Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hdmoore
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
hdmoore
7mo ago
maybe write these personally in the future vs pasting chatbot output? even if you didn't write the code, it would be nice if you wrote the description and post on your own.
2.
▲
by
hdmoore
8mo ago
https://hdm.io/
3.
▲
by
hdmoore
1y ago
I was too! The reason is that the Go x/crypto/ssh library was bailing out on the lack of reply to the channel open request, which prevented it from reaching the auth bypass check via exec. I should have an update out soon with thi
4.
▲
Black Hat 2024: Secure Shells in Shambles [pdf]
(i.blackhat.com)
101 points
by
hdmoore
2y ago
|
30 comments
5.
▲
by
hdmoore
2y ago
The Secure Shell (SSH) protocol has survived as an internet-facing management protocol for almost 30 years. Over the decades it has transformed from a single patented codebase to a multitude of implementations available on nearly every oper
6.
▲
by
hdmoore
2y ago
The CFAA has not been amended, but there was DoJ policy change on enforcement. So everyone is always breaking the law in the course of normal business, and it's still up to the prosector to determine who to go after: - https:/&#
7.
▲
by
hdmoore
2y ago
An underrated focus of Metasploit was making defensive tooling more robust. Spoonm's work on SNG (as well as other payload/encoder randomization efforts) was effective at killing static (and arguably ineffective) payload signature
8.
▲
by
hdmoore
3y ago
The sell-off of captable.io/LTSE Equity was announced to customers a couple months ago, predating the Carta drama (but many folks picked LTSE specifically because it wasn't Carta).
9.
▲
by
hdmoore
3y ago
The move to make all free instances unauthenticated (and effectively RCE-aaS) put a dent in that use.
10.
▲
by
hdmoore
3y ago
Erm, qmail had lots of bugs[1], when compiled for 64-bit processors (lots of integer overflows), but djb pushed back and said 64-bit wasn't supported. If anything, qmail is known as the most annoying MTA to package, since no modificati
11.
▲
by
hdmoore
5y ago
It is based on peak frequency, you can visually see it here: https://speakerdeck.com/hdm/derbycon-2011-acoustic-intrusion... IIRC (it has been a bit), there was a specific frequency only used by modem negotiation but n
12.
▲
by
hdmoore
5y ago
No kidding and thank you!
13.
▲
by
hdmoore
5y ago
I am the author of WarVOX (a mostly dead project these days). Some useful links: - WarVOX 2.0 Presentation: https://speakerdeck.com/hdm/derbycon-2011-acoustic-intrusion... - WarVOX Source: https://github.co
14.
▲
by
hdmoore
6y ago
Anything with massive storage and massive compute that doesn't need low latency is a great fit. I still host ~300TiB and ~250 cores at home because the cloud cost would be astronomical. Edit: This is for personal stuff related to inter
15.
▲
by
hdmoore
6y ago
On the investor front it depends on the debt size. Most seed-stage investors would prefer debt to a competing investment amount. Loaning yourself up to a year of lean run-rate is probably fine, but much more (hiring, paid user acq, etc) is
16.
▲
by
hdmoore
6y ago
Tracking capital contributions as debt is the best choice (after incorporation). Pay yourself back 6% non-compounding interest and make things easy. Don't buy your own equity just to cover short-term expenses. Reach out (email in profi
17.
▲
Microsoft Windows and Apple macOS Use Predictable SMB Session IDs
(rumble.run)
1 points
by
hdmoore
6y ago
|
0 comments
18.
▲
Escalating Privileges with CylancePROTECT
(atredis.com)
4 points
by
hdmoore
8y ago
|
0 comments
19.
▲
by
hdmoore
10y ago
In a similar vein, BitNami makes money licensing full-stack open source components with an integrated installer. I used it/them for a few years and while I wasn't smitten, it got the job done until something better came along. If
20.
▲
by
hdmoore
10y ago
I honestly thought this was satire for the first half of the article. When did working on SaaS products exempt people from understanding how to deliver software? Should we just remove the first [S] from SaaS? I see this attitude a ton in
21.
▲
by
hdmoore
10y ago
Less people voted for Prop-1 than signed the petition to create it (39k vs 65k). Uber and Lyft spent over $8m and lost. Sources: https://www.texastribune.org/2016/01/19/austin-group-gathers... , http:/&
22.
▲
RIP OSVDB.org
(blog.osvdb.org)
6 points
by
hdmoore
10y ago
|
0 comments
23.
▲
by
hdmoore
11y ago
A shortcut to getting com, net, info, org, us, sk, and biz is to give premiumdrops.com $24.95/mo. You can get these for free from the TLD operators, but it takes a few weeks of snail mail (last I checked). The gTLD access via CZDAP is
24.
▲
by
hdmoore
11y ago
The Sonar FDNS set contains about 1.4 billion host names (50m+ domains). The FDNS set is seeded from TLD zones, CZDAP, PTR lookups (RDNS), SSL/TLS scans, and HTTP link extraction. It updates every two weeks: https://github.c
25.
▲
by
hdmoore
11y ago
You might find the processing tips on the Project Sonar wiki useful: https://github.com/rapid7/sonar/wiki/Analyzing-Datasets Project Sonar is one of the primary contributors to scans.io. The DAP utility is ha
26.
▲
Let’s Put the Future Ahead of Us
(medium.com)
2 points
by
hdmoore
11y ago
|
0 comments
27.
▲
by
hdmoore
11y ago
If anyone is interested, you can find the unpacked firmware and some rough diffs online at https://github.com/hdm/juniper-cve-2015-7755/
28.
▲
by
hdmoore
11y ago
Even if you trust the OS and the baseband, you have to trust that the federated server for Signal (OpenWhisper, Cyanogen, etc) isn't storing contact discovery requests.
29.
▲
by
hdmoore
11y ago
If anyone is interested, I have been working on diffing the code for the backdoored vs patched versions: https://github.com/hdm/juniper-cve-2015-7755
30.
▲
by
hdmoore
11y ago
pbzip2 output isn't universally readable by third-party bz2 decompressors (Hadoop, for example).
More ›