0xBB (@bb_hacks) 's Twitter Profile
0xBB

@bb_hacks

Someone who breaks stuff, sometimes even on purpose!

ID: 1133280206

calendar_today30-01-2013 07:35:49

710 Tweet

707 Followers

516 Following

Culture Crave 🍿 (@culturecrave) 's Twitter Profile Photo

Cards Against Humanity is suing Elon Musk & SpaceX for $15M They're being accused of trespassing on and damaging company-owned property in Texas "We bought a plot of land on the US-Mexico border to stop racist billionaire Donald Trump’s dumb wall. But this year, an even

Cards Against Humanity is suing Elon Musk & SpaceX for $15M 

They're being accused of trespassing on and damaging company-owned property in Texas

"We bought a plot of land on the US-Mexico border to stop racist billionaire Donald Trump’s dumb wall. But this year, an even
nyxgeek (@nyxgeek) 's Twitter Profile Photo

Did you know that 7z can browse .VHD and .VMDK files? You can open them right up, and even directly browse ntfs filesystems. On a pentest and find a bunch of disk images? Copy the SAM/SECURITY/SYSTEM hives directly from the images, no mounting, copying, or fussing around.

Did you know that 7z can browse .VHD and .VMDK files? You can open them right up, and even directly browse ntfs filesystems.

On a pentest and find a bunch of disk images? Copy the SAM/SECURITY/SYSTEM hives directly from the images, no mounting, copying, or fussing around.
0xBB (@bb_hacks) 's Twitter Profile Photo

Fancy retrieving plaintext user credentials, deactivation passcodes and uninstall passwords for Palo Alto Global Protect VPN? Thank goodness Palo Alto make that easy for you ... Full write up here : shells.systems/extracting-pla… Tooling available here : github.com/t3hbb/PanGP_Ex…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Oh, you didn't know? Cool kids are now relaying Kerberos over SMB 😏 Check out our latest blogpost by Hugow to discover how to perform this attack: synacktiv.com/publications/r…

Iceman (@herrmann1001) 's Twitter Profile Photo

🐋 Orca has arrived! The latest Proxmark3 source code is here, packed with fixes, features, and expanded capabilities. From enhanced iClass tools to new Python/Lua support, this is our most versatile update yet. 🔗 github.com/rfidresearchgr… #Proxmark3 #RFIDHacking #Orca

0xBB (@bb_hacks) 's Twitter Profile Photo

So Palo Alto apparently silently updated (nothing in the release notes I could see) and decided rather than fix the issue, they would just stop the PoC working. So here is the tool getting plaintext creds on the latest version. Stop blocking the tool and start fixing the issue

So Palo Alto apparently silently updated (nothing in the release notes I could see) and decided rather than fix the issue, they would just stop the PoC working.

So here is the tool getting plaintext creds on the latest version. 

Stop blocking the tool and start fixing the issue
0xBB (@bb_hacks) 's Twitter Profile Photo

Plain text credentials from Palo Alto GlobalProtect v6.3.2-525 Will update github.com/t3hbb/PanGP_Ex… later but the new pattern (~line 300) is {0x48, 0x8D, 0x15, 0x63, 0x62, 0x4E, 0x00} BlueSky Account : [email protected]

Plain text credentials from Palo Alto GlobalProtect v6.3.2-525

Will update github.com/t3hbb/PanGP_Ex… later but the new pattern (~line 300) is 

{0x48, 0x8D, 0x15, 0x63, 0x62, 0x4E, 0x00}

BlueSky Account : bbhacks@bsky.social
0xBB (@bb_hacks) 's Twitter Profile Photo

Fancy breaking out of ConstrainedLanguageMode, disabling userland ETW and bypassing AMSI? All at once and all with one tool? Signed by Microsoft? Well have I got some good news for you : shells.systems/one-tool-to-ru…

Dave Cossa (@g0ldengunsec) 's Twitter Profile Photo

Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can it be identified in an enterprise and misconfigurations that could allow it to be used for out-of-band execution and persistence. ibm.com/think/x-force/…

Signal (@signalapp) 's Twitter Profile Photo

We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EU’s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. signal.org/blog/pdfs/germ…

Ed Krassenstein (@edkrassen) 's Twitter Profile Photo

BREAKING: Alexandria Ocasio-Cortez just completely went off on Trump after ICE murdered Alex Pretti. "Donald Trump [is] accusing a Veteran Affairs ICU nurse (Alex Pretti) as being a terrorist against the United States. A man who was treating services members to our country, who was dedicating