New PuTTY Vulnerability - ThreatWire

Поділитися
Вставка
  • Опубліковано 7 чер 2024
  • ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
    @endingwithali →
    Twitch: / endingwithali
    Twitter: / endingwithali
    UA-cam: / @endingwithali
    Everywhere else: links.ali.dev
    [❗] Join the Patreon→ / threatwire
    0:00 Sophia d’Antoine
    0:36 - Potential T-Mobile Directory Leak
    2:32 - Palo Alto Networks Firewall Python Backdoor
    4:20 - Twitter Hosted the Phishing Olympics
    6:14 - PuTTY Project Vulnerable
    7:28 - Outro
    LINKS
    🔗 Story 1: Potential T-Mobile Directory Leak
    www.t-mobile.com/support/plan...
    www.sciencedaily.com/releases...
    tmo.report/2024/04/t-mobile-e...
    🔗 Story 2: Palo Alto Networks Firewall Python Backdoor
    www.volexity.com/blog/2024/04...
    unit42.paloaltonetworks.com/c...
    security.paloaltonetworks.com...
    labs.watchtowr.com/palo-alto-...
    / 1780239802496864474
    🔗 Story 3: Twitter Hosted the Phishing Olympics
    krebsonsecurity.com/2024/04/t...
    🔗 Story 4: PuTTY Project Vulnerable
    www.chiark.greenend.org.uk/~s...
    thehackernews.com/2024/04/wid...
    www.openwall.com/lists/oss-se...
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Наука та технологія

КОМЕНТАРІ • 110

  • @donamills
    @donamills Місяць тому +79

    YT shorts are like a fridge full of condiments and no "real" food.

    • @NETBotic
      @NETBotic Місяць тому +3

      "We want to be like TikTok" so cringe...

    • @endingwithali
      @endingwithali Місяць тому +1

      You just described my own fridge 😭😭😭

    • @Dirtyharry70585
      @Dirtyharry70585 Місяць тому

      But you leave satisfied

    • @cfx3
      @cfx3 Місяць тому

      it's just easy clickbait mostly for honry kids

    • @robbybankston4238
      @robbybankston4238 Місяць тому

      Sometimes I agree. But there are many YT videos that are 25-35 minutes long that could have been explained in 60 seconds or at least could be used to give an overview of something with a link to the full content if desired.

  • @mytechnotalent
    @mytechnotalent Місяць тому +10

    Thanks Ali! Appreciate the info on PuTTY as so many of us deving in microcontrollers use it for UART.

  • @-FAFO-
    @-FAFO- Місяць тому +8

    "Shoot me a DM".... Famous last words 😅

  • @danl6734
    @danl6734 Місяць тому +49

    IMHO YT shorts devalue and dilute quality content

    • @MeisterJager90
      @MeisterJager90 Місяць тому +4

      Seconded. It’s the final stage of the death of discord (that thing people should do, not the app)

    • @LostArchivist
      @LostArchivist Місяць тому +2

      Thirded (sic)

    • @spicesmuggler2452
      @spicesmuggler2452 Місяць тому

      Fourthed, but it goes hand in hand with these days zoomers that cant hold their focus for more than a minute at a time.

    • @vectoralphaAI
      @vectoralphaAI Місяць тому +1

      I dont know. When done well they could be good just like PirateSoftware.

    • @SlyerFox666
      @SlyerFox666 Місяць тому +3

      IMHO YT devalues & dilutes any quality content with a pathetic layout 😂

  • @cipher3966
    @cipher3966 Місяць тому +8

    I hated shorts at first but I am a little more used to them now, it just depends how they are used. Just don't replace everything with them and I prefer if it is some sort of link or summary of another video. It bothers me when people just make a 10 second video speaking in fast forward on something that could be discussed in detail in ten minutes

  • @familyplans3788
    @familyplans3788 Місяць тому +3

    meh shorts i tend to find myself watching them by accident , i like watching videos where i learn something , but now and again i see a short and before i know it , im clicking through shorts for 10 mins and couldnt tell you a thing about a single one of them , but then im an old bugger who uses the web as a library not , as it seems, like the youngsters who use it to fill their lives
    Great content as always

    • @javabeanz8549
      @javabeanz8549 Місяць тому

      Only ten minutes? I can get lost in them for hours as long as they keep giving me interesting ones. Steve Mould usually has some that draw me in for his full video.

  • @digital0ak
    @digital0ak Місяць тому +2

    Thank you for the link to enable SIM protection. The obvious question is why the hell is that even something that the customer has to opt in for?

  • @KaySwiss21
    @KaySwiss21 Місяць тому +4

    Yubikey works great... Cant even open the authentication app without the hardware key

  • @kevinwetsch5209
    @kevinwetsch5209 Місяць тому

    Thanks for the info.

  • @zainuddinbrahim4625
    @zainuddinbrahim4625 Місяць тому

    thanks for the info

  • @electricsushi
    @electricsushi Місяць тому

    Great job 😊

  • @knghtbrd
    @knghtbrd Місяць тому +4

    As if you needed to pay a T-Mobile employee to do the SIM swap … 😬 *sigh*

  • @natearcetech3551
    @natearcetech3551 Місяць тому

    Hi Ali thanks for the report. I wonder what if any kind of cybersecurity training or pentesting is done at T-mobile...

  • @DNETREAPER
    @DNETREAPER Місяць тому

    Thx again 👨‍💻

  • @iaina3251
    @iaina3251 Місяць тому +2

    re shorts: Hate them and never ever ever watch them, but then again I'm not in teens or early 20s either so maybe I'm the wrong demographic for vertical video!

  • @HadToChangeMyName_YoutubeSucks
    @HadToChangeMyName_YoutubeSucks Місяць тому +4

    I'm curious why your example on the sim sales is a retail level employee making $10 - $18 per hour...what exactly does that have to do with how honest you are? I've worked minimum wage on my way to where I am many times and I never considered it a license to act unethically. At what hourly rate would these employees who commit larceny become honest, or do you have to make them salary to get an honest employee? I see well paid people go to prison for embezzling money all the time, accountants, town clerks, sheriffs, attorneys, sometimes for relatively petty amounts, how much you make doesn't actually determine your sense of morals or ethics, at most it lowers your price.

  • @kaitomakes
    @kaitomakes Місяць тому +7

    Umm university of luxemborough? Is that a real university or did she actually mean Luxembourg?

    • @javabeanz8549
      @javabeanz8549 Місяць тому +1

      she seems a little off, I think that announcement at the start of the video could have something to do with it. She flipped the words when reading the comment as well.

  • @_mrcrypt
    @_mrcrypt Місяць тому

    Good info! Thanks 🏴‍☠️

  • @A_F_Innovate
    @A_F_Innovate Місяць тому

    Have a happy Pesach Ali. Good show.

  • @Richo5566
    @Richo5566 Місяць тому

    What a QT! Good content too.

  • @seraphuziel
    @seraphuziel Місяць тому +4

    Anyone hear that MGM got hit and was shut down for the day I think?

  • @mlogsdon1740
    @mlogsdon1740 Місяць тому

    what'd you hack to get them lip fillers

  • @Videos_Marco_Lista_I._A.
    @Videos_Marco_Lista_I._A. Місяць тому

    excelente canal

  • @atxhooligan
    @atxhooligan 5 днів тому

    do you have to be a member to get their discord access?

  • @c1ph3rpunk
    @c1ph3rpunk Місяць тому +1

    Not only was the Palo issue nasty, but their general handling of it was poor, at best, likely closer to downright bad to horrid. So many things to say, so many NDA’s.

  • @demar1496
    @demar1496 Місяць тому

    String replacement mishaps have been around forever. Sadly, even high-impact mishaps are not that rare.
    Vulnerabilities probably shouldn't be published in great detail. At my former employer, we locked down the details, and only gave a generic overview for the published report. Unfortunately, many will read security vulnerabilities as a step to further exploitation.
    And thanks for reminding me to disable SIM-swapping!

  • @timtomnec
    @timtomnec Місяць тому +1

    You got a chocolate bar.... All i got was this stick that sounds like its raining, how come you get a chocolate bar !

  • @williambrasky3891
    @williambrasky3891 Місяць тому

    I feel Ike that chocolate bar study had to have had participants make an account for something related to the study, or just make up a password, then asked the participants for that password. A password like that wouldn’t be linked to any of the participants’ personal information, and that may have made them less reluctant to share that specific password.
    I could be wrong. About to go look up the study. So I’ll find out. I sure hope I’m right, but wouldn’t be surprised if I’m wrong. If I am right, I’d love to see a similar study with a more robust methodology.

  • @ecwnikos
    @ecwnikos Місяць тому +1

    enjoy youre pass over tc.

  • @karanb2067
    @karanb2067 Місяць тому

    understandable, have a nice day.

  • @lossless4129
    @lossless4129 Місяць тому

    Microsoft MFA App is great, it records login attempts from all over the world haha it’s funny to see India and Indonesia trying so hard to get in

  • @diegodevops4151
    @diegodevops4151 Місяць тому

    YT Shorts are good. Example. The report about Putty was very short. That could be a shorts video. Bring more people to the channel sharing short good videos.

  • @ciaduck
    @ciaduck Місяць тому +1

    Personally don't like shorts, but you should go for it anyway. You've got to play the UA-cam game if you want the views. Getting on shorts is a way you can grow more audience.

  • @ShaunVillafana
    @ShaunVillafana Місяць тому

    1:00 I thought that was patched??? That *still* is a vulnerability??? Duuuuude, I read about that like two years ago 😶

  • @c.n.crowther438
    @c.n.crowther438 Місяць тому

    Didn't Elon disband most of the Twitter security team?

  • @Uncle_Buzz
    @Uncle_Buzz Місяць тому

    You would put out puTTY info on the 22nd. ;)

  • @wilgarcia1
    @wilgarcia1 Місяць тому +1

    ❤❤❤❤❤❤

  • @ManfredWisniewski
    @ManfredWisniewski Місяць тому

    Does the putty bug affect kitty?

  • @SourceCodeDeleted
    @SourceCodeDeleted Місяць тому

    It seems like a bit since we have had a threatwire

    • @hak5
      @hak5  Місяць тому +2

      My apologies for the delay - we had a little trouble with this edit. It was supposed to have gone out Thursday or Friday. We're making some backend workflow changes and running into a few growing pains. Thanks for the patience and understanding. ~Darren

    • @SourceCodeDeleted
      @SourceCodeDeleted Місяць тому +1

      @@hak5 no worries)
      I am just thinking about it, nothing more. Maybe I missed an episode or maybe nothing happened of great significance.
      Don't take my comment to be negative. I love hak5. )

  • @beerreeb123
    @beerreeb123 Місяць тому

    I absolutely love YT shorts, the only thing is that sometimes…. Hey did you see the one with the ADHD people….

  • @loc4725
    @loc4725 Місяць тому

    YT shorts are a tool and like any tool can be used either well or badly. For concise bits of information, which have little depth or which can assume existing knowledge or which at least point people in the right direction they can often work well.
    So kong as you understand how use them and stay away from pointless, 'hollow' content you'll probably be fine.

  • @user-hk6pu8nt1s
    @user-hk6pu8nt1s Місяць тому

    Darren please do it this aint fair it has that guys texts about that tunnel

  • @dragonwisard
    @dragonwisard Місяць тому +1

    Anyone that wants to see shorts already has TikTok for that.

  • @user-hk6pu8nt1s
    @user-hk6pu8nt1s Місяць тому

    About 70 multi character alpha numeric

  • @user-td4pf6rr2t
    @user-td4pf6rr2t Місяць тому

    Heck, I dont even need the whole chocolate bar either. I'de compromise my account just for a bite.

  • @carpentb17
    @carpentb17 Місяць тому

    I use Microsoft for Microsoft, Google for Google, synology for synology, Ubiquiti for everything else

  • @ytreview4390
    @ytreview4390 Місяць тому

    shorts are evel

  • @jonathanrhodes6180
    @jonathanrhodes6180 Місяць тому +1

    UA-cam Shorts contribute to Goldfish Brain.

  • @Messier74
    @Messier74 Місяць тому +1

    🥳🥳🥳

  • @erice6755
    @erice6755 Місяць тому

    When it comes to MFA apps I really like 2FAS
    Shorts can be fun to watch but a lot of them are unfortunately recorded in such a way that to really get information that you want you have to watch the video that the youtuber wants you to watch. So basically another ad and nothing else, and hate these ones.

  • @josejj
    @josejj Місяць тому

    5:35 nah just ctrl f and replace all…. that’ll do it

  • @Leroy0070
    @Leroy0070 Місяць тому +3

    I will not update anything this week.

  • @neverendingstudent
    @neverendingstudent Місяць тому

    Happy Pesach! I was actually snacking on a box of Matzos my dad sent me home with while watching this. As for YT Shorts? I'm going to be the embodiment of the old, set-in-his-ways codger that hates the new generation and thinks these new things are everything bad with the world, etc... but in a less joking response, I do dislike YT Shorts (if only because YT refuses to allow opt-outs).

  • @AdricM
    @AdricM Місяць тому +1

    im pretty Meh on "shorts" i like short videos, but not the youtube shorts.

  • @marcux83
    @marcux83 Місяць тому +1

    smart people use EdDSA instead of ECDSA 🤭

  • @DmnkRocks
    @DmnkRocks Місяць тому +2

    can we get rid of Short all together? - please

  • @sjoervanderploeg4340
    @sjoervanderploeg4340 Місяць тому

    I use a YubiKey!

    • @sjoervanderploeg4340
      @sjoervanderploeg4340 Місяць тому

      Also, I hate UA-cam shorts!
      They always show the most irrelevant videos of yoga and shuffle girls... and never Ali the mmap in my strcpy...

  • @canlelola
    @canlelola Місяць тому

    AH lol, well T-mobile any any other company that sells mobile stuff, pay the front end staff better.

  • @DirtyPlumbus
    @DirtyPlumbus Місяць тому +2

    UA-cam shorts are like clickbait.
    Everyone says they hate them but they just keep watching. 🤷‍♂️

  • @carsonjamesiv2512
    @carsonjamesiv2512 Місяць тому

    Putty is Dutty!😮

  • @Olveron
    @Olveron Місяць тому

    Free otp+.

  • @thaphreak
    @thaphreak Місяць тому

    for some reason threat wire seems.... less lately.

  • @thefrub
    @thefrub Місяць тому +3

    It smells like Upstyle in here

  • @Solarsystemrdffdfyyhh
    @Solarsystemrdffdfyyhh Місяць тому

    This girls cool but is this all hak5 is now?

  • @TheFarFey
    @TheFarFey Місяць тому +1

    I prefer Aegis

  • @palmoliverules
    @palmoliverules Місяць тому +1

    Not a fan of shorts that are more than 1 part. If it is an entire story in 60 seconds no issues from me.

  • @g1zmo85
    @g1zmo85 Місяць тому +2

    I like Shorts for quick digestible content

    • @j0hnny_R3db34rd
      @j0hnny_R3db34rd Місяць тому +3

      I like shorts because they're easy to take off.

    • @g1zmo85
      @g1zmo85 Місяць тому

      @@j0hnny_R3db34rd true :)

  • @Radm0bile
    @Radm0bile Місяць тому +1

    ...What's UPSTYLE? 😉

  • @sukum_limbu
    @sukum_limbu Місяць тому

    Putty 😂

  • @spirit.canada
    @spirit.canada Місяць тому +1

    Please NO UA-cam-shorts, we will wait for a proper video release. This channel is fantastic, don't degrade the content.

  • @slvclw
    @slvclw Місяць тому

    Globalprotect is trash and ironically my last 5 jobs and currently use it haaaa lol

  • @MajesticBlueFalcon
    @MajesticBlueFalcon Місяць тому

    Dios, por favor vuelvan al formato anterior donde se preparaban de antemano para hacer el video, usaban cambios de ángulos de cámara y no se veía tan forzado.

  • @rationalbushcraft
    @rationalbushcraft Місяць тому

    I hate shorts. I also get that the algorithm loves them and will recommend your other content more often if you post shorts. So really I don't think you have a choice if you want to grow.

  • @Agent_Orange_Peel
    @Agent_Orange_Peel Місяць тому +1

    Any short format is awful. It’s the best way to say nothing. It really just causes frustration since the viewer normally wants more.
    Maybe if your subject is super simple, it could work. Like if it’s a tip or something.

  • @tmcarter3
    @tmcarter3 Місяць тому +1

    Please don't waste your time on shorts...

  • @ChairmanHehe
    @ChairmanHehe Місяць тому +1

    who needs sim swapping explained in 2024

  • @cloosat
    @cloosat Місяць тому

    UA-cam shorts is waiting for TikTok to get banned

  • @Laszlo34
    @Laszlo34 Місяць тому

    NO SHORTS! Please! YUCK!!

  • @mitregel3237
    @mitregel3237 Місяць тому

    What happened to the old host? The old host flowed way better.

  • @meh.7539
    @meh.7539 Місяць тому +1

    Not a fan of YT shorts. Honestly, just chill and do your Passover thing with the family.

  • @user-sq8og5jv3f
    @user-sq8og5jv3f Місяць тому +1

    damn 5 views in 15, aly fell off