Hacker News new | past | comments | ask | show | jobs | submit login

From Eva’s post:

> we didnt know much about firebase at the time so we simply tried to find a tool to see if it was vulnerable to something obvious and we found firepwn, which seemed nice for a GUI tool, so we simply entered the details of chattr's firebase

Genuinely curious (I’ve no infosec experience), wouldn’t there be a risk that a tool like this could phone home and log everything you find while doing research?




Sure but it's FOSS, so audits are pretty easy.

Plus as part of the pentesting I watch the network stack in Firefox sometimes so I would tell if it was trying to exfiltrate date


Yes, but that might also be caught by infosec users of said tool who have things similar to “littlesnitch” alerting them to the outbound API call attempt.


there used to be windows GUIs for forcing new connections to ask, but i haven't seen anything like it. I can't recall the name of the one i used to use, but it scored perfectly on shieldsUp - oh, Zone Alarm.

Littlesnitch iirc is macos only, but it sounds lovely for this sort of thing.


There's a very good relatively new open-source GUI firewall app like this called Portmaster:

https://safing.io/

It's available for Windows and Linux


Indeed!

If anyone wants to get to know us, our next Live Q&A is tomorrow at 15:00 CET: https://m.youtube.com/watch?v=S6P8ajLECXg


You can set this with Windows' default firewall. Setting to strict mode with no whitelist causes a UAC alert every time a process attempts communication.


The generic term is “outbound firewall”.


You are looking for simplewall


That would be referred to as a honeypot. Sometimes administrators will set up their own honeypots to see the type of threats they are facing.


No, a honeypot is intentionally insecure infrastructure setup to see who and how it gets attacked. A backdoored pentesting tool is a backdoored pentesting tool.


Im not saying the pentesting tool is a honeypot, but thanks for asking.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: