Rick Ramgattie (@rramgattie) 's Twitter Profile
Rick Ramgattie

@rramgattie

ID: 719285525954359298

linkhttps://ramgattie.com calendar_today10-04-2016 22:06:47

644 Tweet

209 Followers

167 Following

BOGON (@extantbogon) 's Twitter Profile Photo

Ever wondered what kind of stuff ends up in URL shorteners? I did, and then I found out about URL Team. 5+ years of distributed brute forcing, with over 12 billion links found, totaling ~1TB of data. There's some wild stuff in here! archive.org/search.php?que…

Rick Ramgattie (@rramgattie) 's Twitter Profile Photo

Even if there is URL encoding you can get same site SSRF if you control variables between forward slashes. Think '/encode($var1)/encode($var2)/encode($var3)' were those vars are '..' It's allowed per the RFC tools.ietf.org/html/rfc3986#s…

Ming Chow (@0xmchow) 's Twitter Profile Photo

Marcus' tweet prompted me write this piece: "Technical Project Ideas Towards Learning Cyber Security" mchow01.github.io/education/secu…

Rick Ramgattie (@rramgattie) 's Twitter Profile Photo

I was thinking about the SameSite 2 Minute "Post+LAX" workflow this morning and found that someone had already figured out the workarounds I was thinking about medium.com/@renwa/bypass-….

BOGON (@extantbogon) 's Twitter Profile Photo

Quick tip: If you're attacking/defending a *nix box with users that can run limited sudo cmds, check for `more` and `less`. Both tend to be assumed as benign but can execute arbitrary commands. So, if you have a "read only" account with sudo less/more, it's trivial root privesc.

Bsides Orlando (@bsidesorl) 's Twitter Profile Photo

Join us on Nov 7 at 10:30 AM ET when Shea Polansky (Shea Polansky) presents "Adventures in Perimeterless Homelabbing" More info: 2020.bsidesorlando.org/?utm_campaign=… Full Schedule: 2020.bsidesorlando.org/?utm_campaign=… Tickets: …desorlando2020-virtual.eventbrite.com/?utm_campaign=…

Join us on Nov 7 at 10:30 AM ET when Shea Polansky (<a href="/0x5ca1e5/">Shea Polansky</a>) presents "Adventures in Perimeterless Homelabbing"

More info: 2020.bsidesorlando.org/?utm_campaign=…
Full Schedule: 2020.bsidesorlando.org/?utm_campaign=…
Tickets: …desorlando2020-virtual.eventbrite.com/?utm_campaign=…
SecurityTrails, A Recorded Future Company (@securitytrails) 's Twitter Profile Photo

Want to get more credits for SecurityTrails API™? Just retweet this tweet and you will get 100 RECURRING API CREDITS 🎉 Ends 28 Nov 2020, 3pm EST. Make sure we can PM you to ask for the email address you signed up with.

Want to get more credits for SecurityTrails API™?

Just retweet this tweet and you will get 100 RECURRING API CREDITS 🎉

Ends 28 Nov 2020, 3pm EST. Make sure we can PM you to ask for the email address you signed up with.
Rick Ramgattie (@rramgattie) 's Twitter Profile Photo

I finally setup my own collaborator server and it would have been hell without this blog and repo. teamrot.fi/self-hosted-bu…

Rick Ramgattie (@rramgattie) 's Twitter Profile Photo

TGanks for the tip! I will change those right now. I set it up so that it tees it into a file for logging and hits a Slack webhook with valid information. Its going to be very handy for OOB attacks.

BOGON (@extantbogon) 's Twitter Profile Photo

I've encountered a new contender for worst vulnerability disclosure process. NASA. It seemed promising at first, but I've been attempting to exchange PGP keys for over 3 weeks.

🇨🇦Hack The Box Ottawa (Meetup) (@hackthebox_yow) 's Twitter Profile Photo

We're turning up the heat 🔥 for the next meetup! We're tackling a HARD Linux box and we called in the big guns to walk us through it! Offensive security specialist (from Ottawa🇨🇦), t1v0 , is our next guest presenter! Do not miss this one and RSVP🔗: meetup.com/Hack-The-Box-M…

We're turning up the heat 🔥 for the next meetup! We're tackling a HARD Linux box and we called in the big guns to walk us through it! Offensive security specialist (from Ottawa🇨🇦), <a href="/_t1v0_/">t1v0</a> , is our next guest presenter! Do not miss this one and RSVP🔗: meetup.com/Hack-The-Box-M…
Doyensec (@doyensec) 's Twitter Profile Photo

Summer 2023 - 3 months paid, summer #internships available for US/EU residents. Learn #appsec from the best :) Apply today! careers-page.com/doyensec-llc/j… #doyensec

Summer 2023 - 3 months paid, summer #internships available for US/EU residents. Learn #appsec from the best :) Apply today!

careers-page.com/doyensec-llc/j…

#doyensec
Darryl Ruggles (@rdarrylr) 's Twitter Profile Photo

You may have certain files in your repo you want to keep an eye on and be notified if someone is trying to change them. If you're using Github for storing your code then you can take advantage of Github Actions and workflows to perform many different automation tasks and build