cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]mc.fly [he/him] » 🌐
@mcfly@milliways.social

Karl Baron boosted

[?]Rairii :win3_progman: :win3: » 🌐
@Rairii@labyrinth.zone

hi everyone

given one #bitlocker #0day is already out there, here's my own bitlocker 0day, I added it to my repo listing bitlocker attacks.

Introducing "ram leak": https://github.com/Wack0/bitlocker-attacks#ram-leak

As we all know, the boot environment allows booting from a ramdisk. This involves loading a file from disk into RAM, as expected.

However, "file" and "disk" can be arbitrarily chosen, and "disk" being a BitLocker encrypted partition is a supported scenario. Using another trick (same one used with bitpixie earlier) it's possible to get the keys derived without going through the legacy integrity validation checks too if relevant.

You can see where this is going. It's possible to leak any file from a bitlocker encrypted OS partition into RAM as long as you can get the keys derived (ie, TPM-only scenario).

The catch is that booting into the NT kernel marks that memory area as free so it could get overwritten there, but there are other ways to dump the memory area, and a PoC is included with my preferred method (it's only a PoC so just displays a hexdump of the first sector of the file)

The video shows successful exploitation in my test VM, it has secure boot enabled (you can tell because VMware shows an efi shell option on the boot menu when secure boot is disabled).

#infosec #windows

    [?]mc.fly [he/him] » 🌐
    @mcfly@milliways.social

    If you have not read the notes on security by microsoft from last tuesday you should.

    microsoft.com/en-us/msrc/blog/

    Update your shit. Windows, Linux .... keep all the systems up to date.

      [?]mc.fly [he/him] » 🌐
      @mcfly@milliways.social

      NIST has given up on CVE's. They can't deal with it anymore.

      nist.gov/news-events/news/2026

      is from now on only reviewing "important" CVE's.
      This means that only if it affects the (us) government or its really bad they will review CVE Submissions.

      Around 90% of the submissions will not be reviewed anymore (for now)

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from Alibaba.

        - At least 2 uppercase letters
        - Plus 2 lowercase letters
        - Plus 2 numbers
        - Plus 2 punctuation marks

        Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](youtube.com/watch?v=f3lUEnMaiAU),
        then password rules can be equally intelligent too.

        Also, ...

        dumbpasswordrules.com/sites/al

          [?]Fedora Project » 🌐
          @fedora@fosstodon.org

          How does Fedora process patches for security vulnerabilities? The short answer is that we work to stay on top of the news to implement patches, working in the community and with Red Hat for updates.

          The long answer: fedoramagazine.org/how-fedora-

          At the end of the day, the best thing you can do is keep your system updated. :)

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from BDO.

            Please nominate a password which contains UPPERCASE, lowercase, numbers and symbols.
            Password should not be the same as the user ID.
            Avoid using consecutive characters such (ex. abc, DEF, 678) and invalid characters such as [!#$%^&';"].

            dumbpasswordrules.com/sites/bd

              [?]gyptazy » 🌐
              @gyptazy@gyptazy.com

              AI assisted pen testing, coding and arising secvulns. Are we humans still good enough?

              the last weeks we saw more and more security issues coming up. Let's talk!

              Sorry, a pretty long blog post about this...

              https://gyptazy.com/blog/coding-after-ai-are-humans-still-good-enough/


              Let's talk about AI slops - like this image!

              Alt...Let's talk about AI slops - like this image!

                [?]Florian 'floe' Echtler » 🌐
                @floe@hci.social

                I had found a very thorough server checker (e.g. TLS, DKIM, certificates, PFS, DMARC, you name it) here on the fedi at some point and thought I'd bookmarked it, but just can't find it anymore. Any recommendations from the sysadmin crowd?

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from MyAnimeList.

                  Password must be between 6 - 50 characters long and contain at least two of the following: uppercase, lowercase, numbers and symbols.

                  dumbpasswordrules.com/sites/my

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Telekom/T-Systems MyWorkplace.

                    Telekom's MyWorkplace is a Single Sign On / login hub for their
                    Open Telekom Cloud which is basically an Amazon AWS clone. It's
                    rather new and especially for business customers. Especially
                    because it is for business customers, there's absolutely no reason
                    to limit a password to 16 characters. Eve...

                    dumbpasswordrules.com/sites/te

                      [?]Mike Sheward » 🌐
                      @SecureOwl@infosec.exchange

                      So a new, quite effective method I've found during pentests recently:

                      People are starting to connect their work email and calendars to personal AI agents, and are, inevitably, storing the code in publicly accessible repos.

                      There are two things I look for:

                      - Email creds, prevalent where people have given the AI dealy IMAP access to their messages.

                      - If I can't find email creds, the link to the private Google Calendar (either outlook or Google) ICS file.

                      If you grab that ICS file, you download effectively an entire copy of the calendar, which includes the body of the meeting invite - so, various links, attachments, keys/secrets/passwords etc.

                      I have done the email thing maybe once or twice.

                      The calendar thing, at least a dozen times in the last few months.

                        [?]h3artbl33d :openbsd: :antifa: [Try/Me] » 🌐
                        @h3artbl33d@exquisite.social

                        About that... We now have a fourth vulnerability: ssh-keysign-pwn. Despite the first three letters, this is a Linux kernel vuln. PoC already available.

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from NetBank (Commonwealth Bank of Australia).

                          When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
                          And also, it's password strength calculation is shit.
                          An 155 bits of entropy password is "weak."
                          Additionally, passwords are case-...

                          dumbpasswordrules.com/sites/ne

                            [?]Harry Sintonen » 🌐
                            @harrysintonen@infosec.exchange

                            Local file exposure in linux kernels:

                            github.com/0xdeadbeefnetwork/s

                            Apparently this issue was already identified in 2020 but wasn't fixed back then.

                            Mitigation:
                            - runtime:
                            sudo sysctl -w kernel.yama.ptrace_scope=2
                            - To make the migiration persistent:
                            echo "kernel.yama.ptrace_scope=2" | sudo tee /etc/sysctl.d/01-harden-ptrace.conf

                            WARNING: This migation may break existing functionality. Test before deploying.

                            WARNING 2: While this mitigation does block the currently existing PoC, it may not prevent other attack vectors exploiting this vulnerability.

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from Parnassus Investments.

                              A site responsible for protecting your investments limiting you to a
                              four character range with a bunch of other stupid rules? Shocking.

                              dumbpasswordrules.com/sites/pa

                                [?]Dendrobatus Azureus » 🌐
                                @dendrobatus_azureus@polymaths.social

                                This is something that's actually forbidden in our country

                                companies may not call random numbers just to spam them.

                                To compensate for that luxury, the main internet and POTS provider let's companies pay them to spam us with SMS!

                                This is also disallowed by law but no one seems to bother to file a class action suit against this company

                                Those spam SMS you can easily block though

                                @rl_dane

                                #Spam #privacy #InfoSec

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Munich Foerdermittel Portal.

                                  You register on their funding portal and receive an email with an activation link to set a password.
                                  The email further informs you about their password policy:
                                  - At least 8, but no more than 20 characters
                                  - At least one lowercase and uppercase letter
                                  - At least two digits (1,2,3,4,5,6,7,8,9,0) or...

                                  dumbpasswordrules.com/sites/mu

                                    Leah boosted

                                    [?]mc.fly [he/him] » 🌐
                                    @mcfly@milliways.social

                                    depthfirst.com/nginx-rift

                                    Anyone running nginx? Noone does that right?

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from LibraryThing.

                                      "Your password cannot be longer than 20 characters"

                                      dumbpasswordrules.com/sites/li

                                        [?]Mike Sheward » 🌐
                                        @SecureOwl@infosec.exchange

                                        Mini Pen Test Diaries Story:

                                        The year was 2010, and I was onsite at a UK local authority doing an internal network assessment.

                                        One of the tasks was - if given a standard, non-privileged, domain user account, with minimal access afforded to it - what could I do? Could I access sensitive documents? Could I login to systems I shouldn't be able to? Could I elevate myself. Standard stuff.

                                        I got my account, and immediately started fishing around the main file share with the users home directories on it. To my immense surprise, I found out that I was able to access the content of every single users home directory. Including all the top level folks.

                                        They must've accidentally given me some account in an IT group or something, so I check it out. Nope - groups look normal.

                                        The permissions on the share look pretty normal too.

                                        I play around with the account more and more and encounter zero resistance to anything, access wise.

                                        Something must be very wrong - but what?

                                        Finally I go over and speak to the IT people who I'd been working with.

                                        "So," I said. "This account, it's supposed to have a very minimal permissions set right?"

                                        "Yes, the lowest of the low." They reply.

                                        "So how come I can get into all these files?" I ask, and show them my rummaging around the very senior peoples confidential files.

                                        "You shouldn't be able to do that!!"

                                        Now, the three of us are rapidly trying to figure out what the heck is going on. It's surprisingly difficult to figure out.

                                        Eventually, I make what to this day remains one of my all time favorite pen testing discoveries.

                                        This organisation, had somehow, managed to add the entire "Domain Users" group to the "Domain Admins" group!

                                        All 1,500 people who worked there, had domain admin access. And after investigation, we found out it had been like that for 10 months.

                                        Someone couldn't get something working, until they found this "fix".

                                        Amazing.

                                        For more, slightly less mini pen test diaries stories, check out infosecdiaries.com.

                                          [?]AA » 🌐
                                          @AAKL@infosec.exchange

                                          Ars Technica, from yesterday: Twin brothers wipe 96 government databases minutes after being fired arstechnica.com/tech-policy/20 @arstechnica

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Aetna Health Insurance.

                                            - Password cannot be longer than 20 characters
                                            - Password cannot have spaces and more 2 characters repeated in a row
                                            - Password cannot have user's first name, last name or username

                                            dumbpasswordrules.com/sites/ae

                                              [?]mc.fly [he/him] » 🌐
                                              @mcfly@milliways.social

                                              RE: cyberplace.social/@GossiTheDog

                                              This YellowKey Bitlocker Bypass Vulnerability is seriously crazy. As if someone found a government / law enforcement backdoor....

                                              Tim Hergert boosted

                                              [?]Kevin Beaumont » 🌐
                                              @GossiTheDog@cyberplace.social

                                              So I’ve just had a quick play with this and yes, it works. Essentially BitLocker has a backdoor. github.com/Nightmare-Eclipse/Y

                                              Mitigation = BitLocker PIN and BIOS password lock.

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Minnesota Unemployment Insurance.

                                                Locked to *exactly* 6 chars, alphanumeric only, not special chars.

                                                dumbpasswordrules.com/sites/mi

                                                  [?]Dendrobatus Azureus » 🌐
                                                  @dendrobatus_azureus@polymaths.social

                                                  Many people also don't realize that everyone on the globe, who is in a country which is being controlled by Swift banking system, will also suffer.

                                                  @rl_dane

                                                  #Privacy #SSN #InfoSec #breach #sensitive #programming

                                                    [?]Dendrobatus Azureus » 🌐
                                                    @dendrobatus_azureus@polymaths.social

                                                    What is happening over there!?

                                                    It's extremely disturbing that they want your Sierra Sierra November. That is a record you can always be uniquely identified with

                                                    @rl_dane

                                                    #Privacy #SSN #InfoSec #breach #sensitive #programming

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from BBVA.

                                                      Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only.
                                                      For a bank account with all your money in one of the largest financial institutions in the world.

                                                      dumbpasswordrules.com/sites/bb

                                                        [?]mc.fly [he/him] » 🌐
                                                        @mcfly@milliways.social

                                                        Nothing wakes you up as fast as a good information security incident.

                                                        From bed reading infosec news to the computer pressing buttons in like 60 sec.

                                                        now 3 hrs later i'll go and make a first coffee...

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Getin Bank.

                                                          The new password should contain at least 10 and a maximum of 20 characters.
                                                          The password must contain at least one upper case letter, one lower case
                                                          letter and one number. The password cannot contain non-ASCII Polish alphabet
                                                          characters, special characters `&<'"` or spaces.

                                                          dumbpasswordrules.com/sites/ge

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from ADP.

                                                            Forced to change the password during the first login. At least they
                                                            could use proper grammar in their rule list.

                                                            dumbpasswordrules.com/sites/ad

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Dnevnik.ru.

                                                              Silently (sic!) trim password to 30 symbols.

                                                              That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

                                                              dumbpasswordrules.com/sites/dn

                                                                wtfismyip boosted

                                                                [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                @MissConstrue@mefi.social

                                                                Everybody hates . But, despite tech reporting being willing to give the leeway, this new measure is not to stop robocalls, it won’t do a damn thing to stop robocalls. What it does is make burner phones illegal.

                                                                Burners are an integral part of many social justice actions. Protestors use them to record and other . We include them in “Go Bags” to let abused women and children escape. They allow for anonymity.

                                                                They are a thorn in the side of the panopticon, and they are moving to eliminate them.

                                                                Stock up kids.

                                                                gizmodo.com/fcc-attempts-to-so

                                                                wiley.law/alert-FCC-Proposes-S

                                                                mashable.com/article/fcc-propo

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Taleo.net.

                                                                  Oracle Taleo is one of those old-school enterprise Applicant Tracking
                                                                  Systems (ATS) that half the corporate world still uses even though
                                                                  everyone hates it.

                                                                  dumbpasswordrules.com/sites/ta

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Express Energy.

                                                                    Retail Electricity Provider (REP) participating in ERCOT.

                                                                    Minimum 6, maximum 10. Stated requirement of numbers and letters, but special characters are accepted.

                                                                    dumbpasswordrules.com/sites/ex

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Bank Millennium.

                                                                      Passwords limited to 8 digits.

                                                                      dumbpasswordrules.com/sites/ba

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from myezyaccess.com patient portal system.

                                                                        12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

                                                                        dumbpasswordrules.com/sites/my

                                                                          mc.fly boosted

                                                                          [?]mc.fly [he/him] » 🌐
                                                                          @mcfly@milliways.social

                                                                          Automated scanning.

                                                                          What tools do you use to scan your enviroments for security issues? Why?

                                                                          Not looking for virusscanners here, more for a bit more enterprisy enviroment?

                                                                          Are there things i should have a look at?

                                                                          What is your experience in general?

                                                                          RT welcome for reach.

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Waze.

                                                                            After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an error if you use any special characters...

                                                                            dumbpasswordrules.com/sites/wa

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from LINE.

                                                                              Password must:
                                                                              - be between 8 to 20 characters
                                                                              - not contain characters that repeat in a row
                                                                              Password must contain three of the following:
                                                                              - an upper-case letter
                                                                              - a lower-case letter
                                                                              - a number
                                                                              - a symbol

                                                                              dumbpasswordrules.com/sites/li

                                                                                mc.fly boosted

                                                                                [?]mc.fly [he/him] » 🌐
                                                                                @mcfly@milliways.social

                                                                                lwn.net/Articles/1071719/

                                                                                is a broken embargo.

                                                                                Local Privilege Escalation to root.

                                                                                Public working exploit. No CVE assigned yet.

                                                                                No fix in sight.
                                                                                <edit> 7.0.5 was just released which has a fix </edit>
                                                                                <edit 2> CVE-2026-43284 has been assigned</edit 2>

                                                                                -2026-43284

                                                                                This is the documentation & exploit of DirtyFrag:
                                                                                github.com/V4bel/dirtyfrag/blo

                                                                                are you not entertained meme

                                                                                Alt...are you not entertained meme

                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

                                                                                  At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
                                                                                  No more than 3 of the same characters.
                                                                                  At least 1 upper case and 4 lower case characters.
                                                                                  No more than 3 special characters.

                                                                                  It's not like hashing passwords is a thing or something.

                                                                                  dumbpasswordrules.com/sites/du

                                                                                    Back to top - More...