Brandon Rossi (@0xconda) 's Twitter Profile
Brandon Rossi

@0xconda

Pentester / Security Researcher / Content Creator | OSCP | CRTP | OSEP |

ID: 1188942416495157252

linkhttps://bio.link/conda calendar_today28-10-2019 22:15:46

3,3K Tweet

16,16K Followers

1,1K Following

d3d aka dead (dead, мёртв, 死了) (@deadvolvo) 's Twitter Profile Photo

Again, with a slight tweak of the template, I can move from US domains, to bouncing file/command/data transfers over encrypted comms, off the face of major Chinese corporations. Why domain-front, when you can abuse from a list of already established domains? 😈 paper soon maybe?

Again, with a slight tweak of the template, I can move from US domains, to bouncing file/command/data transfers over encrypted comms, off the face of major Chinese corporations.

Why domain-front, when you can abuse from a list of already established domains? 😈 paper soon maybe?
Brandon Rossi (@0xconda) 's Twitter Profile Photo

I’ve submitted plenty of bugs in software and never cared to claim a CVE. To me, saying I discovered CVE-blah never mattered. Most bugs don’t feel novel enough to care. Anyone else feel that way?

Brandon Rossi (@0xconda) 's Twitter Profile Photo

Moving my career away from pentesting feels strange, but I’m excited for this next chapter. Hacking things was super fun!

Dylan (@insecurenature) 's Twitter Profile Photo

Hackers reportedly used something called "TruffleHog" during their attack. They also used "child_process", and something called HTTP, something called TLS, and something called TCP. Please be on the lookout for any of these hacking tools being used in your environment.

Brandon Rossi (@0xconda) 's Twitter Profile Photo

People worry about the latest and hottest vulnerabilities while their environment is full of 10 year old exploitable systems. Don’t get caught up chasing the shiny new objects.

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…