Darren Martyn (@_darrenmartyn) 's Twitter Profile
Darren Martyn

@_darrenmartyn

Professional Belligerent. хакер.
Caretaker of one fluffy cat.

ID: 1189570018444492801

linkhttps://darrenmartyn.ie calendar_today30-10-2019 15:50:05

9,9K Tweet

1,1K Followers

911 Following

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

Dear vendors: the more irritating it is (for me) to download your software, the less likely I am to engage in coordinated disclosure when I find bugs.

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

Dried and powdered oyster mushrooms. Looks like they need another go in the dehydrator, get rid of the last of the moisture for storage. This shit is powdered flavour.

Dried and powdered oyster mushrooms. Looks like they need another go in the dehydrator, get rid of the last of the moisture for storage. This shit is powdered flavour.
Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

I'm gonna hand it to Yunus Aydın, you may disagree with their methods, but they certainly got everyone's undivided* attention. * For about five minutes, before infosec got distracted by some other shit that's probably less fundamentally important than supply chain security.

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

The liquid limit is among the most egregiously pointless, poorly thought out, completely lacking a threat model rules inflicted on us by the aviation security idiots during the US led global war on common sense.

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

Yet again being infuriated by another writeup that uses "inclusion" instead of "disclosure" or "reading" in the context of local files. Unless the file content is evaluated, it's not file inclusion. It's file disclosure or file reading. Thanks for coming to my Ted talk.

starlabs (@starlabs_sg) 's Twitter Profile Photo

Today, we are dropping this repo github.com/star-sg/NotQui… Basically all the bugs in the repo are either ignored or not fixed at all even after vendors acknowledged We hope we will not need to drop in the future Today's bugs are brought to you by Daniel Lim

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

Adventures in disclosure lately: - well known security product vendor: crickets, no security contact, etc. - router vendor that also does firewalls: really responsive PSIRT, surprisingly good. - some other appliance manufacturer: actually directed me to their bug bounty page?!

Darren Martyn (@_darrenmartyn) 's Twitter Profile Photo

Awesome work, using a symlink exploit in unrar to get pre-auth code exec on Zimbra (and as mentioned in the blog post, can be chained with one of my LPE's).