Somebody just offered me a gig doing DFIR with malware analysis for $75-85/hr. That’s not even close to market rates. What the heck is going on these days?
I agree it's a terrible precedent. I'm glad I'm not the one with the authority to make that call because right now my "better angels" are screaming for payback.
The Fall 2022 Scholarship for Service application window is now open at @LSU@LSUCCT. These scholarships provide a living wage, tuition, training funds & guaranteed jobs. @nolaforensix is the main professor and memory forensics R&D is the focus:
lsu.edu/cybersecurity/schola…#DFIR
Of course the root could take action to remove the NS records and glue for .ru or any other TLD. I’m now wondering what the path would be for making that happen under current bylaws?
It's a 64-bit Rocky Linux image, distributed as a directory from VMWare Workstation (vmdks, and a vmx file). You can download it yourself from archive.org/download/HalLinu…
I think we all agree here. SELinux isn't perfect but it will knock out the automated, ankle-biter level exploits and give you more visibility into higher-level attacks. Consider also that more adoption of SELinux would help expose and close the flaws in SELinux itself.
Some great stories about Boggs from @paulvixie during our recent panel discussion during WWHF Deadwood. It feels too soon to be losing these great inventors.
In the 1970s, David Boggs helped create Ethernet, the powerful etworking technology that connects PCs to printers, other devices and the internet in offices and homes. He has died at 71. nyti.ms/3porn9m
I cannot overstate how impossibly difficult it is to attack a system running SELinux with setenforce 1.
Even if it's got openings and misconfigurations, an attacker is going to make buckets of noise finding the flaws.
Know who does ls -laZ? Nobody but attackers.
Q: Why is Hal going on about SELinux again?
A: Because I investigate lots of Linux intrusions that would have failed if SELinux was enabled.
At least come and learn to criticize SELinux from a position of knowledge and not FUD.
Coming up March 9-10 is @hal_pomeranz's 6-hour course, "SELinux – Necessary and Not Evil!" 10% of this course will be donated to @RuralTechFund.
What's your experience with SELinux? Good? Bad? Let us know!
Course details & registration can be found here: ow.ly/7q7a50I6lHa