︎ ︎ (@0xocdsec) 's Twitter Profile
︎ ︎

@0xocdsec

🏴‍☠️ 💚 🇺🇦 computer tester | 603,628 km²

ID: 169596214

calendar_today22-07-2010 18:31:16

18,18K Tweet

4,4K Followers

5,5K Following

Matthew Green 🌻 (@mgreen27) 's Twitter Profile Photo

A cool privilege escalation hunt for linux hosts. 🚀 Link: docs.velociraptor.app/exchange/artif… Reference: dfir.ch/posts/linux_ca… Since Linux 2.6.24, setcap can attach fine-grained privilege bits to executables, letting them perform the specific privileged actions they require instead of

A cool privilege escalation hunt for linux hosts. 🚀

Link: docs.velociraptor.app/exchange/artif…
Reference: dfir.ch/posts/linux_ca…

Since Linux 2.6.24, setcap can attach fine-grained privilege bits to executables, letting them perform the specific privileged actions they require instead of
emma (@carrot_c4k3) 's Twitter Profile Photo

every single thing that people in the exploit business tell you about the importance of ethics and their vetting of customers is a lie because they can’t even keep their tools to themselves

Faith 🇧🇩🇦🇺 (@farazsth98) 's Twitter Profile Photo

Just noticed a defensive patch, most likely a direct result of this kCTF exploit: git.kernel.org/pub/scm/linux/… Makes this vulnerability completely unexploitable at least😅

The Kobeissi Letter (@kobeissiletter) 's Twitter Profile Photo

On top of this, central banks are stocking up on gold while disregarding technicals. On October 13th, gold posted its highest monthly RSI reading in HISTORY, at 91.8. Physical gold demand this year has proven that buyers are ignoring technicals. We don't see this changing.

On top of this, central banks are stocking up on gold while disregarding technicals.

On October 13th, gold posted its highest monthly RSI reading in HISTORY, at 91.8.

Physical gold demand this year has proven that buyers are ignoring technicals.

We don't see this changing.
wetw0rk (@wetw0rk_bot) 's Twitter Profile Photo

Released my write for gaining a fundamental understanding of the Windows _SECURITY_DESCRIPTOR structure. I then created a custom Windows Kernel shellcode stub to perform process injection for privilege escalation which is also implemented in Sickle :P wetw0rk.github.io/posts/understa…

NEXTA (@nexta_tv) 's Twitter Profile Photo

“Russia is lying to everyone that it’s winning,” said Zelensky “But that’s not true. They’ve lost more than a million people — 1.3 million, yes. And their economy is collapsing.”

Enes Şakir Çolak (@enessakircolak) 's Twitter Profile Photo

X64 Syscall Shellcode via ASM I wrote it for ekoparty2025_challenge. So its also a writeUp for BinaryGecko Reach the blog at the link below -> enessakircolak.netlify.app/posts/2025/sys… #Shellcode #Assembly #Windows #binarygecko #exploit #reverseengineering #microsoft #x64

X64 Syscall Shellcode via ASM

I wrote it for ekoparty2025_challenge.
So its also a writeUp for BinaryGecko 

Reach the blog at the link below ->
enessakircolak.netlify.app/posts/2025/sys…

#Shellcode #Assembly #Windows #binarygecko #exploit #reverseengineering #microsoft #x64
freefirex (@freefirex2) 's Twitter Profile Photo

rolled out a bof for getting the dpapi_system key used by mimikatz /system: when ingesting master keys. If that's something you need it's live at github.com/trustedsec/CS-…

rolled out a bof for getting the dpapi_system key used by mimikatz /system: when ingesting master keys.  
If that's something you need it's live at github.com/trustedsec/CS-…
Aura (@securityaura) 's Twitter Profile Photo

"I don't understand how we got ransomwared! We never saw anything in our consoles, there were no alerts, nothing that would make us think that this was happening! The consoles:

"I don't understand how we got ransomwared! We never saw anything in our consoles, there were no alerts, nothing that would make us think that this was happening!

The consoles:
starlabs (@starlabs_sg) 's Twitter Profile Photo

We are pleased to confirm that the Auth Bypass bug in Apache Brooklyn Server reported by our co-worker Jiantao Li has been successfully patched by the Apache team Fix details: github.com/apache/brookly… Great work to the Apache Brooklyn team for their prompt response.

Gray Hats (@the_yellow_fall) 's Twitter Profile Photo

ISC released urgent patches for three BIND 9 flaws. Two cache poisoning bugs (CVE-2025-40780/40778) allow remote DNS spoofing on resolvers by predicting query IDs or injecting forged records. #BIND9 #DNSSecurity #CachePoisoning #PatchNow securityonline.info/isc-patches-mu…

Hamid Kashfi (@hkashfi) 's Twitter Profile Photo

Signal The Iranian gov has recently started blocking Signal activation SMS sent to people during signup. It would be crucial and very helpful to have an alternative verification available beside SMS. Voice calls perhaps?