Posts

This profile is from a federated server and may be incomplete. Browse more on the original instance.

da_667, to random

I love it so much.

da_667, to random

it feels so good to be able to run a bat file that just deletes defender AV.

da_667,

you open the door, you pull out the flechette cannon, you blow off chunks of Windows 11, you close the door.

0x00string,

@da_667 they keep growing back its regenerating

da_667, to random

hey hey, people. Happy monday.

da_667,

@eater yup. XCOM2:War of the Chosen has a feature called the photobooth, where you can put your soldiers in ridiculous ass poses, and take pictures from different points on the map. Huge variety of poster fonts, image effects, etc.

eater,
@eater@cijber.social avatar

@da_667 do they then show up in game as posters again? :o that sounds very neat

da_667, to random

I don't even understand why the fuck windows update even has error codes when every single fucking one of them always has the same advice from microsoft: Delete SoftwareDistribution, run the troublshooter which never works, run dism /cleanupimage /restorehealth or use the windows 11 installer tool to do a clean install. Don't even bother giving me the error code.

Then you go to the event viewer for windows update logs and its like "the update failed to download" and you ponder the pros of lobotomy via soup spoon.

Rairii,

@da_667 you're searching in the wrong place

first you pass it to certutil /error
then you start throwing windows binaries into your favourite reversing tool

da_667, to random
da_667, to random

that one kid screeching in the store that they didn't get what they want, while you quietly wish you had a cattle prod for such moments.

da_667,

in deus ex, you could tase the children. that game was ahead in so many ways.

0x00string,

@da_667 hahahahhaa yeah

da_667, to random

happy concussion sport day.

da_667,

happy "we can afford an ad that is probably priced in the millions of dollars for a few seconds of airtime, but we have to cut 5-15% of our staff" day

da_667,

happy "we always have money to dedicate to this worthless fucking stadium that charges 20 dollars for a beer, but fuck if we have money to maintain infrastructure, schools, feed the children, or literally any-fucking-thing else that returns massive dividends" day

da_667, to random

I let me windows box run again last night after the massive addition to my HOSTS file from this repo:

https://gist.github.com/niutech/1f1c1518ce0eba7e8d429c812d39493d

and also, a whole shit ton of system modifications from privacy.sexy...

I had a grand total of 56kb of traffic recorded overnight

-CRL pickup from microsoft
-ICMPv6 router advertisements
-DHCP
-NTP

That was it. That was all of it. Damn its good.

da_667,

@gsuberland unbelievably, it does.

I ran into a shit ton of issues reaching windows update last night, but it turns out that was likely because mitmproxy was grabbing those connections and the OS didn't appreciate that. After I disabled the proxy, it worked fine.

gsuberland,
@gsuberland@chaos.social avatar

@da_667 sweeeet. might trial blocking these on our main pfsense router at home, just to see if it breaks anything. if not, happy days.

da_667, to random

years of proprietary SSLVPNs and weird connection rituals only to find out that the OS under the hood is like, CentOS 5 or some shit.

da_667, to random

I made some slight changes to my pfblocker config on the firewall. some of these domains just did not want to co-operate with being put in the hosts file.absolutely refused to null route www.msn.com and config.msedge.skype.com so I null routed them on the DNS server. Fuck you: the revengeance

gsuberland,
@gsuberland@chaos.social avatar

@da_667 yeah I will probably be importing your entire list into pfsense because all of this stuff is endlessly annoying

da_667, to random

So I tried keeping ms teams and dropbox installed on my malware box to make it look a little "lived in", and I fucking can't lads. Those two apps alone generated like 180MB of traffic in the span of moments after the machine booted. I didn't create a dropbox or teams account for either app on the system and they were just shitting traffic EVERYWHERE.

da_667,

SAVE SOME TRAFFIC FOR THE MALWARE YOU SHITTERS.

da_667,

Here is a paste of my host file entries, and what I believe these entries affect.

https://pastebin.com/r88TtG90

My goals and yours may be entirely different. I'm looking to make my system as silent as moonlight so that I may more closely monitor malware on it.

da_667, to random

wonderful. Got mitmproxy and tshark working as services on my windows analysis box. I'm able to stop the services, grab the pcaps, keylog file, open it up in wireshark elsewhere, and apply the keylogfile to decrypt SSL sessions seamlessly.

Feelsgoodman

da_667,

ms teams is installed on this box. I haven't created any accounts. its sitting there in the background, and it is SO FUCKING CHATTY.

GODDAMN MICROSOFT. CUT IT OUT.

da_667,

Next steps for KAIDACORP:

-Use fog to grab a new Windows baseline image. I'll worry about populating this thing with data later.
-LIVE MALWARE TESTING
-Set up service automation on the Linux malware box and test it.
-After testing, rebaseline the Linux box as well.
-LIVE MALWARE TESTING

da_667, to random

discovered a new reason to hate snort 2.9 today. Maybe I'll nerd out over it on the Emerging Threats community site.

da_667,

@eater base64 is just so goddamn cursed.

eater,
@eater@cijber.social avatar

@da_667 especially if you only need 64 different characters (which is half of ascii, fair) it's an amazingly fun thing

da_667, to random

in addition to starting MITMproxy on startup, I'm looking to start up tshark. Currently working on perfecting my tcpdump filter to eliminate a bunch of annoying ass noise.

da_667,

@epixoip no worries, I didn't mean to come off as hostile. Thank you for clarifying and thanks again for your time

epixoip,

@da_667 all good brother

da_667, to random
avuko,

@da_667

“We have no evidence of this vulnerability being exploited in the wild as it was found during our internal review and testing of our code.”

Dear Ivanti,

The fact your customers aren’t allowed to look into your systems, actively reduces the possibility to create the “evidence” you say you don’t have.

I’m a strong proponent of Hanlon’s razor, but the likes of you are making it very effin hard…

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • ngwrru68w68
  • InstantRegret
  • thenastyranch
  • magazineikmin
  • GTA5RPClips
  • rosin
  • osvaldo12
  • tacticalgear
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • JUstTest
  • modclub
  • everett
  • provamag3
  • cubers
  • cisconetworking
  • ethstaker
  • Durango
  • mdbf
  • anitta
  • megavids
  • normalnudes
  • tester
  • lostlight
  • All magazines