Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
Дополнение от OpenBLD.net для Chrome, Brave

Лайтовый экстеншн, дополняет сервис, блокируя часть рекламы вшитую в URL'ы корневых доменов.

Чистит ресурсы которые используют рекламные сети без явных принадлежностей к тем или иным поддоменам.

Не имеет внешних, или иных подключений, не собирает данные, идеально дополняет DoH/DoT OpenBLD.net сервис.

Видео, как в принципе помогает жить OpenBLD.net приложено там-же на странице.

Пробуем. Наслаждаемся. Фидбечим:

https://chromewebstore.google.com/detail/openbldnet-blocker/jjpjcmckhkcefefgbgghomdhcbfmklea
Please open Telegram to view this post
VIEW IN TELEGRAM
LogoFAIL - investigates vulnerable image parsing components across the entire UEFI firmware ecosystem and finds all major device manufacturers are impacted on both x86 and ARM-based

Research from the rirst person:

https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/
OpenGPT - open source effort to create a similar experience to OpenAI's GPTs and Assistants API

https://github.com/langchain-ai/opengpts
PyPI: Incident Report: User Account Takeover

reflection: This is not the first time I’ve seen developer accounts taken over, but if you think about it, what will happen. What if they take over, for example, the account of the developer of uBlock..? Where will they go or what will happen with your web requests being called back in it?)) In this context, the manifest v3 reduces such threats to a minimum...

https://blog.pypi.org/posts/2023-12-04-account-takeover/
The penetration testing execution standard consists of seven (7) main sections...

These cover everything related to a penetration test - from the initial communication and reasoning behind a pentest, through the intelligence gathering and threat modeling phases where testers are working behind the scenes in order to get a better understanding of the tested organization, through vulnerability research, exploitation and post exploitation, where the technical security expertise of the testers come to play and combine with the business understanding of the engagement, and finally to the reporting, which captures the entire process, in a manner that makes sense to the customer and provides the most value to it..:

http://www.pentest-standard.org/index.php/Main_Page
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
⚙️ GetMyIP from Sys-Admin

Наконец-то запилил службу, которая возвращает внешний IP по curl или в браузере.

Возможности:
- Может возвращать реальный IP даже если клиент ходит через Cloudflare
- Быстрый. написан на Go
- IP можно смотреть через браузер или curl или wget

Curl: curl https://getmyip.sys-adm.in
Wget: wget -qO- https://getmyip.sys-adm.in
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
📢 OpenBLD.net IPv6 Pre-Release Testing

Last week, last month, this year... I've been meeting and talking to different people, and they all echoed the same sentiment - IPv6 is needed 💯

A few days ago, I got acquainted with VEESP.com, a company that generously provided OpenBLD.net with an incredibly fast server featuring a high-speed Ethernet connection 🛞

Abstract: Usually, I spend some time testing servers, then assign them a secondary role before introducing them to the production environment. However, this time was different...

I was so impressed 😱 with the veesp.com server's speed that it practically flew into production almost immediately... )

I believe this is a great opportunity to start exploring the IPv6 space. In this month or early 2024, I hope we can begin experimenting with IPv6!

If you're ready to participate in the preliminary testing, please let me know through this OpenBLD.net Pre-Release Testing Form. I will reach out to you directly when the time comes, and together we can strive to make this world even better 🌱

P.S. Thanks to veesp.com and everyone who gives incentive to take a step forward 🤝
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
📢 serversAwesome

In OpenBLD.net scoping activities, I created lite Go app - Awesome Servers Inventory Web App, which is a simple web app to manage your servers inventory. Ideal solution for small projects and infrastructures or IT ecosystems.

Features:

- Add new server
- Edit existing server
- Delete existing server
- Copy server IP details to clipboard
- Yaml config file
- Portable sqLite database
- One binary file to run the app

- https://github.com/m0zgen/serversAwesome
Please open Telegram to view this post
VIEW IN TELEGRAM
Dshell

An extensible network forensic analysis framework. Enables rapid development of plugins to support the dissection of network packet captures:

https://github.com/USArmyResearchLab/Dshell