Graham Stevens

Coffee Aficionado, Motorsport Fan, Dog Lover, Security Bod - All-round geek. Views are my own...

Graham Stevens boosted:
2022-12-20

@transcaffeine
PoE = Power over Ethernet
PPPoE = Three-Phase AC over Ethernet

Graham Stevens boosted:
Scott Hanselman 👸🏽🐝🌮shanselman@hachyderm.io
2022-12-19

A reminder, if you own your own domain you can quickly setup webfinger like this hanselman.com/.well-known/webf (can just be a static file, or dynamic) so that if someone searches mastodon (use me as an example) for @shanselman then it will call out to my domain, find me, and tell you my aliases, which is my account at hachyderm.io. Cool eh? Should take you just a few min to implement!

Graham Stevens boosted:
Toot!.app ↙︎↙︎↙︎tootapp
2022-11-26

And now Toot! v17.1 is out, as well!

toot.to/

This is the second in a series of releases that implement support for new Mastodon features. More will come in the near future, but this version offers:

* Support for different limits on different servers. Some servers allow longer toots, more attachments, or more poll options.
* Support for editing your toots if your server is on Mastodon 4.0.

Graham Stevens boosted:
2022-11-25

@Patricia YAML isn't bad, you just need the right accessory on your laptop to debug. :blobfoxcomputerowonotice:

A laptop opened with a YAML file in a code editing application. The laptop has a ruler strapped awkwardly on the screen, to assist in lining up the YAML correctly. YAML relies on correct indentation to get everything structured right.
Graham Stevens boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2022-11-23

This is the only thing really worth saving, and possibly worth reading, that I ever posted to Twitter. #infosec #cybersecurity

Recognize the early stages of infosec: "I just read the top 100 passwords’ and they're super weak!’” 
"I turned on external logging and there's al these brute force attempts!” “People still use Java!"
~ “SHODAN!"

Recognize the secondary stages of infosec: "I stayed up for 30 hours straight an it was awesome!” “Is antivirus actually useless?” “I'm gonna be the best purple teamer!” “But they promised they'd reimage last year!” “Damn, | gotta learn Python..” “But wasn't it China?”

Recogrize the tertiary stages of infosec: “NEVER MIND, they do need antivirus.* “So, attribution is hard...” “Paexec, again?!l” “Stolen creds, again?l” “How is my hard drive full of VM snapshots?” “I went to a con but | just talked to people...” "Do I drink too much?” 

Recognize the quaternary stages of infosec: “You know, forget the pen test, let’s just build an asset inventory and network map.” “I secretly want to skip this con, but I'm speaking about beer.” “I am genuinely considering opening a bar in a few years” “I probably drink too much.”
Graham Stevens boosted:
miekmiek
2022-11-22

@benjojo there's a teardown of a similar card here: blog.hqcodeshop.fi/archives/43 - looks like it's all one coil, with some capacitors formed in series

2022-11-22

Setup an alias as per @maartenballiauw so that I can hand out "[at]graham@grh.am" and it always redirect to whichever is my current Mastodon account. I'm sure it wouldn't, but handy if chaos.social ever disappears one day!

Details:
blog.maartenballiauw.be/post/2

Super easy via Hugo, essentially the same as what @jeffhandley has done via Jekyll - github.com/jeffhandley/jeffhan

Graham Stevens boosted:
2022-11-20

if we scan slowly; blue won't notice

the blue team:

2022-11-20

@darren @tootapp correct, but with v4 of Mastodon there’s now a native edit option, rather that delete and rewrite (which saves threads etc.)

2022-11-19

@tootapp other than that, loving the app - all the little touches make it 👌

2022-11-19

Can I edit a post using @tootapp now that we’re on v4 of Mastodon…?

Edit: Nope, nor Metatext. Had to go directly to chaos.social. Ah well!

Graham Stevens boosted:
Ten🏳️‍⚧️Ten@mastodon.lol
2022-11-18

I have a friend who writes songs about sewing machines.

She’s a Singer songwriter, or sew it seams.

#joke #jokes #puns #joking

Graham Stevens boosted:
2022-11-17

Data from recent #batloader campaigns leveraging digitally signed #malware impersonating popular software:

🧲​ Lure sites:
anyofferdesk[.]com
offerdistancezoom[.]com
offerslack[.]com
teamofferview[.]com
luminar4[.]com
winrarlabs[.]com
getsnotes[.]com

🖊️​ Digital Certificates:
"Digital Designs FL LLC"
"Glacier Digital Ads Inc"
"Danjo Digital LLC"

🌐 ​C2s:
24xpixeladvertising[.]com
t1pixel[.]com
photo-editor-mark[.]com

❓​ What's next?
Batloader is malware-as-a-service that's been observed delivering InfoStealers or in some cases dual-use agents (atera, zoom) along with #cobaltstrike for #ransomware purposes

🔗​ VT query for files signed by these certificates: virustotal.com/gui/search/sign

#ThreatIntel #ThreatIntelligence #Thrunting

4 .msi filesVirusTotal web interface display low detected files
2022-11-13

*no edit functionality 🤦‍♂️
Serves me right for trying the type this on a phone when I should be sleeping

2022-11-13

Damn, spotted a typo but now edit functionality on this Mastodon instance 🙃 nevermind, at least this time I remembered the alt text for all the images!

2022-11-13

3/ So I gave it a quick clean and tried my best to restore the battery connections as best I could with the limited time available. I popped some new batteries into it and… it lives! 🚚

It’s current owner will be very pleased, I can assure you…

2022-11-13

2/ I started tearing it down, and of course one of the first things I did was provide it an external power supply, bypassing the onboard supply, and it sprung to life! An excellent troubleshooting start.

Whilst investigating the battery compartment, I quickly realise the previous owner was indeed not particularly forgiving. The compartment is full of what looks like crisp crumbs and other food items! It was almost as if the previous owner had tried to crush their snacks with the truck…

The battery compartment of a children’s toy truck, which although cleaned, still shows signs of food debris and poor battery connections
2022-11-13

1/ So this weekend I’ve been attempting to fix a secondhand EV truck. It’s completely dead, with no signs of electronic life - not great for an electric vehicle.

So first off, the outside all looks quite tidy, no obvious signs of an accident or the previous owner being particularly harsh. However, I don’t know the previous owner to we can’t be too sure…

A children’s toy truck, which has been dismantled to show the inner electronics
Graham Stevens boosted:
2022-11-11

How remarkable

2022-11-10

Just realised I messed up by not setting alt text for the media in this thread... whoops!

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst