Twitter | Hledat | |
x0rz
Security Researcher & Cyber Observer ㊙
18 768
Tweety
338
Sledovaní
70 318
Sledující
Tweety
Uživatel x0rz retweetnul
Mark 25. 11.
My new debit card 😊😊😊
Reply Retweet Lajknout
Uživatel x0rz retweetnul
Joseph Cox 4 h
You've prob seen coverage about a firm allegedly unlocking iPhones for ordinary consumers. Told me: - 100% success THUS far [???] - wouldn't confirm if that includes up to date iPhones - can take 3 months - declined to unlock iPhone we offered to send
Reply Retweet Lajknout
x0rz 6 h
Interesting Brazilian targeting the financial sector
Reply Retweet Lajknout
x0rz 6 h
Odpověď @vsterkin
;)
Reply Retweet Lajknout
x0rz 9 h
People think of « cyber war » like it’s a grandiose battle between regular forces. The truth is, it’s more like urban guerilla fighters against mercenaries operating in unmarked uniforms. It’s a mess and no one knows exactly what is happening.
Reply Retweet Lajknout
Uživatel x0rz retweetnul
Mark Shapiro 28. 11.
"Granddad? Where did you fight in the Cyber War?" "I was a Blue Teamer, Billy. They had us deployed at 18.228.0.0/16. 'Hold the line!' they told us. And by God, Billy...we did."
Reply Retweet Lajknout
x0rz 19 h
Odpověď @allanfriedman
Thanks :)
Reply Retweet Lajknout
x0rz 22 h
Odpověď @marco_iz0fwk
Apparently it changed since last month, maybe some providers decided to block the port
Reply Retweet Lajknout
x0rz 24 h
Odpověď @x0rz
This serves as a recap of the talk I gave at ZeroNights, I wanted to add more content but the recent Akamai technical paper on UPnProxy was already giving all the technical details, so be it! ()
Reply Retweet Lajknout
x0rz 24 h
How to create the perfect anonymizing botnet by abusing UPnP features — and without any infection
Reply Retweet Lajknout
x0rz 29. 11.
Europol base64 tshirt... nerds! FYI, "RXVyb3BvbCBFQzMg" = base64("Europol EC3")
Reply Retweet Lajknout
x0rz 29. 11.
The 'test' subdomain redirecting to qinetiq-tim[.]com (QinetiQ group) subcontractor
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @GossiTheDog
I received the same DM spam today, lol
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @vysecurity
Yeah that's really sad :/
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @x0rz
They try to make it look like it's a boolean question: whether we disclose it and protect or just use it against targets. But this is not as simple! You can both keep it to yourself AND detect it when used against you.
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @x0rz
Especially if you can detect your own 0days in the wild, you can protect (= detect) the vulnerabilities and at the same time exploiting them as 0days: getting the best of both worlds
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @x0rz
Don’t get me wrong, this is a good move but overall nothing has really changed, offensive capabilities will always be more « strategic » than defensive ones
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @x0rz
These are intelligence agencies, they know how disinformation works and how to keep information confidential. There is zero guarantee all vulnerabilities will go through VEP. Some of them might be compartmentalized to upper classification and only known to a few.
Reply Retweet Lajknout
x0rz 29. 11.
Odpověď @x0rz
The whole process is done in secrecy, there are no publicly available statistics about the vulnerabilities being kept
Reply Retweet Lajknout
x0rz 29. 11.
This is pretty much why I think all VEP are just smokescreens (1/?)
Reply Retweet Lajknout