Chris Frohoff

@frohoff

building things, breaking things, building things that break things

San Diego, CA
ಮೇ 2007 ಸಮಯದಲ್ಲಿ ಸೇರಿದ್ದಾರೆ

ಟ್ವೀಟ್‌ಗಳು

ನೀವು @frohoff ಅವರನ್ನು ತಡೆಹಿಡಿದಿರುವಿರಿ

ಈ ಟ್ವೀಟ್‌ಗಳನ್ನು ವೀಕ್ಷಿಸಲು ನೀವು ಖಚಿತವಾಗಿ ಬಯಸುವಿರಾ? ಟ್ವೀಟ್ ವೀಕ್ಷಣೆಯು @frohoff ಅವರ ತಡೆತೆರವುಗೊಳಿಸುವುದಿಲ್ಲ

  1. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 19

    Story of my two (but actually three) RCEs in SharePoint in 2018: - it all began with a simple question in Jan. 2018: "have you worked with ysoserial .net?" what a year! Glad is in Top 10 Web Hacking Techniques of 2017

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  2. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 19

    Ended up making a slightly bigger update to my Java SerializationDumper, it now does the reverse operation and rebuilds dumped serialization streams to make it easier to edit the raw data. See for the source, and for the JAR.

    ರದ್ದುಗೊಳಿಸು
  3. ಡಿಸೆಂ 19

    I would like to propose product vendor evaluation via the Vendordome

    ರದ್ದುಗೊಳಿಸು
  4. ಡಿಸೆಂ 17

    An excellent piece on asset management, a subject about which I frequently inflict rants upon my coworkers

    ರದ್ದುಗೊಳಿಸು
  5. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 17

    New blog: Beware of Deserialisation in .NET Methods and Classes + Code Execution via Paste! #.NET

    ರದ್ದುಗೊಳಿಸು
  6. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ನವೆಂ 26

    Implemented a new plugin arch for to generate complex payloads. First one is for DNN RCE (CVE-2017-9822). Thanks for testing it! Expect new plugins from soon! Also new Generator for XAML payload. Give it a try

    ರದ್ದುಗೊಳಿಸು
  7. ಡಿಸೆಂ 12

    Constantly annoyed by the conflicting incentives created by best-practices suggesting splitting AWS resources into more granular accounts to reduce blast-radius and improve security, but then security-related services (AWS/vendors) being priced per-account

    ರದ್ದುಗೊಳಿಸು
  8. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 11
    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  9. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 11

    Missed this when it happened, but Mondelez filed a complaint against its for wrongful denial of coverage following the NotPetya attack. Insurer cites an exclusion in the policy for "hostile or warlike action" by a government.

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  10. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 8

    Awesome Red Teaming. Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Exfiltration Command and Control Misc RedTeam Gadgets Ebooks Training Certification

    ರದ್ದುಗೊಳಿಸು
  11. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 8
    ರದ್ದುಗೊಳಿಸು
  12. ಡಿಸೆಂ 6

    New "Lucky" self-propagating, cross-platform Satan ransomware/miner variant spreading via grab bag of 8+ different exploits targeting JBoss, WebLogic, Tomcat, Struts2, Spring

    ರದ್ದುಗೊಳಿಸು
  13. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 4

    Protip: if you set a Google Alert for your name and home address, you'll get a notification every time one of those sketchy "peoplefinder" sites gets your details and you can do a removal.

    ರದ್ದುಗೊಳಿಸು
  14. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 4

    For everyone responding to the new vulnerability (CVE-2018-1002105), the GitHub issue disclosing it is mandatory reading:

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  15. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ನವೆಂ 30

    “We…demonstrate the feasibility of a downgrade attack which could recover all the 2048 bits of the RSA plaintext (including the premaster secret value, which suffices to establish a secure connection) from five available TLS servers in under 30 seconds”

    ರದ್ದುಗೊಳಿಸು
  16. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ಡಿಸೆಂ 2

    “Google Translator Reverse Shell” This tool uses Google Translator as a proxy to send arbitrary commands to an infected machine 😳

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  17. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ನವೆಂ 27

    NIST's chart of "when do you need a blockchain?" IMO it's overly pessimistic in some areas. For example, for auditing use cases, you should just publish Merkle roots of your data on-chain, ie. Plasma without the exit game. This is also useful for privacy-demanding use cases.

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  18. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ನವೆಂ 11

    Serverless ftw! Happy to finally release some example functions I've written to help with pentesting and bug bounties. Security peeps should be taking advantage of how easy and FREE this infrastructure is.

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  19. ಅವರು ಮರುಟ್ವೀಟಿಸಿದ್ದಾರೆ
    ನವೆಂ 28

    Active Directory forests are no longer a security boundary thanks to 's printer bug. Check out for weaponization and mitigation details and 's post for detection guidance

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು
  20. ನವೆಂ 26

    "...first send account details with over 100 bitcoin or 1000 bitcoin cash to ... 111.90.151.134/c, and then inserts a MitM function so whenever credentials.getKeys is called, it conveniently sends the private keys of those accounts to the endpoint ... 111.90.151.134/p"

    ಈ ಥ್ರೆಡ್ ತೋರಿಸಿ
    ರದ್ದುಗೊಳಿಸು

ಲೋಡಿಂಗ್ ಸಮಯ ಸ್ವಲ್ಪ ತೆಗೆದುಕೊಳ್ಳುತ್ತಿರುವಂತೆನಿಸುತ್ತದೆ.

Twitter ಸಾಮರ್ಥ್ಯ ಮೀರಿರಬಹುದು ಅಥವಾ ಕ್ಷಣಿಕವಾದ ತೊಂದರೆಯನ್ನು ಅನುಭವಿಸುತ್ತಿರಬಹುದು. ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಹೆಚ್ಚಿನ ಮಾಹಿತಿಗೆ Twitter ಸ್ಥಿತಿಗೆ ಭೇಟಿ ನೀಡಿ.

    ಇದನ್ನೂ ಸಹ ನೀವು ಇಷ್ಟಪಡಬಹುದು

    ·