Lorenzo Nicolodi (@illordlo) 's Twitter Profile
Lorenzo Nicolodi

@illordlo

Professional puddle jumper

ID: 2446286290

linkhttps://microlab.red calendar_today30-03-2014 05:26:59

365 Tweet

185 Takipçi

420 Takip Edilen

Old Bitshifter (@blackswanburst) 's Twitter Profile Photo

Hackers, I just want to remind you that you're lucky to be built around remote working. Those around you may not be financially, occupationally, psychologically, emotionally, or organisationally. Now is the time to help them by leveraging that privilege.

@mikko (@mikko) 's Twitter Profile Photo

Public message to ransomware gangs: Stay the f away from medical organizations. If you target hospital computer systems during the pandemic, we will use all of our resources to hunt you down.

Claudio CC (Neco) (@claudiocc) 's Twitter Profile Photo

COVID-19. This is an emergency post. Please share. Trying to help an industrial company in Spain which manufactures Ventilators. We need three miniature electro valves urgently: Parker X-Valve X-1-05-L-F, VSO LowPro model 8, VSO LowPro model 4. If you have stock, pls contact me

COVID-19. This is an emergency post. Please share. Trying to help an industrial company in Spain which manufactures  Ventilators. We need three miniature electro valves urgently: Parker X-Valve X-1-05-L-F, VSO LowPro model 8,  VSO LowPro model 4. If you have stock, pls contact me
Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

the moment when you discover that a well known security vendor writes fake blog posts with "advanced technical analysis" that, once you verify, are completely wrong. they just decoded a base64 URL and concluded that the malware exfiltrates info. spoiler: it didn't. rolf.

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

here is another one. leading cybersecurity company, supported by well known investors, explaining how web skimmer use "windows.atob" to *decrypt* the payload (this happens multiple times in the blog post, so not a mistake). base64 != encryption.

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

if your pentest report does not explain to the developers/sysadmins how to improve, if you are not supporting them in every possible way in the process and if you are not ready to learn from them, that is not called "penetration testing", it is called "ego boosting".

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

there are good companies with good products. some companies are even better and provide great products. above them, there is PortSwigger: astonishing support, awesome research capabilities and a product that is simply an industry standard.

Vatican Embassy (@vaticanembassy) 's Twitter Profile Photo

as always the prelates of the Vatican Embassy are on their way to Leipzig. Please, don't wake us up. (we are missing you all, but we'll do our best to be present at #rc3)

Vatican Embassy (@vaticanembassy) 's Twitter Profile Photo

breakfast at #rC3 with panettone with pineapple, papaya, guava and jackfruit. Because whoever said we were born to suffer was a filthy liar.

breakfast at #rC3 with panettone with pineapple, papaya, guava and jackfruit. Because whoever said we were born to suffer was a filthy liar.
Vatican Embassy (@vaticanembassy) 's Twitter Profile Photo

Do you want to get Holy United at #rC3 ? Come to the Vatican Embassy (rc3-get-united.vado.li) and customize your Holy Rite here: vaticanembassy.github.io/TheHolyUnion/ #HolyUnion #GetUnited get in touch to agree a time for the union. The Holy Bishops are here for you!

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

Do you want to exploit a zip slip vuln but are you in a hurry? "Let Me Code That For You(TM)" github.com/illordlo/explo… Thanks to Snyk for publishing the research back in 2018.

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

Stasera Vatican Embassy ore 21: whack-a-service by panda! Come rendere (circa) altamente affidabili servizi esposti non direttamente su internet, a basso costo, usando i DNS. jitsi.rc3.world/rc321vaticanem… Streaming: live.autistici.org): live.autistici.org/#rc3-vaticanem…

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

Stasera Vatican Embassy ore 23:59: IPv6 101 Perché ancora manco si sa che sia ed IPv7 sta arrivando. jitsi.rc3.world/rc321vaticanem… Talk forse in inglese (non abbiamo ancora deciso).

Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

Stasera Vatican Embassy ore 23:59: IPv6 101 Because we still don't know what it is and IPv7 is coming. jitsi.rc3.world/rc321vaticanem… The talk could be in italian (we have still to decide).

Vatican Embassy (@vaticanembassy) 's Twitter Profile Photo

stasera alle 23.59 alla Vatican Embassy (mondo 2D) talk "IPv6 101" a cura di l0rd. Info: rc3.world/2021/event/ipv… Link diretto: jitsi.rc3.world/shared-vatican… The talk will most probably be in Italian, but who knows... #rc3 #vaticanembassy #ipv6

stasera alle 23.59 alla Vatican Embassy (mondo 2D) talk "IPv6 101" a cura di l0rd.

Info: rc3.world/2021/event/ipv…

Link diretto: jitsi.rc3.world/shared-vatican…

The talk will most probably be in Italian, but who knows... #rc3 #vaticanembassy #ipv6
Lorenzo Nicolodi (@illordlo) 's Twitter Profile Photo

i started a series of blog posts to save people the tens of hours i dedicated studying tor internals. hope you enjoy. any feedback/improvement is *really* appreciated. microlab.red/2024/09/03/tor… microlab.red/2024/09/23/tor…