Ing. Yamila Levalle
@ylevalle
Passionate about Information Security Researcher | Speaker | Pentester | Trainer | Developer | Bug Bounty Hunter | @notpinkcon Staff. Tweets are my own. She/Her
ID: 453409655
02-01-2012 22:11:30
3,3K Tweet
3,3K Takipçi
1,1K Takip Edilen
3.14159265358979323846264338327950288419716939937510582097494459230781640628620899862803482534211706798214808651328230664709384460955058223172535940812848111745028410270193852110555964462294895493038196442881097566593344612847564823378678316527120190914564856692346034861045432664
We've just published a quick write up on CVE-2023-23397, which allows a remote adversary to leak NetNTLMv2 hashes: mdsec.co.uk/2023/03/exploi… by Dominic Chell 👻
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of Office 365 accounts. How did I do it? Well, it all started with a simple click in Microsoft Azure… 👀 This is the story of #BingBang 🧵⬇️