Skip Navigation

Posts
1
Comments
591
Joined
2 yr. ago

  • First read this

    Then use the following:

    alert tcp $HOMENET any - $EXTERNALNET 443 (msg:"[CIS] Emotet C2 Traffic Using Form Data to Send Passwords"; content:"POST"; httpmethod; content:"Content-Type|3a 20|multipart/form-data|3b 20|boundary="; httpheader; fastpattern; content:"Content-Disposition|3a 20|form-data|3b 20|name=|22|"; httpclientbody; content:!"------WebKitFormBoundary"; httpclientbody; content:!"Cookie|3a|"; pcre:"/:?(chrome|firefox|safari|opera|ie|edge) passwords/i"; reference:url,cofense.com/flash-bulletin-emotet-epoch-1-changes-c2-communication/; sid:1; rev:2;)

    And the following:

    alert tcp any any - any $HTTPPORTS (msg:"EMOTET:HTTP URI GET contains '/wp-content/###/'"; sid:00000000; rev:1; flow:established,toserver; content:"/wp-content/"; httpuri; content:"/"; httpuri; distance:0; within:4; content:"GET"; nocase; httpmethod; urilen:lt;17; classtype:http-uri; content:"Connection|3a 20|Keep-Alive|0d 0a|"; httpheader; metadata:service http;)

    And also this one:

    alert tcp any any - any $HTTPPORTS (msg:"EMOTET:HTTP URI GET contains '/wp-admin/###/'"; sid:00000000; rev:1; flow:established,toserver; content:"/wp-admin/"; httpuri; content:"/"; httpuri; distance:0; within:4; content:"GET"; nocase; httpmethod; urilen:lt;15; content:"Connection|3a 20|Keep-Alive|0d 0a|"; httpheader; classtype:http-uri; metadata:service http;)

  • I will simply copy/paste here then:

    I have a refurbished server rack system that is running Zeek and also Suricata. I have a managed switch that will duplicate all network traffic to the system that is running those applications and a JBOD setup to store the countless logs. I have scoured through nearly all the CISA documents and alert reports to copy the various Snort rules they mention in each report and also purchased a specific modem to connect with my ISP that provides a service to monitor my traffic that has Minim.

    I am a cybersecurity expert and still don't know what I'm doing most of the time, so this is literally scratching the surface, as well as only detecting threats not really stopping them which requires more knowledge.

  • I have a refurbished server rack system that is running Zeek and also Suricata. I have a managed switch that will duplicate all network traffic to the system that is running those applications and a JBOD setup to store the countless logs. I have scoured through nearly all the CISA documents and alert reports to copy the various Snort rules they mention in each report and also purchased a specific modem to connect with my ISP that provides a service to monitor my traffic that has Minim.

    I am a cybersecurity expert and still don't know what I'm doing most of the time, so this is literally scratching the surface, as well as only detecting threats not really stopping them which requires more knowledge.

  • I have nginx setup and acessing through a Cloudflare tunnel but still getting EMOTET issues detected by my IDS.

  • I do this already and also am inside an encrypted Cloudflare tunnel... Still getting EMOTET warnings from my IDS.

  • My Jellyfin server keeps getting pinged by EMOTET malware lately. Everyone here should be aware if you expose the Jellyfin port to the internet it will get data exfiltration attempts. Use strong passwords.

  • Send us all a maps pin on where y'all are getting hitched.

  • I have very in depth inside knowledge of the optical industry, and Oakley’s aren’t even good glasses.

    Please elaborate, because so do I and not only disagree with you, I have data to prove that Oakley are better. And I don't even own any, nor care to buy them.

  • To anyone wondering why, it is because it is Arch linux with pre-configured drivers and also it is one of the few distros that are on the bleeding edge of updates and features. Bleeding edge because one update might cut you and break everything for no reason. That being said, I've used Arch for almost a decade for my gaming PC and never had huge issues that reverting to the previous kernel at reboot did not fix.

  • I just read the entire article, and as a left leaning voter, the article was poorly written with factual issues and misinformation.

    It now makes me want to buy the Ruger SFAR to protect myself from the violent right wing MAGA morons.

  • Swiss can open carry in hunting areas with a license and allowed to store their own firearms and some duty fireams in their homes. They care more about to control the sales and storage of ammunition moreso than the actual rifles and handguns themselves.

  • Also, yes the OP of this thread is correct; the sweetener added to the capsules for all branded Advils are really nice, and the coating they put on all their pills allows for smoother swallowing (so smooth that I normally don't take them with water anymore). Literally nothing comes close this these fucking amazing pills they make.

  • The liquid gels are so profoundly better than the other types of pills that I've stopped purchasing any other brands or kinds of ibuprofen forever. Liquigels are the GOAT

  • Do you actually want to know the tools for each of the extensions you mentioned or just having a conversation here?

  • Dawn dish soap for both answers.

  • Literally all the extensions you mentioned can be viewed and edited in terminal by various tools.

  • I can’t think of a method for rn is viewing/editing documents

    What is the extension of document? I bet you money it's possible in terminal. PDF? docx?

  • Steam Machines were the solution, but no one fucking bought any of them so the market decided OPs desire was a waste of time and money.