bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

251
active users

#dataexfiltration

0 posts0 participants0 posts today
CyberEthical.Me<p>💣 Full write-up for ToolPie this year's forensics challenge from Hack The Box Cyber Apocalypse CTF - Tales From Eldoria.</p><p>🔸 PCAP (network capture) analysis<br>🔸 Python bytecode, marshalling, decompiling</p><p>🔗 <a href="https://blog.cyberethical.me/htb-ctf-2025-forensics-toolpie" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.cyberethical.me/htb-ctf-2</span><span class="invisible">025-forensics-toolpie</span></a></p><p><a href="https://infosec.exchange/tags/CyberEthical" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberEthical</span></a> <a href="https://infosec.exchange/tags/CyberApocalypse25" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberApocalypse25</span></a> <a href="https://infosec.exchange/tags/HackTheBox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HackTheBox</span></a> <a href="https://infosec.exchange/tags/forensics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>forensics</span></a> <a href="https://infosec.exchange/tags/python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>python</span></a> <a href="https://infosec.exchange/tags/pcap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pcap</span></a> <a href="https://infosec.exchange/tags/wireshark" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wireshark</span></a> <a href="https://infosec.exchange/tags/EthicalHacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EthicalHacking</span></a> <a href="https://infosec.exchange/tags/blueteaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blueteaming</span></a> <a href="https://infosec.exchange/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://infosec.exchange/tags/dataexfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dataexfiltration</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.space/@mwdawson" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mwdawson</span></a></span> Yeah, just like <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> demands from anyone residing within the <a href="https://infosec.space/tags/USA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USA</span></a>, conducting business in the USA or having a parent/subsidiary operating in the <a href="https://infosec.space/tags/US" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>US</span></a>.</p><ul><li>Unlike <em>"<a href="https://infosec.space/tags/OpenAI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenAI</span></a>"</em> you can at least run <a href="https://infosec.space/tags/DeepSeek" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeepSeek</span></a> completely <em><a href="https://infosec.space/tags/airgapped" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>airgapped</span></a></em> and on-premise and thus prevent any <a href="https://infosec.space/tags/leaks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>leaks</span></a> or <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a>.</li></ul><p>Something <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a> work hard to let people do: KEEP <a href="https://infosec.space/tags/selfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfCustody</span></a> of their data!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@gurkanctn" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>gurkanctn</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> not just invading, but <a href="https://infosec.space/@kkarhan/113413999824933801" rel="nofollow noopener noreferrer" target="_blank">illegal</a>...</p><ul><li>Imagine if a Web Mailer (i.e. Protonmail) or eMail client (i.e. Outlook) were to scan your <code>/home/</code> directory and <em>preemptively upload</em> all the PDFs and OOXML files to OneDrive just in case you want to sent them from your laptop...</li></ul><p>This is called an <em>"info stealer"</em> and it's classified as a malware for <em>very good reasons</em>!</p><p><a href="https://infosec.space/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/Instagram" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Instagram</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StasiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StasiBook</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a> <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BDSG</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/PRISM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PRISM</span></a> <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.online/@nickali" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nickali</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> that's because they never faced actual accountability nor consequences.</p><ul><li>And I don't mean a fine, but actual jailtime! </li></ul><p><a href="https://infosec.space/@kkarhan/113413999824933801" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134139</span><span class="invisible">99824933801</span></a><br><a href="https://infosec.space/@kkarhan/113414012396154242" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134140</span><span class="invisible">12396154242</span></a></p><p><a href="https://infosec.space/tags/Accountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Accountability</span></a> <a href="https://infosec.space/tags/Consequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Consequences</span></a> <a href="https://infosec.space/tags/LackOfAccountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfAccountability</span></a> <a href="https://infosec.space/tags/LackOfConsequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfConsequences</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StadiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StadiBook</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mstdn.social/@femme_mal" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>femme_mal</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@Catawu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Catawu</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.sdf.org/@DamonWakes" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>DamonWakes</span></a></span> <span class="h-card" translate="no"><a href="https://merveilles.town/@lrhodes" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>lrhodes</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> either way I'm convinced this shit is so flatout illegal in the EU that it's literally a felony in places like Germany, where even having such functionality may fall under <em>"production, possession, distribution and use of tools to facilitate data manipulation and/or extraction against the owners' consent"</em> (<a href="http://gesetze-im-internet.de/stgb/__202c.html" rel="nofollow noopener noreferrer" target="_blank">§202c penal code</a>)...</p><p>But that's <a href="https://infosec.space/@kkarhan/113413999824933801" rel="nofollow noopener noreferrer" target="_blank">just</a> <a href="https://infosec.space/@kkarhan/113413981213042913" rel="nofollow noopener noreferrer" target="_blank">my opinion</a>, and <a href="https://infosec.space/tags/NotLegalAdvice" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NotLegalAdvice</span></a>! </p><p><a href="https://infosec.space/tags/EU" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EU</span></a> <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Germany</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/InfoSealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSealer</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://apobangpo.space/@jodmentum" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jodmentum</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> why is there no <em>"no thanks"</em> option with a tickbox <em>"don't ask me again"</em> next to it?</p><p>Pretty shure this violates <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> &amp; <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BDSG</span></a>!</p><p>Cc: <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>EUCommission</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@noybeu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>noybeu</span></a></span> <span class="h-card" translate="no"><a href="https://social.bund.de/@bsi" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bsi</span></a></span> <span class="h-card" translate="no"><a href="https://verbraucherzentrale.social/@Bundesverband" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Bundesverband</span></a></span> </p><p><a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/Instagram" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Instagram</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/PRISM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PRISM</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a> <a href="https://infosec.space/tags/NonconsensualUpload" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NonconsensualUpload</span></a> <a href="https://infosec.space/tags/NoThanks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NoThanks</span></a> <a href="https://infosec.space/tags/OptOut" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OptOut</span></a> <a href="https://infosec.space/tags/OptIn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OptIn</span></a></p>