I've released NAT Slipstreaming, a spooky new technique that allows an attacker to remotely access any TCP/UDP service bound to a victim machine, bypassing the victim’s NAT/firewall, just by the victim visiting a website. samy.pl/slipstream/ Happy Halloween!
I created this basic chrome extension to find prototype pollution. You won't believe the applications where PP exist, it's everywhere.
I hope you make internet pollution free :xD.
github.com/msrkp/PPScan
For pentesting, Add this to your .bashrc file:
PS1='[`date +"%d-%b-%y %T"`] > '
test "$(ps -ocommand= -p $PPID | awk '{print $1}')" == 'script' || (script -f $HOME/logs/$(date +"%d-%b-%y_%H-%M-%S")_shell.log)
Now you can have a log of everything you did and when you did it.
Introducing SysWhispers, a tool that helps with AV/EDR evasion by using direct system calls to bypass user-mode API hooks. It works by generating header/ASM pairs supporting all core syscalls from Windows XP to 10.
Check it out here with examples: github.com/jthuraisamy/Sy…
I decided to create a tutorial called "Reversing Windows Internals" and explain about Windows Internals.
The first part describes about Handles, Callbacks and Hidden Callbacks and ObjectTypes in Windows
Thanks to @Dark_Puzzle for answering my questions.
rayanfam.com/topics/reversi…
You were eagerly looking forward to it, well, here we are: the qualification week for SIGSEGv2 (which will happen on 11/30) starts next Wednesday (10/02). Time to polish those CTF skills! #sigsegv2#ctf#quals
Paged Out! #1 is out! (and it's free to download!)
pagedout.institute/?page=issues.p…
There are 57 articles in 12 categories:
Electronics
Programming
Assembly
Reverse Engineering
Sec/Hack
Retro
File Formats
Algorithmics
SysAdmin
Radio
Phreaking
OS Internals
Enjoy! #PagedOut!
New blog post exploring Windows RPC internals, reversing with Ghidra, and how we can use Neo4j to find interesting call paths. blog.xpnsec.com/analysing-rpc-…
5 Followers 172 FollowingR ecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/iaKHEOORlW
80 Followers 7K FollowingPersonal Profile - I've been fighting to better my community my entire life and I'll never stop! Running for Congress in Florida’s 24th District!
661 Followers 361 FollowingFrench security enthusiast / @archlinux user (BTW) / Always learning about Linux and try to share it / Magical sloth
Tweets are my own
437 Followers 2K FollowingIT Security Manager & IT Manager For Several Healthcare and Financial Institutes | InfoSec Community | Offensive and Defense side of IT Security.
351 Followers 5K FollowingCuando uno compara sus talentos con los de Leibniz uno tiene la tentación de tirar todos sus libros e ir a morir silenciosamente en la oscuridad de algún rincón
181 Followers 329 FollowingPentester | Security enthusiast | Curious | Surfer | Tweets and retweets are those of the author and do not reflect the view of my employer.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
551K Followers 664 FollowingCrypto .. 99% will lose all money invested. Check your own country laws before investing / trading. Tweets do not endorse buying Crypto or directed to UK users