Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @ropnop
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @ropnop
-
So much fun presenting this! Happy to share my slides for "Don't Cross Me! Same Origin Policy and all the 'cross' vulns". SOP is an important topic I feel is not adequately explained and understood by many developers and security pros.https://speakerdeck.com/ropnop/dont-cross-me-same-origin-policy-and-all-the-cross-vulns-xss-csrf-and-cors …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Anyways I'm pretty happy with these slides so far. I really don't think you can fully grok XSS and CSRF without putting them in context of SOP
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Me: I'll make some quick overview slides of XSS and CSRF Me: But I can't really explain those without first explaining the SOP and browser security model Me: ... (40 slides later) Me: okay, here's a quick overview of XSS and CSRF
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
Anyone out there deploying container workloads over K8S and using an NGFW to protect those workloads? If so I’d love to discuss. Please R/T.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
Revisiting RDP lateral movement https://posts.specterops.io/revisiting-remote-desktop-lateral-movement-8fb905cb46c3 … and releasing a project that will be part of a bigger tool coming next week
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alright, flipped the switch and http://blog.ropnop.com is now hosted with
@zeithq and@GoHugoIO Hopefully no issues, but lmk if I broke anything or links don't work anymorehttps://twitter.com/ropnop/status/1219083153874223104 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
Hi Blue/CTI. It's me. Would you be willing to test something? It's a tool that takes an IP and tells you if it's Empire. That's it. I don't have access to the kind of sample data you do. Is something like this useful to you in your day to day?https://github.com/audibleblink/bothan …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thinking of migrating my blog to pure static using
@GoHugoIO and@zeithq. Copied over all my posts and trying to make it look/feel the same. Any thoughts or feedback?https://blog-stage.ropnop.com/Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
Don’t forget: we’re THIS WEDNESDAY! Join a great group of infosec and cigar nerds in The West Loop at
@TheClaytonCigar around 5! Cigar noobs always welcome!https://www.meetup.com/Burbsec/events/wqtfkrybccbtb/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
To celebrate the 1st year anniversary of my #Osmedeus. I decided to public the beta version of#Jaeles - a framework for web application testing. Enjoy!
https://github.com/jaeles-project/jaeles …pic.twitter.com/LiVEHAcewh
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
As pipelines get more complex and distributed, making the shift from a "push" to "pull" model makes so much sense. Lots of opportunity to limit attack surface using this model.https://medium.com/@alexkaskasoli/pull-based-cd-pipelines-for-security-4e044b403f56 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Ronnie Flathers proslijedio/la je Tweet
New tool: rubeus2ccache Generates ccache files directly from Rubeus dump output. Major thanks to
@_dirkjan for basically writing anything hard. https://github.com/curi0usJack/rubeus2ccache … Merry Christmas Red Team!
pic.twitter.com/e8MWCDurq2
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Come join us Wednesday!https://twitter.com/cigarsec/status/1206649402749837317 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ronnie Flathers proslijedio/la je Tweet
Tossing PDFs like it’s 1999
@matt_tesauro#DevSecOpsDaysAustinpic.twitter.com/Z01K6AMqlw – mjesto: Norris Conference Center
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Oh and maybe finally get around to submitting to the
@thotcon CFP. Got some deliciously evil ideas on red teaming DevOps toolchains I think it's time to share ;)Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Now gonna fire up the
@SANSHolidayHack and nerd out while the year hopefully comes to a relaxing close :) Happy holidays!Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
And cut a release of the Impacket static binaries to be on par with latest v0.9.20 release. Also updated my Docker image rflathers/impacket to use Python 3 now that it's supported. Great work as always,
@agsolinohttps://github.com/ropnop/impacket_static_binaries/releases/tag/0.9.20-binaries …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Pushed an update to the serverless toolkit too. Since I released it,
@zeithq http://now.sh no longer supports arbitrary Docker images, so I reworked them all to be pure functions. Unfortunately can't port them all, but theyre still super helpful!https://github.com/ropnop/serverless_toolkit …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
New version of Kerbrute released. Some minor improvements and added a --delay option if you want to slow things down and be stealthier. Big thanks to
@4lex for the PR!https://github.com/ropnop/kerbrute/releases/tag/v1.0.3 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.