
Not that I post much on here, but I have a bluesky account now.
Holiday Hack Challenge 2024 just launched!
Did you know that you can look up plaintexts of over a trillion MD5 hashes ... for free?
https://www.nitrxgen.net/md5db/
He's pre-exhausted and stored quite a few combinations as well:
https://www.nitrxgen.net/md5db_info/
And there's an API (but note the restrictions):
https://www.nitrxgen.net/md5db_info/#api
(Not affiliated, just a fan - though I have collaborated with the operator for a few years now on related projects / research)
https://defcon.org/images/defcon-32/dc-32-map-public.pdf
For my own reference too.
At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still havenât set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadnât yet been registered, merely by supplying an email address tied to an existing domain.
From the story:
"...an analysis released by security experts at Metamask and Paradigm finds the most likely explanation for what happened is that Squarespace assumed all users migrating from Google Domains would select the social login options â such âContinue with Googleâ or âContinue with Appleâ â as opposed to the âContinue with emailâ choice.
Taylor Monahan, lead product manager at Metamask, said Squarespace never accounted for the possibility that a threat actor might sign up for an account using an email associated with a recently-migrated domain before the legitimate email holder created the account themselves.
âThus nothing actually stops them from trying to login with an email,â Monahan told KrebsOnSecurity. âAnd since thereâs no password on the account, it just shoots them to the âcreate password for your new accountâ flow. And since the account is half-initialized on the backend, they now have access to the domain in question.â
Trump gets shot, but not fatally.
https://www.cnn.com/2024/07/13/politics/video/trump-secret-service-butler-pennsylvania-digvid
Pentagon ran secret anti-vax campaign on social media
https://www.reuters.com/investigates/special-report/usa-covid-propaganda/