@strawpi
iAccount based inUnited Kingdom!
About this account
- Account based in
- United Kingdom
- Connected via
- Web
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Principal security consultant @nettitude_labs. CHECK Team Leader (Applications). Frequently uninjured snowboarder. @Strawp@infosec.exchange
document.location
Joined April 2008
- Tweets13.4K
- Following381
- Followers798
- Likes3.8K
Pinned Tweet
If you miss Twitter back in pre-2010 days when it was just full of geeks sharing cool stuff, then get on Mastodon.
infosec.exchange/@strawp is where I'll be now
👋
Replying to @sampilgrim
@sampilgrim this guy who rides a penny farthing says he wouldn't know how to pop a wheelie on it. cotswoldjournal.co.uk/news/1… I figured if anyone could manual one, you could. Make it happen! 😁
I did a thing
Popular document storage solution, ONLYOFFICE, affected by multiple vulnerabilities. Our latest post by @strawp shows how to exploit this for unauthenticated remote code execution.
labs.nettitude.com/blog/expl…
Popular document storage solution, ONLYOFFICE, affected by multiple vulnerabilities. Our latest post by @strawp shows how to exploit this for unauthenticated remote code execution.
labs.nettitude.com/blog/expl…
Oh yay, haven't had a fun OpenSSL vuln since heartbleed 🍿
This Post is from an account that no longer exists. Learn more
A masterclass of OSINT. It's wild that:
1. RU military communicate by normal phone calls (I guess TEAMS would be a no-no 😁)
2. In RU you can just buy call records on the black market
bellingcat.com/news/uk-and-e…
Hey everyone👋,
Read my blog about "How I Got $10,000 From GitHub For Bypassing Filtration oF HTML tags". @GitHubSecurity
#bugbountytips #bugbounty #GitHub #cybersecurity
saajanbhujel.medium.com/how-…
This sort of methodology is very useful. Find something that talks HTTP, find the API endpoints, exploit
@[email protected] retweeted
Yup… every single time…
A year ago I would not have bothered attempting to get into an account with MFA, but last week I used this same technique and got 8 accounts in an org over 2 days on a remote SE test.
MFA is snake oil.
grahamcluley.com/ubers-hacke…
Always fabulous to see editors low the Windows Security level
When Citrix SSO is enabled... passwords are stored in *user processes* (in addition to system ones)
Ho yeah, *even if you have Credential Guard*
Yeah, that's what Citrix is calling "SSO"
> Will be in #mimikatz 3 🥝
So weird out of all the fancy places in London this ceremony happens outside what is now just a fancy shopping mall
Oh nice! This was a feature of Burp that I hadn't noticed was added
portswigger.net/research/bro…
Learn four of the most effective network relaying attacks against Windows domains. Defenders - learn how to mitigate against them! By Paul Finger.
labs.nettitude.com/blog/netw…
@[email protected] retweeted
This is something you should watch. These two individuals know more about scanning than a very large majority of Infosec combined. I would sit in DEFCON lines to see this talk.
Thurs Aug 25th, join us for "The Evolution of Network Scanning" w/ @nmap founder Gordon "Fyodor" Lyon and runZero & Metasploit founder @hdmoore , live on Youtube!
Register for a calendar invite & to receive the session recording: eventbrite.com/e/the-evoluti…