pull down to refresh
0 sats \ 0 replies \ @frostdragon 28 Feb \ parent \ on: Social Engineering Practice 0x01 security
Thanks friend!
A magic square is a grid of numbers arranged so that the sum of each row, each column and its diagonals are all equal to the same value, called the magic sum (or magic constant).
For example 39 is the magic sum of this grid:
each row, column, and long diagonal add up to 39 (as do the 4 corner squares, and the 4 center squares).
This is how I would write it as the plot of a Mr. Robot episode (or something similar - idk if this is possible for every real life situation, but I think is 100% plausible).
Step 1:
Try to ID the wristband supplier via OSINT, or possibly via a customer service agent. "Hey, can you let me know who makes the wristbands? I'm allergic to polyester and I wanted to look them up to see if I'll get a rash again this year" or something like that. No idea of a polyester allergy is a real thing, but I'm sure customer service doesn't either.
Step 2a:
Once you have the supplier, the trick would be to impersonate someone from the venue to get more wristbands. You could contact the supplier posing as a venue employee and start with a benign question, like "can you confirm when the wristband order shipped?" This is just to feel out the situation. Are they more than willing to give you information? You might be able to find out more useful things.
Step 2b:
If they're used to dealing with a specific venue contact, you can say something like "oh yeah, that makes sense - just to confirm, who was it that you spoke with? I work in a different department and I've been asked to help pick up the slack on a few things".
Once they've identified that person, then you'll need to need to get a little hacky. Let's say for creativity's sake that the venue has a missing or misconfigured DMARC record, which means you can easily forge emails pretending to come from their domain.
Step 3:
Once you've established trust with the supplier (either via a forged email or via the supplier's complete lack of due diligence), ask them to ship 20 backstage passes to your PO Box and say it's for a production company so their employees can invite friends and family. Or, if the company is local and you don't want to register a PO Box, ask if you can send an intern to pick up the passes since you'll be out of town.
As an added flair, ask if the venue will add a special logo of your own design to the band.
Honestly I super appreciate the straightforward take without the DEVELOPER JOBS ARE DEAD AGI IS HERE IT'S HAPPENING bs
I think yeah, physically, we’re stardust. We reside inside stardust containers. But I think we are conscious souls that have the ability to use free will. And I think we don’t know what most of that sentence even means.
But I think we know absolute truth and absolute morality exist, outside of our souls and our universe. I think that’s what God is, and whatever we are is a finite fragmented derivative of that God’s mind. I think we’re supposed to seek relationship with and journey alongside that being. I think that’s going to look like many of the things mentioned here. Taking responsibility. Helping others. Being creative. Making everything around you better than it was before. I think all of those things are pieces of the meaning of life, because they’re pieces of the thing that made life.
Yep, this is a solid take.
I frequently wonder if the USG is just... unintentionally kneecapping themselves here? Or if there's something way worse going on.
Even without a hard fork, the idea of nations or even corporations accumulating bitcoin faster than the rest of us to the point that they own 90-95+% of all the bitcoins over time is a scary thought. In some ways that sounds worse than our current setup.
Intellectual property laws are not near as strict or enforceable as they are in the US, so that has something to do with it.
Either way, I think what SN has set up is probably the way of the future. Self custody and self sovereignty is just going to get easier with time IMO.
For government use only
*Uploads a selfie w/ blurry background from a vacation a few years ago to ChatGPT
*ChatGPT correctly identifies the city