A friend sent this to me and y'all might enjoy
Chris Partridge
CloudSec manager at that online-bookstore-slash-server-rental company, adjunct professor at RIT, former janitor for r/cybersecurity, and sporadic FOSS contributor. Cat person. Generally cheerful ^_^
Always trying to learn new things, and I'd rather be corrected than be correct. I try to be correct the first time anyway though!
How can I help?
(posts searchable via tootfinder)
Alright I'm speeding up my review of the phishing kits that my project, Phossil, collected. My current estimate is that over the last 5 years I've collected about 1,200 kits. I'm going to review these in two passes - first, just to identify whether they're legit phishing kits (not other malware, webshells, etc.). Later I'll review them for contents - leaked info, trends, targeted companies, etc. I'll be shitposting in this thread with anything funny that I see.
Ah man someone accidentally zipped up their Git repo in a phishing kit and I think their actual personal, professional info is in there. I'm looking at a GitHub and LinkedIn rn and I'm suspicious.
[clickbait] Check out this ONE WEIRD TRICK to make your credentials UNPHISHABLE!
Just add "fuck" ANYWHERE in your password, and when you get phished, the phishing kit will DISCARD your credentials as invalid WITHOUT sending them to the operator!!
Stay safe and don't forget to SMASH that follow button!! 🕵️ 🔒 ✨ 💪 🥰
Hmm. Phishing kits are putting more and more effort into blocking automatic security scanners. This is a relatively short set of evasion rules - I'm seeing some kits with eight *entire files* worth of rules of what IPs, hostnames, user agents, etc. to block.
Did a little explainer on what the request amplification problem is with Mastodon's link previews, what I observed in a small-scale test (traffic amplification of 36,000:1!), what website operators should know, etc. It's here for those curious: https://chris.partridge.tech/2022/request-amplification-in-mastodon/
