Michael Skelton

@codingo_

Global Head of Security Ops and Researcher Enablement , Maintainer of NoSQLMap, VHostScan, Reconnoitre. Co-contributor to Interlace, DNSlistmaint.

Vrijeme pridruživanja: rujan 2013.

Tweetovi

Blokirali ste korisnika/cu @codingo_

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @codingo_

  1. Prikvačeni tweet
    28. srp 2019.

    So thrilled to be working on this book with . We've been at it for a while, with the goal to make something we feel we could pick up ourselves and learn something from - both at this stage in our hunting and when we started.

    Poništi
  2. 3. velj

    A lot of work went into this, very recommended reading for many.

    Poništi
  3. 2. velj

    I'll be coming out for day two of and in and out of . Also working in time at a bug bash, so it will be a busy week, but if anybody wants to catch up at any of those lmk!

    Poništi
  4. proslijedio/la je Tweet
    29. sij

    ffuf 1.0 released! phew, this is a big one. Feature highlights in this thread Huge thanks for all the contributors, and special thanks to for pulling off a feature bounty and for fulfilling it in a record time (and contributing said bounty to charity).

    Prikaži ovu nit
    Poništi
  5. proslijedio/la je Tweet
    29. sij

    Want to understand new tricks are using in 2020? Join as he workshops new reconnaissance and discovery methods being actively used. Reserve your spot:

    Poništi
  6. proslijedio/la je Tweet

    If you need to test HTTP request smuggling on a pool of hosts/urls, check out my new script, its works pretty well on labs

    Prikaži ovu nit
    Poništi
  7. proslijedio/la je Tweet
    27. sij

    I created this repo for the people who want to learn about windows logical privilege escalation bugs. You can contact me to add good article which I missed.

    Poništi
  8. proslijedio/la je Tweet
    26. sij

    Ladies and gentlemen, I present you a working Remote Code Execution (RCE) exploit for the Remote Desktop Gateway (CVE-2020-0609 & CVE-2020-0610). Accidentally followed a few rabbit holes but got it to work! Time to write a blog post ;) Don't forget to patch!

    Prikaži ovu nit
    Poništi
  9. proslijedio/la je Tweet
    24. sij

    ApplicationInspector - A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'what's in it' using static analysis with a json based rules engine.

    Poništi
  10. proslijedio/la je Tweet
    23. sij

    Google Dataset Search is now officially out of beta. "Dataset Search has indexed almost 25 million of these datasets, giving you a single place to search for datasets & find links to where the data is." Nice work, Natasha Noy and everyone else involved!

    Prikaži ovu nit
    Poništi
  11. 24. sij

    I'm going to be in San Francisco next week, free for beers/catchups on Thursday (potentially also Wednesday) night if anybody is up for a drink!

    Poništi
  12. proslijedio/la je Tweet
    21. sij

    We released a Red Teaming book! Red Team Development and Operations. It's been a crazy project that has existed in many forms. It started as simple notes, came together as a SANS class, and will now live as a book. Read about it here.

    Poništi
  13. proslijedio/la je Tweet
    21. sij

    Hey I put my note-taking template (Cherrytree) for the OSCP/HTB/VHL up on the internoodle. I see people asking for these all the time on Reddit and Discord and stuff, so I hope it helps someone:

    Poništi
  14. proslijedio/la je Tweet
    16. sij

    🌱 Grow your community 🔨 Build up your skills 😍 Chance for a 1:1 with Do you need more reasons to join the Discord? Join today!

    Poništi
  15. proslijedio/la je Tweet
    16. sij
    Poništi
  16. proslijedio/la je Tweet
    15. sij

    We're pleased to share our product roadmap for 2020, highlighting what's on the way for Burp Suite Enterprise Edition, Burp Suite Professional, and Burp Scanner.

    Poništi
  17. 15. sij

    Claimed by who landed this within an hour of posting. A great win for ffuf and the community!

    Poništi
  18. 14. sij

    I'm planning another giveaway. I'm thinking the next one will depend on the recipient making a contribution to the community (github pull request, blog, something else) to claim a subscription voucher.. thoughts? Is it better to just free for all?

    Poništi
  19. 14. sij

    Offering a $100USD bounty to whoever can build out ... payable once merged by (DM to receive). This has wide reaching benefits to newcomers and a great one to have your name against!

    Poništi
  20. proslijedio/la je Tweet
    12. sij

    Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :)

    Poništi
  21. proslijedio/la je Tweet
    12. sij

    Citrix Netscaler AMIs on default vulnerable out of the box. The root password is set to the instance ID; that can be read from the metadata URL. CVE-2019-19781 from nobody to ssh as root in seconds.

    Prikaži ovu nit
    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·