home.social

#bruteforce — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bruteforce, aggregated by home.social.

  1. Jemand versucht gerade exzessiv, eine von mir frisch aufgesetzte WordPress-Webseite per Brute Force zu hacken.

    Die Seite ist von Beginn an (seit einigen Tagen) mit einem Wartungsbild online.

    Das besondere dabei ist: der oder die Angreifer verwenden bei jedem neuen Zugriff eine andere IP-Adressen.

    Warum ich denke, dass es sich um einen gezielten Angriff eines Täters oder einer Gruppe von Tätern handelt? Weil es besondere andere Anzeichen genau dafür gibt.

    #BruteForce #WordPress #Login #Attacke

  2. Exhaustive enumeration of Rogue seeds progress:

    I've created an S3 bucket full of bitmaps for each room "feature" (currently only position and size), one bit per seed. This will allow reverse lookups -- if we want to find seeds where room 0 has height 6 and width 17, we can AND the corresponding bitmaps and find which bits are set. This is about 231GiB large.

    But, the slow part is actually uploading to S3. Running a complete enumeration locally takes less than 14 minutes (and this without any particular effort put into optimization or parallelization!) So building a query engine over this data may not be worth the investment if it only takes that little time to run an exhaustive search.

    I'm still thinking of a visualization. There are 2529 possible room configurations so a nice 51x50 grid could plot the relative frequency of each, in each room position. But, this makes large rooms look more probable than they are. (Rogue picks a room size and then places it to fit second, so there are many configurations for small rooms and only one for the largest room.)

    However, this is still Rogue(*) not real Rogue. A small variant in which monsters are placed _after_ room creation, not _during_.

    #Rogue #ProceduralContentGeneration #BruteForce

  3. Анализ безопасности Wi-Fi: атаки на WPA2-Personal / Enterprise и методология взлома WPA3

    Подробное исследование методологии взлома протоколов WPA2-Personal / Enterprise и WPA3: какие атаки и уязвимости существуют, и какой инструментарий применяется для их эксплуатации.

    habr.com/ru/companies/bastion/

    #беспроводные_технологии #wifi #информационная_безопасность #itинфраструктура #wpa3 #wpa2 #пентест #bruteforce #pmkid #wpa2enterprise

  4. Erstmals wird ein Forensik-Tool für Angriffe auf Macs mit T2-Chip vertrieben. Es nutzt wohl eine unpatchbare Schwachstelle des Apple-Chips.
    Macs mit T2-Sicherheitschip: Tool soll Passwort-Knacken ermöglichen