Brian Anderson (He/Him)

1,099 Followers
448 Following
2.6K Posts

InfoSec Pro speaking to just plain folks. Opinions are mine, or someone else's, but definitely not my employer's... He/him

“If I’m not imagined in your future, do I exist in it?”-Hodari Davis

MeInfoSec Pro speaking to just plain folks. Opinions are mine, or someone else's, but definitely not my employer's... He/him
Hashtags#InfoSec #InformationSecurity #BlackMastodon

In today's episode of "Can It Run Doom": DNS fucking TXT records.

Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

blog: https://blog.rice.is/post/doom-over-dns/

repo: https://github.com/resumex/doom-over-dns

Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

It was always DNS.

#infosec #dns #doom #itisalwaysdns

Dawn Staley for President.

Just so we're clear -- the law Israel just passed mandating death by hanging for Palestinians is apartheid.

It. Is. Apartheid.

Israel does not punish Israelis who kill Palestinians. Instead, Israel has illegally detained more than 10,000 Palestinians, including 1000 children, without charge or conviction. These are hostages held without access to counsel in concentration camps.

This. Is. Apartheid. Any politician or journalist who cannot acknowledge that is complicit. Period.

Anthropic Issues Copyright Takedown Requests To Remove 8,000+ Copies of Claude Code Source Code - Slashdot

Anthropic is using copyright takedown notices to try to contain an accidental leak of the underlying instructions for its Claude Code AI agent. According to the Wall Street Journal, "Anthropic representatives had used a copyright takedown request to force the removal of more than 8,000 copies and ad...

YALL.
At 545am, a so-called adult with a baby tried to square up with a 75 year old man, because he was “too close” in the pre-check security line in an airport.

Bro, you’re in the fastest moving line of an already crowded airport, where 1/2 the employees are helping you for free:
1. Getting yoinked out of line by LEO will not improve your chances of catching your flight.
2. Grandpa had “I discovered gummies after Vietnam, but don’t think I won’t give you a two-piece and a side of grief” energy.
3. Your baby is crying.
4. Five. Forty. Five. In the dark.

YALL.
#WTF

#PSA: posting photos and videos of your kids online ensures they'll never be able to meaningfully opt out of privacy invasion.

80% of children have an online presence by age two, with parents sharing an average of 1,500 images before their fifth birthday. —2017, Northumbria University

By the age of 13, children have had an average of 1,300 photos and videos of themselves posted to social media by their parents. —2018, UK Children's Commissioner

#Privacy #DataPrivacy

@VeroniqueB99 @stuartl if they were really that afraid of that, would they just toss it wantonly in an open 20 gallon trash bin while wearing no protective gear (chemical or otherwise) whatsoever?

Nah, next time they toss my slightly-too-normal-size toothpaste tube or hand lotion, I’m going to holler out “NOooo” and then duck and cover like a 1950’s era “kids can survive a nuclear bomb by hiding under the desk” film.

If we’re doing theatre, let’s really do it.

@alexblock rabbits help a whole bunch!