shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

291
active users

#typosquatting

0 posts0 participants0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.ar.al/@aral" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>aral</span></a></span> <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>EUCommission</span></a></span> <span class="h-card" translate="no"><a href="https://social.nlnet.nl/@nlnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnet</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@letsencrypt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>letsencrypt</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@cacert" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cacert</span></a></span> not only that, I think we need self-governing namespaces similar to <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> (even tho they are prone to <a href="https://infosec.space/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a>-esque <a href="https://infosec.space/tags/sibil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sibil</span></a>/#EvilTwin-style <a href="https://infosec.space/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> attacks!)...</p>
0x40k<p>Alright, Go developers, listen up! 🚨 Seriously crazy stuff is happening in the Go world right now. We're talking major typosquatting issues. Attackers are slithering in and spreading malware via fake packages, can you believe it?</p><p>So, for goodness sake, pay super close attention to the names of your modules! One little typo and bam! You've got yourself a nasty infection. As a pentester, I see this kind of thing all the time, sadly. Tiny mistakes, HUGE consequences. This malware then installs a backdoor. Totally not cool, right?</p><p>Therefore, check your imports, folks! And make sure you're getting your devs trained up on security. Automated scans? Nice to have, sure, but they're absolutely no substitute for a manual pentest! What are your go-to tools for fighting this kind of attack? Oh, and yeah, IT security *has* to be in the budget, that's just the way it is.</p><p><a href="https://infosec.exchange/tags/golang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>golang</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a> <a href="https://infosec.exchange/tags/pentesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pentesting</span></a></p>
Scripter :verified_flashing:<p>Jetzt trifft es auch Go: Bösartiges Typosquatting im Ökosystem entdeckt | heise online<br><a href="https://heise.de/-10270016" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">heise.de/-10270016</span><span class="invisible"></span></a> <a href="https://social.tchncs.de/tags/Programmiersprache" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Programmiersprache</span></a> <a href="https://social.tchncs.de/tags/Golang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Golang</span></a> <a href="https://social.tchncs.de/tags/Typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Typosquatting</span></a> <a href="https://social.tchncs.de/tags/TyposquattingPaket" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TyposquattingPaket</span></a> <a href="https://social.tchncs.de/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://tiggi.es/@DeltaWye" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>DeltaWye</span></a></span> <span class="h-card" translate="no"><a href="https://corteximplant.com/@SynAck" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>SynAck</span></a></span> <span class="h-card" translate="no"><a href="https://pounced-on.me/@Kuniti_shino" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Kuniti_shino</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.de/@ErikUden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ErikUden</span></a></span> OFC that's the nature of most services tht are open t new users.</p><ul><li><a href="https://infosec.space/tags/Abuse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Abuse</span></a> being a statistical inevitability:</li></ul><p><a href="https://infosec.space/tags/Shitter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitter</span></a> (rather <a href="https://infosec.space/tags/Teitter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Teitter</span></a> before <a href="https://infosec.space/tags/Mus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mus</span></a> ruined it!) had <a href="https://infosec.space/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://infosec.space/tags/RateLimiting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RateLimiting</span></a> to make <a href="https://infosec.space/tags/Spamming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Spamming</span></a> less effective (255 Statuses per 24hrs) even back when <a href="https://infosec.space/tags/TweetDeck" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TweetDeck</span></a> was a seperate company...</p><ul><li>Making dynamical limits that instantly lockout i.e. brand new accounts sending the same.message to 10+ others as a DM within 48 hours of registration should act as a speed-bump to <a href="https://infosec.space/tags/Spammers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Spammers</span></a>. </li></ul><p>It won't prevent it entirely but make it more cumbersome.</p><ul><li>Sadly <a href="https://infosec.space/tags/Mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a> <a href="https://infosec.space/tags/Developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Developers</span></a> <a href="https://github.com/mastodon/mastodon/issues/28605" rel="nofollow noopener noreferrer" target="_blank">refuse to acknowledge the need for efficient filtering.and ban list managment</a> that every other web-facing application / system can do using blocklist feeds.</li></ul><p>This prevents remediation and correction of <a href="https://infosec.space/tags/banlists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>banlists</span></a> &amp; <a href="https://infosec.space/tags/blocklists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blocklists</span></a>, leaving <a href="https://github.com/greyhat-academy/lists.d/blob/95bab7b3601030e7ad57bfc0516fa91362c8fcd5/blocklists.list.tsv#L21" rel="nofollow noopener noreferrer" target="_blank">a lot if domains burned forever</a> as the only.options are <em>"replace"</em> and <em>"merge"</em> and the average <a href="https://infosec.space/tags/ActivityPub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ActivityPub</span></a> admin or even <a href="https://infosec.space/tags/User" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>User</span></a> isn't going to learn or setup a <a href="https://infosec.space/tags/git" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>git</span></a>!</p><ul><li>which is frustrating as I maintain <a href="https://github.com/greyhat-academy/lists.d/blob/main/activitypub.domains.block.list.tsv" rel="nofollow noopener noreferrer" target="_blank">multiple</a> blocklists to help cleaning up the mess.</li></ul><p>I.e. there isn't really a good way to combat <a href="https://infosec.space/tags/Typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Typosquatting</span></a>-based <a href="https://infosec.space/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> beyond <a href="https://github.com/greyhat-academy/lists.d/blob/main/typos.domains.block.list.tsv" rel="nofollow noopener noreferrer" target="_blank">banning.offending domains</a>...</p>
Chuck Darwin<p>A malicious Python package named '<a href="https://c.im/tags/fabrice" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fabrice</span></a>' has been present in the Python Package Index (PyPI) since 2021, <br>🆘 stealing Amazon Web Services credentials from unsuspecting developers.<br>According to application security company&nbsp;Socket,&nbsp;<br>⚠️the package has been downloaded more than 37,000 times and executes platform-specific scripts for Windows and Linux.<br>The large number of downloads is accounted by fabrice&nbsp;<a href="https://c.im/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a> the legitimate SSH remote server management package “fabric,” a very popular library with more than 200 million downloads.<br><a href="https://www.bleepingcomputer.com/news/security/malicious-pypi-package-with-37-000-downloads-steals-aws-keys/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/malicious-pypi-package-with-37-000-downloads-steals-aws-keys/</span></a></p>
Joachim Viide<p>TIL that running <code>npx foo/bar</code> instead of <code>npx @foo/bar</code> downloads and executes the github.com/foo/bar repo as a package 👍</p><p>Also learned that in a CI context (i.e. when environment variable <code>CI=1</code>) <code>npx</code> doesn't wait for confirmation 👍👍</p><p>On a completely unrelated note, here's a neat way to typosquat some NPM packages:</p><ul><li><p>Find a legit project that recommends running their tool with <code>npx</code>. For example <a href="https://github.com/reactjs/react-docgen/tree/main/packages/react-docgen-cli" rel="nofollow noopener noreferrer" target="_blank">@react-docgen/cli</a> hosted under ReactJS's GitHub org.</p></li><li><p>Check whether the NPM scope name is available as a GitHub user/org name. For example <a href="https://github.com/react-docgen" rel="nofollow noopener noreferrer" target="_blank">react-docgen was</a>.</p></li><li><p>Create a repo that matches the tool name but contains your own code. Like <a href="https://github.com/react-docgen/cli" rel="nofollow noopener noreferrer" target="_blank">github.com/react-docgen/cli</a>.</p></li><li><p>Wait for someone to accidentally forget the @ and run <code>npx your/package</code> in a CI context.</p></li><li><p>Repeat <a href="https://github.com/semantic-ui-react/bootstrap" rel="nofollow noopener noreferrer" target="_blank">for</a> <a href="https://github.com/highlight-run/sourcemap-uploader" rel="nofollow noopener noreferrer" target="_blank">multiple</a> <a href="https://github.com/firebaseextensions/fs-bq-import-collection" rel="nofollow noopener noreferrer" target="_blank">packages</a>.</p></li></ul><p>FWIW, reported this to GitHub - that also owns NPM - through HackerOne. The response: "This is an intentional design decision and is working as expected. We may make this functionality more strict in the future, but don't have anything to announce right now. As a result, this is not eligible for reward under the Bug Bounty program."</p><p><a href="https://infosec.exchange/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://infosec.exchange/tags/npm" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>npm</span></a> <a href="https://infosec.exchange/tags/NodeJS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NodeJS</span></a> <a href="https://infosec.exchange/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a></p>
Alexandre Dulaunoy<p>There is a GPT in ChatGPT which is typosquatting the name of Sora to do rickrolling... So there is no evaluation of new GPTs by OpenAI? </p><p><a href="https://infosec.exchange/tags/openai" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openai</span></a> <a href="https://infosec.exchange/tags/chatgpt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>chatgpt</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a></p>
Alexandre Dulaunoy<p>FIRST.org released the videos from Montreal FIRSTCON2023 including the presentation I did about <span class="h-card" translate="no"><a href="https://social.circl.lu/@circl" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>circl</span></a></span> typosquatting-finder</p><p>Typosquatting finder Python library - <a href="https://github.com/typosquatter/ail-typo-squatting" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/typosquatter/ail-ty</span><span class="invisible">po-squatting</span></a></p><p>Online version of the typosquatting-finder service: <a href="https://typosquatting-finder.circl.lu/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">typosquatting-finder.circl.lu/</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> </p><p>cc <span class="h-card" translate="no"><a href="https://infosec.exchange/@firstdotorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>firstdotorg</span></a></span> </p><p>Video: <a href="https://www.youtube.com/watch?v=s09VFkI4Fn0" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/watch?v=s09VFkI4Fn</span><span class="invisible">0</span></a></p>
Alexandre Dulaunoy<p>We released a new version of the typosquatting Python library </p><p>🔗 Source code - <a href="https://github.com/typosquatter/ail-typo-squatting" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/typosquatter/ail-ty</span><span class="invisible">po-squatting</span></a><br>🔗 Online version - <a href="https://typosquatting-finder.circl.lu/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">typosquatting-finder.circl.lu/</span><span class="invisible"></span></a></p><p>The library has been improved to remove potential TLD/gTLDs which do a catch all for any domain. A random string is queried while testing to limit potential false-positive.</p><p>Another option has been added to combine algorithms together. </p><p><a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a> <a href="https://infosec.exchange/tags/python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>python</span></a> <a href="https://infosec.exchange/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>