Community Archive

🧵 View Thread

🧵 Thread (21 tweets)

Placeholder
UltimApe@ultimape• almost 4 years ago

This is why I don't work in Information Technology anymore. I have twice had superiors unironically complaining about people clicking things in emails when the actual problem was persistent root kit spread via autoruns on network shares randomly downloading new fake-AV payloads. https://t.co/475oGrnDAW

19 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Watching download things from C&C server via wireshark... and showing it to my bosses. Also showing them the way that they persist after having windows reinstalled on them, and how even a new HDD doesn't matter due to the network share.

5 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

But they didn't believe me until I told them to just map the networkshare on boot and see how it goes.I wasn't working there when KB971029 was released.

2 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

I watched this a few days ago. Things are going to get a lot worse.https://t.co/eXtbXjBKVt

2 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Watching supply chain attacks scale out and looking at the future as people are inspired by the ideas.https://t.co/Qy9cH1sEDR

Placeholder
UltimApe@ultimape• about 4 years ago

I was responsible for installing and managing a multi-client implementation of Kaseya in one of my past jobs at a MSP.This is extremely bad. https://t.co/9O2NMZ8d3Q

3 0
3 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Attacks go from "merely hypothetical" to "now people are using them to push advertising and large scale tracking via audio modems". Because ideas like to inspire people.https://t.co/AZzycgjFc5

Placeholder
UltimApe@ultimape• about 7 years ago

Everybody was freaking out when badBIOS hit the news in 2013. Meanwhile I'm sitting here thinking "its about fucking time"... and "why aren't we doing this with HD LEDs yet?"https://t.co/MuJNpsl6wq

1 0
4 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Ya'll got any of them anti-rootkit root-kits?https://t.co/LknviHJtCmOr are you just moving the attack surface around?https://t.co/XZrn2bV7O8

Placeholder
UltimApe@ultimape• over 4 years ago

wat"It's neat that an obscure Unix like MINIX, thanks to Intel putting it on multiple cores in its chips, may be the world's most widely used operating system."https://t.co/2kjyLN0k25https://t.co/yVCtm3SCpp https://t.co/fNAI7EOtQS

Quoted tweet image 1
2 0
6 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

One of the largest bank heist ever to happen used no guns. https://t.co/DOzGBlr3g5https://t.co/zYk3JBfoMG

Placeholder
UltimApe@ultimape• over 10 years ago

RT @ForbesTech: The hacker crew who breached Staples may have taken down over $1 billion from banks: http://t.co/S4lokzZvpw http://t.co/vPv…

0 0
1 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

So how do you solve the scaling problem? Build a platform. https://t.co/HKXNj9QYOS

Placeholder
UltimApe@ultimape• almost 9 years ago

@christianbundy Wish I had no morals or scruples cuz i'd be rich. Had idea ages ago. Old fake AV viruses used an affiliate program IIRC.

1 0
2 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Soon: the world's largest hacking group, has no hackers?Now you're a market maker, harry.https://t.co/cNpxlGs8EO

Placeholder
UltimApe@ultimape• over 8 years ago

The world's largest catalog, has no products.https://t.co/BeQGRp8ylh

3 0
1 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Can I interest you in some VPNs spread via advertising money from wealthy investors and spread via social channels? Thats next. It's the largest fish.

2 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Prebuilt reverse proxy to the mothership."designed to authenticate an endpoint and enable domain scripts to run as soon as the machine powers on. This is useful because it allows admins to manage large fleets of machines without knowing the password"https://t.co/RNy0dN381j

2 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Growth market. This.https://t.co/jqtvWaYIa5

1 1
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

This is how you build skynet. https://t.co/mdhYYIuPUJ

Tweet image 1
1 1
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Another fun thing is this information exfiltration group that probably has hundreds of crowdworkers. They have the Modus Operandi of modern "AI" systems that just farm work out to paid employees. https://t.co/QSBZU8odmU

1 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Data is the new Oil.You can mine oil with people. But without an economic incentive, people don't typically care about oil.And the incentives to mine data are booming.https://t.co/hzAyKuRQ1Y https://t.co/BbV1qGR5c4

Tweet image 1
3 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

and now google is recommending me a video on how to pwn x86"what we're gonna see today is an architectural solution for ring -2 privilege escalation" 🤔https://t.co/GNexg4Tb0R

3 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

So to fight this, we'd have to hack our own system and install an anti-rootkit rootkit in ring -2 while also recreating the bios code so the system would functional without issue.Also, video implicitly suggests a supply chain attack vector https://t.co/5dnDCvGmrI

Tweet image 1
3 0
10/23/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Side Channel Attack your own computer to detect malicious code and hijacked hardware by just cataloguing the entire EMF spectrum. DARPA ain't fsck'ing around.https://t.co/NsJ7cav7qz

1 0
10/26/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

So can that run in reverse? Can we inject code by using high energy EMF and timing attacks?https://t.co/wd8UEM0UEd

Placeholder
UltimApe@ultimape• about 4 years ago

Anybody got a couple thousand arudionos lying around and experience in SDR?We could basically recreate this design, but for pen testing ala RF based fuzzing.Stochastic Optimization for x86 Binaries: https://t.co/DQo8qR0wHy

1 0
1 0
10/26/2021
Placeholder
UltimApe@ultimape• almost 4 years ago
Replying to @ultimape

Tired: @internetofshit Wired: internetofspies"Personalized Advertising Computational Techniques: A Systematic Literature Review, Findings, and a Design Framework" 🤮https://t.co/sqN3Bx8d3Q

1 0
11/29/2021