CyberGingey 🤖

807 Followers
124 Following
782 Posts

Internet explorer | Blue Team | SOC Engineer

Talking Infosec, breaches, threats, IOCs, and a lot of the time just talking about random crap!

For direct messages, use Keybase. Link above/below bio.

Githubhttps://github.com/Cybergingey
Keybasehttps://cybergingey.keybase.pub/Proofs/mastodon.html
Maybe 2025 is the year to get around to those projects/ideas we said we would do 3 years ago.... then 2 years ago... then a year ago... and now we try again by saying next year 🤣
Trying to Christmas shop for things for family, but keep findings things I like for myself......
Or another fun one from the Blachat NOC talk, running a pentest on one of your customers networks from the conference wifi 🤣 .....also while in a pentest training course 🤣
VERY bold statement Microsoft!
Not sure I believe in 100% coverage across detection and prevention....
Just listened to the blackhat europe NOC talk......People pay thousands to come to Blackhat..... and decide it's a good idea to just spend their time watching pornhub and onlyfans on the conference wifi 🤣🤣🤣🤣

But! You could make people hit the remote lock limit and then the feature is void.

So if you knew the targeted person's phone number, hit the limit....steal the phone and the feature won't work

Ok there is a request limit it seems though, so that's good!

And had captcha depending on where I tried it from

Just me who finds this really strange and has a lack of verification?

Android remote lock device feature, when enabled allows you to lock the device remotely with just the phone number.......BUT, you don't need to be logged into Google find my device, ANYONE can input a phone number.....

Note that I am not signed in for the below lock request.

I feel you should have to be signed into an account that has the associated phone number? Or just signed in to any account (so there is a record of who sent the lock request?)

I get that it's for if you get it stolen and need to lock it quickly, but surely someone can just spam this request to be very annoying to random people 🤣

Websites blocking scripts from fetching content.... now my new favourite thing is Selenium :)
You did this @mttaggart 😋