John Woodman
@johnwoodman15
@Mandiant consultant | wadcoms.github.io | github.com/JohnWoodman
ID: 746514928433954816
https://john-woodman.com/research 25-06-2016 01:26:43
127 Tweet
434 Followers
381 Following
Introducing KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). All credits go to James Forshaw Cube0x0 Will Schroeder, most of the code was taken from their tools. github.com/Dec0ne/KrbRela…
Introducing DirtyDict. A series of vulnerabilities found by me and Mickey Jin. Most of this is my perspective, but Mickey did give me permission to share some details about one of his bugs. Enjoy! wts.dev/posts/dirtydic…
Crowdstrike can be bypassed on macOS with tclsh, eg: gist.github.com/tokyoneon/e425… Ncat reverse shell is killed, but this one isn’t. How about that Mr “tom square” tom square hmm? Please provide your insight!!
Want to see what top-notch security research looks like? Look no further than Jakub Domeracki's latest research, a standout contributor to the Google Cloud VRP! 🪲💪 jdsec.cloud/posts/2026-01-…
Our intrepid 20%-er Dillon Franke exploited a vulnerability in CoreAudio. See his process for gaining privilege escalation on a Mac: projectzero.google/2026/01/sound-…