Interesting large and small malspam attachments from 2023, (Wed, Jan 3rd)

At the end of a year, or at the beginning of a new one, I like to go over all malicious attachments that were caught in my e-mail trap over the last 12 months, since this can provide a good overview of long-term malspam trends and may sometimes lead to other interesting discoveries. Over the years, I found that, at a minimum, it is usually instructive to look at what the largest and the smallest pieces of malware that one managed to catch were[1]. This held true even for 2023, as both the smallest and the largest sample I had turned out to be interesting in their own right. But let’s start at the beginning…

Continue reading Interesting large and small malspam attachments from 2023, (Wed, Jan 3rd)

Posted in Uncategorized

Fingerprinting SSH Identification Strings, (Tue, Jan 2nd)

For HTTP, logging and fingerprinting browser user agents is standard practice. Many anti-automation tricks use the user agent and compare it to other browser artifacts, for example, supported JavaScript APIs, to detect bots. SSH offers an “identification string” with a format mandated by RFC 4253.

Continue reading Fingerprinting SSH Identification Strings, (Tue, Jan 2nd)

Posted in Uncategorized

Pi-Hole Pi4 Docker Deployment, (Sun, Dec 31st)

During the holiday season, I&#;x26;#;39;ve tried many different self-hosting solutions. But one of the most basic options is setting up a Pi-Hole DNS for your home. While the installation is pretty easy, I wanted to use docker on my Pi4, which would be an excellent way to get started. Having this as a docker would allow me to quickly redeploy if there was an issue, as DNS is crucial.

Continue reading Pi-Hole Pi4 Docker Deployment, (Sun, Dec 31st)

Posted in Uncategorized