@joohoi

8 Followers
90 Following
33 Posts
Hacks for beer. FOSS, infosec and privacy. Chaotic good. Managing a red team at @visma

Check out the blazing fast web fuzzer I wrote in Go! https://github.com/ffuf/ffuf

It enables you to work with many things that typical directory busters don’t handle, for example fuzzing HTTP headers, matching or filtering by regex matches against response body

GitHub - ffuf/ffuf: Fast web fuzzer written in Go

Fast web fuzzer written in Go. Contribute to ffuf/ffuf development by creating an account on GitHub.

GitHub

I just pushed a #Certbot authentication hook for acme-dns for securing the ACME DNS challenge validation with #letsencrypt

It’s available at https://github.com/joohoi/acme-dns-certbot/

joohoi/acme-dns-certbot

acme-dns-certbot - Certbot client hook for acme-dns

Now that Let’s Encrypt offers wildcard certificates, the DNS challenge method is seeing more use than previously.

Remember that storing DNS zone credentials used for the automation directly on the boxes makes things get ugly really fast if one of those boxes gets compromized!

Some time ago I wrote a blog post going through different ways and levels to mitigate the issue. Readers are expected to have some basic knowledge of DNS:

https://www.eff.org/deeplinks/2018/02/technical-deep-dive-securing-automation-acme-dns-challenge-validation

A Technical Deep Dive: Securing the Automation of ACME DNS Challenge Validation

Earlier this month, Let's Encrypt (the free, automated, open Certificate Authority EFF helped launch two years ago) passed a huge milestone: issuing over 50 million active certificates. And that number is just going to keep growing, because in a few weeks Let's Encrypt will also start issuing “...

Electronic Frontier Foundation
@turumore @jaranta @make @aninapartanen Kuulostaa lupaavalta, seuraan mielenkiinnolla. Local timeline voisi tosissaan ollakin hyödyllinen.

My 3yr old on what she wants to become when grown up;

fireman, pirate or a fox.

She's gonna end up just fine.

@turumore 3 afterwards naturally.
@turumore
2, then 1. Wake up refreshed.
@make @aninapartanen @turumore
Ping @jaranta kyseli aiheesta hiljattain.

@bcrypt always dance when unlocking your phone! Would result in overall more positive tone of everyday communications as a side effect!

:man_dancing:

Also looking forward to see "don", a #mastodon instance in #golang, growing :)

https://github.com/deoxxa/don