Russ (@rustla) 's Twitter Profile
Russ

@rustla

Pentester who often hangs out with the blue team. (he/him) infosec.exchange/@rustla | bsky.app/profile/rust.la

ID: 11191242

calendar_today15-12-2007 08:37:20

2,2K Tweet

245 Followers

639 Following

Russ (@rustla) 's Twitter Profile Photo

A bunch of apps I’ve been poking around with lately interact with Dataverse using $batch queries. Not seen much chatter about it, but really handy to subvert intended logic when the queries and writes are just … there. Any authz issues are super obvious too 👁️👁️

Garrett (@unsigned_sh0rt) 's Twitter Profile Photo

knew win10 had the dsquery.dll laying around but never knew what to do with it "rundll32.exe dsquery.dll OpenQueryWindow" will pop open a console for you and you can do some light LDAP recon you can also open with with win + ctrl + f probably useful for VDI/Citrix type tests

knew win10 had the dsquery.dll laying around but never knew what to do with it

"rundll32.exe dsquery.dll OpenQueryWindow" will pop open a console for you and you can do some light LDAP recon

you can also open with with win + ctrl + f

probably useful for VDI/Citrix type tests
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…

Russ (@rustla) 's Twitter Profile Photo

Missed out on BSides Perth because I’m travelling. Super proud to hear that my nephew won a challenge coin for Lockpicking 💪 … even if that makes me feel super freaking old