Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. I *CANNOT WAIT* until we see this and other strings hit all these “Agentic SOC" environments.

I *CANNOT WAIT* until we see this and other strings hit all these “Agentic SOC" environments.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
110 Beiträge 31 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • hrbrmstr@mastodon.socialH hrbrmstr@mastodon.social

    I *CANNOT WAIT* until we see this and other strings hit all these “Agentic SOC" environments.

    Likely gonna cause a whole bunch of orgs to go blind (telemetry-wise) for just enough time for attackers to do what they need to do. https://infosec.exchange/@morattisec/115929249640927958

    nopatience@swecyb.comN This user is from outside of this forum
    nopatience@swecyb.comN This user is from outside of this forum
    nopatience@swecyb.com
    schrieb am zuletzt editiert von
    #3

    @hrbrmstr Wouldn't it be funny if open source software repositories started to include that string in PRs, or spread throughout code comments?

    I mean... I can certainly imagine that breaking quite a few systems and "agents".

    No?

    dch@bsd.networkD 1 Antwort Letzte Antwort
    0
    • nopatience@swecyb.comN nopatience@swecyb.com

      @hrbrmstr Wouldn't it be funny if open source software repositories started to include that string in PRs, or spread throughout code comments?

      I mean... I can certainly imagine that breaking quite a few systems and "agents".

      No?

      dch@bsd.networkD This user is from outside of this forum
      dch@bsd.networkD This user is from outside of this forum
      dch@bsd.network
      schrieb am zuletzt editiert von
      #4

      @nopatience immediately add this header to Anubis and iocaine responses @hrbrmstr

      nopatience@swecyb.comN 1 Antwort Letzte Antwort
      0
      • dch@bsd.networkD dch@bsd.network

        @nopatience immediately add this header to Anubis and iocaine responses @hrbrmstr

        nopatience@swecyb.comN This user is from outside of this forum
        nopatience@swecyb.comN This user is from outside of this forum
        nopatience@swecyb.com
        schrieb am zuletzt editiert von
        #5

        @dch @hrbrmstr

        Oh... how EVIL to put it as a web server header? Would they process headers as agents?

        Perhaps worth testing 🙂

        dch@bsd.networkD 1 Antwort Letzte Antwort
        0
        • nopatience@swecyb.comN nopatience@swecyb.com

          @dch @hrbrmstr

          Oh... how EVIL to put it as a web server header? Would they process headers as agents?

          Perhaps worth testing 🙂

          dch@bsd.networkD This user is from outside of this forum
          dch@bsd.networkD This user is from outside of this forum
          dch@bsd.network
          schrieb am zuletzt editiert von
          #6

          @nopatience I can neither confirm nor deny if this works but returning it in Anubis and iocaine responses is my current jam. Time to poison the source of the well. @hrbrmstr

          nopatience@swecyb.comN 1 Antwort Letzte Antwort
          0
          • dch@bsd.networkD dch@bsd.network

            @nopatience I can neither confirm nor deny if this works but returning it in Anubis and iocaine responses is my current jam. Time to poison the source of the well. @hrbrmstr

            nopatience@swecyb.comN This user is from outside of this forum
            nopatience@swecyb.comN This user is from outside of this forum
            nopatience@swecyb.com
            schrieb am zuletzt editiert von
            #7

            @dch @hrbrmstr I tried adding it as a server header in nginx, sent Claude Opus that way... but didn't stop it. So my immediate thoughts is that well, it needs to be more closely embedded into contents of webpages rather than "too far down the stack".

            But I'll keep it there just for laughs.

            hrbrmstr@mastodon.socialH 1 Antwort Letzte Antwort
            0
            • nopatience@swecyb.comN nopatience@swecyb.com

              @dch @hrbrmstr I tried adding it as a server header in nginx, sent Claude Opus that way... but didn't stop it. So my immediate thoughts is that well, it needs to be more closely embedded into contents of webpages rather than "too far down the stack".

              But I'll keep it there just for laughs.

              hrbrmstr@mastodon.socialH This user is from outside of this forum
              hrbrmstr@mastodon.socialH This user is from outside of this forum
              hrbrmstr@mastodon.social
              schrieb am zuletzt editiert von
              #8

              @nopatience @dch oh, aye. they have a system that does the fetching and then turns the content into markdown for processing. headers aren't going to get caught in the machine unless someone is asking for a header analysis.

              and, they use a proxy (which claude told me about when it said it could not get to infosec.exchange via their infra) so they will likely be filtering these strings out at that central point.

              thankfully that's not the only way those strings can get in tho.

              dch@bsd.networkD 1 Antwort Letzte Antwort
              0
              • hrbrmstr@mastodon.socialH hrbrmstr@mastodon.social

                I *CANNOT WAIT* until we see this and other strings hit all these “Agentic SOC" environments.

                Likely gonna cause a whole bunch of orgs to go blind (telemetry-wise) for just enough time for attackers to do what they need to do. https://infosec.exchange/@morattisec/115929249640927958

                hrbrmstr@mastodon.socialH This user is from outside of this forum
                hrbrmstr@mastodon.socialH This user is from outside of this forum
                hrbrmstr@mastodon.social
                schrieb am zuletzt editiert von
                #9

                BASE64 THESE EVERYWHERE

                hrbrmstr@mastodon.socialH 1 Antwort Letzte Antwort
                0
                • hrbrmstr@mastodon.socialH hrbrmstr@mastodon.social

                  BASE64 THESE EVERYWHERE

                  hrbrmstr@mastodon.socialH This user is from outside of this forum
                  hrbrmstr@mastodon.socialH This user is from outside of this forum
                  hrbrmstr@mastodon.social
                  schrieb am zuletzt editiert von
                  #10

                  ZOMGOSH I HOPED THIS WOULD WORK the mt agamenticus img is what i asked it to describe)

                  numb_comfortably@hachyderm.ioN stellar@mk.absturztau.beS 2 Antworten Letzte Antwort
                  1
                  0
                  • hrbrmstr@mastodon.socialH hrbrmstr@mastodon.social

                    @nopatience @dch oh, aye. they have a system that does the fetching and then turns the content into markdown for processing. headers aren't going to get caught in the machine unless someone is asking for a header analysis.

                    and, they use a proxy (which claude told me about when it said it could not get to infosec.exchange via their infra) so they will likely be filtering these strings out at that central point.

                    thankfully that's not the only way those strings can get in tho.

                    dch@bsd.networkD This user is from outside of this forum
                    dch@bsd.networkD This user is from outside of this forum
                    dch@bsd.network
                    schrieb am zuletzt editiert von
                    #11

                    @hrbrmstr AI is great at looking for patterns, anything from rot13 to base64 and variants in between will make it through a first cleaning stage @nopatience

                    1 Antwort Letzte Antwort
                    0
                    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                      @hrbrmstr thinking about popping it in my email sig

                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.social
                      schrieb am zuletzt editiert von
                      #12

                      @hrbrmstr @neurovagrant linkedin

                      neurovagrant@masto.deoan.orgN 1 Antwort Letzte Antwort
                      0
                      • viss@mastodon.socialV viss@mastodon.social

                        @hrbrmstr @neurovagrant linkedin

                        neurovagrant@masto.deoan.orgN This user is from outside of this forum
                        neurovagrant@masto.deoan.orgN This user is from outside of this forum
                        neurovagrant@masto.deoan.org
                        schrieb am zuletzt editiert von
                        #13

                        @Viss @hrbrmstr "and this is why we've screamed about sanitizing your inputs for decades."

                        viss@mastodon.socialV hrbrmstr@mastodon.socialH 2 Antworten Letzte Antwort
                        0
                        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                          @Viss @hrbrmstr "and this is why we've screamed about sanitizing your inputs for decades."

                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.socialV This user is from outside of this forum
                          viss@mastodon.social
                          schrieb am zuletzt editiert von
                          #14

                          @hrbrmstr @neurovagrant we should stop screaming

                          1 Antwort Letzte Antwort
                          0
                          • viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            schrieb am zuletzt editiert von
                            #15

                            @hrbrmstr @darfplatypus

                            https://mastodon.social/@Viss/115940022677167824

                            1 Antwort Letzte Antwort
                            0
                            • viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.social
                              schrieb am zuletzt editiert von
                              #16

                              @hrbrmstr @cR0w stuff it into exif fields too

                              bruce@darkmoon.socialB tim_lavoie@cosocial.caT 2 Antworten Letzte Antwort
                              0
                              • viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.social
                                schrieb am zuletzt editiert von
                                #17

                                @hrbrmstr @darfplatypus i dont even know what those are

                                1 Antwort Letzte Antwort
                                0
                                • viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.social
                                  schrieb am zuletzt editiert von
                                  #18

                                  @hrbrmstr @cR0w also there was a site i saw last week that let you stuff arbitrary text into email b64 encoding fields for stuff like images, i bet it would work well there too

                                  kajer@infosec.exchangeK defractal@infosec.exchangeD 2 Antworten Letzte Antwort
                                  0
                                  • viss@mastodon.socialV viss@mastodon.social

                                    @hrbrmstr @cR0w also there was a site i saw last week that let you stuff arbitrary text into email b64 encoding fields for stuff like images, i bet it would work well there too

                                    kajer@infosec.exchangeK This user is from outside of this forum
                                    kajer@infosec.exchangeK This user is from outside of this forum
                                    kajer@infosec.exchange
                                    schrieb am zuletzt editiert von
                                    #19

                                    @Viss @hrbrmstr @cR0w

                                    im drooling right now

                                    1 Antwort Letzte Antwort
                                    0
                                    • cr0w@infosec.exchangeC This user is from outside of this forum
                                      cr0w@infosec.exchangeC This user is from outside of this forum
                                      cr0w@infosec.exchange
                                      schrieb am zuletzt editiert von
                                      #20

                                      @hotsoup @kajer @Viss @hrbrmstr

                                      viss@mastodon.socialV hrbrmstr@mastodon.socialH mistermadge@universeodon.comM 3 Antworten Letzte Antwort
                                      0
                                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                        @hotsoup @kajer @Viss @hrbrmstr

                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.social
                                        schrieb am zuletzt editiert von
                                        #21

                                        @hotsoup @kajer @hrbrmstr @cR0w 100% effective

                                        defractal@infosec.exchangeD hrbrmstr@mastodon.socialH 3 Antworten Letzte Antwort
                                        0
                                        • alex02@elonsucks.orgA This user is from outside of this forum
                                          alex02@elonsucks.orgA This user is from outside of this forum
                                          alex02@elonsucks.org
                                          schrieb am zuletzt editiert von
                                          #22

                                          @cR0w @Viss @hotsoup @kajer @hrbrmstr just get neon paper and slap it on there. idk.

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum