Тёмный
Black Hills Information Security
Black Hills Information Security
Black Hills Information Security
Подписаться
At Black Hills Information Security we were brand new to info sec once too! With that in mind we want to help everyone become more educated in this exciting field that's changing so quickly! We offer webcasts free to anyone who's interested, a blog on our website, and with our pen testing we're hoping to better educate our customers so they can always be improving their environments. We think it's summed up pretty brilliantly in this quote from Richard Feynman: “Study hard what interests you the most in the most undisciplined, irreverent and original manner possible.”
Комментарии
@logicbypass
@logicbypass Час назад
Awesome thx
@maxrodriguez643
@maxrodriguez643 2 часа назад
Like, you get infected through discord? What if Discord is in a flatpak sandbox?
@hs-learn2581
@hs-learn2581 3 часа назад
Great presentation by Jack, appreciated your humor and demo's
@LifeLess1999
@LifeLess1999 22 часа назад
gay
@novianindy887
@novianindy887 23 часа назад
is it detected by antivirus at all?
@BlackHillsInformationSecurity
@BlackHillsInformationSecurity День назад
✉ MailFail Extension (Firefox) and other resources m.ail.fail/ 🔗 Jack's list of DKIM selectors - github.com/ACK-J/MailFail/blob/main/DKIM_Selectors.txt - 🔗 Download the extension - addons.mozilla.org/en-US/firefox/addon/mailfail/ - 🔗 github repository - github.com/ACK-J/MailFail/ - 🔗 Reconstruct private keys from the two prime numbers - gist.github.com/ACK-J/487d0de5737458d953ca818a0645b09b - 🔗 Send DKIM signed emails script with a private key - gist.github.com/ACK-J/76585af46375641ec841cb6b77d345c3 - 🔗 Here's a bonus that wasn't in the presentation - Python script that takes in a list of domains and checks them for DMARC misconfigurations - gist.github.com/ACK-J/8a189bafbb54e00fb1b3f3e22dcd81c9 - 🛝 Webcast Slides - www.blackhillsinfosec.com/wp-content/uploads/2024/06/SLIDES_BHIS_MAILFAIL.pdf /// 🔗 Register for webcasts, summits, and workshops - blackhillsinfosec.zoom.us/ze/hub/stadium
@FieranMason-Blakley
@FieranMason-Blakley День назад
Jack did great -- having someone technical give the webinar is fantastic. We got a good (review for me) technical explanation of SPF/DKIM/DMARC and why they really aren't that great. I'll stay tuned for more on the strength of this presentation --- the inclusion of misuse cases was one of the strongest points.
@piojo003
@piojo003 День назад
awesome , thanks
@bulcub
@bulcub День назад
would be nice if you had chapter markers! and had use microsoft server to demonstrate instead of slides.
@bakedmuffinman87
@bakedmuffinman87 День назад
32:38 I believe you were talking about codespaces
@LimitlessEI
@LimitlessEI 2 дня назад
taking my net+ here soon any good places to study? preferably free other than professor messer
@digitalpilotnm
@digitalpilotnm 2 дня назад
There are still only 13 root servers. The reason for the limit has to do with the UDP packet size. Some roots do allow for an Anycast instance, but that instance is still the same IP as the primary root server that is being anycast’d. Speaking as a person that once ran L-Root for 3+ years
@aagetengesdal6102
@aagetengesdal6102 2 дня назад
So, an interesting discussion all around concerning the biometrics topic. I found that it was missing some context in the discussion however, where no one mentioned that there are already other national protective laws under HIPAA; and there really needs to be correlation related to how that applies as well, and where the cross-over might exist. The CO state law takes inclusive steps to couple biometrics under state privacy laws (in the absence of an overall, cohesive national set), but I'm curious where the thought was that gaps existed in HIPAA that needed this type of additional regulation. Regardless of knowing about this law, this concept has led to some interesting group discussions lately. Are hosted data centers now, or going to be, responsible for providing HIPAA related audit data, in addition to SOC 1/2, as part of the reporting to their clients? Biometrics are a huge part of their security controls and they have lots of client data.
@ds6476
@ds6476 3 дня назад
Man is sending full on helldivers 2 extraction codes 😂
@xCheddarB0b42x
@xCheddarB0b42x 3 дня назад
Shecky bringing the real talk at 23:00 great points sir!
@djninjanz
@djninjanz 5 дней назад
AONE ❤
@dustinzunck
@dustinzunck 6 дней назад
That is not at all how it’s being used. Yes, it is Drone as First Response. But just as they would when physically on scene they can assess. And engage if the presented situation called for engagement and or simply be able to surveil and on going situation and provide live updates for those headed and to arriving on scene.
@pamazgostv
@pamazgostv 7 дней назад
fkn banged my head trying to setup the proxy inside the emulator's settings. It worked super easy via adb. TY so much!
@mickeyreed9628
@mickeyreed9628 7 дней назад
Is it going to help them get the right address ? Before they kick in the wrong door and shoot an innocent unarmed citizen ?
@Kevin_Agapao
@Kevin_Agapao 7 дней назад
Why don't hackers do the right thing and delete peoples loans and mortgages
@h4gg497
@h4gg497 7 дней назад
The DNS and BIND book should be required reading for anyone working in IT. The amount of people that only have surface level understanding of DNS is astounding.
@a-vd9fj
@a-vd9fj 8 дней назад
Windows is malware, stop using it.
@jacksonfunksworth3822
@jacksonfunksworth3822 8 дней назад
ACAB
@schoolguy10
@schoolguy10 8 дней назад
Already in use, mostly for narcotic surveillance and prostitution stings as the test templates
@MRkWl69
@MRkWl69 8 дней назад
Not gonna lie I totally agree with his statement 😂
@bakedmuffinman87
@bakedmuffinman87 8 дней назад
can someone post the article by Daniel Meissler referenced at 3:20
@Danny1o1272
@Danny1o1272 9 дней назад
Its such a evasive move im sure the a community will find a way to disable it
@hvacmisadventures
@hvacmisadventures 8 дней назад
Yeah start using Linux lol
@iam_epa
@iam_epa 9 дней назад
finalyyyyy thanks alot
@franko3p
@franko3p 9 дней назад
This is gold!
@jmr
@jmr 10 дней назад
I used my Flipper to find all the secret codes for my TV. It's been helpful because my TV needs an occasional hard reboot which I can do using an undocumented ir command. It was also awesome when I was pranking my nieces and nephews.
@xCheddarB0b42x
@xCheddarB0b42x 10 дней назад
Thank you for this Serena and BHIS team. :D
@EricWalls-cyber
@EricWalls-cyber 10 дней назад
42
@pyhoff
@pyhoff 10 дней назад
Ethics, company have none. It’s all about money. Disclose after 90’days of just like Google does period. Then sue the vendor aka MS for dragging their feet.
@fredrikzels2637
@fredrikzels2637 10 дней назад
Love these talks!! Thx for taking your time and doing them.
@animelover5849
@animelover5849 12 дней назад
Sir tornet is safe? pip install tornet?
@purrrfectnarrative5201
@purrrfectnarrative5201 12 дней назад
RU-vid why have you been hiding this channel from me? Great video!😻
@BlackHillsInformationSecurity
@BlackHillsInformationSecurity 11 дней назад
We're glad you found us!
@anderjones1547
@anderjones1547 12 дней назад
Hii Serena, Do you know any book that goes deep into this or atleast networkig?
@xCheddarB0b42x
@xCheddarB0b42x 10 дней назад
May I recommend The TCP IP Guide by Kozierok? That is a comprehensive guide from no starch press.
@S_I_P_R_N_E_T
@S_I_P_R_N_E_T 13 дней назад
Thinking about AWS certs...needed to brush my DNS knowledge. Keep it up.
@francisfrancis1153
@francisfrancis1153 14 дней назад
Nice one. Is Bryan Strand a brother to John Strand?
@BlackHillsInformationSecurity
@BlackHillsInformationSecurity 11 дней назад
The rumors are true.
@jmr
@jmr 15 дней назад
To me the biggest problem trying to use direct IP communications are the shared IP addresses. My setup is fairly typical so it's a good example. I have multiple web sites on my primary server and multiple servers behind my IP addresses. Without DNS information in the header the traffic can't be routed properly. In addition I use Cloudflare just like nearly 20% of the web. Direct incoming traffic would just hit my firewall and get "Unable to connect". Cloudflare also uses shared IP addresses unless you want to give them a kidney each and every month. If you try an IP you get from querying my DNS records you get "Error 1003" "Direct IP access not allowed". All that is before we even talk about residential configurations that are often CGNAT. I think DNS is here to stay for a while.
@nobletrout
@nobletrout 15 дней назад
the secret is to screenshot the solution before playing. I wish someone had explained this before on the RSAC speech. Because I had no idea how to share the deck on zoom with other people. dang it people. it's always the simple things.
@nobletrout
@nobletrout 15 дней назад
I like this one more, this webbrowser is up to date. unlike the RSAC one.
@futureferrarimusic
@futureferrarimusic 16 дней назад
Great summary, i'm learning so much about cyber sec!
@RainbowDjinn
@RainbowDjinn 16 дней назад
Thanksss so much!! Helped me a lot cause default way of configuring proxy inside android wasan´t working.
@GuitarSorcery
@GuitarSorcery 17 дней назад
Is Recall any worse than an RCE though? It has an “ultimate use after free vuln” vibe, but from a security perspective, is it really worse? Computers are vulnerable, we might as well get to use the AI.
@philipa2025
@philipa2025 17 дней назад
I think Just a Clever Simulation is exactly right at 28:45ish about Windows Recall. People won't really care until they are personally confronted with something they don't like. It could be a hacker blackmailing them, a family member or friend using your computer and seeing something you didn't want them to see, or SUPER pushy advertising calling out your exact behavior along the lines of "You looked at that potato twice today. Are you sure you don't want to buy it?"
@mindaugasdailidonis
@mindaugasdailidonis 17 дней назад
I took the Cyber Deception course few years ago and can highly recommend it! I did pay what I could at the time, and then got a few additional courses from Antisyphon that were excellent!
@jmr
@jmr 17 дней назад
Love the puppy dog. P.S. People have been editing their genes at home for at least a couple years.
@Bacwood6
@Bacwood6 18 дней назад
That was funny!!
@cyberdronefpv
@cyberdronefpv 19 дней назад
If you know you know.