devmal (@dev_nu1l) 's Twitter Profile
devmal

@dev_nu1l

may or may not work for R7. views be my own, “yada yada yada” - elaine benes

ID: 1034161227218477057

linkhttp://allthemalwares.info calendar_today27-08-2018 19:30:25

171 Tweet

35 Followers

305 Following

vx-underground (@vxunderground) 's Twitter Profile Photo

We have seen many tweets recently about silly malware concepts like "syscalls", "unhooking", or "obfuscation". Here is our #1 #RedTeamTip to avoid EDRs. Use an RPG-7 to obliterate the computer. The EDR cannot detect your malware if the computer is not operational

We have seen many tweets recently about silly malware concepts like "syscalls", "unhooking", or "obfuscation".

Here is our #1 #RedTeamTip to avoid EDRs. Use an RPG-7 to obliterate the computer. The EDR cannot detect your malware if the computer is not operational
N$ (@nav1n0x) 's Twitter Profile Photo

I found 2 Blind time-based SQL Injections in X-Forwarded-For: header just using Burp Intruder. Made a list of 500+ HTTP request and tested one by one for 3+ hours, here is the result.. X-Forwarded-For: 0'XOR(if(now()=sysdate(),sleep(6),0))XOR'Z #BugBounty

I found 2 Blind time-based SQL Injections in X-Forwarded-For: header just using Burp Intruder. Made a list of 500+ HTTP request and tested one by one for 3+ hours, here is the result..

X-Forwarded-For: 0'XOR(if(now()=sysdate(),sleep(6),0))XOR'Z

#BugBounty
Caitlin Condon (@catc0n) 's Twitter Profile Photo

We lost a lot of good #security industry folks today at Rapid7. I know of some incredible (and incredibly kind) researchers, software devs, offsec engineers, support team members, and consultants (IR, pen testing) who are looking for work right now — trawl LinkedIn + hire them <3