ಟ್ವೀಟ್ಗಳು
- ಟ್ವೀಟ್ಗಳು, ಪ್ರಸ್ತುತ ಪುಟ.
- ಟ್ವೀಟ್ಗಳು & ಪ್ರತಿಕ್ರಿಯೆಗಳು
- ಮಾಧ್ಯಮ
ನೀವು @frohoff ಅವರನ್ನು ತಡೆಹಿಡಿದಿರುವಿರಿ
ಈ ಟ್ವೀಟ್ಗಳನ್ನು ವೀಕ್ಷಿಸಲು ನೀವು ಖಚಿತವಾಗಿ ಬಯಸುವಿರಾ? ಟ್ವೀಟ್ ವೀಕ್ಷಣೆಯು @frohoff ಅವರ ತಡೆತೆರವುಗೊಳಿಸುವುದಿಲ್ಲ
-
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Story of my two (but actually three) RCEs in SharePoint in 2018: https://soroush.secproject.com/blog/2018/12/story-of-two-published-rces-in-sharepoint-workflows/ … - it all began with a simple question in Jan. 2018: "have you worked with ysoserial .net?" what a year! Glad https://www.blackhat.com/docs/us-17/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf … is in Top 10 Web Hacking Techniques of 2017
@pwntesterಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Ended up making a slightly bigger update to my Java SerializationDumper, it now does the reverse operation and rebuilds dumped serialization streams to make it easier to edit the raw data. See https://github.com/NickstaDB/SerializationDumper … for the source, and https://github.com/NickstaDB/SerializationDumper/releases/tag/1.1 … for the JAR.
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
I would like to propose product vendor evaluation via the Vendordomepic.twitter.com/OQXPQNUh8o
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
An excellent piece on asset management, a subject about which I frequently inflict rants upon my coworkershttps://twitter.com/DanielMiessler/status/1074770351920435200 …
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
New blog: Beware of Deserialisation in .NET Methods and Classes + Code Execution via Paste! https://bit.ly/2QWjUyC
#Deserialisation #.NET#CodeExecution#Infosecpic.twitter.com/lRMECzCEHJಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Implemented a new plugin arch for http://ysoserial.net to generate complex payloads. First one is for DNN RCE (CVE-2017-9822). Thanks
@GlitchWitchIO for testing it! Expect new plugins from@irsdl soon! Also new Generator for XAML payload. Give it a tryhttps://github.com/pwntester/ysoserial.net …ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Constantly annoyed by the conflicting incentives created by best-practices suggesting splitting AWS resources into more granular accounts to reduce blast-radius and improve security, but then security-related services (AWS/vendors) being priced per-account
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Equifax report megathread while I'm on lunch! https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf …
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Missed this when it happened, but Mondelez filed a complaint against its for wrongful denial of coverage following the NotPetya attack. Insurer cites an exclusion in the policy for "hostile or warlike action" by a government.https://www.techlawx.com/blog/notpetya-insurance-coverage-dispute …
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Awesome Red Teaming. Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Exfiltration Command and Control Misc RedTeam Gadgets Ebooks Training Certificationhttps://github.com/yeyintminthuhtut/Awesome-Red-Teaming …
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
“Analysing and Exploiting Kubernetes APIServer Vulnerability- CVE-2018–1002105” by
@abh1sek https://blog.appsecco.com/analysing-and-exploiting-kubernetes-apiserver-vulnerability-cve-2018-1002105-3150d97b24bb …#exploit#kubernetes#k8sಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
New "Lucky" self-propagating, cross-platform Satan ransomware/miner variant spreading via grab bag of 8+ different exploits targeting JBoss, WebLogic, Tomcat, Struts2, Spring http://blog.nsfocusglobal.com/categories/trend-analysis/satan-variant-analysis-handling-guide/ … https://www.sangfor.com/source/blog-network-security/1094.html …
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Protip: if you set a Google Alert for your name and home address, you'll get a notification every time one of those sketchy "peoplefinder" sites gets your details and you can do a removal.
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
For everyone responding to the new
@kubernetesio vulnerability (CVE-2018-1002105), the GitHub issue disclosing it is mandatory reading:https://github.com/kubernetes/kubernetes/issues/71411 …ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
“We…demonstrate the feasibility of a downgrade attack which could recover all the 2048 bits of the RSA plaintext (including the premaster secret value, which suffices to establish a secure connection) from five available TLS servers in under 30 seconds”https://twitter.com/eyalr0/status/1068520428824481792 …
ಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
“Google Translator Reverse Shell” This tool uses Google Translator as a proxy to send arbitrary commands to an infected machine
https://github.com/mthbernardes/GTRS …pic.twitter.com/W3fyxNRMLQ
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
NIST's chart of "when do you need a blockchain?" IMO it's overly pessimistic in some areas. For example, for auditing use cases, you should just publish Merkle roots of your data on-chain, ie. Plasma without the exit game. This is also useful for privacy-demanding use cases.pic.twitter.com/DhKgGTscvf
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Serverless ftw! Happy to finally release some example functions I've written to help with pentesting and bug bounties. Security peeps should be taking advantage of how easy and FREE this infrastructure is.https://blog.ropnop.com/serverless-toolkit-for-pentesters/ …
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
Chris Frohoff ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
Active Directory forests are no longer a security boundary thanks to
@tifkin_'s printer bug. Check out https://posts.specterops.io/not-a-security-boundary-breaking-forest-trusts-cd125829518d … for weaponization and mitigation details and@Cyb3rWard0g's post for detection guidancehttps://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1 …ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು -
"...first send account details with over 100 bitcoin or 1000 bitcoin cash to ... 111.90.151.134/c, and then inserts a MitM function so whenever credentials.getKeys is called, it conveniently sends the private keys of those accounts to the endpoint ... 111.90.151.134/p"
ಈ ಥ್ರೆಡ್ ತೋರಿಸಿಧನ್ಯವಾದಗಳು. Twitter ಇದನ್ನು ನಿಮ್ಮ ಕಾಲರೇಖೆಯನ್ನು ಉತ್ತಮಗೊಳಿಸಲು ಬಳಸುತ್ತದೆ. ರದ್ದುಗೊಳಿಸುರದ್ದುಗೊಳಿಸು
ಲೋಡಿಂಗ್ ಸಮಯ ಸ್ವಲ್ಪ ತೆಗೆದುಕೊಳ್ಳುತ್ತಿರುವಂತೆನಿಸುತ್ತದೆ.
Twitter ಸಾಮರ್ಥ್ಯ ಮೀರಿರಬಹುದು ಅಥವಾ ಕ್ಷಣಿಕವಾದ ತೊಂದರೆಯನ್ನು ಅನುಭವಿಸುತ್ತಿರಬಹುದು. ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಹೆಚ್ಚಿನ ಮಾಹಿತಿಗೆ Twitter ಸ್ಥಿತಿಗೆ ಭೇಟಿ ನೀಡಿ.