Netsec – Telegram
Netsec
7.4K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Are Google Cloud Instances completely backdoored from their initial launch?
I am testing out GCP at the moment and am impressed with their slick interface.I was initially amazed and then terrified to learn that with the click of a single button from within my GCP console... without ever uploading a private key of the public key that I supposedly secured my instance with then I launched... that I could login to an SSH session in my browser and get root within seconds!I know it's because I'm using a google-created debian operating system... but that seems really fucked up imho.I come from Amazon EC2 originally where they were always very strong to remind you that "if you lose your private key, we can't get into the server for you".So it's a little off putting to see that with the click of a button pretty much any google employee could just go looking around my instance?Am I crazy and is this just a really popular feature of their platform which is completely secure?I have to admit, it seems awesome to securely login to an ssh session with the click of a button in a browser... it's just a big too much magic for my liking.I like things simple, that's why I like debian.

Submitted October 05, 2017 at 07:35AM by archlinuxQuestions
via reddit http://ift.tt/2fRYhiu
Hello Redditor Security Pro's :-) I made a website that links to a lot of IT security documentation in one place. We also have a ton of original content. Is it helpful for you? I'd love to know your thoughts before I sink more time and money into it.
http://ift.tt/2xNeUTK

Submitted October 05, 2017 at 09:53AM by paperboy-
via reddit http://ift.tt/2y1BhUD
OpenSSH 7.6 (2017-10-03): SSH protocol version 1 support has been completely removed, after being compile-time disabled by default since OpenSSH 7.0 (2015-08-11)
http://ift.tt/2fOLmxA

Submitted October 05, 2017 at 12:26PM by Mcnst
via reddit http://ift.tt/2fTODvw
NotRuler: Turning Offence into Defence
http://ift.tt/2ylQ1Pn

Submitted October 05, 2017 at 01:41PM by 0xdea
via reddit http://ift.tt/2wzoYLS
How to Extract HTTP Requests From Packet Captures As cURL Commands
http://ift.tt/2yJvP62

Submitted October 05, 2017 at 08:02PM by dentalfoss
via reddit http://ift.tt/2gddCqI
homemade virustotal (opensource)
http://ift.tt/2duqgOe

Submitted October 05, 2017 at 08:33PM by blackout-314
via reddit http://ift.tt/2yrVILw
Russian Hackers Stole NSA Data on U.S. Cyber Defense via Kaspersky Labs - The breach, considered the most serious in years, could enable Russia to evade NSA surveillance and more easily infiltrate U.S. networks
http://ift.tt/2fN5uMZ

Submitted October 05, 2017 at 10:42PM by SuccessfulOperation
via reddit http://ift.tt/2yqXVGX
New to the world of contracting/staff augmentation. What is a good hourly rate to ask for in the US (Midwest specifically)?
I am about to go through a staffing agency for a senior security risk analyst position. They offered $54 an hour as a passing comment in the conversation, so now I know that is the low ball number. I am curious to know what is a good hourly rate for staffing a security position in the Midwest. I don’t have any clue what the market rate is now so I would hate to ask for astronomical number and price myself out of a job.

Submitted October 05, 2017 at 10:22PM by ghostmanure
via reddit http://ift.tt/2fN16NR