* Posts by razorfishsl

972 publicly visible posts • joined 27 Feb 2014

Hiding a phishing attack behind the AWS cloud

razorfishsl

Re: checking url is bad advice when using outlook cloud shite

Becasue MS is deliberately trying to destabilize the security market so they can insert their own business & user offering.

They have gone out of their way to try and subvert any companies security tools as regards web links and redirects into AZURE masked by cloudflare..

Theri latest offering "microsoft-authenticator" which goes live next month with all MS accounts requiring 2FA is a literal GPS dog collar up every users ass...

it includes full GPS & BLE geo-location... under the guise of "security", not just when you want to 2FA but CONTINUOUS

razorfishsl

And Azure

Indian military ready to put long-range quantum key distribution on the line

razorfishsl

It will get stolen by China within 6 months to a years.

They have Hwawei kit all over china data centers....

Palo Alto bug used for DDoS attacks and there's no fix yet

razorfishsl

DELL SONICWALL

also has something similar due to their marketing dept

using the front page as a fucking advertising banner......

you can request a load of images from URLS without even logging into the firewall...

it works out at about 600-6000% amplification.

send a 40 byte request and get 400-600k of reply.

AI-friendly patent law needed 'as a matter of national security', ex-USPTO boss says

razorfishsl

Patents should be for Humans only,

This prevents greedy bastards entering all man kinds knowledge then using AI to mine it bare all for the sake of a $

Same with DNA, no one should be allowed to "patent " it, it would be like patenting chess moves.

Apple forgoes cooling systems in M2 MacBook Air

razorfishsl

Yep.. just like the filthy perverts in HK sitting on the MTR watching porn with school children about.....

I was walking behind a guy the other day that had a tablet showing full gay on gay porn.

That is shit that is going to be with me for the rest of my very short life.

razorfishsl

The issue is much of this crap is NOT field tested in Asia, even it is made there.

The result is the "water detectors" turn red even if it has never been near real water, and the units. are ALWAYS throttling in a factory env.

where >40Deg back ground is the norm.

It is a complete pain in the ass to not have any sort of cooling, unless ur an Eskimo.

British intelligence recycles old argument for thwarting strong encryption: Think of the children!

razorfishsl

Re: "govern"

it's a nonsense argument, it presupposes that the people you elect actually know & have control of the agencies.

Just take a look at the current things the civil service is doing, with left wing propaganda that benefits less than 2% of the population, all it requires is one radical in a position of power.

Outlook email users alerted to suspicious activity from Microsoft-owned IP address

razorfishsl

cannot be done......

and even on E3, it DOES NOT work wit tcpip v6 addresses!!!!!!

it ONLY works with TCPIP v4.

razorfishsl

iut is a deliberate policy, ready for the new microsoft protection systems they are selling.

they have DELIBERATELY removed critical functionality from 365 & azure then put it behind a pay wall.

A bit like inserting a DELIBERATE exploit into win10, that they did.

basically making it almost impossible to block the MS store in a business unless you are running the enterprise version... whilst still leaving in a policy for blocking the store, that actually does not work if it is enabled.

Then adding in a system for users to bypass any store block put in place ,by making the store accessible from 365 webmail & finally adding in a "linked in back door

it is all leading up to them selling "security services" in the cloud and them trying to force users into azure.

Then we have the dirty business of the MS authenticator

that PHYSICALLY track ANY user that has it on their device, providing telemetry data every 5 minutes back to MS!!!!

yep you thought it was just a random number+salt generator..... nope...... it is a GPS dog collar up your ass.

razorfishsl

Yep.. there is an "exploit" in the login systems of Microsoft. for azure & 365,

it is possible to login as the admin of someone else's 365 instance, if you "catch it right"

nope i'm not going to explain how to do it.

and also an attack exploit against accounts....

MS are NOT interested., they are even LESS interested once i told them i'm not here to work as a "free Q.A staff" for their company, have a massive long running case with them over another of their policies., where they are REFUSING support requests.

Basically this is part of the attack for 365:

You use azure to run your attack systems INSIDE MS azure & in some cases a 365 instance, now becasue you are running these attacks from inside they same system cloud as Ms 365 , most of the traffic is NOT SEEN externally.

you then run desktop instances of clients to leverage the attack(inside azure), get a user to click on a link and get an authentication token, ONCE YOU HAVE THIS YOU DO NOT NEED to log in again.

since MS azure sees the "fake" account as never moving or changing the security status. *(its running inside azure from MS data centers)

The login will NEVER appear inside the azure back end. under the normal authentication systems.

Futher more MS is totally unable to track & resolve TCPIP v6 addresses, there is NO WAY to filter the traffic or set any kind of triggers, country & other filters are useless.

(most mobile phone networks use tcpip v6)

once you have this login, you then leverage dummy email zones to match the users you are attacking, by using "names cheap" and google email re-directors

and start setting up filters to put ALL the users email into the ARCHIVE SPAM folder, at this point the hacker goes thru, reads the email , replaces or deletes the content & marks it as NOT spam, putting it BACK into the user email box.

they also setup dummy businesses with VERY similar names on "namescheap" but set the mx records to google.

They also POISON your address book, removing the "genuine" email addresses" and replacing it with poisoned ones. (same contacts , slightly different domain spelling)

Start typing an email address & you get the poisoned address, which redirects to their dummy domain so they can add "wares" before sending to the real recipients.

It is a highly efficient attack strategy, and they can run inside your business for months , gradually leveraging into customers & suppler systems using the same methods.

They are VERY VERY careful and become highly proficient on the running of the business & financials ,plus all systems related to money relases.

Ex-Coinbase manager charged in first-ever crypto insider trading case

razorfishsl

Ahhh yes "coinbase" again.....

Funny how they can never seem to get clean......

Amazon sues 10,000 Facebook Group admins for offering fake reviews

razorfishsl

No...

becasue you get Chinese supplier giving away products for free as "purchases" to get round this situation.

or sending out "fake" products as sales

it's an old game.

remember all the seeds they were sending out to get postal tracking data.

Is the $10 billion James Webb Space Telescope worth the price tag?

razorfishsl

Re: And the answer to the question is

video tape was invented.....

he did not need to watch them live....

Health trusts swapped patient data for shares in an AI firm. They may have lost millions

razorfishsl

Yep.. so they sold their patients out to get personal profit & then got ripped off

but then that company can sell the data on

Microsoft gives its partners power to change AD privileges on customer systems – without permission

razorfishsl

I have a very angry "support partner" who is spitting blood because i wont give them or allow Admin support in our tenant.

Even MS says "we have to" so that they can file "support" against any problems we might have....

apparently they have to go into your tenant and press the support button from INSIDE to get proper support from MS.

Seems like bullshit to me....

This was after finding that one of their staff had made an admin object that they "did not know what it was for or when it was made or by whom"

keeping in mind we are a publicly traded company... and "admin" has the rights to read every email.

Alibaba joins rivals in offering tool for those under pressure to reduce carbon emissions

razorfishsl

When they close down face book & twitter, THEN I will think about looking at my carbon footprint

But i'm damned if I'm going to worry about something whilst large % of the population is posting fucking cat pictures...

and lecturing me about being "green" and saving the planet.

Supply chain blamed amid claims of Azure capacity issues

razorfishsl

This probably accounts for ALL the problems related to 365 accounts suddenly going

"over quota" and not being able to download any more emails, even when 50% full.

And why all of a sudden "new" folders appear and are taken into account for the overall storage,

like Microsoft metadata files & folders.

they must have figured that it is impossible for users to exactly calculate their storage usage, and are stripping it back by bulking it out.

or staff suddenly loosing 100gb of storage in their 1 drive and being cut down to 50 putting hte account in the red, and MS taking a month to reinstate the storage with no compensation.

Google location tracking to forget you were ever at that medical clinic

razorfishsl

I wonder if Microsoft is going to do the same?

their authenticator app geo-locates/ BLE/GPS every 5 minutes (even they say it is 15..)

then REPORTS it back to AZURE, making it FREELY available to company/police and even 3rd party microsoft agents.

Open source body quits GitHub, urges you to do the same

razorfishsl

Re: What they do

The problem is they are "license stripping"

Taking code as an example but not including the license for that code.

Azure Active Directory logs are lagging, alerts may be wrong or missing

razorfishsl

LOL this is fuck all.....

I have found an exploit where an admin can log off a totally unrelated domain.... as in log off close windows.....

then using another admin account from a TOTALLY unrelated domain log BACK into that old domain.

as in a.com physically log out... close windows

B.com log BACK into A.com..... USING B.com auth.

So in theory a user with admin right is B.com , if caught right can gain access to A.com if they can catch it within say 5 minutes

Mysterious firm seeks to buy majority stake in Arm China

razorfishsl

Re: Chinese communist party

Yep they MUST hold onto ARM, becasue they have this problem with US tech.

in china 5% possession by the communist party makes them the owners of hte company, with a majority stake in every board decision...

oh... and you have to give them the 5% for free, nor is it tax deductible.

razorfishsl

Simple ... just close it down.

Microsoft Bing censors politically sensitive Chinese terms

razorfishsl

in the meatime they are building their own communist dictatorship.

much of MS website for admin & technical support now does not work with anything but edge.

The same inside 365 , it is gradually being locked down to ONLY work with hte MS browser.

Plus functionality is being removed from inside 365 to tackle hackers/spammers and fishing, only for it all to be put behind a per user paywall.

Tere used to be the ability to generate reports on domains contacting your domain...... came back a day later and it was gone.

Seems every-time i find something useful it dissapears.

and don't even talk to me about having paid $60,000 for corporate licenses , that require each computer to be connected to MS support in india for upto 3 hours

just to get the "upgraded" licenses into win 10 after the forced fuck of auto upgrade from win 10->win 11, they are still claiming they don't know what happened...

maybe.. but it is my fucking time & money they are wasting , dealing with this shit.

Export bans prompt Russia to use Chinese x86 CPU replacement

razorfishsl

you know..... it would be far more effective to recycle ewaste....

Microsoft points at Linux and shouts: Look, look! Privilege-escalation flaws here, too!

razorfishsl

They can kiss my ass

I found an exploit today in there azure, where i can get into an account that is signed out and not even using the same login details.

Seems if you can get the cookies of a logged OUT account, the login as admin to another , it auths you into the logged out account...

Reg reader rages over Virgin Media's email password policy

razorfishsl

more interesting is if the internal systems for VM use the same rules....

becasue that could be a massive problem....

China orders web operators to spring clean its entire internet

razorfishsl

War is coming......

I honestly thought i would make it completely thru my life without having to live thru a full war.

but is seems some factions are determined to have the biggie , another reason for all this work to get paperless money.

Microsoft's do-it-all IDE Visual Studio 2022 came out late last year. How good is it really?

razorfishsl

Re: "The top request for Visual Studio is a Linux version. Why?"

you need it for game development.

Unitiy... may people do development on other platforms

main problem is MS.... they did in OLE, foxpro and many other toys thrown out of the pram and STILL peopel don't learn a lesson.

Google Chrome's upcoming crackdown on ad-blockers and other extensions still really sucks, EFF laments

razorfishsl

Google ensuring it is the ONLY ad platform, and you aint gonna control the shit you see on your computer.

CentOS Stream 9: Understanding the new Red Hat OS release for non-Red-Hat-type people

razorfishsl

We just eradicated all our centos machines and will be starting on the other paid RH systems shortly.

Clearly they cannot be trusted to honor their commitments.

We spent a lot of time & money moving to 8, only to get shit on.

Flash? Nu-uh. Windows 11 users complain of slow NVMe SSD performance

razorfishsl

This of course has ABSOLUTELY NOTHING to do with the fact that this manufacturer & others

have recently been caught "substituting" chip-sets for cheaper less performant rubbish.

Same product "same specs" , but on an analysis several tech publications found removed chip numbers & changed controllers ,which wre known to be more problematic.

International Monetary Fund warns crypto-related risks could soon become systemic

razorfishsl

yep... but a Chinese company drops 300 billion and it's just chickenfeed...

IKEA: Cameras were hidden in the ceiling above warehouse toilets for 'health and safety'

razorfishsl

Like all registered charities that always have something kinky to hide.......

razorfishsl

Re: Excuses, excuses

Mc Donalds.....

'Cocaine spoon'

Totally harmless item everyone can carry...

Apple tried to patch this security hole in macOS Finder but didn't consider upper and lowercase characters

razorfishsl

Since Cook took over, Apple has continued its decline into windows territory....

But wHo caREs PROfItS are uP.

Apple responds to critics of CSAM scan plan with FAQs, says it'd block governments subverting its system

razorfishsl

It has nothing to do with kiddie porn.....

They just want to be able to run their classifier over every picture & video in a users private piece of kit.

it it designed to :

1. set a legal precedent

2. use existing material to train their A.I on other none related material.

3. allow their staff to access private content to validate results.....

think they over looked one small matter....

for their staff to validate the results.... it requires them to load the "kiddie porn" onto a viewing device controlled by apple, to be viewed by staff employed by apple...

or are they going to use a 3rd party?

Ex-NSA bigwig Chris Inglis appointed America's national cyber director by Senate

razorfishsl

It should be made a criminal offense to assist hackers by not patching computer systems....

Same way supplying items to a criminal to pull off a heist.....

Tim Cook: Sideloading is a disaster and proposed App Store reforms would harm user privacy and security

razorfishsl

Not so worried that he aint farming off all the private info of Apple users for the benefit of Apple.

That and starting to FORCE users onto Icloud as well as making macs very very difficult to manage in a corporate environment.

Biden expands Chinese tech and military blocklist to 59 companies

razorfishsl

Re: Guess what we found!

No becasue the report will be "secret"

razorfishsl

He needs to add "fs" to that list......

who are taking over from Hua wei.....

Deadline draws near to avoid auto-joining Amazon's mesh network Sidewalk

razorfishsl

Re: I wonder if...

it is very very hard at higher frequencies.

at about 1GHZ it's close to 1cm for a wave length.

the issue is that anything more than a 1CM gap allows higher frequencies in.

so air holes are out....

Generally metalised plastics do very well....

be 100% clear that unless your phone is "off" you are not off.

also "off" is not a physical state, it is a computer coded state that operates some mode inside the phone.

and as such can easily be bypasses to be "on".

the only real way is to remove the phone battery...... but strangely that's not an option any more......

razorfishsl

Yep but most of this shit is going to backfire spectacularly.....

WE were doing "Bag tracking" devices exactly the same as the apple "tile" credit card sized crap

it's an off the shelf product.

but then the Samsung .... let's burn the phones fiasco started & airlines banned the tech.

so all the bag tags with lithium batteries was banned, and now they are trying to re-introduce the tech.

China says its first Mars rover Zhurong has landed on the Red Planet

razorfishsl

You can bet it is there to leach off NASA signals.....

Bill to protect UK against harmful foreign investment becomes law

razorfishsl

Yep.... like you KNOW Apple are behind this with their lobbying.......

The time for this law was BEFORE ARM was sold to Chinese investors.......(go look into who & what REALLY owns ARM....)

Pentagon confirms footage of three strange craft taken by the Navy are UFOs (no, that doesn't mean they're aliens)

razorfishsl

and in some small office in the USSR. there are 3 guys laughing thier tits off....

That their China made drone with LED lighting fucked up a billion $ organization....

Spy agency GCHQ told me Gmail's more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it

razorfishsl

Both are exploitable.......

I wrote to google in 2011 about an exploit I found in gmail....

month later they replied back that , whilst it worked... Gmail was performing within spec....

As far as i know...it's still there....

1Password targets developers with Secrets Automation, acquisition of SecretHub

razorfishsl

1password

used to be good.......

you could have the standalone app and pay for upgrades...

Then they decided to fuck everyone and shove a money hose up your ass.

Converted it to a "cloud version" and started charging monthly,......

WTF would you want all your highly confidential p.w stored in the cloud?

THEN it leaked that the P.W were not actually protected..... when the app loads it totally decrypts all the p.w & stores them in memory.....

but that was spun...... to "it's highly unlikely that the p.w can be recovered in their un- encrypted state..."

UK reseller sues Microsoft for £270m in damages claiming prohibitive contracts choke off surplus Office licence supplies

razorfishsl

There is a complete "rip off" made by a Chinese software company called kingsoft

problem is...... you are replacing MS with perhaps a worse vendor...

razorfishsl

Re: Sympathy?

They do the same with fonts....

recently we found old documents had huge sections of empty areas....

so our old pdf/ stored document archive is basically useless...