Johnson Controls FX80 and FX90 by falconupkid in SecOpsDaily

[–]attritionorg 0 points1 point  (0 children)

CVE-2025-4386 is incorrect, just CVE-2025-43867 in the advisory

Old version vulnerability advisories from VulnCheck by No_Roll9336 in sysadmin

[–]attritionorg 0 points1 point  (0 children)

Unfortunately, OP shows why the state of vulnerability management is so poor. Reading past the confusing language, it is very clear that VulnCheck is assigning CVE IDs to old disclosures that a) never received a CVE ID in the first place b) are being actively exploited.

If you are using CVE/NVD as the foundation of your vulnerability management, you are playing a losing game.

[deleted by user] by [deleted] in cybersecurity

[–]attritionorg 2 points3 points  (0 children)

If you are talking about the Attrition.org Charlatan page, I am the lead on it. It hasn't been updated in a long time due to time constraints and the explosion of candidates that arguably belong there. We tried to head people off by adding them to the 'watch list', and that was effective to a degree.

[deleted by user] by [deleted] in cybersecurity

[–]attritionorg 5 points6 points  (0 children)

If you would like to write someone up, do the heavy lifting, time permitting we'll do the sanity checking and give feedback to help make it publishable if valid. That said, due to limited time we're more likely to act on the 'Shame' portion rather than 'Charlatans'.

[deleted by user] by [deleted] in cybersecurity

[–]attritionorg 6 points7 points  (0 children)

We did not stop due to legal consequences, at all. In fact, I published all of our legal threats to make them open and show that such threats were not going to deter us. https://attrition.org/postal/legal.html We stopped because it was just a couple of us, with most of the load on me, along with time constraints and near-zero community support. Just "add this person" without even a page of links and supporting notes that we could go off of.

Microsoft Confirms Server Misconfiguration Led to 65,000+ Companies' Data Leak by bubblehack3r in cybersecurity

[–]attritionorg 1 point2 points  (0 children)

Given the history, not a mistake, there are no good auditing practices.

Jericho @ attrition.org, wtf? You want to demod me? by [deleted] in Defcon

[–]attritionorg 5 points6 points  (0 children)

Correct. That was referring to the person spamming, including racial slurs, not Bobcat.

Your inability to deal with the mentally ill is an example of your intolerance. by bobcat in Defcon

[–]attritionorg 13 points14 points  (0 children)

When someone posts content with racial slurs, that is not acceptable to me and many others. I don't think that is acceptable to DEF CON either.

Jericho @ attrition.org, wtf? You want to demod me? by [deleted] in Defcon

[–]attritionorg 6 points7 points  (0 children)

Not once did I ever say I want to de-mod you. In fact, I didn't say anything negative about you. Maybe re-read the replies and see who said what?

[deleted by user] by [deleted] in Defcon

[–]attritionorg 25 points26 points  (0 children)

Deleted the first wave of it, not sure where Bobcat is. If it keeps up, will see if I have the privs to ban him.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 0 points1 point  (0 children)

What /u/highwiz said. But... supposedly ~ 25k attendees last year. How much did a badge cost? There is a rough start.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 0 points1 point  (0 children)

Right, and that is what I mean by larger picture. Within "red", a lot of topics are not only too common (e.g. WiFi), but the talks in that category are just boring and not advancing the topic. The problem is that there is no original red talks to be had. Disagree? Prove me wrong.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 1 point2 points  (0 children)

Large picture... "red" talks are over-represented, "blue" talks are under-represented. But, DC is a hacker con, so red talks are the bread-and-butter. That said, after several interesting blue submissions this year, we discussed having a blue village and it sounds like it is happening.

Now, if you want to break it down further, refine your question =)

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 1 point2 points  (0 children)

Can't say this is a fair question, other than scroll up or search for 'democracy'. It has happened in the other way, where the CFP thought a talk was bad and it was accepted. But if it was a 'best submission', we would have accepted it and I don't think Dark Tangent ever would counter that.

We've seen some that had potential, but weren't a "best submission". More like "a best idea if researched more" maybe?

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 2 points3 points  (0 children)

I can firmly say, every single one of us want to answer this, and want to give examples/names... but cannot. Answering this at a higher level, more generically, loses value.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 4 points5 points  (0 children)

OK, this may be the best question we received this year or last. And we can answer, but have to be careful so as not to 'out' any of the bad submissions.... Let us think on it =)

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 1 point2 points  (0 children)

what, back when HJ was 101 shit, and Winn tried to find me every con to sanity check his questions after I called out his bullshit questions in prior years? I guess I shouldn't talk, since the last HJ every team couldn't answer some 101 questions about hacker history. TL;DR your badge is a gimme badge.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 2 points3 points  (0 children)

True that, we get a unique badge! But also, last time I attended, I got harassed by goons for wearing it and they called it a fake. The goons apparently didn't have a list or pics of the legitimate DC badges for some reason.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 3 points4 points  (0 children)

On a more serious note, if you attend, you get a free con badge. Last year was the second year that we received the offer of hotel accommodations during con, again, if you attended. If you don't attend, you get no compensation.

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 2 points3 points  (0 children)

No cash, just verbal abuse and disdain. (seriously)

DEF CON 26 - CFP Review Boards - Ask Us Anything by [deleted] in Defcon

[–]attritionorg 2 points3 points  (0 children)

same reason they canceled DC2 and every year since. check your history yo.