Shikari Senpai (@shikarisenpai) 's Twitter Profile
Shikari Senpai

@shikarisenpai

ID: 242556953

calendar_today25-01-2011 01:55:14

39 Tweet

376 Followers

199 Following

Aleksei Tiurin (@antyurin) 's Twitter Profile Photo

Result of my research about current situation with #deserialization vulns in #javascript / #nodejs acunetix.com/blog/web-secur… #hacking #PenTest

Shikari Senpai (@shikarisenpai) 's Twitter Profile Photo

Wow, I had three talks on #ZeroNights: “Chat with a hacker” on Track2, “CRLF +OpenRedirect” and “CSTI” on WebVillage. I will share the presentations later! :)

Wow, I had three talks on #ZeroNights: “Chat with a hacker” on Track2, “CRLF +OpenRedirect” and “CSTI” on WebVillage. I will share the presentations later! :)
Aleksei Tiurin (@antyurin) 's Twitter Profile Photo

All info about TLS Redirection / Virtual Host Confusion attacks github.com/GrrrDog/TLS-Re… and my presentation about new attack techniques slideshare.net/GreenD0g/mitm-… #ZeroNights

Shikari Senpai (@shikarisenpai) 's Twitter Profile Photo

My slides "CRLF and OpenRedirect for Dummies" from #ZeroNights #WebVillage. Introduction to #СRLF and #OpenRedirect vulnerability: - Basics - Search methods - Payloads - Tricks Slides have many useful links! #XSS speakerdeck.com/shikarisenpai/…

Shikari Senpai (@shikarisenpai) 's Twitter Profile Photo

And another slides about #CSTI vulnerability from #ZeroNights #WebVillage 😅 - Basics (for AngularJS) - Search methods - Sandbox bypass - HTML Sanitizer problem - CSP is hard Slides have many-many references to other hard talks! #XSS speakerdeck.com/shikarisenpai/…

Lemi Orhan Ergin (@lemiorhan) 's Twitter Profile Photo

Dear Apple Support, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it Apple?

ver 1.2 (@ansjdnakjdnajkd) 's Twitter Profile Photo

Personal #cheatsheet for #iOS and #macOS #pentest tools, frameworks, slides and so on. Any feedback, commits and stars are welcome! github.com/ansjdnakjdnajk…

Ben Hawkes (@benhawkes) 's Twitter Profile Photo

Jann Horn (Jann Horn - [email protected]) from Project Zero discovered and reported an attack to read privileged memory with a side-channel: security.googleblog.com/2018/01/todays…

Aleksei Tiurin (@antyurin) 's Twitter Profile Photo

Yet another gadget for java deserialization: Misusing Oracle JDBC for SSRF-attacks agrrrdog.blogspot.ru/2018/01/java-d… #javadeser #ZeroNights

Matt Austin (@mattaustin) 's Twitter Profile Photo

CVE-2018-1000006 (electronjs.org/blog/protocol-…) that affects windows based Electron app (like Slack, Skype, Atom) looks super simple to exploit: "myapp://?--no-sandbox --gpu-launcher=cmd.exe /c start calc". Update all your electron apps now!

Shikari Senpai (@shikarisenpai) 's Twitter Profile Photo

Talk on Windows network authentication mechanism and Windows network pentesting. Topics: - #NTLM - Authentication mechanism - Hash cracking - Hash stealing - #IE #Edge - #NetBIOSSpoofing - #GroupPolicyHijacking For Mail RU and RuCTF speakerdeck.com/shikarisenpai/…