's Avatar

@digitalwarhead.bsky.social

Success is not final; failure is not fatal: it is the courage to continue that counts. https://darknetdiaries.com/

656 Followers  |  419 Following  |  23 Posts  |  Joined: 15.11.2024  |  1.9989

Latest posts by digitalwarhead.bsky.social on Bluesky

Why do you think they all wear masks?

27.06.2025 13:20 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
ICE Is Using a New Facial Recognition App to Identify People, Leaked Emails Show The new tool, called Mobile Fortify, uses the CBP system which ordinarily takes photos of people when they enter or exit the U.S., according to internal ICE emails viewed by 404 Media. Now ICE is usin...

New from 404 Media: ICE is using a new facial recognition app to identify people, leaked emails show. Point camera at person, reveal their identity. It uses the CBP system that records peoples' faces as they enter or exit the U.S. Now, turned inwards to be used by ICE www.404media.co/ice-is-using...

26.06.2025 16:45 β€” πŸ‘ 5881    πŸ” 3561    πŸ’¬ 432    πŸ“Œ 571
Preview
The Protesters' Guide to Smartphone Security Your phone is an essential tool, but it also represents a huge risk to your privacy and security. Understanding these best practices when it comes to securing your smartphone will help keep you and yo...

Full guide covers OpSec, burner phones, data protection, secure communications, and handling law enforcement interactions.
Read: www.privacyguides.org/articles/202...

09.06.2025 20:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Key takeaways: Use strong passphrases to unlock phone, minimize stored data, prefer Signal for messaging, know your legal rights, and consider leaving your main phone at home entirely. #LA #Protests #ICE #DigitalRights #ProtestSafety #OpSec #PrivacyMatters

09.06.2025 20:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

With recent protests and the documented surveillance conducted by law enforcement with aerial drones, protecting your digital privacy has never been more critical. Your smartphone can be both a powerful tool for coordination and documentation, and a significant security risk if not secured. πŸ§΅πŸ‘‡

09.06.2025 20:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
DHS Black Hawks and Military Aircraft Surveil the LA Protests Local police, state authorities, DHS, and the military all flew aircraft over the Los Angeles protests this weekend, according to flight path data.

New from 404 Media: here's our report on the aircraft circling above the LA protests. Local, state, DHS, military all flew. Left: aircraft from air base. Right: a distinctive high altitude/hexagonal flight pattern, looks like a Predator drone (it flew to border after) www.404media.co/dhs-black-ha...

09.06.2025 13:36 β€” πŸ‘ 451    πŸ” 211    πŸ’¬ 10    πŸ“Œ 9
Post image

A picture worth 0x3E8 words at Bsides Seattle. @00wham.bsky.social

19.04.2025 16:51 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
I Built a Mini Truck for Abandoned Railroads
YouTube video by prestongoes I Built a Mini Truck for Abandoned Railroads

Here's part one of his 3-part series. The series is great, but overall PrestonGoes is one of the best YouTube channels I've found. He's an incredibly genuine and positive guy and his videos are fun to watch.
youtu.be/FgOJwFLF26k?...

15.03.2025 02:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@abyssdomainexpert.bsky.social Absolutely loved your talk at HC Seattle last year. When I heard the @jackrhysider.bsky.social episode, I had to do some digging to see if it was the same person or someone else with an identical story lol. Glad to find you on here.

08.01.2025 20:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Bike Index – Darknet Diaries Have you ever got your bike stolen? In this episode we dive into the world of stolen bikes. Who does it and where do the bikes go? We talk with Bryan from Bike Index who investigates this.

Thank you Jack Rhysider and @DarknetDiaries for letting me tell the Bike Index story darknetdiaries.com/episode/153/

07.01.2025 15:18 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Well that was incredibly creepy lol. Nice work!

21.12.2024 07:19 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
I broke IKEA. (or, well, one of their delivery services.) πŸ”Š Just a fair warning - there are some perhaps annoying glitch sounds in the attached recording. The volumes are normalized to limit loud spikes, as they w...

Ok, this is brilliant. @sirocyl.bsky.social set up a DTMF bomb on their voicemail message to spam DTMF tones to spammers and jam up their PBX systems. They accidently broke Ikea.
cohost.org/sirocyl/post...

21.12.2024 07:10 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

β€œif you don’t have a family then make one” okay fine im making an ai family for the holidays

27.11.2024 05:58 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

No I haven't had to log in since creating my account πŸ€·β€β™‚οΈ

27.11.2024 03:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@fixit42.bsky.social Heya FixIt! πŸ’œ

26.11.2024 14:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

the friends of cabal starter pack!
go.bsky.app/JAR9jhy

23.11.2024 22:35 β€” πŸ‘ 9    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

No, not personally. This was one of the challenges on OWASP's WebGoat, and I figured I'd make a post about it.

25.11.2024 22:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@owasp.org too

25.11.2024 15:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@johnhammond.bsky.social should definitely be on this list. He puts out great content.

25.11.2024 15:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - WebGoat/WebGoat: WebGoat is a deliberately insecure application WebGoat is a deliberately insecure application. Contribute to WebGoat/WebGoat development by creating an account on GitHub.

Shout out to @owasp.org and github.com/WebGoat/WebG... for putting together this great example!

24.11.2024 21:59 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Tips to stay safe from cookie hijacking:
βœ… Websites: Use random, encrypted session cookies over HTTPS.
βœ… Users: Log out after use, enable MFA, and avoid untrusted networks. Protect your cookies and keep hackers out! πŸ”

24.11.2024 21:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

We intercept the login request as Admin, swap in the cookie we created for Tom, and boom β€” we're logged in as him! πŸ•΅οΈ This is cookie hijacking in action. Weak session cookies can expose accounts. Secure cookies save lives! πŸ›‘οΈ

24.11.2024 21:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image

The decoded cookies reveal plain text:
Webgoat: nzozZtxkdKtaogbew
Admin: nzozZtxkdKnimda
Reversing these strings, we see the username is reversed at the end.
To impersonate Tom, we reverse β€œTom,” encode it in hex, then Base64. Crafting Tom’s session cookie lets us hijack his account! 😱

24.11.2024 21:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Post image

Authentication cookies like spoof_auth are often Base64 encoded. If predictable, they can be exploited! Logging in with credentials we know of such as Webgoat and Admin, we find:
Webgoat: NmU3YTZm...
Admin: NmU3YTZm...
Decoded, these cookies reveal hex patterns. Time to exploit them! πŸ”“

24.11.2024 21:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

What is cookie hijacking? πŸͺπŸ”’
Authentication cookies keep you logged in, but if they're predictable, hackers can use them to impersonate you. Let’s explore how a vulnerable site can be exploited to log in as someone else. Stay tuned! πŸ•΅οΈβ€β™‚οΈ

24.11.2024 21:59 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
-----BEGIN PGP MESSAGE-----hQIMA3PiNz2hRYmGAQ/+IAKjSSRVXEY4bFVp0Q9uPpZy1a/Zx - Pastebin.com Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

@gachikuku.bsky.social
pastebin.com/mhm4u0Mk

24.11.2024 07:39 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@bryanbrake.bsky.social you may be interested in this starter pack.

21.11.2024 23:27 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@jameskettle.com has put together a great starter pack for bug bounty hunters and InfoSec creators on BlueSky. #infosec #bugbounties #contentcteators
go.bsky.app/GD7hKPX

21.11.2024 23:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@digitalwarhead is following 19 prominent accounts