Johannes Ullrich (maybe not a bot)

Dean of Research, SANS.edu College | SANS Internet Storm Center | Intrusion Detection | Web App Security | Connoisseur of fine packets and honeypot logs

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-11-18

@screaminggoat @buherator you saw current models are affected? Or just that the old one never got fixed.

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-11-18

@screaminggoat not my find. I just saw the expo I’ll being used.

Johannes Ullrich (maybe not a bot) boosted:
SANS Internet Storm Center - SANS.edu - Go Sentinels!sans_isc@infosec.exchange
2024-08-22

OpenAI Scans for Honeypots. Artificially Malicious? Actions gone wild? @openai isc.sans.edu/diary/31196

Johannes Ullrich (maybe not a bot) boosted:
2024-07-22

The world is 16+ hours into what looks like the biggest IT outage in history, triggered by a defective update for Crowdstrike endpoint security software for Windows machines.

helpnetsecurity.com/2024/07/19

#Cybersecurity #Crowdstrike #outage #EDR

@jullrich @malwarejake @brianhonan

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-07-13

@heatsink will do next time. Thanks!

Johannes Ullrich (maybe not a bot) boosted:
2024-06-19

This happened exactly 40 years ago.

via: talisman.org/

E-Mail screenshot: 19 June 1984
From: rws@mit-bold (Robert W. Scheifler)
To: window@athena
Subject: window system X
Date: 19 Jun 1984 0907-EDT (Tuesday)
I've spent the last couple weeks writing a window system for the VS100. I stole a fair amount of code from W, surrounded it with an asynchronous rather than a synchronous interface, and called it X. Overall performance appears to be about twice that of w. The code seems fairly solid at this point, although there are still some deficiencies to be fixed up.
We at LCS have stopped using W, and are now actively building applications on X. Anyone else using W should seriously consider switching. This is not the ultimate window system, but I believe it is a good starting point for experimentation. Right at the moment there is a CLU (and an Argus) interface to X; a C interface is in the works. The three existing applications are a text editor (TED), an Argus I/0 interface, and a primitive window manager. There is no documentation yet; anyone crazy enough to volunteer? I may get around to it eventually.
Anyone interested in seeing a demo can drop by
NE43-531, although you may want to call 3-1945 first. Anyone who wants the code can come by with a tape. Anyone interested in hacking deficiencies, feel free to get in touch.
Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-06-18

Due to the June 19th holiday and travel, there will be no podcast for Wednesday and Thursday.

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-06-18

Good weekend with some good dog walks. Need more of it.

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-06-10

The mini PCs for #SANSFIRE arrived. We will give them away during our honeypot workshop and possibly for other raffles.

pile of 20 mini PCs
Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-06-04
Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-06-03

OS Command Injection. It doesn't get much more severe than that regarding web application/API vulnerabilities. Still, these issues keep coming up in security devices. isc.sans.edu/j/osinjection

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-05-28

Interested in joining me at #SANSFIRE? We have some great special events planned. Honeypot Fest, ISC Keynote, great classes, and more. I will be teaching SEC522.. see youtube.com/watch?v=S81x1I6Ti5

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-05-16

@Marco Interesting that Europe does it better. I think they also do not allow luggage to be stored under the exit row seat.

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-05-16

I have traveled quite a bit over the years (less recently). Usually, I try to get an exit seat. In probably 100+ flights with different airlines, I remember only ONE instance where a flight attendant did a thorough exit row briefing. She explained how to open the door, what to watch out for, to wait for signals from the cabin crew before opening, and a couple of other things.

Usually, they do the “verbal yes” to acknowledge that you are in an exit row.

Yesterday, the flight attendant didn’t even do that and only made some jokes about the Delta credit card… no wonder most people look at their phones instead of the emergency briefing. :(

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-04-04

@jesterchen will try to cover this in the next episode. thanks for the pointer.

Johannes Ullrich (maybe not a bot) boosted:
2024-04-01
My heart goes out to xz. A single maintainer, who was clearly in a rough place with mental health, screaming out to the world for some help and additional contributions, and somebody shows up wanting to help. Could you imagine how happy that maintainer was? They were no longer alone.

And it turns out the only reason somebody wanted to help them was nefarious. I can’t imagine how they feel right now as everyone is blaming them. I hope they’re ok.
Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-03-29

@railmeat @adamshostack Agree. A win for open source and thanks to Andres for finding, and immediately reporting the issue.

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-03-29

A quick note about the xz-utils backdoor:
1 - luckily, no mainstream distros are affected.
2 - most run xz-utils 5.2/5.4. 5.6 is vulnerable
3 - quick check: `xz -V`
4 - This makes you wonder what else is happening. Thanks to people who paid attention
cisa.gov/news-events/alerts/20

Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-03-21
nothing matters
Johannes Ullrich (maybe not a bot)jullrich@infosec.exchange
2024-03-15

@kohan @jullrich yes. Typo. But 404 URLs do help to get them to try multiple ways to connect and use real browsers / drop VPNs

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst