32 Followers
218 Following
165 Posts
Performance testing Akkoma at infosex.exchange
Only EBNF's manual should start with a section called "Quick Guide to EBNF".

So I've been building a 100% analog polyphonic synthesizer with an unique twist. To use only vacuum tube era technology from the 1930s.

Over 300 neon gas diodes create the sound you hear. Pretty awesome for technology from 100 years ago.

Still a work-in-progress, but I wanted to post a video of it with the innards spread out across the workbench. : }

I call it the "Neon String Machine"

#synthesizers #music #electronics #audio #synthwave

For those of you interested in the recent and ongoing ESXiArgs #ransomware campaign exploiting CVE-2021-21974 in #ESXi servers worldwide, here a detailed PoC write up: https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9
My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability

During a recent engagement, I discovered a machine that is running VMware ESXi 6.7.0. Upon inspecting any known vulnerabilities associated with this version of the software, I identified it may be…

Medium
Here are the 1 month uptime statistics from my personal #Akkoma instance running on a 4GB RAM, 2 core VPS instance.

Memory seems sufficient, disk consumption looks tolerable.

And I can #search my timeline.

(I'm following <250 accounts, mostly from infosec.exchange)
Akkoma

Please enter your username.

Please enter your password.

Thanks! For your security, please enter your 2FA one-time token.

You haven't signed in in a while. We've sent a confirmation code to your phone.

We don't recognize this browser. Please enter the security code we sent to your email.

Is your phone number up to date? Please confirm it by entering the code we just sent.

Did your email change? If not, please call the phone number we emailed to you, then enter the number read to you.

Just to be sure it's you, we've gotten in touch with your mom. Next time you see her, please enter the six-digit code she gives you.

IBM sends you a 14 digit OTP via e-mail. Then helpfully renders a number input with little arrows to help you increment the value to ~500 trillion by clicky-clicky if you are in that kind of mood 🥰
These videos by Fermilab are great (esp. with curious little kids):

https://www.youtube.com/watch?v=CUjt36SD3h8
Why does light slow down in water?

YouTube
From an accessibility perspective toothpaste and ketchup are related. #wisdom
Akkoma

Lord, grant me this not-giving-a-fuck energy

https://youtu.be/fX1kUoeUhPg?t=3171
POWER HOUR 2022 | Defqon.1 Weekend Festival | Sixty minutes of pure insanity

YouTube
Gotta love the irony in these:

Skyhigh Security [aka McAfee, aka Trellix] Secure Web Gateway: Cross-Site Scripting in Single Sign-On Plugin

https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin
Skyhigh Security Secure Web Gateway: Cross-Site Scripting in Single Sign-On Plugin

RedTeam Pentesting identified a vulnerability which allows attackers to craft URLs to any third-party website that result in arbitrary content to be injected into the response when accessed through the Secure Web Gateway. While it is possible to inject arbitrary content types, the primary risk arises from JavaScript code allowing for cross-site scripting.