|
Michael Kruger
@
_cablethief
South Africa
|
|
Security analyst at @SensePost.
Random code bits at github.com/Cablethief/
|
|
|
28
Tweetovi
|
170
Pratim
|
265
Osobe koje vas prate
|
| Tweetovi |
|
Michael Kruger
@_cablethief
|
24. pro |
|
Yay got a blackhat asia talk accepted :D. blackhat.com/asia-20/briefi…
|
||
|
|
||
| Michael Kruger proslijedio/la je tweet | ||
|
Dominic White
@singe
|
5. pro |
|
I’ve been waiting for this for most of the year. Craig Koorn built a BloodHound for AWS IAM & related elements. Which finally just got a public release. Hugely useful for securing your AWS environments. github.com/FSecureLABS/aw… cc @0xdabbad00
|
||
|
|
||
| Michael Kruger proslijedio/la je tweet | ||
|
Ion Todd
@IonTodd
|
5. pro |
|
My close personal friend has been working on a tool to more accurately visualise effective access within AWS. We've found awspx to be really useful internally, we hope you do too. labs.f-secure.com/tools/awspx/
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
15. stu |
|
It's a single Auth for all your services using it, rather than basic Auth for each time you use a service.
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
14. stu |
|
The very beta thing I did is over here: github.com/Cablethief/Sim…, Ill probably move to yours tho and archive this one.
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
25. srp |
|
Published a little write up on the wpa_sycophant tool I created for relaying PEAP last year.
sensepost.com/blog/2019/peap…
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
23. srp |
|
Woops, add a "--network host" to that else you try connect to your containers network without a port forward.
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
23. srp |
|
Colleague needs to build and run a docker container while using capped internet. I suggested he build and run his docker on a jump box to save bandwidth. XD
Dockerless docker. pic.twitter.com/PuVBZxTb3y
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
19. srp |
|
Pretty cool episode from @Freakonomics, I didn't realise that girl scouts had a cyber security badge :D
freakonomics.com/podcast/girl-s…
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
19. lip |
|
Made a docker for doing SSH tunneling rather than setting up a new sshd and config every time. "Tried" to make it secure as well so you don't get pwned back if someone tries to log into you.
hub.docker.com/r/cablethief/s…
|
||
|
|
||
| Michael Kruger proslijedio/la je tweet | ||
|
mitt (alive)
@housetrotter
|
22. svi |
|
we are absolutely getting 5g and it is absolutely going to kill people grist.org/article/5g-net… pic.twitter.com/OZf7KBEZNd
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
23. svi |
|
This is what I used to do :D. But this is so much more convenient.
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
23. svi |
|
For a once off:
sudo sysctl net.ipv4.ip_unprivileged_port_start=0
For permanence add to sysctl.d config:
sudo vim /etc/sysctl.d/allow_user_lower_ports.conf and add net.ipv4.ip_unprivileged_port_start=0
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
23. svi |
|
Apparently well known, but in case you don't know, Linux provides a way to disable the privileged nature of sub 1024 ports. This allows you to run listeners, services, etc on sub 1024 ports without root/sudo. For a single user system where I spin up random services its perfect. pic.twitter.com/rj2xCfoLm3
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
21. svi |
|
Most of the hard work is from github.com/oblique/create… :D
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
21. svi |
|
Created a small script to toggle unmanage interfaces (And reloads NetworkManagers config) so that NetworkManager is less annoying when its your turn with the interface.
github.com/Cablethief/Net… pic.twitter.com/50cnivVNrN
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
20. svi |
|
Updated berate_ap with support for wpa_sycophant to make wireless relaying a bit easier.
Some other new things are adding the certificate subj in command by @R4g3D_, some WPA attack flags, Mana taxonomy, and coloured Mana output. :D
github.com/sensepost/bera…
github.com/sensepost/wpa_…
|
||
|
|
||
|
Michael Kruger
@_cablethief
|
29. tra |
|
Two simple scripts and an explanation for sharing internet with a interface and creating a quick RADIUS server using hostapd-mana. gist.github.com/Cablethief/9b7…
I am torn on whether this should be a gist or a git /:
|
||
|
|
||
| Michael Kruger proslijedio/la je tweet | ||
|
Dominic White
@singe
|
11. tra |
|
Yeah! I'm really honoured to be offering our brand new Wi-Fi hacking course @_ringzer0 at The Excaliber in Vegas on 3-6 Aug 2019. If Wi-Fi isn't your thing, check out the badass courses from the other trainers. twitter.com/sensepost/stat…
|
||
|
|
||
| Michael Kruger proslijedio/la je tweet | ||
|
Dominic White
@singe
|
26. velj |
|
If you want to extract the certificates used in EAP (TLS/PEAP/TTLS etc.) interaction, you can use this gist.github.com/singe/40bda2a1…
Useful for closing them with github.com/sensepost/apos… especially when going after macOS/iOS clients (who will present the cert details & ask the user). twitter.com/MarkRaatsWiFi/…
|
||
|
|
||