#redteam
Now, you can dump the #Windows password from the LSASS process with help from the past: WerFaultSecure.exe
Github: 2x7EQ13/WSASS
Experimental version: Windows 11 24H2
#Blueteam
I've got an arbitrary file (not folder) delete bug on hand. Anyone know the latest privilege escalation techniques on Windows 24H2, since the changes around ::$INDEX_ALLOCATION?
🚀Exciting News! Introducing my latest work: Beyond XSS
This series of articles aims to introduce front-end security topics, perfect for frontend devs and those intrigued by frontend security. Suitable for all skill levels from beginners to intermediates
aszx87410.github.io/beyond-xss/en/
#oldnewthing
Need something blue? Create the file "C:\Windows\System32\config\OSDATA" and restart Windows. You’ll get a permanent Blue Screen of Death( BSOD ).
#pentester#redteam
Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:
Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:
New blog post! It took me a few months to get motivated to write again, but here we are with a remarkable client-side chain I found with @xssdoctorvitorfalcao.com/posts/hacking-…
(A new class of symlink attacks is mentioned below.)
According to Microsoft (MSRC), attacks involving symlinks stored on removable drives or in file system images (like VHDX) are not vulnerabilities.
If an unprivileged user manages to quickly replace a regular file... 1/7
I try an avoid this hellsite, but I did a quick dive into sudo in Windows and here are my initial findings. tiraniddo.dev/2024/02/sudo-o…
The main take away is, writing Rust won't save you from logical bugs :)
58 Followers 1K FollowingHacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Founder @StackTarget, Boss @MetaphorSecurityLLC https://t.co/afaG53RBBR 🌌💻⚡️📍MNL🇵🇭
348 Followers 2K Followingjust Security (ʘ‿ʘ) / bug hunter / web penetest /problem solver
some knowledge in AI
وما قتلَتْني الحادثاتُ وإنما حياةُ الفتَى في غير موضعه قَتْلُ
112 Followers 2K Following🐞 Bug Bounty Hunter | 🧠 Think like a dev, hack like a ghost
Focus: Business Logic | RCE | LFI | SSRF
On a $10K mission | #YesWeHack #bugcrowd
3K Followers 1K FollowingMVH @ H1-468 | Exterminator H1-6102 Salesforce | Most Impactful Team H1-0131 AWS x Amazon | Best collab H1-407 | Bootstrapped a 7 figs biz | Victor Poucheret
48K Followers 2K FollowingSpecializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
4K Followers 551 Following• Irish/Japanese web hacker living in Scotland.
• Researcher for @ctbbpodcast Lab.
I run https://t.co/Ja1P3vco1X | Newsletter weekly at https://t.co/KA5b2kY8ih
1K Followers 891 Following"Vulnerability researcher" doing Bug Bounty on free time (https://t.co/j46EMrTT5T) Also doing some Reverse on many targets but find no vuln 😒
20K Followers 313 FollowingShugyosha. Paranoia principal, privacy developer. Programming language nerd. In a previous life, I was a JRuby core developer and language designer - he/him
7K Followers 598 FollowingHacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
796 Followers 707 FollowingAdvance-sec platform: is one of the top leaders in research and acquisition of vulnerabilities and 0day exploits.
Email: [email protected]
Wire: @advance_sec
135 Followers 227 FollowingEntering the world of Malware (◎▼◎) =========== Since August 2022. Opinions expressed are my own and not those of my employer
No recent Favorites. New Favorites will appear here.