• Home
  • Moments

Saved searches

  • Remove
  • In this conversation
    Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
pwnallthethings's profile
Pwn All The Things
Pwn All The Things
Pwn All The Things
@pwnallthethings

Pwn All The Things

@pwnallthethings

Mostly #infosec or #natsec tweets. Also @foiathethings | email: matt.tait$gmail,com | RTs are not emoluments

Joined December 2013
  • © 2017 Twitter
  • About
  • Help Center
  • Terms
  • Privacy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified account @
Suggested users
  • Verified account @
  • Verified account @

Retweet this to your followers?

Optional comment for Retweet
 

Saved searches

  • Remove
  • In this conversation
    Verified account @
Suggested users
  • Verified account @
  • Verified account @
 
140

Are you sure you want to delete this Tweet?

Promote this Tweet

Block

  • Add a location to your Tweets

    When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    Preview

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Buy Now

    Buy Now

    Hmm... Something went wrong. Please try again.

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Pwn All The Things ‏@pwnallthethings Jan 4

    Pwn All The Things Retweeted Donald J. Trump

    Could have hacked? Sure. Did hack? No. Let me go through why not.https://twitter.com/realDonaldTrump/status/816620855958601730 …

    Pwn All The Things added,

    Donald J. Trump @realDonaldTrump
    Julian Assange said "a 14 year old could have hacked Podesta" - why was DNC so careless? Also said Russians did not give him the info!
    • Retweets 3,811
    • Likes 4,772
    • Harrell Margery Patrick Adam Held Scott Elam m Filha Pródiga sad cosmonaut Phils Hot Dogs DeplorablyVictorious
    4:25 AM - 4 Jan 2017
    150 replies 3,811 retweets 4,772 likes
      1. Pwn All The Things ‏@pwnallthethings Jan 4

        So the actual email used to phish John Podesta ended up in the WIkileaks dump. It's herehttps://wikileaks.org/podesta-emails/emailid/36355 …

        24 replies 457 retweets 660 likes
      2. Pwn All The Things ‏@pwnallthethings Jan 4

        This is a reconstruction of that phishing email. (All of the information is bogus - the mention of Ukraine isn't relevant here).pic.twitter.com/EvFhdYfZaI

        8 replies 215 retweets 405 likes
      3. Pwn All The Things ‏@pwnallthethings Jan 4

        You can't tell just by looking, but that "Change Password" link doesn't take you to Google. It takes you to Bit.ly.pic.twitter.com/e6Rm71YTfG

        11 replies 250 retweets 406 likes
      4. Pwn All The Things ‏@pwnallthethings Jan 4

        This link expands to a fake login page (note URL is for a .tk site). This is what Podesta saw when he accidentally gave creds to hackers.pic.twitter.com/3Cc8KxvjNf

        16 replies 322 retweets 472 likes
      5. Pwn All The Things ‏@pwnallthethings Jan 4

        But the hackers screwed up. The hackers weren't hacking one-by-one; so URL contraction wasn't done manually. It was done via the Bitly API.

        5 replies 220 retweets 391 likes
      6. Pwn All The Things ‏@pwnallthethings Jan 4

        Using the Bitly API requires you create an account. So the hackers had to create an account. And they forgot to make their account private.

        6 replies 215 retweets 502 likes
      7. Pwn All The Things ‏@pwnallthethings Jan 4

        It's no longer possible - the hackers have changed their settings - but before you could simple enumerate ALL of the contracted links.

        6 replies 163 retweets 356 likes
      8. Pwn All The Things ‏@pwnallthethings Jan 4

        The Bitly link in John Podesta's email is visible in the Wikileaks dump here https://wikileaks.org/podesta-emails/emailid/36355 …pic.twitter.com/PNEN96Cfq3

        6 replies 186 retweets 384 likes
      9. Show more
      1. Braxton S. Cook ‏@BSamCook Jan 4

        @pwnallthethings @PeterDEdmonds Ah, the same folks who gave us WMDs in Iraq are right without question, but Assange is lying. Really?

        43 replies 3 retweets 36 likes
      2. Pwn All The Things ‏@pwnallthethings Jan 4

        @BSamCook @PeterDEdmonds None of this is info from the IC.

        9 replies 9 retweets 362 likes
      3. Peter Edmonds ‏@PeterDEdmonds Jan 4

        @pwnallthethings Great sleuthing there, by the way.

        2 replies 1 retweet 114 likes
      4. Matt the Brat  🤔 ‏@Karna6e Jan 4

        @PeterDEdmonds @pwnallthethings It should also be noted that there were dissenting opinions in the IC on WMDs but it was Bush who misused it

        9 replies 23 retweets 333 likes
      5. El Presidente ‏@BfloDude Jan 4

        @Karna6e @PeterDEdmonds @pwnallthethings Absolutey correct. Team Bush cherry picked the hell out of the intelligence.

        4 replies 16 retweets 197 likes
      6. MomsThoughts™ ‏@MomsThoughts Jan 4

        @BfloDude @Karna6e @PeterDEdmonds @pwnallthethings the source for WMD came via Hannah and Libby (Cheney's office). It wasn't from CIA,FBI.

        6 replies 32 retweets 222 likes
      7. Scott S, Resisting ‏@DigiRanger1994 Jan 4

        @MomsThoughts @BfloDude @Karna6e @PeterDEdmonds @pwnallthethings Indeed

        1 reply 0 retweets 18 likes
      8. Tara ‏@tgruka Jan 4

        @DigiRanger1994 @MomsThoughts @BfloDude @Karna6e @PeterDEdmonds @pwnallthethings I've been screaming that from rooftops. Trumpers don't care

        6 replies 3 retweets 83 likes
      9. Show more
      1. Dave Mosher ‏@DaveMosher Jan 4

        .@pwnallthethings Compelling argument. My question for other #infosec experts: Any room for reasonable doubt? Or is this a 99.9% sure thing?

        12 replies 2 retweets 37 likes
      2. Jesse Emspak ‏@Mad_Science_Guy Jan 4

        @DaveMosher Curious if @pwnallthethings would class this as "hired help" as opposed to state actor (strictly speaking)

        4 replies 0 retweets 15 likes
      3. Dave Mosher ‏@DaveMosher Jan 4

        @Mad_Science_Guy My guess, based on evidence touted by @pwnallthethings, is hired help. Counterpoint: maybe designed to look that way?

        4 replies 2 retweets 34 likes
      4. Jesse Emspak ‏@Mad_Science_Guy Jan 4

        @DaveMosher @pwnallthethings Hired help fits Occam's razor, given that you can hire ppl to mount any damn thing and get LOIC attacks free.+

        1 reply 2 retweets 21 likes
      5. DaveS ‏@darsal Jan 4

        @Mad_Science_Guy @DaveMosher Didja read the source of @pwnallthethings's graphs? https://www.secureworks.com/research/threat-group-4127-targets-google-accounts … and https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign …

        4 replies 5 retweets 26 likes
      6. Daniel Ƀ ‏@csuwildcat Jan 5

        @darsal @Mad_Science_Guy @DaveMosher @pwnallthethings these links are 504, where is the full Bitly src of all links generated by this acct?

        3 replies 0 retweets 0 likes
      7. DaveS ‏@darsal Jan 5

        @csuwildcat @Mad_Science_Guy @DaveMosher @pwnallthethings Ask @SecureWorks.

        1 reply 0 retweets 0 likes
      8. Show more

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2017 Twitter
      • About
      • Help Center
      • Terms
      • Privacy
      • Cookies
      • Ads info