Benjamin DelpyVerified account

@gentilkiwi

A kiwi coding mimikatz & kekeo github: Security Research & Development Tweets are my own and not the views of my employer

France
Joined June 2011

Tweets

You blocked @gentilkiwi

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @gentilkiwi

  1. Apr 14

    Please remember: Port 445 is just ONE of the ports that may reach (CVE-2022-26809) on Windows. does Port 135 (and high port) or in some cases HTTP as well. Don't "close some ports" but "only open ports you need open".

    Undo
  2. Apr 12
    Undo
  3. A new attack is coming?

    Undo
  4. Not naming , but not the first time I saw Windows Passwords passed to an user process... you know, "for Single Sign On"... despite Credential Guard 1/, all of $vendors are Microsoft Partners 2/, no need to be admin to have our own - malwares welcome!

    Undo
  5. Your best security measure is to block Bing search. Or I missed something?

    Undo
  6. Mar 24

    the real hard problems in crypto are 1) key management and 2) endianness

    Undo
  7. Show this thread
    Undo
  8. Be careful on what servers your libssl clients/blackbox appliances are connecting to... Patch your appliances now against CVE-2022-0778, clients or servers ones.

    Show this thread
    Undo
  9. Show this thread
    Undo
  10. With explicit TLS 1.2 to be able to see certificate on the network...

    Show this thread
    Undo
  11. Thanks to & , just played with CVE-2022-0778 against vulnerable (web) servers Just few tweaks, and ready to scan servers accepting certificates... 🫤 If it is not done yet: patch...

    Show this thread
    Undo
  12. Undo
  13. Mar 12

    ... not just files.. It will do files, spiffs files, emulator mem and if I get the mood, also a magic gen1 dump .. (cview)

    Show this thread
    Undo
  14. Mar 1

    Just learn that my GIDS smart card applet is distributed on Serbian Taxpayer card. It’s an app running on smart card to handle certificates (sc logon) Open source, native driver on Windows, supported by opensc, even available virtually on android phone.

    Undo
  15. Feb 26

    If someone have a MIFARE Plus EV1 card. And a proxmark or phone w taginfo, can I get the UID and the signature data, please?

    Undo
  16. Feb 24
    Replying to

    You probably enjoying fresh Windows 10 builds on your fancy brand new laptop but real networks built on the legacy shit

    Undo
  17. *Not* thank you Device Manager :(

    Undo
  18. Feb 15

    New version and related blog post (with multicolor arrows) out now! "Stealing and faking Azure AD device identities": Credits to /!

    Undo
  19. I don't understand... Hotpatching is 2004, introduced with 2003 SP1, isn't it ? >

    Undo
  20. Feb 16

    It's easy to backdoor a Windows box to log all passwords in plaintext when someone logs in. Great article on this by here with implementations from both and

    Show this thread
    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·