Advertisement · 728 × 90

Posts by Patrice <GomoR> Auffret

Post image

📣 ANNOUNCEMENT: we have reached the 2,100+ scanned ports milestone, at Internet scale with a weekly refresh rate.

Next step: 5,000+ ports, weekly refresh. Then 10,000 by end of next year.

We will be the competitor number 1 to @censys.bsky.social in 2026.

#ASM #CTI #ASD

3 months ago 2 2 0 1
Post image

📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #MongoDB product:

CVE-2025-14847: remote unauthenticated memory reading #MongoBleed

search.onyphe.io/search?q=cat...

3 months ago 3 1 0 1

Perl

5 months ago 0 0 0 0
Preview
GitHub - bee-san/RustScan: 🤖 The Modern Port Scanner 🤖 🤖 The Modern Port Scanner 🤖. Contribute to bee-san/RustScan development by creating an account on GitHub.

RustScan est un outil de scan de ports écrit en Rust. Il mise tout sur la rapidité et se veut scanner l'ensemble des ports d'une machine en quelques secondes ⬇️

github.com/bee-san/Rust...

5 months ago 14 4 0 0

Cc @onyphe.io

10 months ago 0 0 0 0
A chart showing Internet scan data plots for three countries; Spain, Portugal and France. The three lines are stable, with minor variations from 09:00 to 12:30. At 12:30 the lines for  Spain and Portugal drop almost vertically to roughly 50% of their original levels. The line for France continues as for the start of the day.
The lines for Spain and Portugal have not returned to their original levels.

A chart showing Internet scan data plots for three countries; Spain, Portugal and France. The three lines are stable, with minor variations from 09:00 to 12:30. At 12:30 the lines for Spain and Portugal drop almost vertically to roughly 50% of their original levels. The line for France continues as for the start of the day. The lines for Spain and Portugal have not returned to their original levels.

The electrical power outage in Spain and Portugal as seen from the Internet (France included for reference)

11 months ago 2 2 0 1

Patch management is a multi-decade failure.

1 year ago 0 0 0 0
Post image
1 year ago 26 9 0 0
Preview
VPN Vulnerabilities Emerges As The Key Tool for Threat Actors to Attack Organizations

VPN Vulnerabilities Emerges As The Key Tool for Threat Actors to Attack Organizations

1 year ago 6 4 0 0
Installation | ONYPHE Installation

The latest version of our cli tool has been released. Get v4.19.0 and find wrappers with sweet new APIs inside.

Available here ➡️
search.onyphe.io/docs/onyphe-...

or here 🐳 hub.docker.com/r/onyphe/ony...

or even here 🥷 metacpan.org/dist/Onyphe

1 year ago 3 2 0 0
Advertisement

🧙‍♀️Cc @fs0c131y.com @gazlacrymo.fr @hacker0x01.bsky.social @gandalfistari.bsky.social @jnocetti.bsky.social @korben.info @tariqkrim.bsky.social @reesmarc.bsky.social @jeromenotin.bsky.social @oliviertesquet.bsky.social @patriceauffret.bsky.social @untersin.gr ça devrait t’intéresser 🪄

1 year ago 2 1 0 0

Mais il a bien dormi.

1 year ago 0 0 0 0

Oui enfin, c'est comme un moustique qui s'écrase contre le pare-brise d'une voiture.

1 year ago 0 0 0 0
Preview
RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access 

RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access

1 year ago 4 3 0 1
Post image

📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #PaloAltoNetworks PA product:

CVE-2025-0108: authentication bypass on management interface

search.onyphe.io/search?q=cat...

Thanks to @assetnote.io for having shared the detection method.

1 year ago 6 3 0 0
Preview
The XE Files - Trust No Router hack.lu 2024 On the 16th October 2023 Cisco Talos shared intelligence about a handful of compromised routers discovered while resolving customer support requests. As the full story unfolded, a handful of backdoore...

Yet by performing an awkward legal waltz around the subject, Talos have helpfully supported my hypothesis that compromised IOS XE devices are part of an ORB network serving multiple APTs.

archive.hack.lu/hack-lu-2024...

1 year ago 2 2 1 0
Preview
OpenRA Classic strategy games rebuilt for the modern era

"Command & Conquer : Red Alert" en version Open source :
www.openra.net

1 year ago 26 10 1 0

Roughly same numbers as @onyphe.bsky.social

1 year ago 1 0 0 0
Preview
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.

Back in the dayz the fake exploit did "rm -rf /" www.trendmicro.com/en_us/resear... #CTI

1 year ago 2 1 0 0

More than 50k *vulnerable* devices.

This one is pretty bad.

1 year ago 1 0 0 0
Advertisement

Don't expose DCERPC protocol on the Internet.

1 year ago 1 0 0 0

Je plussoie.

1 year ago 0 0 0 0
A Brief Introduction to OCI Containers on FreeBSD - Random Musings O for a muse of fire, that would ascend the brightest heaven of invention!

FreeBSD 14.2-RELEASE now includes OCI-compatible images, and the Podman toolkit is ready to use them, on both amd64 and arm64 systems - A brief Introduction by Dave Cottlehuber #FreeBSD #BSD

1 year ago 5 3 0 0

répondez à vos emails

putain dire que j'ai connu un temps où les gens répondaient à un FAX

1 year ago 60 3 12 0
2. **Truncated SHA-256 Hash Collisions**: The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.

2. **Truncated SHA-256 Hash Collisions**: The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache and deliver compromised images to unsuspecting users.

Stop. Truncating. Hashes.

www.phoronix.com/news/OpenWrt...

1 year ago 23 6 3 1
Post image

📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Mitel MiCollab product:

CVE-2024-35286: unauthenticated SQL injection on login page
CVE-2024-41713: unauthenticated arbitrary file read

www.onyphe.io/search?q=cat...

1 year ago 5 2 0 0

Certes. Mais un recruteur qui jette un CV parce qu'il fait plus d'une page ... Que peut-on en penser ?

1 year ago 0 0 1 0

#Cyberattaques : une étude dévoile la porte d'#entrée préférée des #ransomwares
www.01net.com/actualites/cyberattaques...

1 year ago 0 1 0 0
Advertisement

Cette "règle" est débile. 3 ou 4 pages, ça ne me choque pas, surtout après 20 ans d'XP.

1 year ago 1 0 1 0

Optimist: the cup is 1/2 full

Pessimist: the cup is 1/2 empty

Excel: the cup is January 2nd

1 year ago 6320 1463 68 127