97 Followers
192 Following
140 Posts
7 minutes til #caturday

Stealing passwords from infosec Mastodon - without bypassing CSP | PortSwigger Research

https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp

Stealing passwords from infosec Mastodon - without bypassing CSP

The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose

PortSwigger Research

Yesterdays's *daily* migration to Mastodon was a record.

The picture doesn't capture fully what happened in the 24 hour period after Musk's 'hardcore' deadline. In that particular 24hour period there were 240 thousand registrations!

A few weeks ago, back in October and prior to Musk being in charge of Twitter, there were only a few thousand daily registrations to Mastodon.

@mastodonusercount
#twitterexodus #riptwitter #Mastodon #MastodonMigration

Migration to Mastodon is easy a little now. Still massive volumes though.

@mastodonusercount
#twitterexodus #riptwitter #Mastodon #MastodonMigration

Highly recommended reading: https://pingthread.com/thread/1593307541932474368 Tl;DR: "Elon Musk has lied for 27 years about his credentials. He does not have a BS in Physics, or any technical field. Did not get into a PhD program. Dropped out in 1995 & was illegal. Later, investors quietly arranged a diploma - but not in science."
Thread by capitolhunters: Someone has to say it: Elon Musk has lied for 27 y... - PingThread

Someone has to say it: Elon Musk has lied for 27 years about his credentials. He does not have a BS in Physics, or any technical field. Did not get into a PhD program. Dropped out in 1995 & was illegal. Later, investors quietly arranged a diploma - but not in science. ๐Ÿงต1/

PingThread

Brett Johnson, AKA Gollumfun was involved with the websites Counterfeit Library and Shadow Crew. He tells his story of what happened there and some of the crimes he committed.

https://darknetdiaries.com/episode/128

Gollumfun (Part 1) โ€“ Darknet Diaries

Brett Johnson, AKA Gollumfun was involved with the websites Counterfeit Library and Shadow Crew. He tells his story of what happened there and some of the crimes he committed.

@Sol0mand yeah surprise surprise ๐Ÿ˜†โ€‹
@Sol0mand I mean, do they even still have a data protection office after the culling? Genuinely curious
@Adam_Mashinchi @jerry Jerry from Mastodon
@danhon and I just start blastin...