Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

faker

@faker@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I work on stuff ¯\_(ツ)_/¯

Terrible music connoisseur. Security dude. Ex-Pentester.

@faker_ on Twitter.
#infosec #osint #threatintel

227 Followers
239 Following
24 Posts
Joined August 18, 2018
Blog:
https://infosec.rm-it.de/
Location:
Munich, Germany
Open post
faker @faker@infosec.exchange
· 3mo ago
I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from? Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE. Setting the CVSS attack vector to "network" seems overinflating. By that standard any software that somebody built a webapp around is "network" facing. And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled. [1] https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ #FFmpeg #vulnerability #infosec #PixelSmash
jfrog.com
36
6
23
2
Open post
faker @faker@infosec.exchange
· 3mo ago

The #infosec knee jerk reaction to https://bumsrake.de appears to be:
"Wait are they having FUN with vulnerability disclosure? Not on my watch!"

If you want your vulnerability details in a boring format feel free to buy a TI feed. Don't tell researchers who invested a ton of their time how to disclose stuff.

#bumsrake #bumsrakete

infosec.exchange

Infosec Exchange

9
2
1
0
Open post
faker @faker@infosec.exchange
· 4mo ago

@campuscodi@mastodon.social funny how that shared responsibility appears to be 100% on the researchers side. Not a word on improving their own processes.
Talk to anyone who tried to submit findings to MSRC and it's always a tale of nightmares.

9
0
1
0
Open post
faker @faker@infosec.exchange
· 3mo ago

You've got to be kidding me, Lenovo! The stupid Vantage software that is (pretty much) required to install BIOS updates is pushing Ad notifications?!

3
0
1
0
Open post
faker @faker@infosec.exchange
· 5mo ago

It was not part of my threat model when I moved my email address to my own domain that the entire .de TLD could fail

4
0
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago

Foo Fighters

2
1
0
0
Open post
faker @faker@infosec.exchange
· 5mo ago

ffs YouTube, I watched one professionally shot live video of a band. Do not recommend me shitty live videos that fans take out of the crowd with like 40 views.

3
0
1
0
Open post
faker @faker@infosec.exchange
· 5mo ago
Replying to

@bagder@mastodon.social

Use a library (e.g., libcurl for C, requests for Python) instead of calling the system's curl binary.

Yeah! Have you considered changing the curl binary to use libcurl?

4
0
0
0
Open post
faker @faker@infosec.exchange
· 5mo ago

What has #DNSSEC ever done for us?

infosec.exchange

Infosec Exchange

2
2
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago

In case you thought that buying a perpetual license for Microsoft Office on macOS means that you can use it for as long as it runs on your device: haha, nope!

Their certificate to verify the Office 2019 license expires next month, there will not a patch, and it will operate in read-only mode like it's unlicensed. For Office 2019 there will not be a fix at all.

1
0
1
0
Open post
faker @faker@infosec.exchange
· 3mo ago

There is no way to disable the animated Google Doodles on Chromes new tab page.
This is driving me insane, I usually have Chrome and a new tab open on a second screen, now it just constantly shows this soccer animation.
I think this is the final push to move me to another browser.

1
0
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago

Can someone create a MSCI World ex-Musk ETF?
I think there's enough demand for that.

1
0
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago

One of the guys who often typos his email address so their mails end up with me has done it again: He got a job offer, well, I guess I got it now?
Believe it or not, this is the *second* time I got a job offer by accident due to typos in the mail address (I think it was a different guy last time, there are a few people that manage to give out my address as theirs...).

1
0
0
0
Open post
faker @faker@infosec.exchange
· 5mo ago

Say what you will about Java, this is actually pretty cool.

1
1
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago

The stock market has the potential to do the funniest thing of all time on Friday.

0
0
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago

I can't figure out how to mute a hashtag in @IceCubesApp@mastodon.online - that must be possible, right?!

mastodon.online

IceCubesApp (@IceCubesApp@mastodon.online) - Mastodon

0
0
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago

Paypal sent me a (legit) mail that my account is being closed due to inactivity. But it sent that mail to an address that is no longer attached to my account.
And trying a password reset with that email address paypal says it's not registered?!

0
0
0
0
Open post
faker @faker@infosec.exchange
· 5mo ago

@leonido@chaos.social gerade https://www.tagesschau.de/wirtschaft/digitales/social-media-europa-alternative-100.html gelesen: soweit ich weiss ist chaos.social nicht vom CCC betrieben oder der "offizielle" CCC Mastodon Server, sondern ein community Projekt (natürlich sehr Chaos-nah) - aber eben ein eigener Verein.

Kann ein europäisches Netzwerk die Social-Media-Riesen schlagen?
tagesschau.de

Kann ein europäisches Netzwerk die Social-Media-Riesen schlagen?

Falschinformationen, Suchtgefahr, mangelnder Datenschutz: Die Kritik an sozialen Netzwerken ist groß. Es gibt zwar Alternativen - aber haben diese eine Chance? Ein neues Netzwerk aus Schweden geht andere Wege. Von Paula Protzen.

0
2
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago
Trying to figure out how to dispose expired RSA tokens, came across a german help page by RSA in which they mis-translate token several times to pretty much "coins" :blobcatfacepalm:
0
0
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago
I migrated recently to KeePassXC, but they are actively disabling macOS Handoff - you cannot copy a password on your Mac and paste it on iOS. They pretty much say its because of security and just sync all your passwords to your iOS instead if you want that [1]. I really don't want to do that. This is super annoying. Anyone use an alternative that allows this (100% local running)? [1] https://github.com/keepassxreboot/keepassxc/issues/7279
GitHub

Issue · keepassxreboot/keepassxc

KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”. - Issue · keepassxreboot/keepassxc

0
3
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago
✅ Last day at current job done 🫡
0
0
0
0
Open post
faker @faker@infosec.exchange
· 2w ago
Replying to
@gwizit@infosec.exchange nonsense. Your bank uses HTTPS, nobody sees anything. It's not the 2000s anymore. https://www.hacklore.org
hacklore.org
0
0
0
0
Open post
faker @faker@infosec.exchange
· 3mo ago
Replying to
@studiolo_rb@mastodon.online from what I've read it's not really made for macOS, they say use something like KeePassXC in their forums all the time
0
1
0
0
Open post
faker @faker@infosec.exchange
· 4mo ago
Replying to
@xeniac@troet.cafe @bagder@mastodon.social it depends on how you count. Mobile iOS and Android applications often use sqlite. If you count any database file as an installation it wins (IMO). If you count every sqlite client library it might still (since devs might still include a library and not use the system provided ones).
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:59:30 UTC