Lukas Forst's Avatar

Lukas Forst

@forst.dev.bsky.social

engineer forced to talk to people, teaching cyber security at fel.cvut.cz, co-founder reconwave.com, previously co-founder mild.blue talks abou infosec, encryption, exploiting, engineering, guitars and music

65 Followers  |  235 Following  |  26 Posts  |  Joined: 05.11.2024  |  1.9414

Latest posts by forst.dev on Bluesky

Post image

Welcome Recon Wave as an organizing partner of the Honeynet Project Workshop 2025 in Prague! Recon Wave is a powerful attack surface monitoring platform that requires no installation or internal access.

๐Ÿ“… June 2โ€“4, 2025
๐Ÿ“ NTK, Prague
๐Ÿ”— prague2025.honeynet.org

#Honeynet2025

20.05.2025 15:07 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Speaking on @bsidesprg.bsky.social with @rozumbrada.bsky.social today!

04.04.2025 06:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

docs: WARNING do not pass untrusted data to this function!!!

devs: hm yeah my users are pretty trustworthy I think

19.02.2025 15:38 โ€” ๐Ÿ‘ 408    ๐Ÿ” 29    ๐Ÿ’ฌ 11    ๐Ÿ“Œ 1
Preview
Learn, Hack, Defend: Transforming Cybersecurity Education with MOOC | Artificial Intelligence Center | CTU Prague Our first-ever cybersecurity online course attracted over 1,500 students from 84 countries, proving that high-quality, hands-on security education can be accessible to all.

We officially closed the first edition of our Introduction to Security class as a Massive Open Online Course! After an incredible semester, the results are in, and we couldnโ€™t be more thrilled! Read more ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
www.aic.fel.cvut.cz/news/cyberse...

13.02.2025 14:07 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

As we're wrapping up our Cyber Security course at fel.cvut.cz we're sorting through the feedback and there's so much love coming from our students!

Looking forward to the next year!

03.02.2025 21:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

My latest work has been published:

"CTU Hornet 65 Niner: A network dataset of geographically distributed low-interaction honeypots"

The dataset has a unique value for studying the nature of Internet attacks over time and their changes and characteristics.

www.sciencedirect.com/science/arti...

13.01.2025 10:26 โ€” ๐Ÿ‘ 12    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why Your Business Needs External Attack Surface Management EASM secures businesses by identifying vulnerabilities, protecting data, and offering real-time threat monitoring for online operations.

Why Your Business Needs External Attack Surface Management

09.12.2024 16:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Quiz time: can you think of a single legit reason to put RSA private keys to DNS TXT records? Sounds like a nonsense but people really do that

We did a small research on this topic some time ago

09.12.2024 11:52 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stratosphere News #2 Words from the editor: Hello everyone! It has been yet another crazy month in our research laboratory! Attackers never stop, and this month that meant for us to urgently 'get more storage!' We hope yo...

What has Stratosphere been up to? You can find out in the second edition of our newsletter! Grab a cup of your favorite warm beverage and enjoy the read!๐Ÿง‰

www.linkedin.com/pulse/strato...

04.12.2024 09:19 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Avocados should come with little pop-up timers to signal before they become overripe.

03.12.2024 08:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

a bit of shameless self-plug, but we run some nice recon tools like search.reconwave.com that you might like

28.11.2024 09:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
a man wearing glasses and a plaid shirt is sitting in front of a computer and saying " help me " . ALT: a man wearing glasses and a plaid shirt is sitting in front of a computer and saying " help me " .

I actually enjoy being IT department. It's fun!

But it took quite a while to figure out things that I needed. Now it's mostly just copy paste.

21.11.2024 15:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hehe, it really helps when you're getting bombarded with things all the time. I know use it mainly to figure out if this needs my attention or not.

21.11.2024 08:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

it's awesome! it just highlights how inclusive they want to be

20.11.2024 17:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hello World ๐Ÿฆ‹!

19.11.2024 10:35 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

hello @reconwave.com!

19.11.2024 10:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I think it's because it is still small social network. And it's full of open minded enthusiasts.

Honestly, it feel so refreshing here.

19.11.2024 10:29 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Having Wordpress in your attack surface is problem by definition...

Best is to sandbox it as much as possible!

19.11.2024 10:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Out of curiosity, how do you keep track of what is exposed to the internet and what is not?

19.11.2024 09:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

> complexity breeds vulnerability

I'd sign that.

Companies have crazy big attack surfaces these days... And more often than not, they don't even know what they expose.

19.11.2024 09:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

more importantly, there will be so many bots as well...

it's beautiful when it's smaller!

19.11.2024 09:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Wow, this is awesome!

There're so many different and cool usecases for TXT records!

19.11.2024 08:41 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Totally random question - what is your opinion on TW? I started recently using it but I'm not 100% convinced.

I like that it really makes me more productive. But reading the code after that... that's pretty annoying at least.

18.11.2024 23:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I have a dream where I buy dumb TV and just plug my Raspberry for the "smart" component.

Sadly, this is not really possible anymore.

18.11.2024 22:58 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

... and if it is not, it's BGP

18.11.2024 18:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

When not DNS, it's BGP!

18.11.2024 16:37 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

6/8 โ˜„๏ธ So imagine this - all private and sensitive user data, including DMs stored on servers being moved by homeless people without any IDs and locked on truck with basic locks from Home Depot tracked by AirTags.

EU would've had mental breakdown.

13.11.2024 20:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

5/8 ๐Ÿš› Musk, his team and few homeless guys loaded servers onto trucks without protective crates, using basic straps bought from Home Depot. Guys moving the servers were paid $1 / server

At one point, they even used Apple AirTags to โ€œtrackโ€ the servers - the DIY chaos.

13.11.2024 20:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

4/8 ๐Ÿ”ช Declaring, โ€œThese things do not look that hard to move,โ€ Musk attempted to open floor panels with a pocket knife and crawled under the server floor to disconnect the equipment.

Yup, he literally cut power from servers with "fuck it, I'll do it myself".

13.11.2024 20:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@forst.dev is following 20 prominent accounts