Spyke

Replies

dach

Comment on

Unerwünschte Zivilcourage bei Hackern?

"Nicht jeder Computerbegeisterte kann sich selbst zum Sicherheitsforscher ernennen und damit einen Freibrief zum Hacking bekommen", so CDU-Politiker Günter Krings auf Anfrage der ARD-Rechtsredaktion.

Ich möchte kotzen. Herr Krings hat nichts verstanden. Es geht doch nicht darum, wer mit welcher Expertise Sicherheitslücken findet. Es geht darum, damit verantwortungsvoll umzugehen und Responsible Disclosure zu betreiben, damit die Lücke geschlossen werden kann und Schäden für eine Vielzahl von Menschen und ggf. das Unternehmen abgewendet werden können...

Comment on

My bikes been ruined

That's rough, dude; my sympathies. You're definitely not alone though: Recently, both wheels were stolen from my bike and since there were no cameras or witnesses, the chance of police finding the perpetrator(s) is slim to none. Worth of the stolen parts is ~150 €, cost to replace them around ~400 €...

linux

Comment on

Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet

Reply in thread

This link should be working.

Quoting from the OP tweet:

* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
* Devs are still arguing about whether or not some of the issues have a security impact.

I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.

piracy

Comment on

Are these two rar files malware? (virustotal results)

TLDR: I can't say for 100% sure, but there are multiple reasons to believe that this is malware.

Long version: I'm seeing multiple suspicious things here.

  • The IPs being connected to are part of some hoster and have some abuse reports: https://www.abuseipdb.com/check-block/217.20.58.98/29

  • The domain being resolved is qcloud[.]com, which belongs to Tencent Cloud and definitely not Microsoft.

  • Other domains in memory like counter-strike[.]com[.]ua are very new and definitely sound fishy.

  • A standalone version of 7zip is being run and extracts the created rar file with the password "infected". Real alarm bells here.

  • A lot of the registry actions look like anti-debugging, which does not sound like something an Illustrator Plugin would do.

Comment on

*Permanently Deleted*

Reply in thread

I am a Patreon supporter of Jim Browning. Incidentally, I got this email today:

At last, I can reveal something I've been working on in conjunction with a major UK cellphone operator, O2. Meet dAIsy. Daisy is an AI bot who answers scam phone calls. Thanks to the mobile operator who can fingerprint scam phone calls via the calling pattern, source, sequence of calls and other markers, scam calls are being diverted to an AI bot who has been trained to keep the scammers on the phone as long as possible.

This is my recording of a Zoom interview I had today with Channel 5 news in the UK where you can see dAIsy in action.

I will continue to train dAIsy with real scam phone calls. When we perfect her, the aim is to work with other cell and landline operators to divert scam calls to thousands of instances of dAIsy. [...]

So you're not wrong about this being a project of some anti-scam YouTuber, you just guessed the wrong one. ^^