#techtuesday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #techtuesday, aggregated by home.social.
-
In 2025, Interledger brought Open Payments to Mexico 🇲🇽
4 cities. 4 universities. 500+ students building real solutions.
47 teams at the Mexico City hackathon explored remittances, device-less payments, and more.
🌍 Watch highlights:
https://www.youtube.com/playlist?list=PLDHju0onYcAJTqclf030A87CiX-8KxapZ -
🌟 Breaking AI News! 🚀 Discover the latest advancements revolutionizing our world 🌍 Stay ahead with insights into cutting-edge tech, innovation, and AI dreams coming true 🤖✨ #AINews #TechTrends #InnovationNation #FutureForward #TechTuesday #AIRevolution #DigitalTransformation https://t.co/wYJKJ1Jo84 on https://twitter.com/AcerboLivio/status/2034912963346190826
-
VIDEO: Hands On Windows – The New OneDrive App – OneDrive’s Secret Upgrade
As the TWiT podcast network host Paul Thurrott explains, Microsoft is rolling out an overhauled version of OneDrive. -
Proton Authenticator
As more and more of our important personal data is stored online and more and more hacks of corporate databases make that data available to the worst people, the need for added security on our online accounts has grown considerably. It’s no longer enough to have a secure, hard to crack password. We now need to enable two-factor/multi-factor authentication (2FA/MFA). These services allow you to use something you have, such as your smartphone, along with something you know, in this case your […]
-
Have you heard? Biggest databreach in history just a few weeks ago!
Be sure to keep yourself safe by looking into measures like multi-factor authentication and/or password managers!#techsupport #technews #techtuesday
#msp #serviceprovider
#businessIT #ITconsulting -
🚨 🥳 @ozoned is live on Owncast! 🥳
Catch the stream here: https://stream.ozoned.net/#LinuxGaming #GamingOnLinux #TechTuesday #SteamLinux #owncast #livestream #twitch
-
Fraud Alert: Beware the SIM Swap Scam.
#TechTip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #Scam #Spam #Phishing #ScamAlert #FraudAlert #BeCyberSmart #GetCyberSafe #ThinkBeforeYouAct #ThinkBeforeYouPost #InternetSafety #OnlineSecurity #eSafety #CyberSecurity #DataSecurity #CyberTips #online #digital #DigitalMarketing #OnlineMarketing #ContentMarketing #Hack #Trick #SocialEngineering #usability #UX #UserExperience #techie…
https://trulyjuly.wordpress.com/2024/12/03/fraudalert-beware-the-sim-swap-scam/
-
Tech News: Google Calendar finally offers dark mode.
#TechNews brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #techsupport #DarkMode #DarkTheme #GoodDesign #usability #UX #UI #UserExperience #UXdesign #UIdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC…
https://trulyjuly.wordpress.com/2024/11/26/technews-google-calendar-finally-offers-dark-mode/
-
Tech News: Google Calendar finally offers dark mode.
#TechNews brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #techsupport #DarkMode #DarkTheme #GoodDesign #usability #UX #UI #UserExperience #UXdesign #UIdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC…
https://trulyjuly.wordpress.com/2024/11/26/technews-google-calendar-finally-offers-dark-mode/
-
Tech News: Google Calendar finally offers dark mode.
#TechNews brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #techsupport #DarkMode #DarkTheme #GoodDesign #usability #UX #UI #UserExperience #UXdesign #UIdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC…
https://trulyjuly.wordpress.com/2024/11/26/technews-google-calendar-finally-offers-dark-mode/
-
Good Practice Tip: Notify users when redirected to a different site.
#Good #Practice #Tip brought to you by Yours *TrulyJuly*.
#GoodPracticeTip #YoursTrulyJuly #TechTuesday #TechBlogger #HowTo #tech #digital #online #DigitalMarketing #OnlineMarketing #ContentMarketing #usability #UX #UserExperience #uxdesign #WebDesign #DesignThinking #CustomerJourney #BetterDigitalWorld #InternetSafety #OnlineSecurity #ConsumerProtection
-
Usability Fail: Google Doodle promotes shooting street signs.
#UsabilityFail brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent #Google…
-
Usability Fail: Microsoft blocks its own content.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent
https://trulyjuly.wordpress.com/2024/08/27/usabilityfail-microsoft-blocks-its-own-content/
-
Usability Fail: When 'Phone' means 'Email'.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UI #UX #UserExperience #UsabilityFail #uxdesign #uidesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent
https://trulyjuly.wordpress.com/2024/08/20/usabilityfail-when-phone-means-email/
-
Usability Fail: Using generic newsletter name.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UI #UX #UserExperience #UsabilityFail #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #BrandFail #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent
https://trulyjuly.wordpress.com/2024/08/20/usabilityfail-using-generic-newsletter-name/
-
Tech Tip: Google search tips & tricks.
#TechTip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #HowTo #techsupport #usability #UX #UserExperience #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent
https://trulyjuly.wordpress.com/2003/07/19/techtip-google-search-tips-tricks/
-
#UsabilityFail: Google Analytics displays calendar unaligned.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UI #UX #UserExperience #UsabilityFail #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #BrandFail #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent
-
Brand Fail: Twitter X almost looks like close window X.
Usability Fail brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UI #UX #UserExperience #UsabilityFail #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #BrandFail #GoodPractice #BetterDigitalWorld #Twitter #X #TwitterX
https://trulyjuly.wordpress.com/2024/05/14/brandfail-twitter-x-almost-looks-like-close-window-x/
-
Usability Fail: Google Analytics uses generic 'report' as default file name.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #UserInterfaceDesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity…
-
Usability Fail: Google Analytics uses generic 'report' as default file name.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #UserInterfaceDesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity…
-
Usability Fail: Google Analytics uses generic 'report' as default file name.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #UserInterfaceDesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity…
-
Usability Fail: Google Analytics uses generic 'report' as default file name.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UI #UserExperience #uxdesign #uidesign #UserInterfaceDesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity…
-
Usability Fail: Facebook forgets 'Post' button for creating a new post.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UserExperience #uxdesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent #MonopolyIsBad
-
Active Directory Certificate Services (AD CS) is Microsoft's way to establish and manage a public key infrastructure in Active Directory. It can be used to manage certificate templates, issue certificates or revoke them. And because those certificates can be used for client authentication, AD CS is a very appealing target for attackers.
We have already looked at the escalation primitive "ESC1" before (https://infosec.exchange/@lutrasecurity/112399051244845571). Today we will have a look at ESC4. Just like ESC1, an attacker can abuse this misconfiguration to escalate their privileges from a regular domain user to Domain Admin.
This time, the misconfiguration is that a regular domain user can modify a certificate template. This means, that an attacker can simply modify the template and configure it to be vulnerable to ESC1. Then, the attacker can easily exploit the ESC1 misconfiguration they added and escalate their privileges.
The tool "Certify" can be used to identify and perform almost all AD CS attacks. In case of ESC4, an attacker only needs to change the certificate template to allow the enrollee to supply a subject (CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT). Then, an attacker can request a certificate using the modified template and provide the username that they want to impersonate as an argument. That’s it. They can now impersonate the user and take over the entire domain.
So how can you detect and defend against it?
First and foremost: CA servers are Tier 0 assets. This means that they are as important as your Domain Controller and should be hardened as such. To fix the misconfiguration, you need to review the permissions for the certificate template in question. For this, open “Certificate Authority”, right-click on “Certificate Templates” and choose “Manage”. There you can view the “Security” tab within the properties and manage the permissions (see screenshot). In this case, remove the dangerous permissions of the Domain Users group (Full Control, Write).
For detection, monitor requests (EID 4886) and issuing (EID 4887) of certificates as well as the modification of CA settings, such as certificate template modifications. And of course: Search for these types of misconfigurations to find them before the real attackers do.
#itsecurity #adcs #esc4 #ttp #mitre #redteam #redteaming #TechTuesday
-
Good Practice Tip: Instant reward for quiz participation.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#GoodPracticeTip #YoursTrulyJuly #TechTuesday #TechBlogger #TechBlog #HowTo #tech #digital #online #DigitalMarketing #OnlineMarketing #ContentMarketing #usability #UX #UserExperience #uxdesign #UI #uidesign #WebDesign #DesignThinking #CustomerJourney #BetterDigitalWorld #quiz #interaction #InteractionDesign #DailyUI #GreatContent #ContentCreaton…
https://trulyjuly.wordpress.com/2024/07/30/goodpracticetip-instant-reward-for-quiz-participation/
-
Tech Blog: Are you human CAPTCHAs get more complex.
#TechTip brought to you by Yours *TrulyJuly*.
#TechTuesday #online #digital #internet #Hack #Trick #Tech #Tip #HowTo #usability #UX #UserExperience #TechBlogger #YoursTrulyJuly #techie #techtrick #techhack #techsupport #CAPTCHAs #BetterDigitalWorld
https://trulyjuly.wordpress.com/2024/05/07/techblog-are-you-human-captchas-get-more-complex/
-
Active Directory Certificate Services (AD CS) is Microsoft's way to establish and manage a public key infrastructure in Active Directory. It can be used to manage certificate templates, issue certificates or revoke them. And since those certificates can be used for client authentication, AD CS makes for a very appealing target for attackers.
This is probably also the reason why @SpecterOps took a deep dive into attacking AD CS in 2021. During their research, @harmj0y and @tifkin_ uncovered several ways to abuse AD CS, for example, to escalate privileges. Those privilege escalation techniques are labelled with the prefix "ESC" (no, not affiliated to the music contest Germany loses every year) followed by a number.
Today, we will have a look at ESC1, which an attacker can abuse to escalate privileges from a regular domain user to Domain Admin.
ESC1 refers to a misconfiguration in a certificate template that can be used for client authentication. It occurs if a normal domain user is allowed to request such a certificate and can supply an arbitrary subjectAltName (SAN). What this essentially means is that a user can supply an arbitrary username in the SAN and impersonate any user.
For more details see the whitepaper, it's great: https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf
Think of a really bad gatekeeper: He looks at your ID and checks that you belong. He turns around to grab your keys and by that time he already forgot your name. And asks you again. And of course you, as a hacker, say: "I am the head of the company". He grabs "your" keys, opens the door and is like: "Whatever, go inside. Here are the keys to all rooms".
The tool "Certify" can be used to identify and perform almost all AD CS attacks. In case of ESC1, an attacker only needs to request a certificate using the vulnerable template and provide the username that they want to impersonate as an argument. That’s it. They can now impersonate the user and take over the entire domain.
🔐 So: How can you fix the vulnerability and detect abuse? 🕵️
First and foremost: CA servers are Tier 0 assets. 💎 This means that they are as important as your Domain Controller and should be hardened as such. To fix the misconfiguration you need to disable the option to supply the subject name in the request (see screenshot). For detection, monitor requests (EID 4886) and issuing (EID 4887) of certificates as well as the modification of CA settings, such as certificate template modifications (e.g. ESC4 abuse).
#itsecurity #ttp #mitre #redteam #redteaming #TechTuesday #adcs #esc1
-
Usability Fail: Google puts its own email into Gmail spam.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UserExperience #uxdesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent #Google #Gmail
https://trulyjuly.wordpress.com/2024/04/23/usabilityfail-google-puts-its-own-email-into-gmail-spam/
-
Brand Fail: X (formerly Twitter)
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UserExperience #UsabilityFail #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #BrandFail #GoodPractice #Twitter #X #TwitterX
https://trulyjuly.wordpress.com/2024/04/16/brandfail-x-formerly-twitter/
-
Tech Blog: If the url says 'Twitter', it's 'Twitter'.
#YoursTrulyJuly #TechBlogger #TechBlog #TechTuesday #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UserExperience #UsabilityFail #uxdesign #WebDesign #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #Twitter #X
https://trulyjuly.wordpress.com/2024/04/09/techblog-if-the-url-says-twitter-its-twitter/
-
Usability Fail: Wrong shades of grey.
#GoodPractice #Tip brought to you by Yours *TrulyJuly*.
#YoursTrulyJuly #TechTuesday #TechBlogger #TechTip #tech #techie #digital #online #DigitalMarketing #OnlineMarketing #usability #UX #UserExperience #uxdesign #WebDesign #UsabilityFail #DesignThinking #CustomerJourney #ContentMarketing #GoodPractice #BetterDigitalWorld #ContentIsKing #QualityOverQuantity #VAC #ValueAddedContent #typography
https://trulyjuly.wordpress.com/2024/03/26/usabilityfail-wrong-shades-of-grey/
-
@jamesmontemagno
Just so happens I'm posting a blog on that (suitable for beginners up) this week as part of #MAUIUIJuly ! #dotnet #dotnetmaui #csharp #TechTuesday
CC @mattgoldman