K. Reid Wightman :verified: 🌻 on Nostr: Infosec pro tip: If you're a vulnerability researcher, and you find some gnarly vulns ...
Infosec pro tip:
If you're a vulnerability researcher, and you find some gnarly vulns in stuff, go hunt on Shodan. And, do what you can to track down the owners of the vulnerable equipment to give them a heads-up/warning.
ISACs have been really helpful at this. In the past, we've reached out to MS-ISAC (RIP?), E-ISAC, REN-ISAC, and others. Given them a list of IP addresses and owners, a brief synopsis of what the problem is, and remediation advice (ports to block, stuff to look out for).
Vulnerability crap can seem overwhelming at times, but I've gotta say: seeing even a couple of IP addresses of vulnerable devices disappear due to just reaching out to owners, is an incredibly rewarding feeling. There's no money in it, but dang it feels good...
Published at
2025-03-19 15:03:53Event JSON
{
"id": "ee2520da06d24eb364574c62a66b9470a3706cd223d799c50522aebd83ba4d31",
"pubkey": "7eb3d5d2f214457cdc9906adf5d19db9ff087112b4822741946e7fa9de0f6dcb",
"created_at": 1742396633,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/users/reverseics/statuses/114189705805504460",
"activitypub"
]
],
"content": "Infosec pro tip:\n\nIf you're a vulnerability researcher, and you find some gnarly vulns in stuff, go hunt on Shodan. And, do what you can to track down the owners of the vulnerable equipment to give them a heads-up/warning.\n\nISACs have been really helpful at this. In the past, we've reached out to MS-ISAC (RIP?), E-ISAC, REN-ISAC, and others. Given them a list of IP addresses and owners, a brief synopsis of what the problem is, and remediation advice (ports to block, stuff to look out for).\n\nVulnerability crap can seem overwhelming at times, but I've gotta say: seeing even a couple of IP addresses of vulnerable devices disappear due to just reaching out to owners, is an incredibly rewarding feeling. There's no money in it, but dang it feels good...",
"sig": "90e91b23bc5647695de8d6479430a8be4bee59db0be26a7d7899d7311b09d0862b259350d1a44a77b407fcad8efc129dc1cb8057b90362c513314a407276bc65"
}