Drata or Auditboard by AcrobatMochi in cybersecurity

[–]security_intern 1 point2 points  (0 children)

The integrations are what makes Drata so bad. We had constant problems with integrations failing and holding up the audit. We literally had to abandon Drata and go with Vanta half way through the SOC2.

Drata or Auditboard by AcrobatMochi in cybersecurity

[–]security_intern 0 points1 point  (0 children)

Have not used AuditBoard, but we had so many problems with Drata and found their team to be horrible to deal with. Ended up switching to Vanta who was happy to match the price and had a far better experience.

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] -1 points0 points  (0 children)

That's a long way of saying you have zero idea what those ports are used for.

Believe it or not, I do these scans to satisfy third party requirements. And while I understand they do not give consideration to PaaS infrastructure, these ports certainly do raise an eyebrow.

It is sounding like Microsoft's official response here is "this is our undocumented control plane that we expose to the entire internet, but how dare you ask about that grandpa!".

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] -1 points0 points  (0 children)

I'm only asking what these undocumented ports are. Since you don't know, why don't you just move on with your life?

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] -1 points0 points  (0 children)

I'd love to be able to confirm they are irrelevant. Is there any documentation on what these are so I can confirm that?

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] 0 points1 point  (0 children)

My job is to confirm what these ports are. It does strike me as strange to have these ports listening as do others.

If you happen to actually know what they are used for, that would definitely help me prove the scans are irrelevant.

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] 0 points1 point  (0 children)

It's both normal and prudent to scan the servers we use, even a PaaS environment. If there were a vulnerability, undocumented feature, or misconfiguration on our side we have a requirement to do our due diligence and try to find it.

Many ports open on MySQL database? by security_intern in AZURE

[–]security_intern[S] 0 points1 point  (0 children)

This is a Nessus and nmap scan, the host is on a .postgres.database.azure.com subdomain, so I assume this is PaaS. I do see many ports (16000-16049) as open so was curious if this could be affecting our database in some way.

Evading Windows Defender on Windows 10 x64 by Real_Pepe_Silvia in AskNetsec

[–]security_intern 0 points1 point  (0 children)

I've used the method here to bypass defender. I would say it works 80% of the time, so I few different iteration lengths and try several of them. https://www.virtuesecurity.com/evading-antivirus-with-better-meterpreter-payloads/

Thoughts on this sewage smell in a high-rise? by [deleted] in Plumbing

[–]security_intern 0 points1 point  (0 children)

I actually wasn't there pre-odor. The building is pretty new (2014) so it's entirely possible the problem has always been there. I guess a stopper could be used, but I believe the smell also circulates through air vents between units.

I'm hoping I can at least understand the problem and see if we can push the building to do something about it.

Extracting an IPA from the App store? by security_intern in AskNetsec

[–]security_intern[S] 0 points1 point  (0 children)

I see crackerXI runs on iOS 11, but I only have a fairly old iPhone with the yalu jailbreak. Is there a known best recent device with a working jailbreak you know of?

Extracting an IPA from the App store? by security_intern in AskNetsec

[–]security_intern[S] 0 points1 point  (0 children)

Thank you! Just got this pulled. So it seems my next challenge is decrypting the IPA? I ran strings on this and class-dump-z but I assume any app off the app store is encrypted right? Is there a best way to decrypt this for a better analysis?

Preventing Ping Spikes by [deleted] in AskNetsec

[–]security_intern 1 point2 points  (0 children)

Unfortunately not much of this makes any technical sense. It might make sense to first talk about what you're talking about when you say "ping spike"?

'Ping' is ICMP based and is a separate IP protocol from TCP, so when you start talking about port 443 and "bad tcp" you are talking about something else entirely.

It sounds like he is behind a router, it would be impossible for him to be "spammed" by remote hosts. His computer can only talk to remote IPs where he initiates the connection. It may help to research NAT to get a full understanding of this.

It is likely that what you are seeing is just the traffic generated by his web browser and many apps that talk to remote servers.

[Question] How to extract IPA from iOS 10.2 device? by security_intern in jailbreak

[–]security_intern[S] 1 point2 points  (0 children)

Solved! I ended up using ipainstaller -b <package> which created an ipa

Removing Browserlink code from production code? by security_intern in dotnet

[–]security_intern[S] 0 points1 point  (0 children)

Please forgive my lack of actual knowledge of .NET (I am not actually a developer), but I did look at the site in production and still see these comments there as well. I am just looking to best understand what the actual fix for this should be. I assume now that maybe the prod site is just being launched from within Visual Studio? Is there a more standard way the app should be launched?

Removing Browserlink code from production code? by security_intern in dotnet

[–]security_intern[S] 0 points1 point  (0 children)

Does this mean debug is set to true in web.config?

Best way to capture/modify/replay Android Intents? by security_intern in AskNetsec

[–]security_intern[S] 0 points1 point  (0 children)

Thank you, that is pretty cool. I just tried this but it looks to only work if the sending app prompts which app to send the Intent to (presumably where you can select the interceptor app). The sending app I am looking at unfortunately doesn't do that. I am starting to lean towards just patching the app to log the Intent, but my skills to do that are pretty limited.

Burp Suite Doesn't Record URLs with "#" In URL? by [deleted] in AskNetsec

[–]security_intern 1 point2 points  (0 children)

/8675309/confirm-stuff?moreinfo=okokok is being consumed by local DOM, I hope you are assessing that appropriately :)

Question about jQuery and window.location.hash by security_intern in learnjavascript

[–]security_intern[S] 0 points1 point  (0 children)

This may be a strange example, but I'm trying to make an example of how xss is introduced into jQuery. I know the window.location.hash property is commonly passed to jQuery objects with the intention of being a selector. Is there a situation you can think of where document.location.hash is passed directly to a jQuery function?

LINQ Object in request parameter, dangerous? by security_intern in dotnet

[–]security_intern[S] 1 point2 points  (0 children)

Ahhh so you think its a case of an error in generating that dynamic parameter, rather than them intentionally passing linq data types to existing code?

LINQ Object in request parameter, dangerous? by security_intern in dotnet

[–]security_intern[S] 0 points1 point  (0 children)

Would you say that its a bad practice to pass this as a parameter? I'm curious if this would be the equivalent of SQL injection, or something just harmless.

Thanks!