Profile for joern

Display name
joernchen :cute_dumpster_fire:
Username
@joern@threatactor.club
Role
admin

About joern

Bio

Your mom's favorite hacker!

My other account is @joernchen

Stats

Joined
Posts
687
Followed by
1129
Following
261

Recent public posts

exclude boosts

IDK but all those AI prompt injections like

https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/

seem to rely on in-band signalling which could have been avoided at design time by having separate channels for configuration and user input. But instead the 70s are calling and want their cereal whistles back

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @postmodern@infosec.exchange
postmodern , @postmodern@infosec.exchange
(open profile)
speculation about layoffs and security posture
Toggle visibility

It's going to be interesting to see how the layoffs will impact security. According to birbsite and Mastodon, already some InfoSec people have been hit by layoffs. Fewer people means things stay broken longer, incidents take longer to respond to, etc. Meanwhile, hackers and ransomware gangs do not have to deal with layoffs... Guess who's going to have the competitive advantage?

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @tomituominen@infosec.exchange
Tomi Tuominen , @tomituominen@infosec.exchange
(open profile)

CALL FOR PAPERS T2’23

Tired of your bosses suspecting conference trips to exotic locations being just a ploy to partake in Security Vacation Club? Prove them wrong by coming to Helsinki, Finland on May 4-5 2023! Guaranteed lack of sunburn, good potential for rain or slush. In case of great spring weather, though, no money back.

CFP and registration both open. Read further if still unsure:
t2.fi/2023/01/19/call-for-pape

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @jiska@chaos.social
jiska πŸ¦„:fairydust: , @jiska@chaos.social
(open profile)

Want to learn mobile reverse engineering and security analysis on iOS πŸ“±πŸŽ but can't afford a training since you're a student? We'll do a free edition of day 1+2 of the Nullcon training end of February at TU Darmstadt. Drop me a DM if you're interested. Limited spaces, so better be fast πŸ”₯

nullcon.net/berlin-2023/traini

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @freddy@security.plumbing
Frederik Braun οΏ½ , @freddy@security.plumbing
(open profile)

Hey friends in ! Please remember to submit your research to the SecWeb workshop, a venue about building security for the web. The event is co-located with IEEE S&P in San Francisco (May 25) and our paper deadline os February 24th. We welcome new security flaws, solutions, wild ideas and even position papers. Let me know if you want to know more! secweb.work/2023.html

Please boost! πŸ”ƒ

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @hdm@infosec.exchange
HD Moore , @hdm@infosec.exchange
(open profile)

OK, so what does fidget mean? What information do you have around you, right now? Take a deeper look. Why is that WiFi AP named XNF998FE? Why is your laptop's serial number XY3327S? How often is that helicopter circling? Why are so many license plates from a particular state with a specific prefix? Look for the lack of entropy that is an encoded signal.

In the early Metasploit days this involved dumping function addresses of DLLs from a literal binder of DVDs. The opcode database and later analysis by folks like skape (matt miller) and spoonm made exploit development much easier as a result.

Scanning the internet is easy. Understanding all the data coming back takes a lifetime. Grab some data dumps and sift through specific protocols and fields. Toss Fiddler at a Windows thick client (or enable HTTP event tracing).

We are flooded in dodgy software, weak numeration, and information leaks. Stop for a bit, breath, pick one, and go deep.

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @thedarktangent@defcon.social