home > posts
  • July 1, 2024
    HD Moore
    @hdm

    Today is a big day for OpenSSH patching: https://www.runzero.com/blog/openssh-servers/

    Amazing work as always by the Qualys security research team, you can find the full advisory on "regreSSHion" at https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt

    The OpenSSH release notes are a fantastic read as well, especially the bits about timing analysis: https://www.openssh.com/txt/release-9.8

    Lastly, if anyone else planning to drop SSH zero-day before summer camp, please give me a heads up, it's tough keeping a list of all of the cool research that our talk won't cover 😆

    ↪ reply
  • June 25, 2024
    HD Moore
    @hdm

    Is This the Blind Spot in K-12 Cybersecurity and Student Privacy? https://www.linkedin.com/pulse/blind-spot-k-12-cybersecurity-student-privacy-ray-zeisz-obrdc/

    ↪ reply
  • June 24, 2024
    HD Moore
    @hdm

    I really enjoy using the @trailofbits weAudit extension for VSCode; it took the place of the Bookmarks extension and markdown files for my code review work: https://blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/

    ↪ reply
  • June 21, 2024
    HD Moore
    @hdm

    "One Weird Trick" to find Kaspersky products in your network. Don't worry, we link the "Packing the K" video at the end:

    https://runzero.com/blog/kaspersky/

    ↪ reply
  • June 19, 2024
    HD Moore
    @hdm

    Off-path TCP hijacking in NAT-enabled Wi-Fi networks https://blog.apnic.net/2024/06/18/off-path-tcp-hijacking-in-nat-enabled-wi-fi-networks/

    ↪ reply
  • June 18, 2024
    HD Moore
    @hdm

    Completed traceroute with 108,165 tasks in 18s

    ↪ reply
  • June 17, 2024
    HD Moore
    @hdm

    High-severity vulnerabilities affect a wide range of Asus router models: https://arstechnica.com/security/2024/06/high-severity-vulnerabilities-affect-a-wide-range-of-asus-router-models/ via @dangoodin

    ↪ reply
  • June 16, 2024
    HD Moore
    @hdm

    @immibis@social.immibis.com this makes for a handy get-my-ip-and-region-from-the-cli too! curl https://www.cloudflare.com/cdn-cgi/trace

    ↪ reply
  • June 12, 2024
    HD Moore
    @hdm

    📺 ⏰ Tune in at the top of the hour (12pm US Central) for our next episode of runZero Hour! We are thrilled to welcome Brianna Cluck of @greynoiseio. We'll dive into Brianna's "x-files," her collection of fascinating payloads, & new threat intel insights. Register here 👉
    https://runzero.zoom.us/webinar/register/WN_mk62HbrzTaO6Fd9MO7LKCw#/registration

    ↪ reply
  • June 9, 2024
    HD Moore
    @hdm

    Oona Räisänen (@windytan) does amazing analysis and writes about it, the latest is no exception -- "Ultrasonic investigations in shopping centres" https://www.windytan.com/2024/06/ultrasonic-investigations-in-shopping.html

    ↪ reply
  • << View newer posts View older posts >>

Copyright 1998-2025 HD Moore