Zeroed (@zeroedtech) 's Twitter Profile
Zeroed

@zeroedtech

Just a guy that talks at conferences sometimes

ID: 1148816308735074304

calendar_today10-07-2019 04:48:46

44 Tweet

239 Followers

74 Following

Zeroed (@zeroedtech) 's Twitter Profile Photo

The IIS mods for #bsidescbr are coming together. These screenshots show the interception of a directory listing payload being run via a chinachopper shell

The IIS mods for #bsidescbr are coming together. These screenshots show the interception of a directory listing payload being run via a chinachopper shell
Zeroed (@zeroedtech) 's Twitter Profile Photo

Is it hackback if you tamper with what an adversaries code sends back to their C2? Defensive part of my #bsidescbr presentation is done, onto the offensive side.

Is it hackback if you tamper with what an adversaries code sends back to their C2?
Defensive part of my #bsidescbr presentation is done, onto the offensive side.
Zeroed (@zeroedtech) 's Twitter Profile Photo

If you've ever wondered what those weird "App_Web_das2318.dll" files on IIS servers are, I've written a blog post detailing where their names come from, what they do and the forensic benefits they can provide zeroed.tech/blog/analysing… This is the first in a series of IIS posts

Zeroed (@zeroedtech) 's Twitter Profile Photo

How much do you know about IIS Machine Keys and View State? Are you confident you could not only identify an exploited host but also remediate it? If not, check out my new blog post which covers exploitation, detection and remediation zeroed.tech/blog/viewstate…

Zeroed (@zeroedtech) 's Twitter Profile Photo

I'll be running a free 3 hour training session at BSidesCanberra teaching people how to defend IIS servers by learning how to attack them. I'll be posting recommended host setups closer to the event so be sure to give me a follow. cfp.bsidescbr.com.au/bsides-canberr…

Zeroed (@zeroedtech) 's Twitter Profile Photo

For those planing to attend my "Attacking and Defending Microsoft IIS" training session at BSidesCanberra next week, checkout the following post for the list of recommended software to have reaady to go zeroed.tech/blog/bsides-20… See you all Friday

Zeroed (@zeroedtech) 's Twitter Profile Photo

Thank you to everyone who attended my training session and a massive thanks to BSidesCanberra for providing me the opportunity to run it. The slides and any code we used can be found here zeroed.tech/blog/bsides-20… I'd love any feedback on the session

Zeroed (@zeroedtech) 's Twitter Profile Photo

Not a bad read, I think they may be overanalysing a compiled webshell and its a shame they didn't get a memory dump but its great to see more companies talking about this stuff github.com/RedDrip7/Night…

Zeroed (@zeroedtech) 's Twitter Profile Photo

12 months ago I presented a 3 hour course on attacking and defending Microsoft IIS servers to a packed room at BSides Canberra, today the 30+ hour version went live on XINTRA !

Zeroed (@zeroedtech) 's Twitter Profile Photo

I've recently been experimenting with using .NET profilers to hook .NET functions under IIS and decided to write up a blog post while it was fresh in my mind zeroed.tech/blog/hooking-n…