Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Chris Partridge

@tweedge@cybersecurity.theater
mastodon 4.7.3
  • Open on cybersecurity.theater

CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^

Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though!

How can I help?

(posts searchable via tootfinder)

0 Followers
0 Following
7 Posts
Joined April 28, 2022
Blogging:
https://chris.partridge.tech
GitHub:
https://github.com/tweedge
Proofs:
https://tweedge.proven.lol
Pronouns:
he/him
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 32mo ago

A friend sent this to me and y'all might enjoy

1891
51
998
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 3mo ago
I found a super old file on my NAS back from when I was typosquatting NLTK (then in the top 250 Python packages!) with a package named NTLK. My inspiration was simple: I'd made that typo three times in a row, and so I made a package which would fail to install + give people the correct install command + send a ping telling me someone tried to install NTLK. 7 months and 28k installs later, I got a bunch of data that I forgot to write up 😅 but better late then never: https://chris.partridge.tech/2026/typosquatting-nltk-on-pypi
Seven months of watching people typo NLTK on PyPI | tweedge's blog
Chris Partridge

Seven months of watching people typo NLTK on PyPI | tweedge's blog

A long time ago, I uploaded a benign typosquatting package to PyPI to measure how often people accidentally type 'ntlk' instead of 'nltk'. Over seven months,...

5
1
3
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 6mo ago

Alright I'm speeding up my review of the phishing kits that my project, Phossil, collected. My current estimate is that over the last 5 years I've collected about 1,200 kits. I'm going to review these in two passes - first, just to identify whether they're legit phishing kits (not other malware, webshells, etc.). Later I'll review them for contents - leaked info, trends, targeted companies, etc. I'll be shitposting in this thread with anything funny that I see.

14
1
9
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 6mo ago

Ah man someone accidentally zipped up their Git repo in a phishing kit and I think their actual personal, professional info is in there. I'm looking at a GitHub and LinkedIn rn and I'm suspicious.

6
1
0
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 6mo ago

[clickbait] Check out this ONE WEIRD TRICK to make your credentials UNPHISHABLE!

Just add "fuck" ANYWHERE in your password, and when you get phished, the phishing kit will DISCARD your credentials as invalid WITHOUT sending them to the operator!!

Stay safe and don't forget to SMASH that follow button!! 🕵️ 🔒 ✨ 💪 🥰

6
0
4
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 6mo ago

Hmm. Phishing kits are putting more and more effort into blocking automatic security scanners. This is a relatively short set of evasion rules - I'm seeing some kits with eight *entire files* worth of rules of what IPs, hostnames, user agents, etc. to block.

2
0
0
0
Open post
Chris Partridge @tweedge@cybersecurity.theater
· 46mo ago

Did a little explainer on what the request amplification problem is with Mastodon's link previews, what I observed in a small-scale test (traffic amplification of 36,000:1!), what website operators should know, etc. It's here for those curious: https://chris.partridge.tech/2022/request-amplification-in-mastodon/

Request Amplification in Mastodon | tweedge's blog
Chris Partridge

Request Amplification in Mastodon | tweedge's blog

Mastodon is a great replacement for Twitter, but who knew it was also a replacement for LOIC too? I'm joking - but an observed traffic amplification factor o...

2
1
2
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:32:06 UTC