101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

483
active users

#auditing

0 posts0 participants0 posts today
Frontend Dogma<p>Tool: npm Package Checker, by (not on Mastodon or Bluesky):</p><p><a href="https://npmpackage.info/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">npmpackage.info/</span><span class="invisible"></span></a></p><p><a href="https://mas.to/tags/tools" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tools</span></a> <a href="https://mas.to/tags/exploration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploration</span></a> <a href="https://mas.to/tags/auditing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auditing</span></a> <a href="https://mas.to/tags/debugging" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>debugging</span></a> <a href="https://mas.to/tags/npm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npm</span></a> <a href="https://mas.to/tags/dependencies" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dependencies</span></a></p>
Cycling Europe<p><a href="https://www.cyclingeu.com/654505/amsterdam-handhaving-seizing-bikes-%f0%9f%87%b3%f0%9f%87%b1/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cyclingeu.com/654505/amsterdam</span><span class="invisible">-handhaving-seizing-bikes-%f0%9f%87%b3%f0%9f%87%b1/</span></a> AMSTERDAM HANDHAVING SEIZING BIKES 🇳🇱 <a href="https://pubeurope.com/tags/arrest" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>arrest</span></a> <a href="https://pubeurope.com/tags/auditing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auditing</span></a> <a href="https://pubeurope.com/tags/Audits" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Audits</span></a> <a href="https://pubeurope.com/tags/Bicycling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bicycling</span></a> <a href="https://pubeurope.com/tags/BicyclingNetherlands" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BicyclingNetherlands</span></a> <a href="https://pubeurope.com/tags/Biking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Biking</span></a> <a href="https://pubeurope.com/tags/Cycling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cycling</span></a> <a href="https://pubeurope.com/tags/detained" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>detained</span></a> <a href="https://pubeurope.com/tags/Netherlands" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Netherlands</span></a> <a href="https://pubeurope.com/tags/police" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>police</span></a> <a href="https://pubeurope.com/tags/PoliceStation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PoliceStation</span></a> <a href="https://pubeurope.com/tags/Tyranny" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tyranny</span></a> <a href="https://pubeurope.com/tags/Unlawful" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Unlawful</span></a></p>
Frontend Dogma<p>Tool: ECMAScript&nbsp;5 Parser, by @pvdz.ee:</p><p><a href="https://pvdz.ee/project/esparser/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">pvdz.ee/project/esparser/</span><span class="invisible"></span></a></p><p><a href="https://mas.to/tags/tools" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tools</span></a> <a href="https://mas.to/tags/exploration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploration</span></a> <a href="https://mas.to/tags/auditing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auditing</span></a> <a href="https://mas.to/tags/debugging" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>debugging</span></a> <a href="https://mas.to/tags/ecmascript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ecmascript</span></a> <a href="https://mas.to/tags/parsing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>parsing</span></a></p>
Continued thread

‘It’s a Heist’: Real Federal Auditors Are Horrified by DOGE

WIRED talked to actual federal auditors about how #government auditing works—and how DOGE is doing the opposite.
wired.com/story/federal-audito

"federal #auditors with years of #experience... say that DOGE’s actions are the furthest thing from what an actual #audit looks like...

“Honestly, comparing real #auditing to what #DOGE is doing, there’s no comparison... None of them are auditors”

#ElonMusk#Musk#Coup

Lately I got a some new followers, so let me introduce myself again: Dutch citizen interested in Unix, #Linux and #infosec, in particular the combination. Was the original author of rkhunter, a #malware detector, nowadays doing primarily #Lynis development, an #auditing tool that is #FOSS. I share my knowledge as much as possible, as I believe there this will benefit us all. My primary channel is my #blog (see bio) and with a copy to here.

Got questions? Happy to answer them.

Curious... we've covered a number of things on the IC_Null streams so far, is there anything people are curious about in particular? I'm streaming tonight after about a month of not doing so and I'm not quite set on a topic yet :)
If this is new to you, I stream #programming, #cybersecurity, #tech etc. stuff from the perspective of a fully #blind practitioner of such things. No monitors here, just #screenReader and keyboard.
So, what do I do? #TryHackMe? #HTB Academy? Something else entirely like working with #audio? Some kind of #auditing demo? Have a website/tool for me to roast/review? Requests welcome :)
#a11y #accessibility #selfPromo #infoSec #AMA

🔍 Enhance your financial operations with #AI in accounting and auditing! Osiz leverages cutting-edge AI technology to boost accuracy and efficiency, transforming traditional processes. Experience real-time data analysis, automated error detection, and streamlined reporting. Trust #Osiz to elevate your financial management to the next level.

Visit: osiztechnologies.com/blog/ai-i

Any IT auditors out there? Specifically those who audit security systems/programs. I've got a few questions for ya!

- What are some things that made you successful in your role?
- Are there any technical skills that are critical for your success?
- Any common challenges your face in your role?
- Do you have any advice for anyone trying to make a transition into auditing?
- Recommended readings?

#ITAuditor
#Auditing
#ITAuditJob

One of the weirdest aspect of #EndStageCapitalism is the collapse of #auditing, the lynchpin of investing. Auditors - independent professionals who sign off on a company's finances - are the only way that investors can be sure they're not handing their money over to failing businesses run by crooks.

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

pluralistic.net/2024/01/26/noc

1/

Conservatives may deride the #RealityBasedCommunity as a drag on progress and commercial expansion, but even the most noxious pump-and-dump capitalism is supposed to remain tethered to reality by two unbreakable fetters: #auditing and #insurance:

en.wikipedia.org/wiki/Reality-

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

pluralistic.net/2023/11/28/re-

1/

A common misconception when working with #auditing of #authorization systems is that "deny" events would be particularly interesting. Even to the extent that I've seen some people suggest purging "allow" decisions as noise. But while frequent deny decisions should be investigated, they are mainly a result of the system working as intended. When you have allowed users/actions that *shouldn't* have been allowed, is when you have real problems. Store everything!

I'm seeing the Pre-Auth RCE in Aspera Faspex article making the rounds, which gives some tips on how to spot vulnerable deserialization code in Ruby, such as YAML.load. As a Rubyist and security enthusiast, I need to point out that as of Ruby 3.1.0 and psych-4.0.0 YAML.load is now an alias to YAML.safe_load which will only deserialize core primitive classes (ex: Integer, Float, String, Array, Hash, etc).

YAML.load(YAML.dump(Object.new))
# /usr/share/gems/gems/psych 4.0.4/lib/psych/class_loader.rb:99:in `find': Tried to load unspecified class: Object (Psych::DisallowedClass)

YAML.unsafe_load(YAML.dump(Object.new))
# => #<Object:0x00007f7f37770750>

Simply grepping for YAML.load will not make it rain 0days, unless the code/app is running on Ruby < 3.1.0 or psych < 4.0.0.
#ruby #security #infosec #rails #rubyonrails #bugbountytips #auditing

AssetnotePre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on RailsApplication security issues found by Assetnote