Forumi


Povratak   PC Ekspert Forum > Ostalo > Razno
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 12.07.2025., 13:40   #241
Night
Premium
 
Datum registracije: Oct 2008
Lokacija: Dbk
Postovi: 1,236
Ako tko ima potrebe za takvim nečim postoji Buskill, spoji se USB stick preko magnetskog konektora (par dolara na Aliju) i onda skripta u slučaju odspajanja trenutno okida shutdown, brisanje LUKS ili Vera headera ili što već treba da se onemogući pristup podacima. Ideja je ako ti netko otme laptop iz ruke da se odmah nukaju svi ključevi za enkripciju i tako zaštite privatni ključevi i ostale bitne informacije.

https://github.com/buskill/buskill-app
Night je offline   Reply With Quote
Staro 12.07.2025., 14:09   #242
Neo-ST
Buying Bitcoin
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,202
Šta će ti onda LUKS ?
Neo-ST je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 12.07.2025., 14:28   #243
Night
Premium
 
Datum registracije: Oct 2008
Lokacija: Dbk
Postovi: 1,236
LUKS enkriptira podatke 256bitnim ključem, a taj ključ enkriptira šifrom (ili keyfileom) koji mu daš i koji imaš/znaš. Ta šifra ne mora nužno imati entropiju 256 bita, u pravilu je slabija od toga i onda ako se radi bruteforce raditi će se na headeru da se probije šifra i tako dođe do tog 256bit ključa jer direktni napad na 256bit ključ nije realano izvediv u trenutnom svemiru.

Tako ako si pobrisao header maknuo si taj vektor napada, kao i mogućnost da će netko izvući šifru od tebe i onda ostaje samo mogućnost da se bruteforca sam ključ enkripcije, a onda si nekih par milijardi godina miran

Ni wrench decryption metoda neće imati učinka https://xkcd.com/538/

Također smisao tog Buskilla je da napravi shutdown i tako počisti ključeve iz memorije i vrati disk u encrypted-at-rest stanje.

Zadnje izmijenjeno od: Night. 12.07.2025. u 14:35.
Night je offline   Reply With Quote
Staro 13.07.2025., 10:13   #244
tomek@vz
Premium
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,628
Citiraj:
Several browser extensions with a combined total of more than 2.3 million downloads were reportedly hijacking browsing sessions and tracking user activity. Many of these malicious add-ons remained available on the Chrome and Edge web stores for years, with some even receiving the coveted "Featured" and "Verified" badges, raising serious questions about the extension review processes used by Google and Microsoft.
According to researchers at Koi Security, the malicious extensions were part of a coordinated operation involving at least 18 known add-ons listed on the Chrome and Edge extension stores. Dubbed "RedDirection," the browser hijacking campaign is believed to have infected more than 2.3 million users across both browsers, making it one of the largest operations of its kind ever documented.
One of the suspicious extensions, The Color Picker – Geco, had over 100,000 installs on Chrome and a 4.2-star rating from more than 800 reviews. It also received similarly high ratings on Microsoft's Edge Add-ons store, with over 1,000 installs, giving it an appearance of legitimacy.

> Techspot
tomek@vz je offline   Reply With Quote
Staro 13.07.2025., 13:29   #245
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,283
Pitanje je samo jesu li se te ekstenzije ponašale tako od početka ili su ih preuzeli naknadno.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je online   Reply With Quote
Staro Jučer, 14:49   #246
Colop
Premium
 
Datum registracije: Sep 2011
Lokacija: Split
Postovi: 1,105
Evo jedna zanimljiva stvar.
Netko je sastavio skriptu koja čita sudski registar Republike Hrvatske
https://sudreg.pravosudje.hr/ords/r/...ic/1?clear=APP
i šalje na službene e-mailove tvrtki mail sa imenom i prezimenom od direktora tvrtke koji pita:
Colop je offline   Reply With Quote
Staro Jučer, 14:53   #247
Colop
Premium
 
Datum registracije: Sep 2011
Lokacija: Split
Postovi: 1,105
Citiraj:
Autor Colop Pregled postova
Evo jedna zanimljiva stvar.
Netko je sastavio skriptu koja čita sudski registar Republike Hrvatske
https://sudreg.pravosudje.hr/ords/r/...ic/1?clear=APP
i šalje na službene e-mailove tvrtki mail sa imenom i prezimenom od direktora tvrtke koji pita:





1:37 PM (1 hour ago)

to me
Bok,

Koliki je naš bankovni saldo? Moramo izvršiti uplatu od 39.755,19 eura. Možemo li platiti danas?

Lp,


Citiraj:
Autor Colop Pregled postova
Direktor Direktorić

1:37 PM (1 hour ago)

to me
Bok,

Koliki je naš bankovni saldo? Moramo izvršiti uplatu od 39.755,19 eura. Možemo li platiti danas?

Citiraj:
Autor Colop Pregled postova
Bok Direktore Direktorić

Bankovni saldo to može pokriti i možemo platiti danas.
Da li želiš da ti pošaljem novce na tvoj uobičajni račun?

Pozdrav

Eustahije Brzić

Citiraj:
Autor Colop Pregled postova
Molim Vas da izvršite uplatu na račun naveden u nastavku.

Podaci o primatelju;

IME RAČUNA: Sai Krishna N
ADRESA: Waterside Court, Western Avenue, Chatham Maritime, ME4 4RT
IBAN: GB84NWBK53701172951591
BIC: NWBKGB2L
BANKA: National Westminster Bank
SVRHA: ELR Projekt
REFERENCA: INV/GB19-82017
OTPLATA: 39.755,19 EUR

Poslat ću kopiju fakture kasnije.
Molim vas da mi javite kada uplata bude izvršena.

Lp,
Direktor Direktorić




Citiraj:
Autor Colop Pregled postova
Bok Direktore

Nema problema, odmah ću poslati novce.
Sa računa koje od naših banki želiš da platim račun, Hrvatske narodne banke ili Kent Banke?


Lijep pozdrav

Eustahije Brzić


Citiraj:
Autor Colop Pregled postova
Hrvatske narodne bankey.


Lijep pozdrav

Direktor Direktorić

Citiraj:
Autor Colop Pregled postova
Hvala ti na brzom odgovoru.
Šaljem novce.

Lijep pozdrav

Eustahije Brzić

Citiraj:
Autor Colop Pregled postova
Čekam potvrdu o uplati.


Lp,
Direktor Direktorić

Citiraj:
Autor Colop Pregled postova
Uplaćeno!

Pozdrav

Eustahije

Citiraj:
Autor Colop Pregled postova
U redu, hvala.

Lp,
Direktor Direktorić
Citiraj:
Autor Colop Pregled postova

Jel ti stvarno misliš da je itko toliki idiot da ti pošalje novce na neki nepoznati račun?
Pozdrav

Eustahije




Malo smo popričali, ne znam jel AI sa druge strane ili čovjek sa CHAT GPTom

Zadnje izmijenjeno od: Colop. Jučer u 15:00.
Colop je offline   Reply With Quote
Staro Jučer, 20:51   #248
tomek@vz
Premium
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,628
Citiraj:
Security researchers and ethical hackers are uncovering new and unexpected places where malicious code can be hidden within IT infrastructure. Even the seemingly innocuous Domain Name System (DNS) – the foundational naming system for all internet-connected devices – can, in theory, be exploited by clever cybercriminals or state-sponsored attackers. This underlines a growing trend: no part of the digital stack is too mundane to become a vector for sophisticated threats.
Hiding ransomware inside a CPU was strange but now, attackers are going even deeper and broader across networks. In a recent discovery, security researchers revealed that a piece of malware had been embedded directly within the Domain Name System, effectively bypassing nearly all advanced security tools.

> Techspot


Citiraj:


As GenAI tools make their way into mainstream apps and workflows, serious concerns are mounting about their real-world safety. Far from boosting productivity, these systems are increasingly being exploited – benefiting cybercriminals and cost-cutting executives far more than end users. Researchers this week uncovered how Google's Gemini model used in Gmail can be subverted in an incredibly simple way, making phishing campaigns easier than ever.
Mozilla recently unveiled a new prompt injection attack against Google Gemini for Workspace, which can be abused to turn AI summaries in Gmail messages into an effective phishing operation. Researcher Marco Figueroa described the attack on 0din, Mozilla's bug bounty program for generative AI services.
We strongly recommend reading the full report if you still think GenAI technology is ready for deployment in production or live, customer-facing products.

> Techspot
tomek@vz je offline   Reply With Quote
Staro Jučer, 22:12   #249
tomek@vz
Premium
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,628
Citiraj:
FortiGuard Labs researchers have uncovered a sophisticated cryptomining campaign where the H2Miner botnet, active since late 2019, has expanded its operations to target Linux, Windows, and containerized environments simultaneously.
The campaign represents a significant evolution in cross-platform cryptocurrency mining attacks, with threat actors leveraging updated scripts and infrastructure to maximize financial gains from compromised systems.
The investigation revealed that H2Miner operators have updated their arsenal with new deployment URLs while maintaining core functionalities from previous campaigns documented in 2020.

> gbhackers
tomek@vz je offline   Reply With Quote
Staro Danas, 12:54   #250
spiderhr
Premium
 
spiderhr's Avatar
 
Datum registracije: Jul 2021
Lokacija: Sesvete
Postovi: 984
Pojavila se fejk/phising stranica e-Građani na domeni gov-nias DOT com

Registrirana je i nias-gov DOT com (trenutno ne radi).

__________________
tomek@vz: ajd nemoj | Mali Čile SAD Češka Peru | Windows Free
spiderhr je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro Danas, 13:14   #251
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 9,983
Hvala, updejtane blackliste naivnih penzica!
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Uključeno

Idi na