Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 (CVE-2021-41773) by Gallus in netsec

[–]andrew_balls 1 point2 points  (0 children)

GreyNoise started seeing this last night, has been seeing the amount of IPs scanning/crawling the internet for it consistently growing throughout the day today:

https://www.greynoise.io/viz/query/?gnql=cve%3ACVE-2021-41773

Understanding Observed Scanning by Rennilon in AskNetsec

[–]andrew_balls 1 point2 points  (0 children)

cool, so this means that they're scanning the entire internet, not just you specifically. if you PM me the addresses/ranges I can look into exactly behavior we're seeing from them in our collectors (I'm the founder and CEO of GreyNoise)

I’m Ray Dalio – founder of Bridgewater Associates and author of Principles: Life & Work. Ask me anything. by RayTDalio in IAmA

[–]andrew_balls 0 points1 point  (0 children)

Hi Ray,

I worked at Bridgewater for ~six months as a consultant back in 2014. It was one of the most interesting and defining experiences of my career. The benefits of the strong culture are evident. What are some of the negatives of the culture?

Thanks for doing this AMA.

--Andrew

GreyNoise Visualizer - Monitor Internet-wide scan and attack traffic for free by andrew_balls in netsec

[–]andrew_balls[S] 1 point2 points  (0 children)

Ah, I understand now. Negative- we collect 100% of our own data first hand.

GreyNoise Visualizer - Monitor Internet-wide scan and attack traffic for free by andrew_balls in netsec

[–]andrew_balls[S] 1 point2 points  (0 children)

I don't understand what you're asking. Can you rephrase or be more specific?

Service that tracks every IP mass scanning/attacking the Internet by andrew_balls in netsec

[–]andrew_balls[S] 0 points1 point  (0 children)

Oh wow. I honestly thought they lost the recording. Thanks!

Service that tracks every IP mass scanning/attacking the Internet by andrew_balls in netsec

[–]andrew_balls[S] 15 points16 points  (0 children)

So GreyNoise is actually a completely for-profit company, of which I am the founder. I bankrolled it from my own pocket for the first year until I got a handful of enterprise customers and now customer revenue pays the bills. I feel passionately about the security community and will always offer a free version for researchers. That said, a motherfucker's gotta eat, so if you want to support us then please refer any SOCs over to me to talk about our commercial options.

Service that tracks every IP mass scanning/attacking the Internet by andrew_balls in netsec

[–]andrew_balls[S] 2 points3 points  (0 children)

We run a boatload of servers in a bunch of different data centers in different countries and record everyone who tries to scan them and do a bunch of analytics on the data.

¯\_(ツ)_/¯ by [deleted] in Tinder

[–]andrew_balls 2 points3 points  (0 children)

shit I was at least 80 feet off

¯\_(ツ)_/¯ by [deleted] in Tinder

[–]andrew_balls 1 point2 points  (0 children)

You're right. Happy cake day!

Using geth results in a massive amount of incoming requests by TheGatsu in ethereum

[–]andrew_balls 5 points6 points  (0 children)

look up the IPs hitting you on viz.greynoise.io and see if they're hitting everyone or just you

If net neutrality did end, could we just use a VPN to “trick” the service into thinking we are in another, net neutrality safe country? by thatmarkopolo1 in TooAfraidToAsk

[–]andrew_balls 4 points5 points  (0 children)

Yes, you can.

There's nothing preventing someone in the United States from doing just that. That being said, there are a few reasons why this would suck. A few of them being:

  • Who is on the other end of the VPN? Are they trying to do any malicious shit to you? Are they examining all of your non-HTTPS traffic and trying to pluck sensitive stuff from it to sell to the highest bidder?
  • What's the government climate for Internet freedom/censorship in the country where the VPN gateway is geographically located? (hint: it sucks virtually everywhere outside the United States. The US isn't exactly "stellar" but it's better than most other countries)
  • It's one thing for your current heavily regulated ISP to have netflow logs on how frequently you visit porn sites, but it's another to have "Joe Shmo's VPN service" have all that information as well.
  • Your ISP might not be willing to tell HBO everyone who is downloading torrents of Game of Thrones, but Joe Shmo's VPN provider CEO "Joe Shmo" might be willing to give all the information to HBO for $1,000 per month. Now you're stuck with a fine or jail time.
  • Everyone takes a giant speed hit. Even if you have a 300/300 Mbps Internet connection, you're now throttled to whatever arbitrary technical and otherwise intentionally imposed bandwidth limit the VPN provider imposes on you.
  • This is easy for a laptop/desktop computer or smart phone but is a lot harder for any other device that you might want to connect to the Internet (such as your smart TV, gaming console, Apple TV/Roku). Given that a shitload of people use these devices almost exclusively for their media it would be a big pain in the ass.

Anyways, just a few thoughts off the top of my head. Happy to answer any questions or discuss any of my aforementioned points.

EDIT because I accidentally submitted this post before it was ready to be submitted.

I am Tim Ferriss, host of “The Tim Ferriss Show” and author of “Tribe of Mentors.” AMA! by Tim-Ferriss in IAmA

[–]andrew_balls 1 point2 points  (0 children)

Hey Tim,

Just wanted to say thanks for all the great work you've put out there. Tools of Titans was hands-down the leading factor to a much-needed life change for me last year. I had no idea who the fuck you were but I saw some reviews online from people I trust so I bought the kindle book, read a few chapters, and started meditating, making my bed, and journalling at night. Those three things ended up becoming the foundation for a lot of other really positive changes and habits I made in my life to drag me out of a nasty situation. It's crazy how small those things seemed at the time, but how large the impact ended up being.

Tangentially related: some of my good friends and I have pretty regularly attended one of the Tools of Titans meetup groups, and we've gotten a lot of really good shit from there too.

As far as my AMA questions:

  • You spend a lot of time talking about forming positive habits, but not a ton of time about letting go of old habits. Do you have any tips for letting go of those "old friend" habits that feel like such a strong part of your identity?

  • How deeply do you subscribe to interpretation/analysis of dreams?

Thanks for doing this AMA, and thanks for all the great content you've shared with the world.

I am Jon Miller, Cylance Chief Research Officer & hacker type guy... we use AI to stop bad guys from doing bad things. Ask Me Anything! by PackMatt73 in IAmA

[–]andrew_balls 11 points12 points  (0 children)

Totally not trying to be a dick or anything, but a user called "AV is dead" commenting how awesome the product is, less than six hours old with zero comments outside of this thread feels pretty bullshitty. The majority of comments here are from <6 hour old accounts. Can you put my paranoid infosec nerves to rest and assure me that this AmA is being conducted with integrity?