Handbrake malware analysis
objective-see.com
objective-see.com
[0] - https://objective-see.com/about.html [1] - https://www.patreon.com/bePatron?u=4857001
- KnockKnock: perform system scan to list everything you have installed, like kexts, browser components, startup scripts, etc.
- BlockBlock: continuously monitor system for changes to startup scripts
- TaskExplorer: tool to examine a running processes
- Oversight: continuously monitor microphone and webcam activity
Nice UX too.
I am against centralization and all as well, but I think that is the lowest barrier to entry for them right now, as they already have a repo there.
Also if GitHub goes down and everything is hosted there then the internet stops working as well. Remember how broken the internet was when that DNS outage happened a few months ago?
Also, google code never went away. It just stopped working as an active platform, but Google still keeps the archive of what already existed there, to this day:
https://code.google.com/archive/
Microsoft is doing the same after shutting down their Code Plex because of moving toward GitHub:
https://blogs.msdn.microsoft.com/bharry/2017/03/31/shutting-...
> At that time, CodePlex.com will start serving a read-only lightweight archive that will allow you to browse through all published projects – their source code, downloads, documentation, license, and issues – as they looked when CodePlex went read-only. You’ll also be able to download an archive file with your project contents, all in common, transferrable formats like Markdown and JSON. Where possible, we’ll put in place redirects so that existing URLs work, or at least redirect you to the project’s new homepage on the archive. And, the archive will respect your “I’ve moved” setting, if you used it, to direct users to the current home of your project.
If there is anything to lose after GitHub's shutdown at some distant point in the future, it probably won't be something people cared for.
"Don't use a very valuable, and more secure service, because of possible distant future, very tiny harm" doesn't sound like a convincing argument. You take "risks" every day in your life. Driving your car is a risk. In the US there's 12 deaths per 100k people per year on the roads, and that's only counting deaths, not crippling injuries. But it's valuable enough that you end up taking it, as living without a car is difficult in many places. Life is about calculated risks and using GitHub is not exactly at the top of the risk pyramid.
condition:
Macho and filesize < 600000 and filesize > 10000 and all of themHas anyone used a platform that had an unspoofable one of these?
This prevents hostile apps from stealing your root password, but doesn't stop them from tricking you into giving them root access (which is nearly as bad).
The shasum need to be digitally signed with a valid signature otherwise it can be manipulated as well.
ps. Ofc tools like littlesnitch and blockblock help, but keeping track of all the applications that try to access the internet is kinda hard these days, especially on a user machine.
How else can you sign a binary?
The alternative would be to sign the actual binary file using code signing (internally I assume that relies on a hash ).
Similar thing happened to TransmissionBT. For a while, their legit website was serving a hacked binary.
Pinned long-term public keys are the only way to verify this stuff. Even that isn't fool-proof if the rogues get commit access.
It might work in the way that generating a hash collision for an arbitrary string works??
Probably wouldn't help in these situations, just curious.