Infosec company pwned by 4chan user
11–20 of 234 posts
Re: Infosec company pwned by 4chan user
#12Earlier quoted context omitted.
Anyone setting up a honey pot. Half of 4chan posts are 3 letter agencies trying to bait people into violence.
But what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this
2. see who clicks it
3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan
Something like that.
Re: Infosec company pwned by 4chan user
#13Who makes their Jenkins instance world accessible!
Anyone setting up a honey pot. Half of 4chan posts are 3 letter agencies trying to bait people into violence.
Re: Infosec company pwned by 4chan user
#14Found this on the same blog. Wild read. Apparently they found a copy of the nofly list from 2019. https://maia.crimew.gay/posts/how-to-hack-an-airline/
Re: Infosec company pwned by 4chan user
#15Found this on the same blog. Wild read. Apparently they found a copy of the nofly list from 2019. https://maia.crimew.gay/posts/how-to-hack-an-airline/
Re: Infosec company pwned by 4chan user
#16Who makes their Jenkins instance world accessible!
Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…
Re: Infosec company pwned by 4chan user
#17Re: Infosec company pwned by 4chan user
#18Re: Infosec company pwned by 4chan user
#19Earlier quoted context omitted.
Anyone setting up a honey pot. Half of 4chan posts are 3 letter agencies trying to bait people into violence.
Do not attribute to NSA conspiracy what can more simply be explained by the company being fucking stupid and not caring about walking the walk of infosec
Re: Infosec company pwned by 4chan user
#20Who makes their Jenkins instance world accessible!
Who still uses Jenkins? It's an abomination of an obsolete system that is just a pain to use, manage, maintain, setup, etc. while there are much better, more featured, easier to use and maintain alternatives out there. And it has been like this for close to ten years now . It should have been ripped out in favour of either the "native" CI/CD (e.g. GitLab CI if GitLab is used for VCS, GitHub Actions if GitHub, etc.) o…