Victor vdH(@D0y0u3v3nl33t) 's Twitter Profileg
Victor vdH

@D0y0u3v3nl33t

Red team enthusiast, malware tinkerer and pentester

ID:1403710604418953217

calendar_today12-06-2021 13:47:56

339 Tweets

193 Followers

790 Following

Victor vdH(@D0y0u3v3nl33t) 's Twitter Profile Photo

Randomly had this idea to check changelogs of the vendor affected by my CVE from ~2.4 years ago. Can't see any s/w updates which reference a mitigation to the CVE.. If it's still not fixed that's pretty mad

account_circle
Adam Svoboda(@adamsvoboda) 's Twitter Profile Photo

Ever find yourself on an endpoint with SentinelOne and have Local Admin? Just ask SentinelAgent.exe nicely, and it will dump a process for you, including itself!

gist.github.com/adamsvoboda/8e…

It bombs out on LSASS, but most other processes work.

Ever find yourself on an endpoint with SentinelOne and have Local Admin? Just ask SentinelAgent.exe nicely, and it will dump a process for you, including itself! gist.github.com/adamsvoboda/8e… It bombs out on LSASS, but most other processes work.
account_circle
Antonio Cocomazzi(@splinter_code) 's Twitter Profile Photo

Do you want to start the RemoteRegistry service without Admin privileges?
Just write into the 'winreg' named pipe 👇

Do you want to start the RemoteRegistry service without Admin privileges? Just write into the 'winreg' named pipe 👇
account_circle
Kunal Thakrar(@Root_Kunal) 's Twitter Profile Photo

CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿 and I identified a couple of issues on Fujifilm and Xerox multi function printers which allows you to get encrypted credentials from the web interface (without authentication) and then decrypt them. Read about it here:

account_circle
SEKTOR7 Institute(@SEKTOR7net) 's Twitter Profile Photo

Bypassing Crowdstrike Falcon EDR hooks with targeted algo, decomposing agent's hooking logic.

Although extremely Falcon-specific, nevertheless good exercise for any maldev.

Great work, inbits!



inbits-sec.com/posts/in-memor…

account_circle
Aravind Srinivas(@AravSrinivas) 's Twitter Profile Photo

This actually happened to Evernote. They took the advice of “keep talking to your customers and ship whatever they want” as the only guiding principle for product development. And what ended up happening was paying users liked it, but the product become unintuitive and feature…

This actually happened to Evernote. They took the advice of “keep talking to your customers and ship whatever they want” as the only guiding principle for product development. And what ended up happening was paying users liked it, but the product become unintuitive and feature…
account_circle