#bruteforce — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bruteforce, aggregated by home.social.
-
Das #internet macht auch keinen Spaß mehr.
Das sind die Top-Sperren mit fail2ban bei 2 Domains, die nicht einmal aktiv irgendwo sind. Nur der Webserver steht da rum und langweilt sich. Alles mit #fail2ban geloggt.
Hauptursache: Globale #BruteForce auf #ssh. Also sichert eure Webserver von Anfang an ab.📊 Länder-Statistik: 🇻🇳 Vietnam: 6 (54,5%) 🇷🇺 Russland: 1 (9,1%) 🇨🇴 Kolumbien: 1 (9,1%) 🇺🇿 Usbekistan: 1 (9,1%) 🇭🇰 Hongkong: 1 (9,1%) 🇩🇪 Deutschland: 1 (9,1%)
-
Das #internet macht auch keinen Spaß mehr.
Das sind die Top-Sperren mit fail2ban bei 2 Domains, die nicht einmal aktiv irgendwo sind. Nur der Webserver steht da rum und langweilt sich. Alles mit #fail2ban geloggt.
Hauptursache: Globale #BruteForce auf #ssh. Also sichert eure Webserver von Anfang an ab.📊 Länder-Statistik: 🇻🇳 Vietnam: 6 (54,5%) 🇷🇺 Russland: 1 (9,1%) 🇨🇴 Kolumbien: 1 (9,1%) 🇺🇿 Usbekistan: 1 (9,1%) 🇭🇰 Hongkong: 1 (9,1%) 🇩🇪 Deutschland: 1 (9,1%)
-
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
288,493 Requests – How I Spotted an XML-RPC Brute Force from a Weird Cache Ratio
https://marcindudek.dev/blog/xmlrpc-brute-force-cache-rate/
#HackerNews #XMLRPC #BruteForce #CacheRatio #Security #Analysis #Cybersecurity #TechInsights
-
288,493 Requests – How I Spotted an XML-RPC Brute Force from a Weird Cache Ratio
https://marcindudek.dev/blog/xmlrpc-brute-force-cache-rate/
#HackerNews #XMLRPC #BruteForce #CacheRatio #Security #Analysis #Cybersecurity #TechInsights
-
GPU Price Doesn't Dictate Password Cracking Success
You don't need to break the bank on cutting-edge AI hardware to crack weak passwords - a recent study found that a $30,000 GPU doesn't outperform readily available consumer cards, proving that attackers can succeed with everyday tech.
#PasswordCracking #BruteForce #WeakCredentials #EmergingThreats #AiHardware
-
So I didn't write down the password to one of my new routers and for shits and giggles I'm trying to #bruteforce it on my network with #hydra
I've never used it before but it looks superb, the way it multi threads and does not overload the server.
I didn't want to factory default because I want the port data for diagnostic. -
When trying to solve a difficult problem, do not under-estimate the power of brute force & ignorance.
#solve #solution #problem #BruteForce #Ignorance #BruteForceAndIgnorance
-
When trying to solve a difficult problem, do not under-estimate the power of brute force & ignorance.
#solve #solution #problem #BruteForce #Ignorance #BruteForceAndIgnorance
-
На «РусКрипто’2026» рассказали, как защитить пароли от взлома на ASIC и FPGA
С 24 по 27 марта в Подмосковье проходит ежегодная международная конференция «РусКрипто’2026», отражающая развитие криптографии и информационной безопасности. В этом году многие участники затрагивали вопросы цифрового суверенитета и построения доверенной цифровой среды. Особый интерес вызвал доклад сотрудников лаборатории криптографии компании «Криптонит» Анастасии Чичаевой и Степана Давыдова, посвящённый защите от взлома на специализированном «железе». В своём выступлении Анастасия Чичаева рассказала о современных подходах к построению и анализу так называемых memory-hard functions (MHF) — криптографических функций, требовательных к объёму памяти. Они становятся эффективным противодействием использованию специализированных вычислителей для перебора паролей и вырабатываемых из них ключей. К таким устройствам относят ASIC (специализированные интегральные схемы) и FPGA (программируемые логические интегральные схемы). Те и другие можно «заточить» на параллельное выполнение алгоритмов одного типа (например — хэширования) и достичь большей эффективности, чем , при использовании процессоров общего назначения. Следовательно, ASIC и FPGA существенно снижают затраты на проведение атак методом перебора. При этом у них ограниченный объём памяти (особенно у ASIC), и это свойство можно использовать в стратегии защиты. Memory-hard функции как раз устроены так, что для их вычисления требуется значительный объём памяти, поэтому их применение делает массовый перебор паролей на специализированных вычислителях экономически невыгодным, а это – универсальная стратегия защиты.
https://habr.com/ru/companies/kryptonite/articles/1015358/
#Memoryhard_functions #MHF #ASIC #FPGA #Scrypt #Argon2 #bruteforce #password
-
⚠️ CVE-2026-32292: CRITICAL vuln in GL-iNet Comet KVM (CVSS 9.3) — web UI lacks brute-force protections. No patch yet. Restrict access, use strong creds, monitor logs! Details: https://radar.offseq.com/threat/cve-2026-32292-cwe-307-improper-restriction-of-exc-7d4b6f55 #OffSeq #Vulnerability #Cybersecurity #BruteForce
-
Quanto tempo serve a un Computer per indovinare la tua Password?
Immagina di essere davanti al computer, la sera, mentre crei un nuovo account. Scrivi una password qualunque, clicchi su “Registrati” e ti senti al sicuro. Ma dall’altra parte del mondo una macchina potrebbe essere in grado di provare milioni o addirittura miliardi di combinazioni al secondo per indovinare proprio quella parola segreta che hai appena scelto. E non si tratta di fantascienza. È matematica, potenza di calcolo e – spesso – sfruttamento dei nostri errori più umani e […]https://www.psicospace.it/quanto-tempo-serve-a-un-computer-per-indovinare-la-tua-password/
-
IP2Ban для Exchange средствами PowerShell
Привет! На связи Виктор из Cloud4Y. Хочу поделиться практической историей о том, как сделать fail2ban-подобную механику для Exchange на Windows: быстрое обнаружение brute-force по IIS-логам и автоматическая блокировка атакующих IP . Fail2ban и аналоги привычны для Linux, но когда у тебя on-prem Exchange на Windows , нужен свой инструмент для быстрого обнаружения массовых неудачных логинов и такой же быстрой блокировки источника.
https://habr.com/ru/companies/cloud4y/articles/986202/
#Exchange #PowerShell #bruteforce #информационная_безопасность #IPблокировка #учетные_записи #IPадреса #IIS_W3C
-
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
https://neodyme.io/en/blog/drone_hacking_part_1/
#HackerNews #DroneHacking #FirmwareDumping #ECC #BruteForce #Cybersecurity #TechBlog
-
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
https://neodyme.io/en/blog/drone_hacking_part_1/
#HackerNews #DroneHacking #FirmwareDumping #ECC #BruteForce #Cybersecurity #TechBlog
-
Хотят многие, делают единицы: наш опыт автоматизации рутины пентеста
Привет, Хабр! Меня зовут Дмитрий Федосов, я руковожу отделом наступательной безопасности в Positive Technologies. В этой статье мы с ведущим специалистом нашего отдела Владиславом Дриевым расскажем про автоматизацию рутины в пентесте на основании нашего опыта построения результативной безопасности. Вообще, автоматизация рутины пентеста — довольно очевидная идея, но на пути от идеи до работающего средства множество препятствий: от неочевидных багов популярных инструментов до проблем с масштабированием и конкуренцией за сетевые ресурсы. В статье речь пойдёт о том, как автоматизация меняет сам подход к оценке защищенности инфраструктуры. Разберем, с каких атак начать исследователю, как избежать скрытых проблем с Masscan, Kerbrute, Impacket, и почему на рынке до сих пор так мало готовых решений.
https://habr.com/ru/companies/pt/articles/984606/
#автоматизация_рутины #пентест #тестирование_на_проникновение #pt_dephaze #masscan #bruteforce #impacket #векторы_атак #уязвимости_и_их_эксплуатация
-
Shame #eBay rejected my request for dev account way back then...
I'd really like a #php n #js based #notification fetch
Guess without #api s programmers are nothing...
(And #bruteforce ing js out of question) -
Shame #eBay rejected my request for dev account way back then...
I'd really like a #php n #js based #notification fetch
Guess without #api s programmers are nothing...
(And #bruteforce ing js out of question) -
Bitte erzählt mir jetzt nicht, dass beim weltgrößten #Messenger schon immer eine simple #BruteForce-Attacke reichte, um die #Metadaten fast aller Profile in einem milliardengroßen Nummernraum ungehindert abzuschnorcheln.
-
Что еще могёт курсор
Началось все весьма прозаично, клиент позвонить к нам в техподдержку и спросил «а как бы мне поставить ваш софт но в другую схему БД». Собственно вопрос проще некуда — мы писали на спринге, а значит лезем в application.yml и ставим схему. Но, клиент не из тупых и уже это попробовал — не сработало. Начинаем разбираться что сломалось и кто виноват. Первым делом ДевОпс повторяет кульбиты клиента и выдает простой вердикт: «В 151 миграции лажа». Я открываю и: «батюшки родный, да это же лосенок явное указание схемы!»
-
SonicWall Says All Firewall Backups Were Accessed by Hackers https://hackread.com/sonicwall-hackers-breached-all-firewall-backups/ #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #databreach #SonicWall #Security #Privacy #Backup
-
SonicWall Says All Firewall Backups Were Accessed by Hackers https://hackread.com/sonicwall-hackers-breached-all-firewall-backups/ #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #databreach #SonicWall #Security #Privacy #Backup
-
Hm. Over at the facesite I commented on a post about #bruteforce attacks on a commercial network product with a link to https://nxdomain.no/~peter/badness_enumerated_by_robots.html, and got a followup asking whether I have bruteforce protection "in front of" my ssh servers.
And this only hours after I scared the cat by LOL from seeing that the #pop3gropers are actively trying the local parts of my freshly random spamtraps (see https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html a bit down the page). #passwordgroping #cybercrime
-
Hm. Over at the facesite I commented on a post about #bruteforce attacks on a commercial network product with a link to https://nxdomain.no/~peter/badness_enumerated_by_robots.html, and got a followup asking whether I have bruteforce protection "in front of" my ssh servers.
And this only hours after I scared the cat by LOL from seeing that the #pop3gropers are actively trying the local parts of my freshly random spamtraps (see https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html a bit down the page). #passwordgroping #cybercrime
-
SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations https://www.securityweek.com/sonicwall-prompts-password-resets-after-firewall-configurations-exposed-in-breach/ #NetworkSecurity #passwordreset #bruteforce #SonicWall #firewall #password
-
SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations https://www.securityweek.com/sonicwall-prompts-password-resets-after-firewall-configurations-exposed-in-breach/ #NetworkSecurity #passwordreset #bruteforce #SonicWall #firewall #password
-
Dein achtstelliges Passwort ist in Sekunden geknackt!
Passwortlänge zählt 🔑 Ein 8-stelliges #Passwort kann in Sekunden #geknackt werden, während ein 16-stelliges Passwort selbst modernen Rechnern jahrelange Rechenzeit abverlangt.
Exponentielle Sicherheit 📊 Jede zusätzliche Stelle verdoppelt oder vervielfacht die möglichen Kombinationen und macht #BruteForce-Angriffe erheblich schwerer. (1/2)