103 karma · joined April 17, 2023
> Our future plans include letting you save a secure backup archive to the location of your choosing
Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.
They also snapshot your disks, cloning them to Wiz accounts to provide secrets scanning / vuln scanning / etc against your infra.
These resulting risks / findings are scored and provided in their SAAS Wiz console via dashboards / APIs / integrations with remediation guidance.
Ensure all your passwords get reset at some point after vaulting, long randomly generated from Bitwarden extension/app is easy enough. Ensure you enable strong 2FA at each service you have an account at too.
https://bitwarden.com/help/setup-two-step-login/ https://bitwarden.com/resources/guide-how-to-create-and-stor...
Based on this it sounds like you exposed your resource and advertised it for others. Reverse dns, get IP, scan IP.
Probably simpler, you exposed resource on IPV4 publicly, if it exists, it'll be scanned. There's probably 100s of companies scanning entire 0.0.0.0/0 space at all times.
2. When (not in your lifetime obviously) Waterfox is broken, what canaries do you have deployed that we can archive now, like Mozilla's tell here?
3. What keeps waterfox afloat? Where/how do you accept funds?
4. How do I find a sync alternative or provide my own? Such that, I'm not reliant on Mozilla sync/backend? ... If none exists, how much would it cost for you to embed one? Would you accept a serious bounty for it assuming the focus is self hosted / no Waterfox backend services?
[1]https://www.justice.gov/archives/opa/pr/four-states-join-jus...
[2]https://farmaction.us/2023/10/12/food-price-fixing-is-still-...
Does the reliance on Firefox ESL or based on Gecko rule this one out?
[1]https://github.com/electronicarts/CnC_Remastered_Collection/...
I know exactly what you're referring to those "content hovers". Like the substack highlight, sign up overlays on immediate visit, or upsells in shopping cart flows.
The provided link of https://m.facebook.com/story.php?story_fbid=1015993413146151... redirects me to https://www.facebook.com/login/?next=https%3A%2F%2Fwww.faceb... which is a hard auth page. No modals, no pop-overs, no X / bypass on the redirected page.
I tried the archive.is for content a work around on the share link, also didn't work.
[]https://highon.coffee/blog/sqlmap-cheat-sheet/#sqlmap-dump-d...
There's also significant aggregation of traffic at handfuls of service providers amongst service categories, all generally HTTP(s) type services too ... Mail, CDN, Video, Voice, Chat, Social, etc. Each of these are still likely to employ Load Balancing & WAF.
Most WAF/Load Balancing providers have documentation about when/where to perform decrypt in your architecture.
How many Cloudflare sites are just using the Cloudflare wildcard cert?
From there, plenty of 3 letter agency space to start whiteboarding how they might continue to evolve their attack chain.