Are Leaked Credentials Dumps Used by Attackers?, (Fri, Aug 4th)

Leaked credentials are a common thread for a while. Popular services like “Have I Been Pwned”[1] help everyone know if some emails and passwords have been leaked. This is a classic problem: One day, you create an account on a website (ex: an online shop), and later, this website is compromised. All credentials are collected and shared by the attacker. To reduce this risk, a best practice is to avoid password re-use (as well as to not use your corporate email address for non-business-related stuff).

Continue reading Are Leaked Credentials Dumps Used by Attackers?, (Fri, Aug 4th)→

Posted in Uncategorized

Summary of DNS over HTTPS requests against our honeypots., (Tue, Aug 1st)

Our honeypots see a lot of DNS over HTTP(s) requests against the “/dns-query” endpoint. This endpoint is used by DNS over HTTPs requests to receive queries. Queries can use different encodings. You may either see the more readable URL encoding, like “?name=google.com&type=A” or the raw DNS data encoding, like “?dns=mNwBAAABAAAAAAAABmdvb2dsZQNjb20AAAEAAQ”.

Continue reading Summary of DNS over HTTPS requests against our honeypots., (Tue, Aug 1st)→

Posted in Uncategorized