Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @christophetd
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @christophetd
-
Prikvačeni tweet
New blog post! ➟ Stealthier persistence using new services purposely vulnerable to path interception. https://blog.christophetd.fr/stealthier-persistence-using-new-services-purposely-vulnerable-to-path-interception/ … Allows you to create services which appear to point to a binary but will actually run another one.
#redteam#threathuntingpic.twitter.com/AktbmQfRPh
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
I'm exited to start working at
@ProtonMail If you want to join: We're already hirign the next Security Analyst: http://careers.protonmail.com/o/security-analyst ….Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
In the past year, I was researching Azure Stack, which is an on-premise version of Azure Cloud. In the following blog posts, we present information on what is Azure Stack and its architecture and disclose a vulnerability in Azure App Service that allowed a sandbox escape.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Link: https://github.com/christophetd/censys-subdomain-finder … Happy to discuss it and to write a proper test suite if that helps.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
New Blog Post from
@Haus3c on Azure. Ryan discusses Azure and Azure AD's components, reviews some of the attacks, and release PowerZure to help understand the attacks. Link: https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a … PowerZure:https://github.com/hausec/PowerZure …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
Some study notes on LSASS hooking for harvesting interactive logon credentials. https://ired.team/offensive-security/credential-access-and-credential-dumping/intercepting-logon-credentials-by-hooking-msv1_0-spacceptcredentials … Thanks to
@_xpn_ for his inspiring posts about mimikatz.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
"The remaining commands send feedback by posting data into Google Forms"
https://twitter.com/r00tbsd/status/1218081709213745153 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
To clarify the Windows crypto fail: The problem isn't in signature validation. The problem is the *root store/cache*. CryptoAPI considers an (attacker-supplied) root CA to be in the trust store if its public key and serial match a cert in the root store, Ignoring curve params.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Security architecture anti-patterns: Six design patterns to avoid when designing computer systemshttps://www.ncsc.gov.uk/whitepaper/security-architecture-anti-patterns …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
@TimMedin Something to add to SEC660 in "MiTM tooling" ;)Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Took a few hours to attempt a PoC myself, reach about half of the write-up and got stuck by my lack of knowledge of the tooling. Overall the PoC is pretty simple, I don't even want to imagine how many actors have been exploiting it in the wild.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Good write-up with PoC of CVE-2020-0601 by
@AnomalRoilhttps://research.kudelskisecurity.com/2020/01/15/cve-2020-0601-the-chainoffools-attack-explained-with-poc/amp/?__twitter_impression=true …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Super thrilled to say that I will be presenting a talk at Insomni'hack this year! https://twitter.com/1ns0mn1h4ck/status/1217033955943292929 …pic.twitter.com/vlXCUAdbgz
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
Interesting tidbit from report. “The attacker utilized the anti-virus management console service account to distribute the malware across the network.” Sounds similar to
#APT32 deploying Cobalt Strike via McAfee EPO server@ItsReallyNick & I discussed recently on#StateOfTheHackhttps://twitter.com/campuscodi/status/1215128139271147520 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
At Google Project Zero, the team spends a *lot* of time discussing and evaluating vulnerability disclosure policies and their consequences. It's a complex and controversial topic! Here's P0's policy changes for 2020 (with our rationale for the changes): https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je TweetPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Personal goals: 2020 is the year of me running a half-marathon and climbing a 4000m mountain.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
Excellent introduction to the implementation of Windows Event Logs and why they can be missing critical information. Michael Cohen includes an open source Velociraptor parser as a solution. https://buff.ly/2OcvvqP https://buff.ly/37rDist pic.twitter.com/9z3HurxNe5
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
Looking to get more conferences and events filmed, I'm working to assemble and distribute video additional rigs. Can you help me carry the cost? https://administraitor.video/fundraiser.html RT very much appreciated.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
[
#MUSTREAD] The Navy installed touch-screen steering systems to save money. Systems it didn’t understand and the crew didn’t receive training on. Ten sailors paid with their lives.https://features.propublica.org/navy-uss-mccain-crash/navy-installed-touch-screen-steering-ten-sailors-paid-with-their-lives/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Christophe proslijedio/la je Tweet
“Winter2019” is coming
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.