mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

379K
active users

#netsec

3 posts3 participants1 post today

ICMP is an part of the IPv4 protocol, so it cannot officially be carried by other protocols. Although the IP protocol can be carried on a different protocol than the ethernet protocol.

#netsec
Many network security devices block all ICMP messages for perceived security benefits, including the errors that are necessary for the proper operation of PMTUD. This can result in connections that complete the TCP three-way handshake correctly but then hang when attempting to transfer data. This state is referred to as a black hole connection.[7]
stackoverflow.com/questions/19

Stack OverflowWhat data is included in ICMP (ping) request?I know the ICMP request contains the IP address. Is the client MAC address included in an ICMP request? What other info (if any) is included in a ping request?

I've been tinkering with microsegmentation lately and felt like I was constructing a digital fort.

Imagine partitioning your network into tiny, secure rooms so that if one gets breached, the invader can't roam freely, also technically called reducing the risk of lateral movement by the attackers.

It's like building your own castle floor by floor.

Last night, while lying awake in bed, I managed to p0wn some (2) TP-Link TAPO IP Cams within the long AP range, someone forgot to disable their hotspot...oops.

:cortexprofen_pack: :cortexprofen_pill: :ci_floppy:

I created an isolated SSID, a fake relay account for the cam setup, and paired them to the WLAN. Got full control, then reset the cameras, deleted the SSID, and archived the app.

TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records

Many organizations maintain a broad portfolio of domain names, acquired for branding, strategic planning, or defensive purposes. However, a significant portion of these domains often remains unused or lacks proper DNS configurations...

Read more circl.lu/pub/tr-92/

www.circl.luCIRCL » TR-92 - Unused Domain Names and the Risks of Missing DNS SPF RecordsTR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records