#askinfosec

2025-03-31

Posted about it yesterday already. But it looks like archive.today shows the default page of #Apache #webserver on #Ubuntu. The alternative domain name archive.is instead redirects with a 301 - Moved Permanently to a new domain krola.org, a website apparently comparing pet rabbit species?? It's also interesting, that the redirect to the new domain responds with an #HTTP header server: nginx/1.18 (Ubuntu). Apparently, the default Apache landing page also returns the same HTTP header information on the server. Perhaps the landing page is a decoy/deflection?

Anyone on #infosecexchange has any speculations on the website?

#InternetArchive #ArchiveOrg #ArchiveToday #InfoSec #AskFedi #AskMastodon #AskMastodonMondays #AskInfosec

2025-02-20

Is it just me or is every demo/overview of the #FlipperZero extremely unimpressive (especially those for a mainstream audience).

I regretfully watched one such video earlier and one of the features highlighted was the ability to copy TV remote signals :blobcatgoogly2: ...I get it was aimed at a non-technical audience but I literally had a watch that could do that when I was a kid and to this day grandparents around the world have universal remotes with this capability...

So I want to put it out there to the #infosec community - where are the cool flipper zero #projects? And I don't mean installing #DOOM or some other quirky play thing. I want to see legit #RF #hacking, or at least using the #GPIO!
#askfedi #askinfosec #rfhacking #pentesttools #hackingtools

Aaravchen :linux: :suspicious:aaravchen@fosstodon.org
2025-02-12

Does anyone know how booting Linux in FIPS mode gains any use or security from the `.vmlinuz.hmac` file? The interweb has no info at all.

It's a basic SHA of the vmlinuz file, but it has no way to verify authenticity or integrity of the hash, and is distributed with the thing it supposedly verifies. How does that have any purpose?

#cybersecurity #security #infosec #InfosecCommunity #askInfosec

2024-03-18

OK, so #AskFediSec seemed to win that particular round but many people offered up the suggestion #AskInfosec which I also really like, so here's a run-off. For the folks that liked the idea of having a *dedicated* hashtag for this kinda thing, what is your preference below?

I'll also note that some variations of #AskInfoSex were also floated and tbh could be quite popular 😉🤣.

#infosec #cybersecurity

2024-03-14

@shellsharks Great idea! - As some others before me I'd prefer something like #AskInfoSec / #AskSec - you know, something like this

Lisi Hockelisihocke
2023-12-02

looking back on my personal challenge for 2023: | A Tester's Journey: AskAppSec - Finding Closure lisihocke.com/2023/12/askappse

Lisi Hockelisihocke
2023-11-27

what do you do to practice your security skills? | A Tester's Journey: AskAppSec - Capturing Flags lisihocke.com/2023/11/askappse

Lisi Hockelisihocke
2023-11-07

what do you do to make keeping dependencies up to date work? | A Tester's Journey: AskAppSec - Dependency Updates lisihocke.com/2023/11/askappse

2023-11-07

@gvwilson 👆 @wehackpurple and #AskInfoSec is a great community to turn to with these questions

Lisi Hockelisihocke
2023-10-18

was awesome as my first security conference - what are your recommendations for the next? | A Tester's Journey: AskAppSec - BSides Munich 2023 lisihocke.com/2023/10/askappse @BSidesMunich

Lisi Hockelisihocke
2023-10-13

what makes security champions programs effective? | A Tester's Journey: AskAppSec - Security Champions lisihocke.com/2023/10/askappse

Lisi Hockelisihocke
2023-10-03

what's your approach to move towards painless, usable security? | A Tester's Journey: AskAppSec - Painless Usable Security lisihocke.com/2023/10/askappse

Lisi Hockelisihocke
2023-09-25

I've received feedback on my question "should BFFs validate input?" - check out the updated blog post for community insights! 💡 lisihocke.com/2023/09/askappse

Lisi Hockelisihocke
2023-09-12
Lisi Hockelisihocke
2023-07-16

I'm eager to connect with more folks. Are there any online communities around , , you can recommend or heard others recommend? I've joined a few already, yet any pointers on good ones are much appreciated. 🙏🏻

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst