🐣 (@sysgoblin) 's Twitter Profile
🐣

@sysgoblin

principal threat researcher and professional pleb

ID: 4854215951

linkhttp://rm-rf.lol calendar_today27-01-2016 17:27:03

768 Tweet

808 Takipçi

519 Takip Edilen

MG (@_mg_) 's Twitter Profile Photo

Hey... did anyone notice that PAN 0day was fixed in a version that was released over a year ago? Guess it wasn't easy to notice under all the loud opinions about ethics. 🤣

Hey... did anyone notice that PAN 0day was fixed in a version that was released over a year ago? 

Guess it wasn't easy to notice under all the loud opinions about ethics. 🤣
Nixintel (@nixintel) 's Twitter Profile Photo

How can you identify the plane, location, and mission commander in this image? With the intelligence cycle and a little automation! This Verif!cation Quiz Bot challenge from Fiete Stegers | @[email protected] is the hardest one I've tried so far. New #geolocation blog post: nixintel.info/osint/planes-a…

How can you identify the plane, location, and mission commander in this image?

With the intelligence cycle and a little automation!

This <a href="/quiztime/">Verif!cation Quiz Bot</a> challenge from <a href="/fiete_stegers/">Fiete Stegers | @fiete@mastodon.social</a> is the hardest one I've tried so far.

New #geolocation blog post: nixintel.info/osint/planes-a…
Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

#log4j thread Detection Ideas + Yara by Florian Roth ⚡️ - gist.github.com/Neo23x0/e4c8b0… Hashes for vulnerable LOG4J versions by Rob Fuller - github.com/mubix/CVE-2021… SIGMA by SOC Prime - tdm.socprime.com/tdm/info/XY2Ej… tdm.socprime.com/tdm/info/4SiOs… Payloads list by GreyNoise - gist.github.com/nathanqthai/01…

Steve Ragan ⚠️ (@steved3) 's Twitter Profile Photo

I promised I would write a report covering my phishing research in 2021. That report is now live: steved3.io/data/Phishing-… Shout out to @AmandaFGoedde for helping me edit, as well as にのせき for making Miteru, and urlscan.io for creating an awesome tool to help defenders.

I promised I would write a report covering my phishing research in 2021.

That report is now live:

steved3.io/data/Phishing-…

Shout out to @AmandaFGoedde for helping me edit, as well as <a href="/ninoseki/">にのせき</a> for making Miteru, and <a href="/urlscanio/">urlscan.io</a> for creating an awesome tool to help defenders.
🐣 (@sysgoblin) 's Twitter Profile Photo

just pushed a quick update to emulate apache/elastic, process query params, and accept POST data with a fake login form. have at it! 🍯

ilikecats (@0xilikecats) 's Twitter Profile Photo

A few hours ago, a promising token called $YEAR was airdropped. It was set up as a "year in review" of your Ethereum transaction history. Less than an hour ago, this turned into a painful experience for buyers of the token. Here's how $YEAR pulled the rug in under 6 hours🧵 1/

Stephan (@FirehaK@infosec.exchange) (@_firehak) 's Twitter Profile Photo

Sad that I got beat to posting about this publicly after looking at it on and off since October, but there are a lot of great details in here about a previously unknown botnet written in Go! Here are some screenshots (including the operator's desktop) I had as well!

Sad that I got beat to posting about this publicly after looking at it on and off since October, but there are a lot of great details in here about a previously unknown botnet written in Go! Here are some screenshots (including the operator's desktop) I had as well!
jess (@milkjuus) 's Twitter Profile Photo

It saddens me to announce that Sukon, the startup I’ve been working on since September 2021, will be shutting down. It was a hard decision, but ultimately it was the right call to make. There were 3 main reasons why Sukon failed, which is what I’ll go over in this thread🧵