
Alberto
@__ar0d__
Infosec | Tech | Entrepreneur 👋. badsectorlabs.com | ludus.cloud
ID: 1160241353487474690
https://ar-infosec.com 10-08-2019 17:27:49
703 Tweet
443 Followers
1,1K Following






D'oh, so you leaked your AWS credentials 🤦♂️ Does it matter 𝐰𝐡𝐞𝐫𝐞? It turns out there's a HUGE difference in how fast attackers will find them. Idan Ben Ari deployed canary tokens (fake AWS credentials) using Thinkst Canary to a number of different locations and analyzed:


The Record From Recorded Future News tl;dr it's cool and badass when your car parses your conversations to determine vehicle passengers, passengers name, locations, traveling speed, objects of interest around them, road conditions, traffic, etc. then sells it to advertisers and data collection groups

I just released a tailscale deploy/remove role for Bad Sector Labs Ludus. Thank you to Chihuahua in charge NotMe for all the testing. Please let me know if you encounter any bugs or if you have any ideas for improvement. Feel free to submit a PR. github.com/NocteDefensor/… #Ludus #Tailscale

MSSQL domain privesc (Scott Sutherland), .mobi whois takeover (watchTowr), LLM CTF (Bishop Fox), mac filesystem 🪄 (Gergely Kalman), and more! blog.badsectorlabs.com/last-week-in-s…







WinRMS relay (Aurélien Chalot), plaintext Zip attacks (pfiatde), SQL Server Crypto deep dive (Adam Chester 🏴☠️), and more! blog.badsectorlabs.com/last-week-in-s…

