Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @gentilkiwi
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @gentilkiwi
-
Benjamin Delpy Retweeted
Please remember: Port 445 is just ONE of the ports that may reach
#RPC (CVE-2022-26809) on Windows.#MSRPC does Port 135 (and high port) or in some cases HTTP as well. Don't "close some ports" but "only open ports you need open".#allowlist#dontblocklistThanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
That's one hell of a way of using the phrase "secure by default." https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-24545 …pic.twitter.com/x7c6eIy14f
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Thanks. Twitter will use this info to make your timeline better. UndoUndo
-
Not naming
$vendor, but not the first time I saw Windows Passwords passed to an user process... you know, "for Single Sign On"... despite Credential Guard 1/, all of $vendors are Microsoft Partners 2/, no need to be admin to have our own - malwares welcome!pic.twitter.com/EjJTFLqTFZThanks. Twitter will use this info to make your timeline better. UndoUndo -
Your best security measure is to block Bing search. Or I missed something?https://twitter.com/BillDemirkapi/status/1508527487655067660 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
the real hard problems in crypto are 1) key management and 2) endiannesspic.twitter.com/nh82JsJlks
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Video quality: https://video.twimg.com/tweet_video/FOab_F4XEAIJJCP.mp4 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Be careful on what servers your libssl clients/blackbox appliances are connecting to... Patch your appliances now against CVE-2022-0778, clients or servers ones.
#JustSaying https://twitter.com/gentilkiwi/status/1505685363792166920 …pic.twitter.com/yOXLrCV5eWShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
And as usual, video quality: - https://video.twimg.com/tweet_video/FOVEuowXIAE5t8H.mp4 … - https://video.twimg.com/tweet_video/FOVEv-LXMAA2LBU.mp4 …
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
With explicit TLS 1.2 to be able to see certificate on the network...pic.twitter.com/xL9EHHd5rn
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Thanks to
@___wr___ &@taviso, just played with CVE-2022-0778 against vulnerable (web) servers Just few tweaks, and ready to scan servers accepting certificates... 🫤 If it is not done yet: patch...pic.twitter.com/N86rbjlzNKShow this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Technically, they still stop
#mimikatz
https://twitter.com/chompie1337/status/1504166538772942854 …Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
... not just files.. It will do files, spiffs files, emulator mem and if I get the mood, also a magic gen1 dump .. (cview)
#proxmarkpic.twitter.com/4jQGHzHlzF
Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
Just learn that my GIDS smart card applet is distributed on Serbian Taxpayer card. It’s an app running on smart card to handle certificates (sc logon) Open source, native driver on Windows, supported by opensc, even available virtually on android phone.https://github.com/vletoux/GidsApplet …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
If someone have a MIFARE Plus EV1 card. And a proxmark or phone w taginfo, can I get the UID and the signature data, please?
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
You probably enjoying fresh Windows 10 builds on your fancy brand new laptop but real networks built on the legacy shit
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
*Not* thank you Device Manager :(pic.twitter.com/diW8cIiLa9
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
New
#AADInternals version and related blog post (with multicolor arrows) out now! "Stealing and faking Azure AD device identities": https://o365blog.com/post/deviceidentity/ … Credits to@gentilkiwi/#Mimikatz!#infosec#redteam#blueteampic.twitter.com/4mRgV2ZYxy
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
I don't understand... Hotpatching is 2004, introduced with 2003 SP1, isn't it ? > https://patents.google.com/patent/US20040107416A1/ …https://twitter.com/NerdPyle/status/1494026323844472833 …
Thanks. Twitter will use this info to make your timeline better. UndoUndo -
Benjamin Delpy Retweeted
It's easy to backdoor a Windows box to log all passwords in plaintext when someone logs in. Great article on this by
@0x6d69636b here with implementations from both@gentilkiwi and@0gtweethttps://twitter.com/0x6d69636b/status/1494190594805190659 …Show this threadThanks. Twitter will use this info to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
