tonghuaroot (@tonghuaroot) 's Twitter Profile
tonghuaroot

@tonghuaroot

Staff Security Engineer. Cyber Security enthusiast, not Hacker. Focus on Application Security, Penetration testing. #OSCP #OSEP #RedTeam #AppSec #WebSec

ID: 1359352281720713221

linkhttps://tonghuaroot.com/ calendar_today10-02-2021 04:03:44

230 Tweet

408 Takipçi

2,2K Takip Edilen

CyKor (@cykorku) 's Twitter Profile Photo

We just posted last two DEFCON 33 CTF write-ups on our blog! Check their creative insight! 🦾 Junhyun Song (KU, 4th year) wrote dialects (pwn) - 🔗 blog.cykor.kr/2025/04/DEFCON… 🚩 Seohyun Jang (KU, 3rd year) wrote im‑pio‑sible (misc) - 🔗 blog.cykor.kr/2025/04/DEFCON… #CTF #DEFCON #CyKor

We just posted last two DEFCON 33 CTF write-ups on our blog! Check their creative insight!
🦾 Junhyun Song (KU, 4th year) wrote dialects (pwn)
 - 🔗 blog.cykor.kr/2025/04/DEFCON…
🚩 Seohyun Jang (KU, 3rd year) wrote im‑pio‑sible (misc)
 - 🔗 blog.cykor.kr/2025/04/DEFCON…

#CTF #DEFCON #CyKor
tonghuaroot (@tonghuaroot) 's Twitter Profile Photo

JNI Helper Find JNI function signatures in APK and apply to reverse tools. github.com/evilpan/jni_he… A awesome tool created by evilpan 🫡

JNI Helper

Find JNI function signatures in APK and apply to reverse tools.

github.com/evilpan/jni_he…

A awesome tool created by <a href="/evilpan_/">evilpan</a>  🫡
ippsec (@ippsec) 's Twitter Profile Photo

The HackTheBox Vintage video is now up! This was a Hard Assumed Breach Box that was almost 100% Active Directory, the only piece that isn't technically AD is decrypting the DPAPI Credential Store. Definitely a fun one for those AD Lovers youtube.com/watch?v=-JM--K…

SunSec (@1nf0s3cpt) 's Twitter Profile Photo

🚀 New Features Just Dropped in DeFIHackLabs Incident Explorer The latest update to our platform includes: 1️⃣ DeFi Incident Analytics (at the bottom of the page) 2️⃣ Multi-currency display (10+ currencies) 3️⃣ Visual effects toggle 4️⃣ Light mode support 🌞 #DeFi #Web3Security

🚀 New Features Just Dropped in DeFIHackLabs Incident Explorer

The latest update to our platform includes: 
1️⃣ DeFi Incident Analytics (at the bottom of the page)
2️⃣ Multi-currency display (10+ currencies)
3️⃣ Visual effects toggle
4️⃣ Light mode support 🌞

#DeFi #Web3Security
Mandiant (part of Google Cloud) (@mandiant) 's Twitter Profile Photo

In 2024, attackers exploited 75 zero-days across end-user platforms and enterprise tech. Google’s latest report unpacks what this trend says about evolving threat priorities. Full analysis here: bit.ly/4cTQzMI

In 2024, attackers exploited 75 zero-days across end-user platforms and enterprise tech. Google’s latest report unpacks what this trend says about evolving threat priorities.

Full analysis here: bit.ly/4cTQzMI
Mirror Tang (@mirrorzk) 's Twitter Profile Photo

我是Mirror Tang,在Crypto创业这几年,我越来越确认一件事:再牛逼的技术、再聪明的人,如果团队协作不透明,增长就是错觉. 前阵子我在团队内部看到一种典型的热情假象——表面大家都很积极,私下沟通不断,仿佛每个人都在高效推进.

4n6lady (@4n6lady) 's Twitter Profile Photo

Snapshot first, ask questions later. DO NOT TERMINATE. If you're investigating an EC2 instance — snapshot volumes before you do anything else, and then isolate it on an island. Evidence disappears fast in the cloud - turning the EC2 off destroys what you need.

zhiniang peng (@edwardzpeng) 's Twitter Profile Photo

New blog: Be careful of Your UDP Service: Preauth DoS on Windows Deployment Service (remote, 0-click) sites.google.com/site/zhiniangp…

Akamai Security Intelligence Group (@akamai_research) 's Twitter Profile Photo

Today we unveil BadSuccessor - a new no-fix Active Directory privilege escalation technique. We will explore the recently introduced dMSA feature, and show how it enables turning a very common, seemingly benign permission, into a full domain take over. akamai.com/blog/security-…