0x_aalex (@0x_aalex) 's Twitter Profile
0x_aalex

@0x_aalex

ID: 1456702232385179649

calendar_today05-11-2021 19:17:45

85 Tweet

37 Takipçi

113 Takip Edilen

Jord (@0xlegacyy) 's Twitter Profile Photo

Yearly blog post just dropped: Control Flow Hijacking via Data Pointers 🐸 Showcasing how to find your own in Binary Ninja, how to weaponize and write a shellcode stub etc. Hopefully people find it useful :) legacyy.xyz/defenseevasion…

Yehuda Smirnov (@yudasm_) 's Twitter Profile Photo

What if you skipped VirtualAlloc, skipped WriteProcessMemory and still got code execution? We explored process injection using nothing but thread context. Full write-up + PoCs: blog.fndsec.net/2025/05/16/the…

Yuval Gordon (@yug0rd) 's Twitter Profile Photo

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️
Read Here - akamai.com/blog/security-…
MSec Operations (@msecops) 's Twitter Profile Photo

Rumour has it that Jonas Lykkegaard's self-delete technique doesn't work on Windows 11 anymore. Well, the original proof of concept (PoC) does not, but slight modifications bring this technique back to Win11!😎 With #RustPack, you can easily generate self-deleting executables or

OtterHacker (@otterhacker) 's Twitter Profile Photo

Okta chained with Azure with auto MFA subscription for Okta and frame-buster bypass to perform Bitb ! Evilginx is really nice to setup custom phishing campaign whatever the environment is... Phishlet available here : github.com/OtterHacker/Ok…

RedTeam Pentesting (@redteampt) 's Twitter Profile Photo

👀 We have also released a paper which really goes into the nitty-gritty for those who are interested 🕵️‍♀️: redteam-pentesting.de/publications/2… For those that only need a short overview, here's our advisory 🚨: redteam-pentesting.de/advisories/rt-…

John Hammond (@_johnhammond) 's Twitter Profile Photo

Learning Active Directory Certificate Service hacking-- with @Shikata! Starting with ESC8 using unauthenticated PetitPotam & Responder, we relay hashes to CA to get a certificate as the domain controller. This is the first video in an ADCS mini-series 😜 youtu.be/tYxJMr8jAgo

Learning Active Directory Certificate Service hacking-- with @Shikata! Starting with ESC8 using unauthenticated PetitPotam & Responder, we relay hashes to CA to get a certificate as the domain controller. This is the first video in an ADCS mini-series 😜 youtu.be/tYxJMr8jAgo
André Baptista (@0xacb) 's Twitter Profile Photo

I like to bypass XSS filters and sanitizers, so I keep forgetting to test for CSS exfiltration when I have HTML injection. This reminded me of the sic tool by d0nut 🦀 from a Singapore LHE, but there's also a cool list from PortSwigger 👇 github.com/PortSwigger/cs…

R.B.C. (@g3tsyst3m) 's Twitter Profile Photo

I'm starting another series - Buffer Overflows in the Modern Era. I'll go over the basics of using a debugger all the way to successfully achieving a buffer overflow exploit on Windows 11 24H2, using ROP gadgets and bypassing ASLR, etc. Here's part 1! g3tsyst3m.github.io/binary%20explo…

DirectoryRanger (@directoryranger) 's Twitter Profile Photo

DLL injection fundamental Part 1 systemweakness.com/dll-injection-… Part 2 systemweakness.com/dll-injection-… Part 3 systemweakness.com/dll-injection-…

Alex Vacca (@itsalexvacca) 's Twitter Profile Photo

BREAKING: MIT just completed the first brain scan study of ChatGPT users & the results are terrifying. Turns out, AI isn't making us more productive. It's making us cognitively bankrupt. Here's what 4 months of data revealed: (hint: we've been measuring productivity all wrong)

BREAKING: MIT just completed the first brain scan study of ChatGPT users & the results are terrifying.

Turns out, AI isn't making us more productive. It's making us cognitively bankrupt.

Here's what 4 months of data revealed:

(hint: we've been measuring productivity all wrong)
Marci Ujlaki (@ujlakimarci) 's Twitter Profile Photo

oh no 🟥 CVE-2025-32463, CVSS: 9.3 (#Critical) #Sudo version 1.9.14 to 1.9.17 #Vulnerability allows local users to gain root access via the --chroot option due to improper handling of /etc/nsswitch.conf. #CyberSecurity #CVE #PrivilegeEscalation openwall.com/lists/oss-secu…

oh no

🟥 CVE-2025-32463, CVSS: 9.3 (#Critical)

#Sudo version 1.9.14 to 1.9.17

#Vulnerability allows local users to gain root access via the --chroot option due to improper handling of /etc/nsswitch.conf.  

#CyberSecurity #CVE #PrivilegeEscalation

openwall.com/lists/oss-secu…
Rad (@rad9800) 's Twitter Profile Photo

An excellent, in-depth malware analysis article. Refreshing depth and clarity from Tony/Humpty c-b.io/2025-06-29+-+S… Demonstrably understands Yara's strengths and weaknesses. Take note Florian Roth ⚡️.

Huntress (@huntresslabs) 's Twitter Profile Photo

A hacker clicked a Google ad. They thought they were grabbing a tool to help their ops. Instead, they installed Huntress on their own machine. 👀 And just like that—we got a front-row seat.

A hacker clicked a Google ad.
They thought they were grabbing a tool to help their ops.
Instead, they installed Huntress on their own machine.
👀 And just like that—we got a front-row seat.