Portmantologist.

Joined January 2007
408 Photos and videos
@Jofo@infosec.exchange retweeted
26 Sep 2023
Announcing JA4 Network Fingerprinting! JA4 is a suite of new fingerprinting methods for multiple protocols, detecting everything from entire c2 frameworks, to session hijacking, to reverse SSH shells. blog.foxio.io/ja4-network-fi…

12
178
450
67,699
@Jofo@infosec.exchange retweeted
Goodnight room Goodnight moon Goodnight cow jumping over the moon Goodnight light And the high altitude Chinese spy balloon
27
416
2,135
201,550
@Jofo@infosec.exchange retweeted
My fool godson, William, went down to the basement to get a snack four days ago I told him--every time I tell him--to COUNT the stairs as he goes down. There's only 12. If it goes to 13, come back up and try again. And don't follow the thing singing down there But does he listen?
197
7,703
58,146
@Jofo@infosec.exchange retweeted
the most consequential figures in the tech world are half guys like steve jobs and bill gates and half some guy named ronald who maintains a unix tool called 'runk' which stands for Ronald's Universal Number Kounter and handles all math for every machine on earth
100
9,547
43,727
@Jofo@infosec.exchange retweeted
When we say Kyiv is winning the information war, far too often we only mean information spaces we inhabit. Pulling apart the most obvious RU info op to date (as we did using semantic modelling), very clear it is targeting BRICS, Africa, Asia. Not the West really at all.
408
6,577
16,937
@Jofo@infosec.exchange retweeted
The rage & fear you feel after the Russian invasion are ancient parts of your mind preparing - like clockwork - for a world of conflict. After 10 years of research in the lab & field, it is surreal to feel it unfold in my own mind A 🧵 on what happens & with what effects (1/16)
18
297
1,068
@Jofo@infosec.exchange retweeted
🕸️Inside the Ransomware Economy🕸️ Ryuk is the biggest Saas unicorn u've never heard of. $150M ARR. 3 yrs old. Maybe it’s taboo to learn business strategy from a cybergang. But the ransomware industry-- from supply chain operations to market microstructures-- is truly genius. 👇
20
349
897
I've been away from the internet this week, but this opinion piece is so bad it's worth saying what's already been said by hundreds of others. Security's job is to reduce risk, and elimination is usually impractical, incredibly expensive, or impossible. (1/n)
1
2
Punishing the *victims* of breaches (who are often randomly targeted) will push defenders to hide flaws and breaches, instead of sharing learning opportunities that would lead to the "renaissance" the author is calling for. (3/n)
1
1
In this context, the Ed. note is no better -- punishing infosec leadership for anything but gross incompetence will result in fewer competent leaders willing to put their careers on the line. Practice before you profess, professor. (4/4)
1
@Jofo@infosec.exchange retweeted
16 Nov 2020
Since Cisco PSIRT became unresponsive and the published release 4.22 still doesn't mention any of the vulnerabilities, here are 12 PoCs in 1 gist: gist.github.com/Frycos/8bf5c…
11 Nov 2020
120 days ago, I disclosed 12 vulnerabilities to @Cisco affecting the web interface of Cisco Security Manager. All unauthenticated, almost all directly giving RCE. #cisco #RCE #unauth
8
183
325
@Jofo@infosec.exchange retweeted
I was a very early Facebook user, long before they opened for public registration. Boy, at the time I never would have guessed that they might be the specific tool used to decimate Democracy, local news, and free reporting around the world.
47
67
771
@Jofo@infosec.exchange retweeted
I’ve commented before that Star Trek’s most prescient prediction was communication via memes in ‘Darmok’. So it was only a matter of time before someone started making these:
324
7,020
19,490
Can we put this guy on the 2020 ballot? Is it too late?
Finally a platform to unite us all. Dude wore a tie to make this statement so the city council would know he means business, too. #saucynugs #trash 🤣
1
2
@Jofo@infosec.exchange retweeted
Let’s end the war on drugs. Retweet if you’re in.
70
1,718
2,553
@Jofo@infosec.exchange retweeted
URGENT: Patching CVE-2020-5902 and 5903 should not be postponed over the weekend. Remediate immediately.
3 Jul 2020
The BIG-IP Traffic Management User Interface (TMUI) has a Remote Code Execution vulnerability (CVE-2020-5902) in undisclosed pages. F5 recommends upgrading to a fixed software version to fully mitigate this vulnerability, more details here: go.f5.net/dk3nl #BIGIP #AskF5
20
698
977
My wife is apparently shopping at a different grocery store than I.
2
3
@Jofo@infosec.exchange retweeted
So I was talking with my mom about #DefundThePolice. And she asked me a question: how could what happened to Rayshard Brooks happen, at this moment, in this uprising? How could police keep...doing this? So this is what I said.
515
23,921
61,375
@Jofo@infosec.exchange retweeted
Due to less air pollution the sky is so clear ! I can see the Universal logo !
1,737
247,573
1,167,426