nitter
Hal Pomeranz
@hal_pomeranz
I am retiring this social media account. Find me as
@hal_pomeranz
@infosec.exchange
Orlando, FL
deer-run.com/~hal/
Joined November 2008
Tweets
19,311
Following
237
Followers
13,672
Likes
12
228 Photos and videos
228 Photos and videos
Tweets
Tweets & Replies
Media
Search
Filter
Retweets
Media
Videos
News
Verified
Native videos
Replies
Links
Images
Safe
Quotes
Pro videos
Exclude
Retweets
Media
Videos
News
Verified
Native videos
Replies
Links
Images
Safe
Quotes
Pro videos
Time range
-
Near
Load newest
Hal Pomeranz
@hal_pomeranz
18 Nov 2011
If your vendors have usernames/passwords on your systems "for support", then your attackers have usernames/passwords "for abuse".
#sec101
3
Hal Pomeranz
@hal_pomeranz
18 Nov 2011
Not going to use a tool that would help you make your case because it's not on some arbitrary list of "approved" forensics tools? Really?
3
Hal Pomeranz
@hal_pomeranz
16 Nov 2011
Ok, somebody please explain the meaning of "< this" comment after a RT. I'm totally not "with it", I know, so please educate me!
5
Hal Pomeranz
@hal_pomeranz
16 Nov 2011
Reminder for my fellow DoD Cyber Crime Conf presenters: slides are due Friday. Spent several hours tonight working on mine...
1
Hal Pomeranz
@hal_pomeranz
30 Oct 2011
@ericjhuber No. That explains it. Can't we all just get along?
Hal Pomeranz
@hal_pomeranz
30 Oct 2011
@ericjhuber OK, I missed something. Do you have a link?
Hal Pomeranz
@hal_pomeranz
30 Oct 2011
Replying to
@littlemac042
@littlemac042
@brad_garnett
@Patories
@KDPryor
@kylemaxwell
@4n6woman I only bust out the hex editor when Sleuthkit doesn't work.
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
Replying to
@elpie
@elpie
I am so sorry that you all are going through this. That's no way to leave the world.
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
@ericjhuber Still don't understand why any of us need to be screened.
1
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
Replying to
@jgarcia62
@jgarcia62
Forensic artifacts from a
#KenSMASH
incident.
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
Could be the APT (Airport Persistent Threat)
twitpic.com/77o9xb
1
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
@ericjhuber Fed LE show their creds and bypass TSA.
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
If POTUS, Congress, and Law Enforcement had to put up with the same TSA BS as normal travelers, the TSA would be dismantled in a week...
1
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
TSA checking IDs and boarding passes again as we're boarding the aircraft. What exactly is the point of this ridiculous security theatre?
4
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
@ericjhuber Thou shalt not covet thy neighbor's CSS.
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
RT
@mikko
: This is why you do not want to link to the original CSS if you steal somebody's website design:
inspr.in/BMUM
[LOLz!]
Hal Pomeranz
@hal_pomeranz
29 Oct 2011
Road trip weeks 12&13 (of 14): VACATION! Meeting Laura at <undisclosed location>. We haven't slept in the same bed in two months.
Hal Pomeranz
@hal_pomeranz
28 Oct 2011
RT
@lennyzeltser
: Reminder to self: Write every email with the assumption that it will end up being shared with everyone in the company.
1
Hal Pomeranz
@hal_pomeranz
28 Oct 2011
Replying to
@tuxcomp
@tuxcomp
Also some sample AIDE config files under
deer-run.com/~hal/aide/
1
Hal Pomeranz
@hal_pomeranz
28 Oct 2011
Replying to
@tuxcomp
@tuxcomp
Look on
deer-run.com/~hal/
for my old "Detecting Break-ins" talk. There's some AIDE info there as I recall.
Load more