HPH (@heinrichsh) 's Twitter Profile
HPH

@heinrichsh

{"work": "leveraging full-spectrum cyber for @CrowdStrike", "interests": ["binary exploitation", "cryptography", "embedded hacking", "@EatSleepPwnRpt", "JSON"]}

ID: 243765628

linkhttps://heinrichs.io calendar_today27-01-2011 19:27:51

202 Tweet

455 Takipçi

463 Takip Edilen

HPH (@heinrichsh) 's Twitter Profile Photo

The tale of a short-lived bug 🐛 affecting a NAS device which Luks and I planned to use at #Pwn2Own Tokyo. crowdstrike.com/blog/pwn2own-t…

CrowdStrike (@crowdstrike) 's Twitter Profile Photo

This blog post describes our journey of identifying and exploiting a vulnerability on the Western Digital My Cloud Pro Series PR4100 NAS (already identified and fixed by WD). bit.ly/3otHkI2 via HPH Luks #cybersecurity

This blog post describes our journey of identifying and exploiting a vulnerability on the Western Digital My Cloud Pro Series PR4100 NAS (already identified and fixed by WD). bit.ly/3otHkI2 via <a href="/HeinrichsH/">HPH</a> <a href="/___luks___/">Luks</a> #cybersecurity
Sin__ (@mztropics) 's Twitter Profile Photo

Had lots of fun with CrowdStrike's #AdversaryQuest. Here are my timings and writeups for a few selected tasks github.com/Sin42/writeups…

Had lots of fun with <a href="/CrowdStrike/">CrowdStrike</a>'s #AdversaryQuest. Here are my timings and writeups for a few selected tasks github.com/Sin42/writeups…
Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Starting soon: Benjamin Grap (Ben Grap), Hanno Heinrichs (HPH), and Lukas Kupczyk (Luks) of CrowdStrike Intelligence target the LAN interface of the Cisco RV340 in the router category. $15,000 and 2 Master of Pwn points on the line.

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Success! The CrowdStrike team of Benjamin Grap (Ben Grap), Hanno Heinrichs (HPH), and Lukas Kupczyk (Luks) wasted no time in their 1st #Pwn2Own by taking over the LAN interface of the #Cisco RV340 router. They're off to provide all the details.

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Another bug collision: the CrowdStrike team used 4 bugs to gain code execution on the Cisco RV340 router, but some of the bugs were previously known. They still earn $10,000 and 1.5 Master of Pwn points.

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Success! Benjamin Grap (Ben Grap), Hanno Heinrichs (HPH), and Lukas Kupczyk (Luks) of CrowdStrike Intelligence were able to exploit the #Lexmark MC3224i printer. They're headed to the disclosure room for drop the details. #Pwn2Own #P2OAustin

Success! Benjamin Grap (<a href="/blightzero/">Ben Grap</a>), Hanno Heinrichs (<a href="/HeinrichsH/">HPH</a>),  and Lukas Kupczyk (<a href="/___luks___/">Luks</a>) of CrowdStrike Intelligence were able to exploit the #Lexmark MC3224i printer. They're headed to the disclosure room for drop the details. #Pwn2Own #P2OAustin
Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

The penultimate entry of the contest ends in a collision. The #CrowdStrike team combined 3 bugs to get code exec on the #Lexmark printer. Alas, all 3 had been previously seen in the contest. They still earn $10,000 and 1 Master of Pwn point. #Pwn2Own #P2OAustin

CrowdStrike (@crowdstrike) 's Twitter Profile Photo

CrowdStrike discovered vulnerabilities that can be used to compromise the Cisco RV340 router. Read more. ⬇️ crwdstr.ke/6017KqvEZ

Maddie Stone (@maddiestone) 's Twitter Profile Photo

One Windows in-the-wild 0-day in today's patch Tues: CVE-2022-24521. Discovered by NSA and Crowdstrike 🔥 #itw0days msrc.microsoft.com/update-guide/v…

Karsten (@gr4yf0x) 's Twitter Profile Photo

Small blog by me about using chompie's late eBPF exploit and modifying it for container escapes. crowdstrike.com/blog/exploitin…

Halvar Flake (@halvarflake) 's Twitter Profile Photo

Since there is no good way to do mass layoffs: People underestimate the cost of undisciplined over-hiring, because trying to undo it will demoralize the rest of the company. The cost is higher than just the salaries etc.

adam_cyber (@adam_cyber) 's Twitter Profile Photo

I am very excited to publicly unveil our new CrowdStrike Counter Adversary Operations! Consolidating our market leading Threat Intelligence and game changing OverWatch Threat Hunting teams into a new entity charged with raising the cost for adversaries! crowdstrike.com/blog/crowdstri…

HPH (@heinrichsh) 's Twitter Profile Photo

I think the stock exchange moved out of this building 25 years ago. But there are still a lot of brokers around even today. 🤔 #hexacon2023

I think the stock exchange moved out of this building 25 years ago. But there are still a lot of brokers around even today. 🤔 #hexacon2023
HPH (@heinrichsh) 's Twitter Profile Photo

Verifying myself: I am hanno_heinrichs on Keybase.io. GcZ-6NcxJYKK9wj7WFhiOD7AGmRTKFK2UljT / keybase.io/hanno_heinrich…