i started a series of blog posts to save people the tens of hours i dedicated studying tor internals. hope you enjoy. any feedback/improvement is *really* appreciated.
https://t.co/9xLrKWtLLe
https://t.co/SYEctXCpLn
Stasera @VaticanEmbassy ore 23:59: IPv6 101
Because we still don't know what it is and IPv7 is coming.
https://t.co/M3HySbKDnX
The talk could be in italian (we have still to decide).
stasera alle 23.59 alla Vatican Embassy (mondo 2D) talk "IPv6 101" a cura di l0rd.
Info: https://t.co/pSAEihfSIW
Link diretto: https://t.co/Mcq2GElXmh
The talk will most probably be in Italian, but who knows... #rc3#vaticanembassy#ipv6
Stasera @VaticanEmbassy ore 23:59: IPv6 101
Perché ancora manco si sa che sia ed IPv7 sta arrivando.
https://t.co/M3HySbKDnX
Talk forse in inglese (non abbiamo ancora deciso).
Stasera @VaticanEmbassy ore 21: whack-a-service by panda!
Come rendere (circa) altamente affidabili servizi esposti non
direttamente su internet, a basso costo, usando i DNS.
https://t.co/M3HySbKDnX
Streaming: https://t.co/0GFDcJxvCo): https://t.co/BSHh7SSyrK
Do you want to exploit a zip slip vuln but are you in a hurry? "Let Me Code That For You(TM)" https://t.co/hjWIuE6NXr
Thanks to @snyksec for publishing the research back in 2018.
Do you want to get Holy United at #rC3 ? Come to the Vatican Embassy (https://t.co/BYaZFCA1QV) and customize your Holy Rite here: https://t.co/4FB47FUw18 #HolyUnion#GetUnited get in touch to agree a time for the union. The Holy Bishops are here for you!
as always the prelates of the Vatican Embassy are on their way to Leipzig. Please, don't wake us up. (we are missing you all, but we'll do our best to be present at #rc3)
there are good companies with good products. some companies are even better and provide great products. above them, there is @PortSwigger: astonishing support, awesome research capabilities and a product that is simply an industry standard.
@cybergibbons@securelyfitz@wrongbaud@SecurityJon@tautology0@notameadow quite heavy to manage and to prepare on my side (delivey good training IS hard) but from my experience the outcome for the students is way better than a multiday course. jm2c (and I will definitely look at the your site, thank you!)
@cybergibbons@securelyfitz@wrongbaud@SecurityJon@tautology0@notameadow whenever i do some training for companies i can easily reach, i always suggest to split the training in "once every week", to avoid impacting the office productivity and to let students try things (either suggested by me or decided by them) between lessons. 1/2
if your pentest report does not explain to the developers/sysadmins how to improve, if you are not supporting them in every possible way in the process and if you are not ready to learn from them, that is not called "penetration testing", it is called "ego boosting".
here is another one. leading cybersecurity company, supported by well known investors, explaining how web skimmer use "windows.atob" to *decrypt* the payload (this happens multiple times in the blog post, so not a mistake). base64 != encryption.
the moment when you discover that a well known security vendor writes fake blog posts with "advanced technical analysis" that, once you verify, are completely wrong. they just decoded a base64 URL and concluded that the malware exfiltrates info. spoiler: it didn't. rolf.