HNHacker News
TopNewBestAskShowJobs

syntheticcorp

94 karma · joined October 31, 2019

submissionscomments
syntheticcorp··on Defenders think in lists, attackers think in graphs (2015)
I get your point but I think pentesters are perfectly capable of thinking in graphs, including web security. Bug chains are the immediate example, where a couple of CVSS 4-7 vulns can be turned into a full rce/whatever 9.8 equivalent. This bug chaining fundamentally occurs via elements of compromise i.e a graph traversal.

Bloodhound is great, and a nice visual tool for people to conceptualise attack graphs but it’s just a part of the process of understanding the target domain from an attackers perspective. No nice tool like bloodhound exists for web pentesting because a chain of compromise can’t simply be reduced into tool form there because a chain is often specific to the app and not an underlying framework, unlike AD where the security boundaries are well(ish) understood and codified.

Pentest reports include stuff like SMB signing and “don’t admin everything with your DA account ” because they are glowing hot nodes very early in a chain of compromise, meaning that is often how stuff gets popped IRL. It’s (hopefully) not that the pentester doesn’t understand graph thinking, it’s just the the first node in the graph represents effectively complete compromise, so why traverse?

syntheticcorp··on Content Injection Attack on GitHub
It’s pretty infrequent outside of target attacks. Most recent is probably the roundcube XSS CVE-2023-43770 that was actively exploited as 0day by a threat actor last year.
syntheticcorp··on Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
Specifically, Marriott was deauthing rather than just plain jamming.
syntheticcorp··on Outlook is Microsoft's new data collection service
You can’t serve a valid certificate chain to the client even if you control their traffic, because your malicious certificate isn’t signed by a trusted CA. And you can’t get a CA signature without demonstrating control of the domain to a CA.
syntheticcorp··on Outlook is Microsoft's new data collection service
Control over a clients DNS doesn’t let the VPN provider view the contents of TLS encrypted traffic. However they can view unencrypted data from connections like SNI headers, DNS queries etc.
syntheticcorp··on Snoop unto them as they snoop unto you
It’s a vlc issue with h265 - I actually noticed this with videos from defcon last year. Pull the YouTube version or reencode to h264 to fix.
syntheticcorp··on Microsoft is killing WordPad in Windows
Yes it can do that now, at least on Windows 10
syntheticcorp··on The Pentagon’s $52k trash can
I’ve also encountered that a few times where a fairly anodyne bug in a codepath prevents a serious security bug from being reachable. With my attacker hat on it is very tempting to just report the first one…
syntheticcorp··on Oxy is Cloudflare's Rust-based next generation proxy framework
The commenter you’re replying to is CTO of Cloudflare, so I’d say they likely know why the company makes these blog posts.
syntheticcorp··on What is the randomart image for?
Found it, pg 47 https://www.cs.auckland.ac.nz/~pgut001/pubs/defending.pdf
syntheticcorp··on Substack was down
Browsers already include this feature in a coarse grained (but utterly sufficient) manner in the form of a scroll bar.
syntheticcorp··on Ask HN: Anyone tired of everything being a subscription now?
It’s a good disassembler that is fairly expensive. https://hex-rays.com/ida-pro/
syntheticcorp··on Everyone going to World Cup must have this app, experts are sounding the alarm
Yes it is still optional. I travelled on an ESTA a few months ago , left the social media handles section blank, and they made no comment at the border. That said it is still very capricious.
syntheticcorp··on Companies are paying huge sums to show their ads to bots
Rate limiting access to the enclave? Somewhat related, I fear this is where we are going to end up with secure attestation, limiting web access to approved devices.
syntheticcorp··on Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
I work in offense and they can be a huge impediment. Significant work goes into bypassing or staying undetected from these products. While not all the detection occurs at runtime, they report a lot of data back from the endpoint so historical detection can happen.

However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.

syntheticcorp··on Pirate Library Mirror: Preserving 7TB of books (that are not in Libgen)
ESNI has been dropped, a new spec alters how it works and renames it Encrypted client hello (ECH)

https://blog.mozilla.org/security/2021/01/07/encrypted-clien...

syntheticcorp··on Founding Uber SRE
I’ve worked in tech in NZ for 7 years or so, never actually met someone who calls themselves an SRE. Obviously I know the term, but IME we don’t use that title here
syntheticcorp··on Rocket Mortgage to trim 8% of workforce as home-loan market shrinks
I can’t believe you can get 30 year fixed in the US , that’s amazing. The longest terms I can see where I live are 5 year fixed.
syntheticcorp··on Rocket Mortgage to trim 8% of workforce as home-loan market shrinks
I suppose you could have income from interest on capital or stock dividends
syntheticcorp··on The Colorado Safety Stop is the law of the land
Are you aware which website you’re on? Having strong opinions on esoteric topics is a HN mainstay. Also as a non-American driving in the US made me think about a lot of things I wouldn’t otherwise consider. (Yes you have too many stop signs)
syntheticcorp··on Why I will never buy another Samsung device
There is none. This has been asserted for years on HN but I’ve never seen a modicum of evidence for it.
syntheticcorp··on North Korea hacked him, so he took down its internet
NK did personally target security researchers for compromise. See the TAG post referenced inTFA.
syntheticcorp··on Locked-out New Zealanders outraged as visa scheme for rich foreigners resumes
Postal 2 and manhunt are two fairly popular video games that were legally censored. Banned modern movies I am less familiar with, but there were many banned historically where the decision still stands today.
syntheticcorp··on Group of monkeys kill over 250 dogs for 'revenge' in Indian town
Average adult would include women, which are much weaker than men. It is sad if it applied to just men.
syntheticcorp··on Log4Shell update: second Log4j vulnerability published
If it’s in the class path? Deserialisation gadgets.
syntheticcorp··on This shouldn't have happened: A vulnerability postmortem
I believe Java’s ZGC has max pause times of a few milliseconds
syntheticcorp··on Fingerprints can be hacked
They used several close range photos, not the one in the article.
syntheticcorp··on Chile wants to export solar energy to Asia via 15,000km submarine cable
Australia already has a plan for this in the works to supply Singapore with solar from the outback. It’s called Sun Cable - see: https://suncable.sg/
syntheticcorp··on Drug Users Are Nostalgic for ‘Old-School Heroin’ as Fentanyl Takes Over
Terrible job hiding the drug dealers identity in this article. They included her first name and location, googling that combination returns her full mugshot in a wanted poster put out by the local police.
syntheticcorp··on The main thing with kids is to keep them alive
Looks like they have doubled or tripled? Schools are still safe in absolute terms, shootings are a very small number.
Page 1 of 3Next →