I discovered a Server-Side Request Forgery (SSRF) vulnerability in InvoiceNinja, which allowed unauthorized access to local files on the server. For a more detailed explanation, you can refer to the following link:
pretera.com/cve-2024-53353…#CVE-2024-53353 #bugbounty#pentest
A few months ago, we successfully utilized a Blind Cross-Site Scripting (XSS) vulnerability that was impacting two major companies.
In this blog post, we explained in detail on how we were able to achieve this.
#bugbounty#pentestingblog.pretera.com/blind-xss-in-r…
New blog: Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust
I teased this a bit during my Windows Hello talks, now found some time to write about this interesting technique. Also contains defenses and detection opportunities.
dirkjanm.io/obtaining-doma…
I'm thrilled to announce that I've recently become a Burp Suite Certified Practitioner!
I highly recommend PortSwigger Academy's labs to anyone looking to improve their skills in this area.
#burpsuitecertified
991 Followers 892 FollowingI want to die in sleep like my Grandfather did, not screaming like his passengers. Tweets are mine and don't represent my employer
30K Followers 561 FollowingCyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | securing and breaking AI @PaloAltoNtwks | Ex @spacex
12K Followers 488 FollowingSr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
16K Followers 2K FollowingTargeted Ops Red Team @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | I speak for myself only | K1HAQ
26K Followers 1K FollowingSenior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
2K Followers 1 FollowingSecurity company focusing on Microsoft Entra and Active Directory security. Need an expert view or pentest on your cloud/AD? [email protected]
20K Followers 2K FollowingPrincipal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK).
And yes, opinions are my own ;)
28K Followers 206 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
223K Followers 6K FollowingFounder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
240K Followers 200 FollowingBreaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
30K Followers 1K Following⚠Tech Enthusiast, Open Source Advocate, Content Creator, DM's are not for tech support but forums are. ⚠ https://t.co/xbxWZOT69J