Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @0xm1rch
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @0xm1rch
-
Prikvačeni tweet
Earlier this month I discovered a privilege escalation vulnerability in the Signal Desktop Windows client. This vulnerability has been patched in v1.29.1 which was released yesterday. Write-up: http://blog.mirch.io/signal-desktop-windows-lpe … 1/2
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Hey bug hunters! Want a look at some of the top vulnerabilities ever found on
@Dropbox ? They just released the last blog post I wrote before leaving. Enjoy!#bugbountytipshttps://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/ …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
#OSINT Awesome OSINT https://github.com/jivoi/awesome-osint … OSINT SubReddit https://reddit.com/r/OSINT/ http://WhotWi.com Spiderfoot https://spiderfoot.net Pymeta https://github.com/m8r0wn/pymeta OSINT Stash https://osint.best My tutorials https://0x00sec.org/t/my-personal-osint-techniques-part-1-of-2-key-layer-contingency-seeding/13033 … https://0x00sec.org/t/my-personal-osint-techniques-volume-2-the-kitchen-sink/13198 …pic.twitter.com/IpqYcWHZM0
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
TeamViewer stored user passwords encrypted, not hashed, and the key is now publichttps://whynotsecurity.com/blog/teamviewer/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
w00t! So excited to announce our new course at
#BHUSA2020 - Adversary Emulation and Active Defense! 4Day - https://www.blackhat.com/us-20/training/schedule/index.html#adversary-emulation-and-active-defense-19136 … Combining the spheres of offense and defense to teach core concepts.@BlackHatEvents@TeamAresSec@CRITICALSTART@paragonsec@BlaiseBrignacHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Hello hunters ! last year i published my recon map, this year i share with you my
#bugbounty checklist ! Feel free to ask questions and make comment to improve it ! and hope you enjoy ;) https://bit.ly/2RBvEVq#bugbountytips#togetherwehitharderpic.twitter.com/1LPF8qf7y0
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Some study notes on LSASS hooking for harvesting interactive logon credentials. https://ired.team/offensive-security/credential-access-and-credential-dumping/intercepting-logon-credentials-by-hooking-msv1_0-spacceptcredentials … Thanks to
@_xpn_ for his inspiring posts about mimikatz.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Despite its incredible security enhancements, PowerShell continues to be abused by adversaries. A strong knowledge of PowerShell enables defenders to effectively manage and respond to its abuse. (1/4)
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Revisiting RDP lateral movement https://posts.specterops.io/revisiting-remote-desktop-lateral-movement-8fb905cb46c3 … and releasing a project that will be part of a bigger tool coming next week
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Our first intern,
@0xdab0 created a project called Satellite to automate C2 traffic redirection. In this post, he talks about some of the keying, proxying, and filtering options of the project. Read more here: https://posts.specterops.io/satellite-a-payload-and-proxy-service-for-red-team-operations-aa4500d3d970 … Project link:https://github.com/t94j0/satelliteHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Kudos to SparkLabs for fast response, great communication, and for the design decision to limit privileges. Most VPN clients do not take this approach. I will post the technical details at a later date.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CVE-2020-5180 Viscosity macOS, Windows Limited Elevation of Privilege Vulnerability. This was a fun to research but was unable to leverage it to do much due to the dropping of privileges. It's refreshing to find an application with security baked in.https://www.sparklabs.com/blog/viscosity-for-mac-windows-version-1-8-4/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
Sources say Microsoft on Tuesday will fix an extraordinarily scary flaw in all Windows versions, in a core cryptographic component that could be abused to spoof the source of digitally signed software. Apparently DoD & a few others got an advance patch https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Rich Mirch proslijedio/la je Tweet
I may not have many followers, but if anyone knows someone who needs an IT veteran with 20 years’ experience, who learned Cisco when telnetting to a switch was not a security risk, and who has a CISSP, SSCP, and several other certs, my DMs are open.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Rich Mirch proslijedio/la je Tweet
How to drive someone completely nuts at Linux shell prompt (add to their ~/.bashrc): alias ls='ls -l | lolcat -a' ls
#Prankspic.twitter.com/AjUZM3CbkkHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
To bring in the new year here's a new blog post about empirically testing Windows Service Hardening to see if it is really not a security boundary even on Windows 10. https://tyranidslair.blogspot.com/2020/01/empirically-assessing-windows-service.html … h/t
@cesarcerHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
New year gift
Set up a free server to exploit blind vulnerabilities!
1. https://ssh.cloud.google.com/cloudshell/editor …
2. sudo apt-get install apache2 pagekite
3. add "ServerName localhost" to /etc/apache2/apache2.conf
4. 80->8080 in /etc/apache2/ports.conf
5. pagekite 8080 http://xyz.pagekite.me pic.twitter.com/j7UovMdYCr
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Rich Mirch proslijedio/la je Tweet
SharpSploit v1.5 is out! Includes amazing work from
@_RastaMouse,@checkymander,@001SPARTaN,@FuzzySec, and@TheRealWover. Includes: lateral movement over SCM and PSRemoting, an AMSI bypass, CreateProcessWithToken, and DynamicInvoke improvements.

https://github.com/cobbr/SharpSploit …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.