|
Rohit Mothe
@
rohitwas
Portland, OR
|
|
Security Resea____ , Part Time Janitor. Tweets/Replies/Retweets/Likes entirely my own doing/undoing
|
|
|
595
Tweetovi
|
138
Pratim
|
523
Osobe koje vas prate
|
| Tweetovi |
| Rohit Mothe proslijedio/la je tweet | ||
|
Vector 35
@vector35
|
4. velj |
|
1.3 is out! (binary.ninja/2020/02/03/1.3…) lots of features from dev landing on stable.
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Spring Training Dustin
@dustin_childs
|
17. sij |
|
No fix yet, but #Microsoft released an advisory for active attacks in #IE. Restrict access to JScript.dll as a workaround. Hurray for Friday afternoon releases. portal.msrc.microsoft.com/en-US/security…
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
17. sij |
|
potentially ^
haven’t tested out the TLS vector yet
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
17. sij |
|
Yeah, I do remember some article also mentioning the serial match requirement. But I was just able to spoof a valid code sign certificate and the serial definitely doesn't match with the root cert
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
17. sij |
|
Maybe I'm missing something but based on my tests it seems that even the serial doesn't need to be the same? Just a public key match seems enough to trigger it
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
ϻг_ϻε
@steventseeley
|
14. sij |
|
I'm excited to share my post about discovering & exploiting multiple critical vulnerabilities in Cisco's DCNM.
Busting Cisco's Beans :: Hardcoding Your Way to Hell srcincite.io/blog/2020/01/1…
PoC exploit code:
srcincite.io/pocs/cve-2019-…
srcincite.io/pocs/cve-2019-…
srcincite.io/pocs/cve-2019-…
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
7. sij |
|
🎶"I'm so f***in' sick and tired of the CVE-shop
Show me somethin' natural like full-poc on github
Show me somethin' natural like a researcher without some verified check marks"🎶
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
iDefense
@iDefense
|
7. sij |
|
We are excited to join forces with the Symantec DeepSight cyber threat intelligence and incident response teams and MSS team! Welcome to the @AccentureSecure family! #CTI #IncidentResponse #ManagedSecurity accntu.re/2sWauc6 pic.twitter.com/4GJgref60E
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
7. sij |
|
Last 2 minutes of my twenties ... :|
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Siguza
@s1guza
|
7. sij |
|
New blog post. ARM hardware bug. In the specification.
siguza.github.io/PAN/
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Pedram Amini
@pedramamini
|
31. pro |
|
Second SHA1 hash collision found, how neat! privacylog.blogspot.com/2019/12/the-se… pic.twitter.com/NiCqOziahs
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Vector 35
@vector35
|
18. pro |
|
Looking to start 2020 off on a good foot by taking time to improve yourself? The most knowledgable Binary Ninja expert outside V35 is teaching his highly regarded course Jan 20-23: eventbrite.com/e/automated-re…
|
||
|
|
||
|
Rohit Mothe
@rohitwas
|
14. pro |
|
congrats man! :)
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Rodrigo Branco
@bsdaemon
|
14. pro |
|
Today was my last day going to the office at Intel (I will still be available for my team til the end of the month). Soon I will talk about the next steps! Sad to leave the amazing @IntelSTORMTeam behind, but excited with the new challenges ahead.
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
jonathan Afek
@JonathanAfek
|
4. pro |
|
It was an honor to present our research at #BHEU. Thanks everyone for attending. It was a pleasure to see the interest of the community and we promise to keep the progress going. For everyone who missed the talk: alephsecurity.com/2019/06/25/xnu… pic.twitter.com/r3UiYi5QMr
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Shellphish
@shellphish
|
2. pro |
|
Full source code for our USENIX Security paper, which passed the first-ever USENIX Sec Artifact Eval, and found some cool CVEs, is available here: github.com/ucsb-seclab/ha… #RehostReuseRecycle #ArtiFactual #NeverSkipARMDay
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Calle Svensson
@ZetaTwo
|
28. stu |
|
We are less than 48 hours away from the 10th episode of Pwny Racing! Bookmark the stream: youtube.com/watch?v=6wmyaY…, set a reminder and be there when the live #CTF 4-way action goes down with my co-host and pwnsmith @0xb0bb and myself to guide you through the action!
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
m0n0sapiens
@m0n0sapiens
|
29. stu |
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Daniel Hückmann
@sanitybit
|
26. stu |
|
Do you know someone looking to make the jump to information security in Portland Oregon? Have a great team and excellent manager looking to hire a Jr. SOC analyst; can give a direct referral. DMs open.
#informationsecurity #jobs #infosec
|
||
|
|
||
| Rohit Mothe proslijedio/la je tweet | ||
|
Vector 35
@vector35
|
20. stu |
|
If you didn't watch Josh's stream live, make sure to subscribe to his YT (youtube.com/user/Swarlemag…). Yesterday's stream was great. He built a binary diffing prototype in two hours! twitter.com/josh_watson/st…
|
||
|
|
||