the grugq's newsletter

Subscribe
Archives
May 2, 2022

May 1, 2022

The Ukrainian volunteer cyber army is possibly the worst thing to happen for Ukrainian cyber security since the 2015 electrical grid hack. They are providing almost no operational benefit to the Ukrainian war effort, while simultaneously forcing the Russians into a more secure cyber posture.

https://www.washingtonpost.com/technology/2022/05/01/russia-cyber-attacks-hacking/


Twitter avatar for @ptuxerman
Anton Ptushkin @ptuxerman
“People of the Chechen Republic!” This is the header of a leaflet from a propaganda reactive shell (a red thing in the background) I found in Chernihiv. One of the shells that were fired by the Russian army at the city and suburbs. Wrong with the country, wrong with the year.
Image
2:41 PM ∙ Apr 30, 2022
4,091Likes780Retweets


ACAB.

Twitter avatar for @deenafaywinter
Deena Winter @deenafaywinter
I have read the 72-page state report on MPD, and compiled some of the most jaw-dropping portions. Here are some of them. 🧵
9:53 PM ∙ Apr 27, 2022
11,053Likes4,011Retweets


Ukraine is doing the partisan thing, only it’s behind Russian borders, not just lines.


Blasts, Bombs, And Drones: Amid Carnage In Ukraine, A Shadow War On The Russian Side Of The Border

Ukrainian officials have not taken responsibility for a series of explosions and attacks on Russian territory. Similarly, Russian officials have not made a big deal over the fact that Russian territory appears to be routinely targeted by a foreign military.


The Info Op is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.


Great thread on drones equipped with grenades and bombs as the new snipers.

Twitter avatar for @ChrisO_wiki
ChrisO @ChrisO_wiki
By now, many will have seen the video of a Ukrainian drone dropping a small bomb through the sunscreen (!) of a car driven by Russian soldiers. Here's a short thread on how it was done (with thanks to @ian_matveev, on whose thread this is based). /1
12:33 AM ∙ May 1, 2022
4,933Likes1,386Retweets


Twitter avatar for @JenMsft
Jen Gentleman 🌺 @JenMsft
I feel old now
<img class="tweet-photo" src="https://pbs.substack.com/media/FRoVl5vVEAA0vmE.jpg" alt="A post on the PC master race subreddit with a picture and the question "Anyone know what type of port this? I was thinking Ethernet but it's too small"

The photo is of a land line phone jack

" loading="lazy">

11:57 PM ∙ Apr 30, 2022
3,279Likes234Retweets


America, fuck yeah!

Twitter avatar for @ampol_moment
crazy ass moments in american politics @ampol_moment
President Eisenhower sketches a buff version of himself on a memo about how the CIA had just overthrown the Guatemalan government. (1954)
Image
10:41 PM ∙ Apr 30, 2022
32,549Likes3,394Retweets


Some interesting findings about the diets of early medieval elites.


Cambridge University study finds Anglo-Saxon kings were mostly vegetarian

Peasants occasionally hosted lavish meat feasts for their rulers, researchers say.


Twitter avatar for @histoftech
Mar Hicks @histoftech
this feels canon
Character from the Star Trek next generation episode Darmok at Tanagra. Instead he is saying “crypto bro, his apes stolen.”
12:41 AM ∙ May 1, 2022
1,216Likes288Retweets


Jailbreak kindle. Exploits here

Tutorial WatchThis - Software Jailbreak for any Kindle <= 5.14.1 - MobileRead Forums


Some handy helpers for hacking

Twitter avatar for @_nwodtuhs
Charlie Bromberg (Shutdown) @_nwodtuhs
In case you missed it, here are two diagram and table to help understand and abuse NTLM relay attacks 😃 (I could use some help to finish them and do some foolproofing, but they're already helpful as is imo)
Image
Image
10:13 AM ∙ Apr 30, 2022
602Likes194Retweets

Coverage on how the intelligence war fed the hot war.


U.S. intel helped Ukraine protect air defenses, shoot down Russian plane carrying hundreds of troops

Ukrainian forces have used specific coordinates shared by the U.S. to direct fire on Russian positions and aircraft, current and former officials tell NBC News.


Strong signalling happening these days. Pelosi and a bunch of senators went to meet Zelensky in Kyiv.


Ignorant legislation about data retention ends up targeting privacy services. News at 11.

Twitter avatar for @FredericJacobs
Frederic Jacobs @FredericJacobs
Very shortsighted legislation in Belgium on data retention. The bill is effectively outlawing Signal. I doubt it’s going to hold up to scrutiny from the Belgian Constitutional Court, but it’s going to be detrimental for privacy in Belgium.

Thanks @bpreneel1 for speaking out

Twitter avatar for @nikolasvh
Nikolas Vanhecke @nikolasvh
‘Signal wordt eigenlijk verplicht metadata bij te houden en de autoriteiten er toegang toe te verlenen als ze dat vragen. De implicaties voor Signal zijn enorm, die zullen waarschijnlijk moeten sluiten voor België.’ https://t.co/zT5pvfG3ws
8:57 AM ∙ May 1, 2022
32Likes29Retweets


Woah

Twitter avatar for @ReedTimmerAccu
Reed Timmer @ReedTimmerAccu
Highest-res drone footage of the Andover, KS #tornado which has received a preliminary rating of EF3. Note how the tornado propagates via vortex dynamics and likely terrain. Incredibly, no lives were lost by this tornado
11:14 PM ∙ Apr 30, 2022
19,245Likes5,583Retweets


Apparently Russian troll farms are a thing? Who knew??

Here’s the takedown thread by a skeptical journalist.

Twitter avatar for @AlexMartin
Alexander Martin @AlexMartin
New: Britain has accused a "sick Russian troll factory" of "plaguing social media with Kremlin propaganda" after funding what it said was expert research into the organisation.
news.sky.comUkraine war: Britain accuses ‘sick Russian troll factory’ of ‘plaguing social media with Kremlin propaganda’An organisation based in St Petersburg called Cyber Front Z is said to pay locals about £500 a month to target senior politicians and media outlets on social media platforms and in comment sections.
11:13 PM ∙ Apr 30, 2022
23Likes11Retweets

Here’s part of the story I thought was worth extracting.

Activities on Twitter and Facebook were detected, but were found to be particularly concentrated on Instagram, YouTube and TikTok. A key role in the network is said to be performed by a Telegram channel called “Cyber Front Z”, with the letter Z signifying Russian support for the war.

(I’ll be honest, the fact that Russia is also using a telegram channel to control a crowd of ppl is a datapoint on organization in cyber conflict.)

Here is the dumb ass story:


‘Troll factory’ spreading Russian pro-war lies online, says UK | Ukraine | The Guardian

St Petersburg outfit hijacks discussions on Twitter, TikTok, world leaders’ social accounts and media websites, as well as manipulating opinion polls


The school of elicitation.

Twitter avatar for @soychotic
annie @soychotic
Every time I have a programming question and I rly need help, I post it on Reddit and then log into another account and reply to it with an obscenely incorrect answer. Ppl don’t care about helping others but they LOVE correcting others. Works 100% of the time
7:44 PM ∙ Apr 29, 2022
110,908Likes10,566Retweets

This is a good video on how user interface and human factors impact security.


Twitter avatar for @dpatrikarakos
David Patrikarakos @dpatrikarakos
Odesa security expert tells me: “Security is really tight atm as there's a real fear of infiltration by saboteurs. Last week the security services caught someone skulking around post-curfew. When then grabbed him, he screamed: "It's ok, it's ok, I'm just a drug dealer!"
8:01 AM ∙ May 1, 2022
3,644Likes625Retweets

Thank you for reading The Info Op. This post is public so feel free to share it.

Share

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X