Marduk_James :verified_paw:

Aspiring cybersecurity "something".
Just starting my journey, lets see where I end up!

Discord: marduk_james
Twitter: @Marduk_James
Medium: @marduk.i.am

Marduk_James :verified_paw:Marduk_James@infosec.exchange
2024-08-04

I just published SQL Injection Attack, Querying the Database Type and Version on MySQL and Microsoft link.medium.com/hHxIw42EMLb

#BugBounty #bugbountytips #SQL #SQLI #injection #informationsecurity #PortswiggerLabs

Marduk_James :verified_paw:Marduk_James@infosec.exchange
2024-05-26

Morning coffee view

Three dogs sitting on a porch.
Marduk_James :verified_paw: boosted:
2024-04-15

So, Microsoft is silently installing Copilot onto Windows Server 2022 systems and this is a disaster.

How can you push a tool that siphons data to a third party onto a security-critical system?

What privileges does it have upon install? Who thought this is a good idea? And most importantly, who needs this?

#infosec #security #openai #microsoft #windowsserver #copilot

Marduk_James :verified_paw: boosted:
2024-04-11

There is something potentially huge popping up now. Has to do with a compromise at business intelligence vendor Sisense. I'm hearing this is a supply chain attack affecting many millions of credentials and hundreds of tenants. This is a message the Sisense CISO just sent to customers.

*29 minutes ago Good afternoon Q We are aware of reports that certain Sisense company information may have been made available on what we have been advised is a restricted access server (not generally available on the internet). We are taking this matter seriously and promptly commenced an investigation. We engaged industry-leading experts to assist us with the investigation. This matter has not resulted in ‘ an interruption to our business operations. Out of an abundance of cautio'n; and while we continue to investigate, we urge you to promptly rotate any. credefifialslha( you use within your Sisense application. . Should you have any qusfion§ related to this matter, please email i incidentquestions@sisense.com At Sisense, we give paramount importance to security and are committed to our customers' success. This is a proactive measure to ensure that our customers are secure. Thank you for your. partnership and commitment to our mutual security. Regards, Sangram Dash Chief Information Security Officer
Marduk_James :verified_paw: boosted:
Jan Wildeboer 😷:krulorange:jwildeboer@social.wildeboer.net
2024-02-12

“I made a decision. I want to learn Go”

Replies I hoped for: “Cool! I won’t question your reasons out of respect and here are some links/books/code that helped me. Enjoy your journey!”

Replies I got: “you should learn Rust. Go sucks.”

Le sigh, people. When I share something I am looking for help and support. Not attacks.

(I’ll stick with Go. Just as I had an Atari 400 and not a Commodore 64 like almost all ;)

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst