h4sh

Security generalist, purple teamer, open source enthusiast, bullshit detector.

2025-05-24

@alina Do it, we need more p2p networks

2025-05-24

The #EUVD API is a lot better than NVD's. It includes EPSS info, CVE aliases and severity base score in a much easier to parse JSON schema.

One catch tho, if you're using Python requests the default User Agent is banned probably due to LLM scraping reasons

2025-05-23

EUVD-2018-11103 (PRTG Network Monitor LFI) now has a nuclei template:

github.com/projectdiscovery/nu

Exploitation is likely to return, better make sure you're patched against re-emergent N-days.

#EUVD #nucleitemplate

2025-05-20

@troyhunt @haveibeenpwned The new UI looks like it was made by a crypto startup..

What was the reason for a UI change? The previous UI is perfect fine and modern

h4sh boosted:
2025-05-16

ESXtortion!

*Satirical cryptolocker style dialog window* 

title: “your hypervisors have been patched!”

Instead of encrypting files we have installed random VMware
patches across your infrastructure.

Pay us millions of ponzi-coins or we'll report yo ass to
Broadcom licensing.
2025-05-16

@da_667 @catsalad I deeply enjoy this addition of Chinese on mastodon memes, especially this canto-mando accent written out

h4sh boosted:
hagen terschürenhagen
2025-05-14

it’s a thing we see over and over again in our society. fixing stuff around the house. building your own pc. changing the tire on your bike. so many things seem daunting because we were never tought to just diy things.

the largest obstacle in our daily lives is the lack of confidence in our abilities. learning that you can just pick up a screwdriver, try and nothing bad will happen is one of the most fulfilling experiences of your life.
tldr.nettime.org/@tante/114505

h4sh boosted:
Work Chronicles comicsworkchronicles
2025-05-14

(comic) With great responsibility comes great... never mind workchronicles.substack.com/p/

2025-05-14

@petrol You moderate the rego process (with something like Anubis) so that it can't be easily automated with bots. Then when a legit user starts acting like a scraping bot you kick them out

2025-05-14

Crazy idea.. ever thought about hosting fediverse services behind a overlay network? The amount of bots scraping information for AI use is insane these days and must be causing a lot of unneccessary performance and privacy issues.

I'm starting to think that the internet is now just a wasteland and with an authenticated and well moderated overlay network (like tailscale), detecting and killing scrapers would be a lot easier.

@jerry

h4sh boosted:
2025-05-12

Am I worried that AI will destroy jobs?

No. I'm never worried about any technology destroying jobs. Because jobs aren't sacred things to be preserved. Destroying jobs is progress. (Do we want to bring back the coal-mining jobs we've lost?)

What I worry about is AI, or the people promoting it, destroying LIVES. The problem is the system in which jobs are being destroyed—with what happens to the people who held those jobs.

I could give a fuck if AI does my job. The problem is the douchebags pushing it don't have a plan for how I'll keep my house and pay my family's medical bills if it does.

It's not about the jobs. To build a just and sustainable world we'll need to destroy so many jobs it would make a Silicon Valley executive's head spin. What worries me, and offends me, is that these assholes have no plan for how to absorb and take care of the people they displace. They never do.

h4sh boosted:
2025-05-09

As strategies go, that's a solid one.

h4sh boosted:

Another baffling thing I saw recently was this shop selling phone cameras basically by the kilo. I would love to know how many modules are in the first photo

A photo down a shop shelf full of plastic bags filled with something coarse and black. It’s a huge number of bagsCloseup of one of the bags reveals that is full of small camera modules with a lens and flatflex cable. It must be hundreds if not thousands of cameras in a single bag
2025-05-03

#auspol

The Australian people have overwhelmingly rejected the center right (LNP), fringe right (TOP/ONP) and the fringe left (Greens) in this election.

h4sh boosted:
2025-05-03

Slightly envious of Australia right now: 'It has been so long since we have not had culture wars or grievances dominating our politics — or its undertones — it is hard to imagine what it might look like.

It opens up the scope for rational discussion about policy at a time when we need it.'
abc.net.au/news/2025-05-04/ele #AusPol

h4sh boosted:
2025-05-03
h4sh boosted:
Heidi Li Feldmanheidilifeldman
2025-05-02

Santa Fe, New Mexico.

h4sh boosted:
2025-05-02

This is damning.

Kevin Collier, journalist from NBC News states:

"I will say [Kristi Noem] has come out swinging, insisting her vision of CISA will improve [DHS] and falsely describing its previous work as being substantially devoted to policing misinfo.

The crowd has been relatively into it. Tepidly bit on her laugh lines. No boos, no heckling. This is a corporate crowd, not Def Con, but I would have not been surprised to have seen some disruption."

Source: bsky.app/profile/kevincollier.

#infosec #RSAC

A screenshot of Kevin Collier's reporting via blue sky. A snippet of which is quoted in the post above.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst