Hey @h2hconference, on your CFP page you have 2 deadlines - Oct 1 for proposals and Oct 17 for slides. Does that mean that you expect both proposals and slides before you make the decision about acceptance? Or only those who've received an acceptance note need to submit slides?
Thing I learned today: Decrypting arbitrary TLS sessions
on Windows (for code utilizing schannel):
https://t.co/WU6u3aRPru
Great explanation, and very easy to use code, by @webpentest
@alterm4nn@alexx_mikh @annita_oreo @andrey_sitnik Понятно что почти всегда можно извернуться (обычно с потерей и в деньгах и во времени и в удобстве). Алсо, возвращаясь к исходной постановке вопроса - где ты щас валютный кэш найдешь?)
@alterm4nn@alexx_mikh @annita_oreo @andrey_sitnik Далеко не везде можно заплатить кешем есличо) Попробуй арендовать в европе машину за кеш, в большинстве мест это просто невозможно.
@SVSoldatov@rostov_prizrak Не трудитесь, знаю я такие "объяснения". Нацисты, кстати, уже пытались такое объяснять, только мир им в конце концов объяснил другое.
@SVSoldatov@rostov_prizrak "Сегодня ты играешь джаз, а завтра родину продашь". Ксенофобия гораздо ближе к насилию, чем нестандартные сексуальные предпочтения.
Some time ago I had a task where I needed to extract TLS session keys from win apps that use schannel (i.e. mstsc). Did some reversing and ended up creating a frida script that hooks key creation in lsass. Feedback welcome! https://t.co/Knrt566M5i
@SVSoldatov "дальше - раскрутит" - если повезет =D По факту далеко не все и далеко не всегда "раскручивают". А еще можно специально шуметь не там, где реальная движуха, тогда пока будут "раскручивать" не с того конца, все уже закончится)
@exploitph@_nwodtuhs I have to say, for the work I do most of the time, your research is more important. As definitely more fun to repro and study! That said, the lifespan of the bug will be limited for most orgs due to updates, and log4j vuln in internal nets is likely to stay literally forever.
@a66ot @InfoSecDJ @Hacker0x01@Bugcrowd I'm perfectly aware of that, but ppl from MC were like: google your name name => see the org name => nah fuck it we have a reason to not communicate and not lose face.
So I understand their though process, but this doesn't make their decisions any less dumb
@a66ot @InfoSecDJ @Hacker0x01@Bugcrowd Have any business with sanctioned ppl or orgs = suffer penalties and fines from govt, and also bad PR among potential clients. That is how sanctions are designed to work - 1% is legally prohibited from having business, other 99% just fear and don't want to bother.
@a66ot Sincerely though, how do people use an 0day in an engagement without disclosing? What will go in the report as an entry vector? Or are 'private pentesters' just another name for criminals? So many questions.