn't imagine how much fuel it took to burn that strongly. I was told 'The Elders' were cold blooded and liked the heat. When we got closer to the fire, I saw them, 10 pale faces with bright eyes sharing a deeply set opulent sofa, watching me, following me, each body bundled in heavy blankets or furs. “That's a good sign,” Melinda assured me. They had ignored other applicants, I was told. We stood between 'The Elders' and the fireplace. “Great and Honored Elders,” she said, bowing. “I present Misty Allen Shaffer for your approval.” I heard a sound like sighing or coughing, but so faint I couldn't tell from where. “Thank you,” she said, bowing again. She smiled at me, so wide her teeth shimmered in the firelight, “They will allow it.” Apparently, it meant I got the gig. She asked me to bring some modern science fiction from the library to read. She defined “modern” as anything after 1900. In spite of the walls of books we'd passed, they were awfully tired of what they had on hand. I'd come in and sit by the fire and read out loud for them for three hours once a every weekend, doing different voices for the different characters. They'd study me with their inscrutable eyes the entire time, never speaking, but occasionally making small noises. When I moved around, they followed me with their gazes, sometimes imperceptibly moving their heads, but often just with their eyes. I could tell what authors they liked and which they didn't although I'm not sure how. I could feel it. The particularly liked Asimov, Bradbury, and Frank Herbert but weren't fans of Philip K. Dick. When I read even newer authors like Liu Cixin or N. K. Jemisin, the vibe in the room was particularly electric. I'd caught an uneasy amusement from them when I read Peter Watts' 'Blindsight'.

Today, I was bringing a classic, HG Wells' 'The Time Machine'. Down 40 stone steps around a column, lit and warmed by torches at every fifth step. Into the visitation hall. Even in the dim light of the fire, I can see them watching me. I feel loved and involuntarily smile. “Good afternoon, everyone!” I call out. “As promised, HG Wells' 'The Time Machine' with a nameless protagonist and a look at what the future may hold, written in 1895. “I know that's few years older than you'd prefer, but trust me, it is worth it. “It gets pretty 'out there' toward the end. “You'll love it.” They study me as I read from the elaborate, carved seat by the fire. “Chapter 1,” I began, using an English accent befitting the author. “The Inventor.” I'd made it to the section where The Time Traveler loses The Time Machine to the Morlocks (who I voiced as deep throated aristocrats – inspired by Jeremy Irons performance in the movie) when the first rumble shook dust from the walls. As I look around for a source, I spot a red strobing light above the door. “Shit!” Evacuation? What was happening up there? “Uh, everybody?” I call out. They watch me intently, “We've got to go.” I'd been trained for this, drills even, although I was told it would probably never be required. I jog over to the hidden emergency exit door, trying to remember the pattern. Like a backwards treble clef, then three parallel lines, then eleven o'clock, three o'clock, seven o'clock. POP A handle appears and I struggle to slide the door which has probably been closed for longer than I've been alive. I create an opening about three feet before turning back around. The Elders still sit. They are watching me but not standing, not moving. They are supposed to follow me. “Come on!” I yell, waving at them with both arms above my head. Nothing. I reach into my bag and pull out my multitool. I stare at it in my hand, breathing hard. I slide it open and expose the knife, seeing flames dancing in reflection. “Hey, y'all!” I call out. Nothing. I'm going to have to do this. I bite my lower lip, hard, and cut a shallow, inch long gash in my left arm. The Elders lean forward but do not rise. Damn. I cut a second, longer and deeper gash close to the first. It burns and try not to scream through gritted teeth. “Mother fucker” I mutter. Blood runs down my arm to my elbow where it falls and splatters on the floor. The Elders stand and shuffle toward me, rasping from slightly open mouths. I squeeze into the hidden hallway and hold my arm where they can see it. Where they can smell it. The burning sensation runs all the way from my arm to my chest, making it hard to breathe. I did not expect it to hurt that much. How deep did I cut? I hear shouting from further down the corridor. Their language. A language I don't recognize. Flashlight beams play upon the walls and naked feet slap against the stonework. I still do not understand them but I catch words that seem familiar. 'anthropos' 'aima' Men, women in fatigues churn up from the catacombs, swarming around me, taking the arms of The Elders and leading them deeper into the passages. A man I've never seen leads me back to the reading room. I'm dizzy. “Foolish” I hear him say as he pulls a first aid kit out of his backpack. He's examining my cut which I can see spurts blood every couple of seconds. Whoops. The ground is shaking or it could just be me. “Skata” says the man looking at my arm. “Ti krima“ He shakes his head and sprays something that cleans the blood away. Then he places an absorbent pad and begins to wrap gauze. Something cracks, my ears ring, I'm on the floor. I can't move. I can't see. I hear the man scream, “Gamo to!!” Then “Gia to aima!” I can't feel my legs or arms. I'm not sure if I'm breathing. It's so heavy. I'm cold. Tired. Exhausted. I should sleep. Sleep. Yes. It's quiet. Warm. Like floating in river. Darkness.

. .. ... .... ..... —

Lightning strikes my heart. My head explodes. My arms and legs vibrate like plucked guitar strings. I hear myself screaming but the voice isn't mine. Something burrows into my throat, wiggling its way up to my mouth. My teeth clench, tear, I taste blood and bile. Sound pours itself into my ears, squeaks, groans, gasps. Pumping sounds. The flow of liquid. Sizzling steam, fire. Breaths, whispers. I smell sand, sweat, decay, perfume, incense. Something sweet. I can't name it. But I desire it more than anything I've ever wanted in my life. I can see colors that I do not recognize, outlines of life and probability. I sit up, grab my head. “Misty, you were chosen.” Chosen. I hear it. She's talking. It's Melinda. I love her. I would do anything for her. “For your selfless actions to save The Eldest Among Us, for your kindness and devotion, for your courage and calm under pressure.” My heart swells with each word of praise. “Where once there was death, now there is new life.” I feel her take my hand, our souls intermingle, our life force blends. I am hers. She helps me up. To my feet. I do not waver. I stand like a statue. I look down at my body. Naked. Small breasts, slightly protruding gut hanging over an equally small penis. Cold, but I do not shiver. I frown. This is not what I'm supposed to look like. For a moment I am ashamed. “Welcome our sister,” she says. “Misty Allen Shaffer,” a chorus of voices replies. “Receive your second gift and your secret name.” The crowd parts. “Become what you were meant to be.” A woman wearing only a solemn expression walks toward me. “Receive your second gift,” the crowd repeats. The smell from earlier. I catch it again, thicker, a current guiding me. My mouth twitches, my tongue curls itself into knots. The woman is directly in front of me now. She kneels and tilts her head to the right, exposing her neck. My heart pounds. I feel something slide and shift inside my mouth. Something stabbing my gums and lips. Without thinking, I bend down and bite the woman on the jugular. My exposed fangs effortlessly pierce the skin. The warmth of blood pouring into me is like nothing I've ever experienced. I see memories of her life, a child of poverty, sold, bought, raised almost as livestock but wanting for nothing. I feel her relief, honor, fear at being brought here tonight for me. Fire floods my body, every nerve ending tinkling like a bell, every cell ravenous and renewed. The blood wakes me, the world fills with song, like angels, like a chorus of stars in the heavens. Light pours from me. I feel strong, fast, free. Alive. I was dead. Now I am alive. “Enough,” Melinda whispers to me. I immediately stand. Someone takes the girl aside to bandage her wounds. I know their language now. I see it. I see a word. My word. “Υδατογενής“ Because I adapted myself, changed, flowed into true being. “I am Υδατογενής.”


#WhenIDream #Dreams #Dreaming #Dreamlands #Writer #Writing #Writers #AmWriting #WritingCommunity #ShortFiction #Fiction #Paranormal #Vampires #Transgender


CC BY-NC-SA 4.0 This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License

 
Read more...