Will Dormann is on Mastodon

Will Dormann is on Mastodon

@wdormann.bsky.social

I play with vulnerabilities and exploits. While this site initially showed promise, I've grown tired with its lack of improvement. You'll find me @wdormann@infosec.exchange on Mastodon.

1,735 Followers 251 Following 146 Posts Joined Apr 2023
6 days ago

It is much more difficult to stock it when it's locked, yes.

0 0 0 0
2 months ago

Social media user swipes left on a picture in a post with multiple pictures in their web browser...
Twitter, Mastodon: Swipes to next picture.
BlueSky: Do nothing.

I get that when Twitter doused itself in gasoline and lit a match, BlueSky had potential.

But seriously. How is the web app SO BAD? πŸ€¦β€β™‚οΈ

0 0 0 0
3 months ago

Social media user double taps image in their web browser...
Twitter, Mastodon: Zoom in.
BlueSky: Close image, re-open it.
πŸ€¦β€β™‚οΈ

0 0 2 0
5 months ago

There is nothing that distinguishes a CVE that is disputed because it's fake and one that is disputed because the vendor didn't want to acknowledge it.
This is a problem.

0 0 0 0
9 months ago

Did one really need to look any further than hearing that it used "bitcoin style encryption"?

4 0 0 0
10 months ago
Post image Post image

Eh, I just enabled passwordless for my 20-year-old hotmail account.
And RDP still accepted my old password. (No Microsoft Authenticator required)
πŸ€·β€β™‚οΈ

1 0 0 0
10 months ago

When you log in to windows using a Microsoft account (eg hotmail), you can use that account's credentials to RDP in.
No RDS AAD or web view here.

2 0 1 0
10 months ago

I don't know what RDS AAD is.
Simple repro:
1) Log in to Windows 11 with a Microsoft account (eg hotmail)
2) Enable RDP
3) Connect to Windows via RDP using hotmail account
4) Change hotmail password
5) Connect to Windows via RDP using old hotmail password

2 0 1 0
10 months ago

I'm using a web browser for this website.

1 0 0 0
10 months ago
Video thumbnail

Testing GIF upload from an iPhone...

0 0 1 0
10 months ago

With BlueSky, animated GIFs are uploaded with the video icon.
Because GIF89a files are clearly videos and not images.
Cross-posting apps don't recognize this silly behavior. (Yet??)

0 0 2 0
1 year ago
Post image

If the desire is to implement your own homemade WDAC block policies, tread lightly. If you simply apply a "block this thing" policy, you might very well end up preventing Windows from booting, as a "block this thing" without a corresponding "allow this", well...
WDAC will only block and not allow.😬

0 0 0 0
1 year ago
Preview
GitHub - mattifestation/WDACTools: A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies - mattifestation/WDACTools

If you wish to inspect an on-device (binary) policy file, you'll need WDACTools: github.com/mattifestati...

With this, you can run ConvertTo-WDACCodeIntegrityPolicy to get a stripped-down human-readable XML policy.

3 1 1 0
1 year ago
GitHub - vu-ls/applywdac Contribute to vu-ls/applywdac development by creating an account on GitHub.

If you enable HVCI and then run:
ApplyWDAC -auto -enforce
you'll be good to go, as it will pull the more-complete online list. github.com/vu-ls/applyw...

If you can't enable HVCI, you'd need to wait for MS to fix WDAC to get complete coverage. But that's not going to happen if I am to believe MSRC.

0 0 1 0
1 year ago

You've made both of these statements:

- Threat actors are manipulating the ICT to bypass detection
- Run the ICT checker

Doesn't the former sort of invalidate the latter? πŸ€”
Or is hope that you've got one of the not-so-good attackers that result in an ICT flagging something?

1 0 0 0
1 year ago

I suppose my gripe about the wording is that electricity itself has no sound.
*Physical objects* energized by electricity can emanate sound by vibration. πŸ˜€

4 0 1 0
1 year ago

Electric vehicles run on DC. Not AC.

9 0 2 0
1 year ago

"they can hear electricity circulating but not enough to power anything else"

I'm curious what electricity sounds like?

27 0 5 0
1 year ago

Sounds about right for the person who left the Superbowl early because Biden's Tweet got more attention than his. πŸ˜‚

But heck, drawing attention to your and @kateconger.com 's book is surely a good idea. Everybody should read it!

10 0 0 0
1 year ago
Post image Post image

No, I don't have a Facebook or Reddit account.
I suppose I was referring to Twitter and Mastodon.

With either of those you can upload a media thing (image, animated, GIF, MP4, etc.), and the trigger to do that is you click a single "media" button.

Separate buttons is completely unnecessary.

0 0 0 0
1 year ago

BlueSky is the first social media app I've ever used that has a different icon to pick depending on what file type the media is.

This seems unnecessarily complicated.

0 0 0 0
1 year ago

The fact that BlueSky decides to take the GIF I uploaded and convert it to MP4 does not change the fact that what I'm loading is a GIF file and not a movie file. πŸ€·β€β™‚οΈ

1 0 0 0
1 year ago
Video thumbnail

Wait...
Animated GIF images maybe need to be uploaded using the "Movie" icon, because GIF89a's are clearly not images? πŸ€”

2 0 1 0
1 year ago

There goes my hopes for a viable post-Twitter platform where we all hang out.
😑

1 0 0 0
1 year ago
Post image

Oh, BlueSky doesn't even support uploading animated GIFs.
FFS why is this platform so slow to improve?

3 0 2 0
1 year ago
Post image

So you have to use BlueSky directly to get animated GIFs? Lame...

1 0 1 0
1 year ago
Post image

Testing multi-posting app Croissant...

1 0 2 0
1 year ago
Post image Post image

Eventually your client will get throttled with an HTTP 429 (Too many requests), or the site will otherwise fail.
If you have a lot of posts to delete, it's going to take a while.
But is worth it, IMO.

1 0 0 0
1 year ago
Post image

You'll note that what you get is not just a blob of text that you'll have to grep through, but a FULLY FUNCTIONAL website including search! And all uploaded media will be there in the form that it was in on the Twitter website.
Delete away, friends!

1 0 1 0
1 year ago
Preview
Delete all <s>anime.exe</s> tweets Delete all <s>anime.exe</s> tweets . GitHub Gist: instantly share code, notes, and snippets.

2) Delete your posts. e.g. by pasting in this javascript to your authenticated web browser session's JavaScript console.
gist.github.com/nsuan/a2e42d...
Obviously closely inspect what you're about to paste, as pasting JavaScript into a web browser session can be VERY DANGEROUS.

2 0 1 0