HEY Infosec Mastodon! Wanna help me out?
I'm looking for screenshotable quotes about pentesting. Wanna respond to any of these questions? If you do you may be included in my next talk!

What's the biggest pitfall a pentester can make?
What makes a good pentest?
What makes a bad test?
Vuln scan versus pentest - which one is "better"?

Or just whatever you want. I will include any memes I get, so reply away.
Boosts help :)

I keep hearing people say that Microsoft has finally come clean and provided an honest reckoning of the mistakes that led to the breach.

Allow me to push back on that HARD.

Wednesday's update is the first time Microsoft disclosed that hackers connected to Storm-0558 were inside the corporate network. In journalism parlance, Microsoft (intentionally?) buried the lede.

This allowed the company to omit key details we need to fully assess the damage these hackers did. How long were the hackers inside Microsoft's network? Did they access other data beside the crash dump? Were any other employee accounts hacked? How did they get in? Has Microsoft remediated whatever weakness or vulnerability made the network breach possible?

Storm-0558 is among the world's most skilled hacking outfits. As Microsoft observed: "The actors are keenly aware of the target’s environment, logging policies, authentication requirements, policies, and procedures. Storm-0558’s tooling and reconnaissance activity suggests the actor is technically adept, well resourced, and has an in-depth understanding of many authentication techniques and applications." In short, Storm-0558 has telemetry into Microsoft's network that's a par with Microsoft's own telemetry.

Storm-0558's technical tradecraft prowess is on full display by its ability to suss out a signing key in a crashdump made two years prior to the hack. It's further bolstered by the hackers' success in exploiting the failure of a Microsoft API to validate signatures properly.

So Microsoft reveals for the first time on Wednesday that Storm-0558 was inside its network. It provides no other details and doesn't respond to reporters' emails seeking them. And people say Microsoft has finally put the issue behind it?

Er, no. This should be the very beginning of the inquiry. We need to press Microsoft to answer these questions.

Wie genial ist das denn? Unter dem Motto "Weil Appelle nicht mehr reichen – Wer blockiert, muss mit fast dreimal höherer Strafe als bisher rechnen" Ab sofort kostet in #Wien das Falschparken im Gleisbereich der Tram oder auf der Busspur so viel ... wie eine Jahreskarte: 365 Euro. Das sind verkehrspolitische Zeichen - in Deutschland undenkbar.

Let's stop ! The showdown in the European Parliament is near! So, bombard your MEPs with phonecalls. You may phone them from Monday till Thursday. Together, we can stop this law.

If you don't know how to reach them, are afraid of high call fees or don't like to phone people, go to These guys made an app that makes callinh MEPs easy.

I ordered a gorgeous #lateart of #peppercarrot from @davidrevoy at Reissue Cafe in Tokyo.

It also felt cool that I was probably one of the only customers asking to reproduce a drawing they were formally allowed to use thanks to #CreativeCommons ❤️

Was gerade passiert, ist prägend für den Sport Fußball und die Gesellschaft. Ich bin froh und habe riesigen Respekt vor den Frauen, die jetzt dagegen aufstehen, um sich zu nehmen, was sie verdienen: Anerkennung, Respekt, Gleichberechtigung. Volle Solidarität mit ihnen. Wir als privilegierteste Gruppe der Gesellschaft (weiße Männer) dürfen das nicht ignorieren. Wir dürfen nicht wegsehen. Wir müssen realisieren, dass das die Regel und nicht die Ausnahme ist. Wir können etwas ändern.

Darum liebe ich ICE fahren: Es ist einfach toll, mit 300 Sachen durch die Republik zu rasen und neben bei in Ruhe seine Gummibärchen zu genießen.

I have a quite full schedule today... So many interesting talks and stuff. I would need n > 3 units of myself to visit everything I would like. Anyone having a that I can use?

Currently travelling with RE 5 to Rostock Central Station.
Train is (15 Minutes). Because of that, I cannot get my connection to Zehdenick. I changed my plans and travel to Gransee
ETA at : 17:00 - 18:00
Next change: Gransee.

Currently travelling with ICE 800 to Hamburg-Altona.
Despite the of the last train, I got my connection.
ETA at : 17:00 - 18:00 CEST
Next change: Central Station

Currently travelling with IC 1290 to Frankfurt (Main).
Train is . Therefore, it is unlikely that I can reach my follow-up connection. Zugbindung aufgehoben.
ETA at : 18:00 - 20:00 CEST
Next change: Munich central station.

En route to . Currently travelling with RB54 to Munich. Next change: Rosenheim

And.... online! I proudly announce that my known as ElshidsWolke7 is running. @torproject

"Inequality isn’t just an observable statistical phenomenon; it’s also a belief system. It comes from the idea that one group of people is better than another and that you deserve better things than someone else."

So! Jetzt habe ich auch mein für den 2023. Ich freue mich schon so!

Knapp am Ziel vorbei…
Familie aus Österreich will nach Kroatien - und landet in Rheinland-Pfalz

Stellt euch vor, ihr wollt in den Urlaub fahren und befindet euch knapp sechs Stunden später in der genau entgegengesetzten Richtung. Wie kann so etwas passieren?

#Salzburg #Westerwald #Osterreich #Urlaub #Kroatien #Familie #Verfahren

As we've long predicted, the misapplication of obscenity laws hasn't stopped with the most taboo content. Some states are now going after companies that support the LGBTQ community - and using these dangerous laws as justification.

