[-] borari@sh.itjust.works 9 points 3 months ago* (last edited 3 months ago)

My dude, I am positive. My cake day: June 8 2023. Your cake day: June 12, 2023. Do you not realize that people can have multiple accounts? Dick measuring and attempts at gate keeping based on time on a platform is super cringe.

I created the community you’re posting in right now. You should probably get off the internet and chill bro. You woke up and made the choice to behave this way, and it’s pretty fucking embarrassing tbh.

[-] borari@sh.itjust.works 2 points 5 months ago

That’s been my life for the past 10 years, you won’t regret it at all.

[-] borari@sh.itjust.works 17 points 5 months ago

Saying they banned VPNs isn’t completely, technically correct I’d guess. If I were another country then VPN’d in to my house, I would probably be fine. A pedantically correct statement would be that they banned known VPN IP ranges, so if you’re attempting to connect while your traffic is routed through one you get blocked.

[-] borari@sh.itjust.works 11 points 5 months ago

Oh damn. Yeah fuck that place, glad I left.

Semi-related, I was searching for some hyper specific job related technical cybersecurity stuff a few weeks ago and the first result with the verbatim error message was a reddit post, so i clicked. No dice, loads a reddit branded error page. My employer has their own ARIN number/ASN. As far as i could tell every connection from an IP in one of our blocks was being blocked by reddit. My employer isn’t a faang type tech company, they don’t work in ai, they don’t scrape content for datasets or anything else. I can’t figure out why kind of business would cut off entire swaths of customers from accessing their site during the workday, a prime “take a shit and dick around on the phone” audience. I’ve just made a point to search with stack exchange site dorks since then.

[-] borari@sh.itjust.works 6 points 5 months ago* (last edited 5 months ago)

Yeah, the answer here is cancel prime and pirate whatever amazon video content you want. if you absolutely have to have prime for some reason, don’t sign in to amazon video on any of your devices and pirate the stuff you want to watch so at least your not contributing to views or their prime video ad revenue.

Edit - I see in another comment you said you unsubscribed, good on you.

[-] borari@sh.itjust.works 1 points 5 months ago

I’ve replaced the pads on mine a couple times, the rubber on the thumb rest has a hole worn it it to the plastic, and the braided cable is all frayed and stuff. I’ve had the thing for the past 10 years at least. I know new ones are that cheap and that I should just get a new one at this point but the thing is just a workhorse.

[-] borari@sh.itjust.works 16 points 5 months ago

It is part of the deep web, just like Discord or any sites hosted on private companies intranets. Lemmy is not, you can just hit any instance with a web browser and view stuff.

To be completely clear, dark web/net and deep web are two different things. That wiki link you used is describing dark web stuff like tor etc.

[-] borari@sh.itjust.works -1 points 6 months ago* (last edited 6 months ago)

Oh damn, I’m gonna have to find that shit. I am regularly shocked at how hard CBS Saturday/Sunday Morning goes though, they will throw some savage shit on the air for the grandmas watching human interest stories about Broadway actors and whatever the fuck Mo Rocca has gotten interested in recently.

Edit - Found it on a Ukrainian dead Russian combat footage telegram. Bit rate is garbo but it looks like even ISIL is full sending the whole weeb CS gun skin thing lol. Best part is the posts of air raid sirens and distant explosions from Belgorod, with the caption “Помста за вухо таджика”.

[-] borari@sh.itjust.works 2 points 6 months ago

Ah ok, I misinterpreted your post then. I thought you were insinuating that because refineries are civilian infrastructure Ukraine shouldn’t be targeting them. We’re in agreement here, don’t target actual civilians and slam as many drones as possible into refineries and any other valid targets within Russia.

[-] borari@sh.itjust.works 38 points 6 months ago

detailing that he had been promised 500,000 rubles ($5,418).

Fuck me, this really hammers home that first world privilege. More than that amount of USD hits my checking account each month in my direct wages. This guy knew what would happen to him when he was caught then decided that risking misery in Siberia before being executed was worth less than a month of my take home pay. I mean i get that some level of radicalization is involved here, but still what the fuck.

[-] borari@sh.itjust.works 3 points 6 months ago

The distinction is not between civilian targets and military targets, it is between “civilian objects” and “military objectives”. Targeting a civilian infrastructure such as refineries, and even civilian power stations can be considered valid military objectives if they make an effective contribution to military action or offer a definite military advantage. The refineries being hit by Ukraine definitely meet that definition.

https://www.reuters.com/world/europe/when-are-attacks-civilian-infrastructure-war-crimes-2022-12-16/

[-] borari@sh.itjust.works 0 points 6 months ago

If you go on to any of the pro-Ukrainian telegram channels, Ukrainians are absolutely rejoicing over this. One posted a video of the fire taken by a car driving by on the highway and captioned it “З днем свинячого шашлику” lol.

4

Team Cymru published a report detailing infrastructure and configuration changes to the Vidar info-stealer malware that were made in an attempt to evade detection and anonymize activities.

11

ESET researchers identified an updated version of the Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.

18

It seems like attackers have discovered a way to leverage NPM packages to deliver malicious binaries without needing to make any changes to the NPM package itself.

13

This is an interesting report by Symantec about a Russian 'Cyber Campaign' against Ukraine, targeting security services, military, and government organizations.

It's crazy that we're witness to the first case in history of cyber warfare campaigns being waged alongside, and in support of, a hot war, in real time.

12

Looks like Mandiant has discovered active exploitation of CVE-2023-20867, which was given a CVSS score of 3.9 when it was assigned.

9
submitted 1 year ago* (last edited 1 year ago) by borari@sh.itjust.works to c/cybersecurity@sh.itjust.works

This new malware strain, written in Go, has been seen compromising systems across Europe, Southeast Asia, an the U.S. It's stealing sensitive information from Discord, web browsers, etc.

28

This won't apply to anyone here, because we're all reviewing any code we clone from GitHub prior to executing it on our system, right?

10
12
46

Can't wait for all these monolithic sites to die.

4
submitted 1 year ago* (last edited 1 year ago) by borari@sh.itjust.works to c/cybersecurity@sh.itjust.works

This new stealer has five stages, and shows a high level of sophistication, akin to APTs. Targeted victims have been seen in Europe, the USA, and Latin America.

Several pieces of Russian text were found in the malware.

The first part of the C2 URL is “Privetsvoyu” which is a misspelled transliteration of the Russian word for “Greetings.” Secondly, we found the string “salamvsembratyamyazadehayustutlokeretodlyagadovveubilinashusferu.” Despite the weird transliteration, it roughly translates to: “Greetings to all brothers, I’m suffocating here, locker is for bastards, you’ve messed up our area of interest.”

MD5 sum and C2 URL IOCs are included at the end of the report.

5

The researcher chained an insecure password reset API route to bypass authentication, then discovered an IDOR vulnerability could be leveraged to access sensitive customer data.

For everyone that says "The real world can't be as easy as training labs make it seem out to be!", sometime it really do be that ez.

view more: next ›

borari

joined 1 year ago