home.social

#enumeration — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #enumeration, aggregated by home.social.

  1. @da_667 it is civilized to proxy that shit (it is the vast majority of the traffic, mostly) and use your own certs, should you proxy through yacy and spider every site you visit? should you use squid proxy to speed up browsing? those options are left to the reader - they all work and you can get reports - are most smb going to do lots of threat hunting probably not but they may go hybrid #unknown binary #ntopng #top talkers #comp intel #enumeration #attribution

  2. @da_667 it is civilized to proxy that shit (it is the vast majority of the traffic, mostly) and use your own certs, should you proxy through yacy and spider every site you visit? should you use squid proxy to speed up browsing? those options are left to the reader - they all work and you can get reports - are most smb going to do lots of threat hunting probably not but they may go hybrid #unknown binary #ntopng #top talkers #comp intel #enumeration #attribution

  3. @da_667 it is civilized to proxy that shit (it is the vast majority of the traffic, mostly) and use your own certs, should you proxy through yacy and spider every site you visit? should you use squid proxy to speed up browsing? those options are left to the reader - they all work and you can get reports - are most smb going to do lots of threat hunting probably not but they may go hybrid #unknown binary #ntopng #top talkers #comp intel #enumeration #attribution

  4. @da_667 it is civilized to proxy that shit (it is the vast majority of the traffic, mostly) and use your own certs, should you proxy through yacy and spider every site you visit? should you use squid proxy to speed up browsing? those options are left to the reader - they all work and you can get reports - are most smb going to do lots of threat hunting probably not but they may go hybrid #unknown binary #ntopng #top talkers #comp intel #enumeration #attribution

  5. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  6. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  7. Recently, I wrote a write-up for the vulnerable machine from #VulNyx called Controler. It’s a medium-level #Windows machine. #Enumeration begins with the Kerberos account, which I use to gain initial system access. Through further Active Directory enumeration, I #exploit replication rights, ultimately extracting the Domain Administrator’s password hash and gaining full administrative control.

    Solving this machine took me some time, but I learned a lot. I touched on new tools like #BloodHound, delved a bit deeper into Active Directory, and, in general, kept my #pentesting skills in check.

    If you are starting in #cybersecurity, I would definitely recommend checking some VMs from VulNyx.

    medium.com/@thecybercraft/vuln

  8. STM32 Short #8 - Understanding USB Enumeration (re-enumeration)

    In this videi we will cover the topic of USB Enumeration and how to trigger a USB Host to re-enumerate a STM32 USB Device (or Gadget).

    #STM32 #Tutorial #STM32CubeIDE #STM32CubeMX #USB #Enumeration #STM32World

    youtube.com/watch?v=osNf6gyF_zY

  9. STM32 Short #8 - Understanding USB Enumeration (re-enumeration)

    In this videi we will cover the topic of USB Enumeration and how to trigger a USB Host to re-enumerate a STM32 USB Device (or Gadget).

    #STM32 #Tutorial #STM32CubeIDE #STM32CubeMX #USB #Enumeration #STM32World

    youtube.com/watch?v=osNf6gyF_zY

  10. STM32 Short #8 - Understanding USB Enumeration (re-enumeration)

    In this videi we will cover the topic of USB Enumeration and how to trigger a USB Host to re-enumerate a STM32 USB Device (or Gadget).

    #STM32 #Tutorial #STM32CubeIDE #STM32CubeMX #USB #Enumeration #STM32World

    youtube.com/watch?v=osNf6gyF_zY

  11. STM32 Short #8 - Understanding USB Enumeration (re-enumeration)

    In this videi we will cover the topic of USB Enumeration and how to trigger a USB Host to re-enumerate a STM32 USB Device (or Gadget).

    #STM32 #Tutorial #STM32CubeIDE #STM32CubeMX #USB #Enumeration #STM32World

    youtube.com/watch?v=osNf6gyF_zY

  12. 🤔 Ever wonder how to escape from a container? Or how security tools know what permissions they have from inside that same container? It's nice to have a great script for #enumeration ... but what does it check for and why does it matter?

    (or, I did a little editing and put my workshop from @appsec_village at #DEFCON33 up) :heart_cybre:

  13. 🤔 Ever wonder how to escape from a container? Or how security tools know what permissions they have from inside that same container? It's nice to have a great script for #enumeration ... but what does it check for and why does it matter?

    (or, I did a little editing and put my workshop from @appsec_village at #DEFCON33 up) :heart_cybre:

  14. 🤔 Ever wonder how to escape from a container? Or how security tools know what permissions they have from inside that same container? It's nice to have a great script for #enumeration ... but what does it check for and why does it matter?

    (or, I did a little editing and put my workshop from @appsec_village at #DEFCON33 up) :heart_cybre:

  15. 🤔 Ever wonder how to escape from a container? Or how security tools know what permissions they have from inside that same container? It's nice to have a great script for #enumeration ... but what does it check for and why does it matter?

    (or, I did a little editing and put my workshop from @appsec_village at #DEFCON33 up) :heart_cybre:

  16. 🤔 Ever wonder how to escape from a container? Or how security tools know what permissions they have from inside that same container? It's nice to have a great script for #enumeration ... but what does it check for and why does it matter?

    (or, I did a little editing and put my workshop from @appsec_village at #DEFCON33 up) :heart_cybre:

  17. Subdomain enumeration is an essential OSINT technique. Amass and Subfinder are well-known enumeration tools, but they have limitations. Explore this comprehensive database with over 200 sources.

    osintteam.com/passive-subdomai

    #OSINT #Subdomains #Domains #DNS #enumeration

  18. In this week's Linux Update newsletter, Chris Binnie looks at the enumeration tools feroxbuster and ffuf for automating search during a cyberattack
    linux-magazine.com/Issues/2025

  19. who spies on you more - ms, apple, google or amazon - ai surveillance content from rob braxman
    youtube.com/watch?v=QwxaRPuJky
    #tracking #capital surveillance #enumeration #ever cookie

  20. who spies on you more - ms, apple, google or amazon - ai surveillance content from rob braxman
    youtube.com/watch?v=QwxaRPuJky
    #tracking #capital surveillance #enumeration #ever cookie

  21. who spies on you more - ms, apple, google or amazon - ai surveillance content from rob braxman
    youtube.com/watch?v=QwxaRPuJky
    #tracking #capital surveillance #enumeration #ever cookie

  22. Oh boy. A simple #enumeration #attack could be used to read credit offers at #CHECK24 and #verivox, two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.

    This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any #securityaudit. I wonder how they can state "No indications of miss use.". #cybersecurity

    Article in German:
    correctiv.org/aktuelles/datens

  23. Oh boy. A simple #enumeration #attack could be used to read credit offers at #CHECK24 and #verivox, two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.

    This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any #securityaudit. I wonder how they can state "No indications of miss use.". #cybersecurity

    Article in German:
    correctiv.org/aktuelles/datens

  24. Oh boy. A simple #enumeration #attack could be used to read credit offers at #CHECK24 and #verivox, two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.

    This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any #securityaudit. I wonder how they can state "No indications of miss use.". #cybersecurity

    Article in German:
    correctiv.org/aktuelles/datens

  25. Weekend project: try to solve some #combinatorics #enumeration problems by reduction to #SharpSAT. (Which, to be clear, I thought was unlikely to succeed!)

    I picked c2d reasoning.cs.ucla.edu/c2d/ because it scored highly in the 2020 Model Counting Competition arxiv.org/abs/2012.01323 but I am not sure this is the same version. The one I got is dated 2005 and was 32-bit only. It ran out of memory on this 364-variable 942-clause instance (corresponding to 6 playing cards chosen from a standard 52-card deck.)

    Looking at the 2023 competition instead, I think I should try SharpSAT-TD github.com/Laakeri/sharpsat-td but it is not as well documented. For example, I don't know if it supports the "eclauses" (exactly-one clauses) extension of the Dimacs CNF format.

    #Satisfiability

  26. Weekend project: try to solve some #combinatorics #enumeration problems by reduction to #SharpSAT. (Which, to be clear, I thought was unlikely to succeed!)

    I picked c2d reasoning.cs.ucla.edu/c2d/ because it scored highly in the 2020 Model Counting Competition arxiv.org/abs/2012.01323 but I am not sure this is the same version. The one I got is dated 2005 and was 32-bit only. It ran out of memory on this 364-variable 942-clause instance (corresponding to 6 playing cards chosen from a standard 52-card deck.)

    Looking at the 2023 competition instead, I think I should try SharpSAT-TD github.com/Laakeri/sharpsat-td but it is not as well documented. For example, I don't know if it supports the "eclauses" (exactly-one clauses) extension of the Dimacs CNF format.

    #Satisfiability

  27. Weekend project: try to solve some #combinatorics #enumeration problems by reduction to #SharpSAT. (Which, to be clear, I thought was unlikely to succeed!)

    I picked c2d reasoning.cs.ucla.edu/c2d/ because it scored highly in the 2020 Model Counting Competition arxiv.org/abs/2012.01323 but I am not sure this is the same version. The one I got is dated 2005 and was 32-bit only. It ran out of memory on this 364-variable 942-clause instance (corresponding to 6 playing cards chosen from a standard 52-card deck.)

    Looking at the 2023 competition instead, I think I should try SharpSAT-TD github.com/Laakeri/sharpsat-td but it is not as well documented. For example, I don't know if it supports the "eclauses" (exactly-one clauses) extension of the Dimacs CNF format.

    #Satisfiability

  28. Weekend project: try to solve some #combinatorics #enumeration problems by reduction to #SharpSAT. (Which, to be clear, I thought was unlikely to succeed!)

    I picked c2d reasoning.cs.ucla.edu/c2d/ because it scored highly in the 2020 Model Counting Competition arxiv.org/abs/2012.01323 but I am not sure this is the same version. The one I got is dated 2005 and was 32-bit only. It ran out of memory on this 364-variable 942-clause instance (corresponding to 6 playing cards chosen from a standard 52-card deck.)

    Looking at the 2023 competition instead, I think I should try SharpSAT-TD github.com/Laakeri/sharpsat-td but it is not as well documented. For example, I don't know if it supports the "eclauses" (exactly-one clauses) extension of the Dimacs CNF format.

    #Satisfiability

  29. All sets of integer lattice points symmetric along the X and Y axes, and connected allowing diagonals, of size 14 and 15.

    Code here: gist.github.com/mgritter/8cfc4

    Inspired by this Quora question, quora.com/On-an-XY-array-of-la, although I misinterpreted what he was asking for. That was closer to all polyominoes, allowing diagonal connections, which are horizontally and vertically symmetric. But I don't allow the line of symmetry to run down a half-integer value.

    #enumeration #integer_lattice #polyominoes

  30. All sets of integer lattice points symmetric along the X and Y axes, and connected allowing diagonals, of size 14 and 15.

    Code here: gist.github.com/mgritter/8cfc4

    Inspired by this Quora question, quora.com/On-an-XY-array-of-la, although I misinterpreted what he was asking for. That was closer to all polyominoes, allowing diagonal connections, which are horizontally and vertically symmetric. But I don't allow the line of symmetry to run down a half-integer value.

    #enumeration #integer_lattice #polyominoes

  31. All sets of integer lattice points symmetric along the X and Y axes, and connected allowing diagonals, of size 14 and 15.

    Code here: gist.github.com/mgritter/8cfc4

    Inspired by this Quora question, quora.com/On-an-XY-array-of-la, although I misinterpreted what he was asking for. That was closer to all polyominoes, allowing diagonal connections, which are horizontally and vertically symmetric. But I don't allow the line of symmetry to run down a half-integer value.

    #enumeration #integer_lattice #polyominoes

  32. All sets of integer lattice points symmetric along the X and Y axes, and connected allowing diagonals, of size 14 and 15.

    Code here: gist.github.com/mgritter/8cfc4

    Inspired by this Quora question, quora.com/On-an-XY-array-of-la, although I misinterpreted what he was asking for. That was closer to all polyominoes, allowing diagonal connections, which are horizontally and vertically symmetric. But I don't allow the line of symmetry to run down a half-integer value.

    #enumeration #integer_lattice #polyominoes

  33. Point-in-Time count shows homeless numbers up over 9% in Victoria, BC region

    This year’s count identified 1,665 people who were experiencing homelessness, versus 1,523 in 2020

    Homeless include many seniors, Indigenous and people with disabilities

    timescolonist.com/local-news/p

    #homeless #housing #AffordableHousing #enumeration #PointInTime #yyjpoli #bcpoli #buildhomes #buildjustice

  34. Point-in-Time count shows homeless numbers up over 9% in Victoria, BC region

    This year’s count identified 1,665 people who were experiencing homelessness, versus 1,523 in 2020

    Homeless include many seniors, Indigenous and people with disabilities

    timescolonist.com/local-news/p

    #homeless #housing #AffordableHousing #enumeration #PointInTime #yyjpoli #bcpoli #buildhomes #buildjustice

  35. Point-in-Time count shows homeless numbers up over 9% in Victoria, BC region

    This year’s count identified 1,665 people who were experiencing homelessness, versus 1,523 in 2020

    Homeless include many seniors, Indigenous and people with disabilities

    timescolonist.com/local-news/p

    #homeless #housing #AffordableHousing #enumeration #PointInTime #yyjpoli #bcpoli #buildhomes #buildjustice

  36. Point-in-Time count shows homeless numbers up over 9% in Victoria, BC region

    This year’s count identified 1,665 people who were experiencing homelessness, versus 1,523 in 2020

    Homeless include many seniors, Indigenous and people with disabilities

    timescolonist.com/local-news/p

    #homeless #housing #AffordableHousing #enumeration #PointInTime #yyjpoli #bcpoli #buildhomes #buildjustice

  37. There has to be a better way, right? Brute force can’t be the best way to enumerate zones of subdomains. #pentesting #hacking #dns #zone #enumeration #hackthebox

  38. There has to be a better way, right? Brute force can’t be the best way to enumerate zones of subdomains. #pentesting #hacking #dns #zone #enumeration #hackthebox