HNHacker News
TopNewBestAskShowJobs

MrMrtn

234 karma · joined September 14, 2011

submissionscomments
MrMrtn··on LOLBAS: Living Off the Land Binaries, Scripts and Libraries
> So it seems like a catalogue of (possible?) exploits in commonly-available executables, libraries and scripts that may already be present on a target machine

That is pretty correct, but it is not necessarily an exploit or vulnerability in the binary. More often than not, it is a quirk or a way to use the binary which is unknown/uncommon, but might not appear on a defenders' radar.

We generally try to (ab)use functionality in pre-existing software to avoid security mechanisms (like AppLocker) and detections (like AV/EDR, or rules created by a SOC when analysing execution logs in a SIEM). Often we discover that a target computer has been hardened in some form or fashion, and we have to get "creative" when trying to download, execute or exfiltrate data during security assessments.

MrMrtn··on 30k U.S. organizations newly hacked via holes in Microsoft Exchange Server
For those of us working incident response, it is exactly what is keeping us up at night these days
MrMrtn··on Tell HN: New features and a moderator
To be honest I would rather have the vote arrow moved somewhere else. I'm often more interested in collapsing a comment thread than voting. I'm not sure if this is something only I care about though.
MrMrtn··on Ross Ulbricht’s private journal shows Silk Road’s birth
This also reminds me a bit of http://xkcd.com/538/.

Cryptography is only as strong as its weakest link. That link more often than not is the human factor.