HN user

aaronsdevera

207 karma

[ my public key: https://keybase.io/aaronsdevera; my proof: https://keybase.io/aaronsdevera/sigs/z3Q7SatfIx3VI6nWxjagw8QqYIcUYzvH2HAUpOk3veg ]

Posts31
Comments10
View on HN
rya.nc 9mo ago

Plugin Secure: Exploiting Ambiguous Serialization

aaronsdevera
1pts0
margin.re 1y ago

Civilian hackers in China's military cyber strategy

aaronsdevera
16pts0
webxray.ai 1y ago

WebXray: Search engine for cookie privacy violations

aaronsdevera
1pts0
github.com 2y ago

Observer Ward: Web application and service fingerprinting tool

aaronsdevera
2pts0
github.com 2y ago

Show HN: Sigkill, utility for decrypting and exporting signal chats

aaronsdevera
7pts1
old.reddit.com 2y ago

Signal to roll out usernames in 2024

aaronsdevera
5pts0
blog.aaronsdevera.com 2y ago

What link previews on messaging apps leak about you

aaronsdevera
1pts0
blog.aaronsdevera.com 2y ago

Detecting and blocking OpenAI crawlers with GreyNoise and Cloudflare

aaronsdevera
1pts1
medium.com 3y ago

Boom, bust and adjust: offensive cybersecurity industry trends and updates

aaronsdevera
3pts0
forum.torproject.net 3y ago

Tor v0.4.8.1 alpha gains proof-of-work mitigation against DOS attacks

aaronsdevera
41pts1
margin.re 3y ago

Analyzing Russian Internet Firm Yandex, Its Open-Source Code, and Contributors

aaronsdevera
2pts0
huggingface.co 3y ago

Threat actors using HuggingFace to deliver malware

aaronsdevera
2pts0
margin.re 3y ago

Russia’s Open-Source Code and Private-Sector Cybersecurity Ecosystem

aaronsdevera
1pts0
brew.sh 3y ago

Homebrew macOS package manager 2022 security audit [pdf]

aaronsdevera
6pts0
www.youtube.com 3y ago

Paradies Malware steals cryptocurrency from your clipboard

aaronsdevera
1pts0
github.com 4y ago

FOISted: A MikroTik Remote Jailbreak

aaronsdevera
3pts0
margin.re 4y ago

Jailbreaking MikroTik RouterOS

aaronsdevera
7pts0
connormcgarr.github.io 4y ago

No Code Execution? No Problem Living the Age of VBS, HVCI, and Kernel CFG

aaronsdevera
2pts0
shabarkin.notion.site 4y ago

1-Click RCE in Electron Applications

aaronsdevera
1pts0
cdn.muckrock.com 4y ago

The FBI's Steve Jobs Files [pdf]

aaronsdevera
3pts0
twitter.com 4y ago

Deng Xiaoping's CIA Visit

aaronsdevera
2pts0
margin.re 4y ago

MikroTik authentication revealed

aaronsdevera
180pts49
news.yahoo.com 4y ago

Suicide of clandestine Army operative raises mental health questions

aaronsdevera
6pts0
newsfeed.aaronsdevera.com 4y ago

Show HN: Personal News Feed

aaronsdevera
2pts0
github.com 4y ago

Show HN: Private Browsing

aaronsdevera
2pts0
old.reddit.com 4y ago

What are the methods of securing the geometry/textures used by Three.js?

aaronsdevera
1pts0
sector035.nl 4y ago

A comprehensive guide to determining dates and times in (online) media

aaronsdevera
1pts0
twitter.com 4y ago

Haroon Meer: Moxie’s post changed the tenor of discussions on Web3

aaronsdevera
7pts0
koolaidfactory.com 4y ago

The Kool Aid Factory: zines about the ways organizations coordinate

aaronsdevera
1pts0
twitter.com 4y ago

Electronic warfare history of the Battle of the Bulge

aaronsdevera
78pts65

I would love to try it, but I’ll wait until the registration pop up is gone and the HN attention stops DOSing the backend. But from the sound of the website description this is a next and welcome step in the semi intelligentification of anything

"Stage2.exe is a downloader for a malicious file corrupter malware. Upon execution, stage2.exe downloads the next-stage malware hosted on a Discord channel, with the download link hardcoded in the downloader."

Interesting technique.

or, you know, you could just paste this into the javascript console.

JSON.parse(window.localStorage.getItem("gameState")).solution

One thing I am incredibly cognizant of is the balkanization of the web. Different territories and privacy regimes will dictate various compliance steps... navigating this will be difficult. As a site operator I plan on collecting analytics accordingly, with a polymorphic payload that knows whats allowed to be collected where possible...

Reminds me of the residential proxy services known for fraud and hacking...

Google cache of TrendMicro report https://webcache.googleusercontent.com/search?q=cache:RUzFCa...

Looks like Tor Project is operating with a similar model, using Snowflake proxy users as a sort of broker onto the network.

Clever, but will be interesting to watch how this gets used. My testing so far of the Snowflake broker seems to have attracted less than benign hosts https://twitter.com/aaronsdevera/status/1473354766965035013