chapin :donor:

#DFIR, #DevSecOps, #skiing, & #aviation nerd. Co-author of Learning Python for Forensics & Python Forensics Cookbook. 

Learning #Rust to replace my slow #Python modules. All about #security and how we can build more secure more now.

2024-12-27

Thrilled to speak at Shmoocon this year! We’ll be presenting Luminaut, our open-source tool for detecting exposure of cloud resources from the inside-out to uncover PoC and shadow IT environments.

shmoocon.org/speakers/#shadowc

2024-01-13

If you pick up the Python Digital Forensics Cookbook at the #shmoocon book swap today, find me in the floopy disk repair co shirt and I will sign the copy for you

2024-01-12

Gourd husbandry was not on my #shmoocon bingo card

2023-11-09

This novel web shell “hijacks the underlying Apache Tomcat webserver and silently inserts itself between Confluence and Tomcat–making itself available on every webpage ...”

Interesting CVE-2023-22515 post-exploit behavior discovered by Aon's Stroz Friedberg Incident Response practice.

“… patching Confluence to address CVE-2023-22515 and CVE-2023-22518 will not remediate the web shell if it has been deployed.”

See the blog post for insights on identification of this web shell on your #Confluence server.

aon.com/cyber-solutions/aon_cy

#dfir #cve #webshell #exploit #atlassian #security

chapin :donor: boosted:
daniel:// stenberg://bagder
2023-10-11

How I made a heap overflow in

Let me talk CVE-2023-38545 a bit

daniel.haxx.se/blog/2023/10/11

2023-08-28

#BSidesCT Tickets are now on sale! #CFP open until Sept 6. Join the fun on Sept 30th at Quinnipiac bsidesct.org #dfir #infosec #cybersecurity

BSidesCT logo
2023-07-11

As a part of #RAGBRAI , a 500 mile bike ride across Iowa in 2 weeks, I am raising money for the Children's Organ Transplant Association (#COTA ) honoring Hank Roy, my close friend's 1-year-old who needs a kidney transplant. The Roy's are the ones who introduced me to the event and I hope to ride it with them in the coming years!

All donations made to COTA for Hank will support a lifetime of transplant expenses.

If you'd like to contribute or read more about Hank and COTA, you can do so on our event page: cota.org/campaigns/COTAforHank #HangWithHankRoy #RAGBRAIGives

Hank on his trikeRAGBRAI routeQR code for our fundraiser
2023-07-04

Also provides an advanced view for querying the underlying data including diagrams and details about the crash and conditions

2023-07-04

#til that this resource exists with some good dashboards on different types of crashes: ctcrash.uconn.edu/

2023-06-12

#NYC Subway sheds interactive map: subwaysheds.com/ shows an interesting view of how far you can go in 10/20/30/40 minutes with the subway + transfers + walking. Certainly seems to plot best case scenario, but the negative space is an interesting highlight.

2023-05-18

Why is there no emoji for grilling?

chapin :donor: boosted:
Michael van Niekerk 🦀 ☕️ ⚛mvniekerk@techhub.social
2023-04-27

My little Rust crate made the 250 stars mark on Github.

Go boitjie!

If I can get to learn how to do Rust macros properly, I'll even settle for a 1.0 release.

github.com/mvniekerk/tokio-cro

#rustlang #scheduling #cron #tokio

chapin :donor: boosted:
Michał Górny :gentoo:mgorny@fosstodon.org
2023-02-13

So I'm looking at `git log Misc/NEWS.d/next/Security/` in CPython repository and I see a commit message that's literally:

```
Update Lib/subprocess.py
```

…and I'm thinking… just sigh.

github.com/python/cpython/comm

#Python #GitHub

2023-01-29

#RAGBRAI 50 route announced!

2023-01-21

@BugFireIO I found this playlist helped reinforce the concepts in the books: youtube.com/playlist?list=PLai.

Also I have started re-writing my chickadee GeoIP enrichment tool from Python to Rust: github.com/chapinb/chickadee-r.

Feel free to share on your process/projects!

2023-01-21

@BugFireIO Heh slow and steady! I really enjoy #rust and have found it more approachable than the internet prepared me for. Are you at #shmoocon? If so let's chat more

2023-01-21

Excited for my new book thanks to the #ShmooCon book swap. If you picked up Python Digital Forensics Cookbook, feel free to say hi!

2023-01-21

@ThinkstCanary Excited about the new credit card tokens! A lot of neat use cases for this (and your other) tokens. #shmoocon

Check them out here: canarytokens.org/generate

chapin :donor: boosted:
nicole schwartz amazonvcircuitswan@defcon.social
2023-01-21

Thank you to everyone who attended / streamed my talk! "Ya Got Trouble (and SLSA may help)"

Slides: docs.google.com/presentation/d

Hopefully you are all ready to review and update your software writing and build processes to match the SSDF (tip: start with SLSA)

Thank you #shmoocon

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst