|
Avasdream
@
avasdream_
Fun Society Arcade,Coney Isl.
|
|
CS student, self-proclaimed human, programmer, infosec. #bugbounty Loves challenges like Vulnhub, Hackthebox, .Check out github.com/AvasDream
|
|
|
1.102
Tweetovi
|
490
Pratim
|
151
Osobe koje vas prate
|
| Tweetovi |
| Avasdream proslijedio/la je tweet | ||
|
pry0cc
@pry0cc
|
22 h |
|
Why do I never get any pentests with cookie-cutter vulnerabilities?
I have literally never done a pentest when I've found an RCE, exploited with Metasploit, and gotten a shell that way.
Literally NEVER happened to me.
|
||
|
|
||
|
Avasdream
@avasdream_
|
6 h |
|
Breaking News: The NSA got an exploit where they can hotmic any phone if the user unlocks it.
Downside: Does not work remotely twitter.com/marcusdipaola/…
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Jin Wook Kim
@wugeej
|
9 h |
|
CVE-2019-1388 Microsoft Windows UAC Privilege Escalation
Exploit Tool : HHUPD.exe (github.com/sv3nbeast/CVE-…)
Ref : github.com/Lz1y/imggo pic.twitter.com/cYAyqxSj9k
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Stephen "😭” Woods
@ysaw
|
4. velj |
|
I've worked professionally in software for 18 years and I can say with certainty that you should not use software for anything
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Saleem Rashid
@saleemrash1d
|
4. velj |
|
i've written a working exploit for sudo vulnerability CVE-2019-18634. if you have "Defaults pwfeedback" (apparently the default in Linux Mint and derivatives), any user can become root without any password, even if they're not in /etc/sudoers nvd.nist.gov/vuln/detail/CV…
|
||
|
|
||
|
Avasdream
@avasdream_
|
4. velj |
|
Hi @Comparis could you pls dm me a security contact. You got a pretty big security flaw in your website. I tried to reach out to you via email but you did not even respond. And maybe for the future implementing a security.txt would be awesome. securitytxt.org
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Yonathan Klijnsma
@ydklijnsma
|
3. velj |
|
To the person who figured out my honeypot is a honeypot could you please stop putting the picture of Pooh bear with a jar of honey on it?
Its like this person's life mission, I've blocked him on:
- Client
- IPs (now on Tor ffs)
- The image (he just edits 1 pixel every time...)
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
shubs
@infosec_au
|
2. velj |
|
This month I learnt how to analyse the JavaScript of a React Native application while bounty hunting. I wanted to share what I found out with everyone else.
blog.assetnote.io/bug-bounty/202…
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Abby Fuller
@abbyfuller
|
30. sij |
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Extremely Online Kat Cosgrove
@Dixie3Flatline
|
30. sij |
|
The CEO of a startup that claims to "change the way you meet people" is trying to cyberbully me but he's not very good at it. Going for the old "you're ugly" strategy. Gg bro, PS your beta signup is broken due to your lack of SSL.
|
||
|
|
||
|
Avasdream
@avasdream_
|
31. sij |
|
Terrafrom, because:
"All infrastructure as Code is equal, but some infrastructure as Code is more equal than others." pic.twitter.com/eFYIkVcJFD
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Chetan Puttagunta
@chetanp
|
31. sij |
|
Amazon AWS:
$40B revenue run-rate
Grew 34% annually
67% of Amazon's operating income
Microsoft Azure:
Est. $20B revenue run-rate
Grew 62% annually & accelerating
Tracking to be Microsoft's largest business soon
Remarkable. Two $1T companies are driven by cloud infrastructure.
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Ronen Shustin
@ronenshh
|
30. sij |
|
In the past year, I was researching Azure Stack, which is an on-premise version of Azure Cloud. In the following blog posts, we present information on what is Azure Stack and its architecture and disclose a vulnerability in Azure App Service that allowed a sandbox escape.
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Joona
@joohoi
|
29. sij |
|
We all love Burp suite by @PortSwigger , right? Want to send over all the ffuf job matches to Burp? Easy with -replay-proxy
ffuf -u example.org/FUZZ -w wordlist.txt -replay-proxy http://127.0.0.1:8080
If you ffuf on remote box, this totally works through ssh tunnels too!
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Jin Wook Kim
@wugeej
|
29. sij |
|
SQL Injection WAF bypass techniques
1.Nullbyte:
%00' UNION SELECT password FROM Users WHERE username-'tom'--
2. SQL Comments:
'/**/UN/**/ION/**/SEL/**/ECT/**/password/**/FR/OM/**/Users/**/WHE/**/RE/**/usersame/**/LIKE/**/'tom'--
incogbyte.github.io/sqli_waf_bypas…
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Web Security Academy
@WebSecAcademy
|
28. sij |
|
Check out our new page on escaping the AngularJS sandbox, including new vulnerability labs.
portswigger.net/web-security/c…
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Jan Schaumann
@jschauma
|
28. sij |
|
How I think containers work. pic.twitter.com/823bBoYUTQ
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Igal Tabachnik
@hmemcpy
|
28. sij |
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
daniel@tindall:~#
@ImpetuousDanny
|
28. sij |
|
Great article on attacking Kerberos from Linux twitter.com/CalumBoal/stat…
|
||
|
|
||
| Avasdream proslijedio/la je tweet | ||
|
Shodan
@shodanhq
|
27. sij |
|
A map of Citrix devices that are vulnerable to CVE-2019-19781 pic.twitter.com/38z83Hu4X0
|
||
|
|
||