Scaum (@sscaum) 's Twitter Profile
Scaum

@sscaum

ID: 1114500685851254785

calendar_today06-04-2019 12:10:44

34 Tweet

28 Takipçi

27 Takip Edilen

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

The fluoroacetate duo does it again. They used a type confusion in #Edge, a race condition in the kernel, then an out-of-bounds write in #VMware to go from a browser in a virtual client to executing code on the host OS. They earn $130K plus 13 Master of Pwn points.

The <a href="/fluoroacetate/">fluoroacetate</a> duo does it again. They used a type confusion in #Edge, a race condition in the kernel, then an out-of-bounds write in #VMware to go from a browser in a virtual client to executing code on the host OS. They earn $130K plus 13 Master of Pwn points.
Baptiste Robert (@fs0c131y) 's Twitter Profile Photo

THREAD: If you have a Samsung Mobile phones, whatever your phone model, an attacker with a physical access to your phone can capture your network traffic without your consent. Let me show you ⬇️⬇️⬇️

THREAD: If you have a <a href="/SamsungMobile/">Samsung Mobile</a> phones, whatever your phone model, an attacker with a physical access to your phone can capture your network traffic without your consent. Let me show you

⬇️⬇️⬇️
Pinaki ❄️ (@0xinfection) 's Twitter Profile Photo

I learnt today that IP addresses can be shortened by dropping the zeroes. Examples: http://1.0.0.1 → http://1.1 http://192.168.0.1 → http://192.168.1 This bypasses WAF filters for SSRF, open-redirect, etc where any IP as input gets blacklisted. #infosec #bugbounty #bugbountytip

I learnt today that IP addresses can be shortened by dropping the zeroes.
Examples:
http://1.0.0.1 → http://1.1
http://192.168.0.1 → http://192.168.1
This bypasses WAF filters for SSRF, open-redirect, etc where any IP as input gets blacklisted.
#infosec #bugbounty #bugbountytip
Scaum (@sscaum) 's Twitter Profile Photo

Un nouveau Tian'anmen se prépare à #HongKong, mais la France est fière d'avoir placé Prout en tt... J'ai honte

spidersec (@spidersec) 's Twitter Profile Photo

Manually Detect Remote Integer Overflow: 1. Note Content-Length. EX: 612 2. Take NO < Content-Length. Ex: 610 3. Add (610+612 = 1222) 4. Request Header - 'Range: bytes= -1222' => SAME RESPONSE 5. Subtract 9223372036854775808 - 1222 = 9223372036854774586 Continue.......

Dave Vieira-Kurz (@secalert) 's Twitter Profile Photo

When testing password fields, my preferred password is: %01%E2%80%AEalert%0D%0A Let's break it down: %01 is SOH %e2%80%ae is RTLO %0d%0a is CRLF Test cases on login: 1. can I log in only using %01? 2. without the CRLF in it? 3. is trela accepted instead of alert? (due to RTLO)

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

TIL authorized_keys files can contain more than just public keys. You can control source hosts of each key, limit the port forwarding, execute commands upon login. In 20+ years of working on Unix/Linux systems, I've never seen this used. commandlinux.com/man-page/man5/…

TIL authorized_keys files can contain more than just public keys. 
You can control source hosts of each key, limit the port forwarding, execute commands upon login.
In 20+ years of working on Unix/Linux systems, I've never seen this used. 

commandlinux.com/man-page/man5/…
Octoberfest7 (@octoberfest73) 's Twitter Profile Photo

I’m pleased to release Inline-Execute-PE, a CobaltStrike toolkit enabling users to load and repeatedly run unmanaged Windows exe’s in Beacon memory without dropping to disk or creating a new process each time. github.com/Octoberfest7/I… #redteam #cybersecurity #malware

Synacktiv (@synacktiv) 's Twitter Profile Photo

Bored of managing multiple proxychains configurations? Hugo Clout developed bbs, a swiss army knife proxy manager for red teamers! The project is available on our GitHub: github.com/synacktiv/bbs

Greg Linares (Laughing Mantis) (@laughing_mantis) 's Twitter Profile Photo

Since I'm 6 drinks in for 20 bucks, let me tell you all about the story of how the first Microsoft Office 2007 vulnerability was discovered, or how it wasn't. This was a story I was gonna save for a book but fuck it, I ain't gonna write it anyways.

Synacktiv (@synacktiv) 's Twitter Profile Photo

In our latest article, Quentin Roland and Scaum demonstrate a trick allowing to make Windows SMB clients fall back to WebDav HTTP authentication, enhancing the NTLM and Kerberos relaying capabilities of multicast poisoning attacks! synacktiv.com/publications/t…