Andrew Luke (@sw4mp_f0x) 's Twitter Profile
Andrew Luke

@sw4mp_f0x

Hacking systems, software, finances, and life.

ID: 350458572

linkhttps://pentestarmoury.com/ calendar_today07-08-2011 20:18:44

394 Tweet

1,1K Followers

433 Following

Andrew Luke (@sw4mp_f0x) 's Twitter Profile Photo

TIL IANA called out MSFT's use of "www-authenticate: negotiate" "This authentication scheme violates both HTTP semantics (being connection-oriented) and syntax (use of syntax incompatible with the WWW-Authenticate and Authorization header field syntax)." archive.is/cnps8#selectio…

Shit InfoSec Says (@infosecsays) 's Twitter Profile Photo

Audit finding: Vulnerability scan results reveal host and domain names Remediation: Redact or obfuscate identifiable information in vulnerability reports Management response: We need that information to know where we need to patch, won't fix

Andrew Luke (@sw4mp_f0x) 's Twitter Profile Photo

"Check if a Certificate and a Private Key match" "Enter your Private Key:" 🤨🤔 Yeah, I think I will pass on that, sslshopper.com

"Check if a Certificate and a Private Key match"

"Enter your Private Key:"

🤨🤔 Yeah, I think I will pass on that, sslshopper.com
Andrew Luke (@sw4mp_f0x) 's Twitter Profile Photo

Open redirection is possible with relative paths by prefixing with an @ sign: Ex: "mysite.com" + path If path is "@test.com", a redirect to test.com occurs due to how browsers handle a URL like "[email protected]" Fix: ensure the initial path /

Andrew Luke (@sw4mp_f0x) 's Twitter Profile Photo

Wanted to share my Infosec Income Questionnaire again. It can be a very useful resource for hiring and for requesting salaries/raises. We've had a recent surge in submissions getting us to 358! Form: goo.gl/forms/pAeMbeo6… Results: docs.google.com/spreadsheets/d…

Jake Williams (@malwarejake) 's Twitter Profile Photo

CBP having military drones at all? Questionable CBP deploying military drones that were justified to Congress to patrol the border to instead fly over an area of civil unrest? Eek Yeah, nobody cares that MSP inside the 100 mile CBP "border zone" where "nobody has any rights."

Andy Robbins (@_wald0) 's Twitter Profile Photo

Pivoting from Azure back down to on-prem AD opens up some very exciting attack path possibilities. In this post, I explain what Hybrid Azure Join is, target enumeration, and how to abuse Intune/Endpoint Manager to execute code as SYSTEM on target systems posts.specterops.io/death-from-abo…

Pivoting from Azure back down to on-prem AD opens up some very exciting attack path possibilities.

In this post, I explain what Hybrid Azure Join is, target enumeration, and how to abuse Intune/Endpoint Manager to execute code as SYSTEM on target systems

posts.specterops.io/death-from-abo…
Alex Birsan (@alxbrsn) 's Twitter Profile Photo

Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies 👇Check the thread after reading for a few bonus facts👇 medium.com/@alex.birsan/d…

Troy Hunt (@troyhunt) 's Twitter Profile Photo

So, the Gab data breach situation: Let's start the bizarreness with their CEO's ridiculous statement tweeted yesterday: x.com/getongab/statu…

Tyler Butler (@primarytyler) 's Twitter Profile Photo

Today I'm thrilled to formally launch a project months in the making. Deploying this tool internally has yielded great results, but our goal was always to release it as a robust, flexible, and low-barrier-to-entry tool for any security team. blog.palantir.com/phishcatch-det…

Andy Robbins (@_wald0) 's Twitter Profile Photo

I'm extremely proud to announce The Attack Path Management Manifesto - our perspective, thoughts, and vision for directly dealing with the problem of Attack Paths: posts.specterops.io/the-attack-pat…

I'm extremely proud to announce The Attack Path Management Manifesto - our perspective, thoughts, and vision for directly dealing with the problem of Attack Paths: posts.specterops.io/the-attack-pat…