🦜 /dev/random
@blog.rootshell.be@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
"If the enemy leaves a door open, you must rush in." - Sun Tzu
Your feed and you don't want it here? Just
e-mail the birb.
Hack.lu 2023 Wrap-Up
https://blog.rootshell.be/2023/10/19/hack-lu-2023-wrap-up/
Published: October 19, 2023 21:36
[Edit: Sorry for the “bullet-point” style, it was a lot of details to compile in this blog post] We were back at the Alvisse Parc Hotel after a break of four years! In 2022, only a light CTI summit was organized (see my wrap-up), but this year, hack.lu was…
[SANS ISC] macOS: Who’s Behind This Network Connection?
https://blog.rootshell.be/2023/08/26/sans-isc-macos-whos-behind-this-network-connection/
Published: August 26, 2023 10:59
Today, I published the following diary on isc.sans.edu: “macOS: Who’s Behind This Network Connection?“: When you must investigate suspicious behavior or work on an actual incident, you could be asked to determine who’s behind a network connection. From a…
[SANS ISC] Python Malware Using Postgresql for C2 Communications
https://blog.rootshell.be/2023/08/25/sans-isc-python-malware-using-postgresql-for-c2-communications/
Published: August 25, 2023 08:57
Today, I published the following diary on isc.sans.edu: “Python Malware Using Postgresql for C2 Communications“: For modern malware, having access to its C2 (Command and control) is a crucial point. There are many ways to connect to a C2 server using tons…
[SANS ISC] More Exotic Excel Files Dropping AgentTesla
https://blog.rootshell.be/2023/08/23/sans-isc-more-exotic-excel-files-dropping-agenttesla/
Published: August 23, 2023 07:27
Today, I published the following diary on isc.sans.edu: “More Exotic Excel Files Dropping AgentTesla”: Excel is an excellent target for attackers. The Microsoft Office suite is installed on millions of computers, and people trust these files. If we have…
[SANS ISC] Have You Ever Heard of the Fernet Encryption Algorithm?
https://blog.rootshell.be/2023/08/22/sans-isc-have-you-ever-heard-of-the-fernet-encryption-algorithm/
Published: August 22, 2023 08:35
Today, I published the following diary on isc.sans.edu: “Have You Ever Heard of the Fernet Encryption Algorithm?“: In cryptography, there is a gold rule that states to not develop your own algorithm because… it will be probably weak and broken! They are…
[SANS ISC] Quick Malware Triage With Inotify Tools
https://blog.rootshell.be/2023/08/21/sans-isc-quick-malware-triage-with-inotify-tools/
Published: August 21, 2023 06:43
Today, I published the following diary on isc.sans.edu: “Quick Malware Triage With Inotify Tools“: When you handle a lot of malicious files, you must have a process and tools in place to speedup the analysis. It’s impossible to investigate all files and a…
[SANS ISC] From a Zalando Phishing to a RAT
https://blog.rootshell.be/2023/08/18/sans-isc-from-a-zalando-phishing-to-a-rat/
Published: August 18, 2023 06:22
Today, I published the following diary on isc.sans.edu: “From a Zalando Phishing to a RAT“: Phishing remains a lucrative threat. We get daily emails from well-known brands (like DHL, PayPal, Netflix, Microsoft, Dropbox, Apple, etc). Recently, I received a…
[SANS ISC] Show me All Your Windows!
https://blog.rootshell.be/2023/08/11/sans-isc-show-me-all-your-windows/
Published: August 11, 2023 09:02
Today, I published the following diary on isc.sans.edu: “Show me All Your Windows!“: It’s a key point for attackers to implement anti-debugging and anti-analysis techniques. Anti-debugging means the malware will try to detect if it’s being debugged…
[SANS ISC] Are Leaked Credentials Dumps Used by Attackers?
https://blog.rootshell.be/2023/08/04/sans-isc-are-leaked-credentials-dumps-used-by-attackers/
Published: August 4, 2023 07:52
Today, I published the following diary on isc.sans.edu: “Are Leaked Credentials Dumps Used by Attackers?“: Leaked credentials are a common thread for a while. Popular services like “Have I Been Pwned” help everyone know if some emails and passwords have…
[SANS ISC] Do Attackers Pay More Attention to IPv6?
https://blog.rootshell.be/2023/07/29/sans-isc-do-attackers-pay-more-attention-to-ipv6/
Published: July 29, 2023 13:16
Today, I published the following diary on isc.sans.edu: “Do Attackers Pay More Attention to IPv6?“: IPv6 has always been a hot topic! Available for years, many ISP’s deployed IPv6 up to their residential customers. In Belgium, we were for a long time, the…