Rayan Bouyaiche (@rayanlecat) 's Twitter Profile
Rayan Bouyaiche

@rayanlecat

Pentester @quarkslab

ID: 891705900137893888

linkhttps://rayanle.cat calendar_today30-07-2017 17:03:48

1,1K Tweet

1,1K Followers

795 Following

Daniel Heinsen (@hotnops) 's Twitter Profile Photo

It's alive! Apeman is a graph-based tool to model AWS IAM permissions. This marks the start of a new journey to methodically identify and remediate IAM attack paths, and I look forward to learning together with y'all. github.com/hotnops/apeman

Laluka@OffenSkill - RDV@BarbHack ! (@thelaluka) 's Twitter Profile Photo

Bonjour citoyens de l'InfoSec, Je suis très heureux de vous annoncer ma nouvelle aventure : OffenSkill ! offenskill.com youtube.com/watch?v=g5KP9C… Suite à mon départ de ManoMano (miss you guys 💌), je me mets -enfin ?- à plein temps en tant que travailleur indépendant !

Critical Thinking - Bug Bounty Podcast (@ctbbpodcast) 's Twitter Profile Photo

Latest episode is live! This time around Lupin and I discuss our experience with Google's BugSwat LHE and the takeaways from that experience. It's a chill and short episode - a lot going on in Vegas this past week. Sit back and enjoy! ctbb.show/84

GreHack (@grehackconf) 's Twitter Profile Photo

Hey folks 🚨 AWESOME NEWS 🚨 Our second winner is very generous and offers to give away his prize, the "Learn Fundamentals" by OffSec 🤩 Two rules: 🔔 Follow us 🔔 RT We will do a random draw on 08/30 (Remember, prizes will be distributed during the #GreHack24 CTF)

chompie (@chompie1337) 's Twitter Profile Photo

The past year has been amazing. From marriage, to Pwn2Own to a Pwnie Award, I'm so grateful. I'm using the money I've won from hacking competitions, bounties, & RB for two ppl to travel & attend Hexacon, the premier offensive security con in Paris, France. forms.gle/zt9RaR7EEvTxWG…

Rayan Bouyaiche (@rayanlecat) 's Twitter Profile Photo

I just completed the "Dojo #35 - Chatroom" challenge on @YesWeHack! 🚀 Can you do it?: dojo-yeswehack.com/challenge/play… #ChallengeCompleted #YesWeRHackers #YesWeHackDojo

Critical Thinking - Bug Bounty Podcast (@ctbbpodcast) 's Twitter Profile Photo

Wow, a ton of crazy research dropped at DEFCON this year. This week, ya bois got you covered with practical takeaways on integrating all those gems into your workflow. Feat: the PortSwigger Research team's research hat trick, and a bit from Orange Tsai 🍊. ctbb.show/85

Ash (@_bin_ash) 's Twitter Profile Photo

In the past year I've seen SO many weird permissions granted to the "Domain Computers" group in environments. Always check outbound control from this group! See below for how to gain "Domain Computers" permissions, for later exploitation (with many links from Charlie Bromberg « Shutdown »):

Sonar Research (@sonar_research) 's Twitter Profile Photo

Critical Roundcube XSS technical details: Desanitization, unsafe Content-Types, CSS exfiltration, and a Service Worker come together to persistently leak emails from a victim's browser. Read about it here: sonarsource.com/blog/governmen… (CVE-2024-42008, CVE-2024-42009, CVE-2024-42010)

Critical Roundcube XSS technical details: Desanitization, unsafe Content-Types, CSS exfiltration, and a Service Worker come together to persistently leak emails from a victim's browser.

Read about it here:
sonarsource.com/blog/governmen…

(CVE-2024-42008, CVE-2024-42009, CVE-2024-42010)
Hack'n Speak (@hacknspeak) 's Twitter Profile Photo

🇫🇷🎙️Nouvel épisode du podcast Hack'n Speak avec David B. & vdehors triple vainqueurs de la Pwn2Own 🏆🏆🏆 Au programme, un retour d'expérience sur le hacking de Tesla et des anecdotes croustillantes 🚗 Bonne écoute à toutes et à tous 🎶 podcasters.spotify.com/pod/show/hackn…

quarkslab (@quarkslab) 's Twitter Profile Photo

Operator Fabric is an open source platform built by the LF Energy for use in electricity, water and other utility operations Last May we did a security audit sponsored by OSTIF Official🙏 Read a summary of our findings and find the full report here: blog.quarkslab.com/audit-of-opera…

Operator Fabric is an open source platform built by the <a href="/LFE_Foundation/">LF Energy</a> for use in electricity, water and other utility operations
Last May we did a security audit sponsored by <a href="/OSTIFofficial/">OSTIF Official</a>🙏
Read a summary of our findings and find the full report here:
blog.quarkslab.com/audit-of-opera…
Laluka@OffenSkill - RDV@BarbHack ! (@thelaluka) 's Twitter Profile Photo

Hop hop hop, c'est dans un mois et il reste 2 places ! 🌹 J'en re-profite pour quelques infos : - Les étudiants hors alternance ont 50% de réduction 💌💌 - Les alternants et nouveaux reconvertis en sécu ont 25% également 💌 Si cela vous tente -> la suite (code promo) en DM !

quarkslab (@quarkslab) 's Twitter Profile Photo

Chamilo is an open source e-Learning platform written in PHP and used worldwide. During a red team engagement Quarkslab's engineer Mathieu Farrell learned how to exploit it for Remote Code Execution. Now you can too: blog.quarkslab.com/exploiting-cha…

Chamilo is an open source e-Learning platform written in PHP and  used worldwide.
During a red team engagement Quarkslab's engineer Mathieu Farrell learned how to exploit it for Remote Code Execution.

Now you can too:
blog.quarkslab.com/exploiting-cha…