• 0 Posts
  • 4 Comments
Joined 1 year ago
cake
Cake day: June 10th, 2023

help-circle
  • There are literally hundreds to thousands. Many of them are horded by governments, APTs, and pen testers. I personally abused a 10 year old CVE for pen tests that was known to be used by non US government entities for a zero click code execution on opening a word doc.

    Then there are things that are vulnerabilities but cannot be fixed as they are intensic to how Windows functions. Some can be hardened from the defaults but break compatibility and some cannot be fixed without a complete rewrite of how Windows and AD work. Disa stigs will give you defaults that can be hardened. Requirements for all domain users to see all GPOs, users, groups in order for AD to work is an example of something that cannot be fixed without a complete rewrite. That means an in privileged user can get a list of all users, all domain administrator, names of all computers on the domain, etc. As an attacker, that is invaluable.

    Short answer, that list is to big and changes constantly. None that would be comprehensive, but disa stigs is a good place to start.


  • There are many variables that makes a yes no answer impossible. Currently there are too many instances for a lawsuit to be brought to each. The instances are in different countries, do different laws would have to be navigated for each. For example, in the US, Google has like to piracy websites. Google doesn’t allow housing of piracy on their platform. Google does some removal of listings but it is but exhaustive.

    Google is not being held liable, and I bet if an instance happens to cache piracy content due to a user interacting with another insurance, Google and ISPs would be interested in helping that instance so president isn’t set that creates liability for traffic that happens to traverse servers, if it is but being served by the server.

    This is a very ELI5, and isn’t a full discussion of all the variables. A difficult question even limited to one country’s laws.

    Realistically, the while point of a federation us to make it impossible to shut down, or censor world wide, the community as there are simply too many different servers. This works against corporate attacks as well as legal.