Daniel Cid

2.7K posts

Daniel Cid banner
Daniel Cid

Daniel Cid

@danielcid

Founder of CleanBrowsing, Trunc, Sucuri, and OSSEC. Former VP, GoDaddy. Builder & breaker by heart. https://t.co/zTP7IAqAIO / https://t.co/fk6P2mJON2 / https://t.co/DvBxP9yQch Temecula,Big Bear

Canada انضم Şubat 2009
286 يتبع4.6K المتابعون
تغريدة مثبتة
Daniel Cid
Daniel Cid@danielcid·
My 7yo: "When I grow up, I want to be just like my daddy. He doesn't work and just spends his day at the computer doing nothing."
English
12
33
178
0
Daniel Cid أُعيد تغريده
Brasil Zero Grau
Brasil Zero Grau@BrasilZeroGrau·
🏂 Após bronze nos EUA, Priscila Cid é top 8 na Suíça e se despede de temporada no Snowboard Halfpipe com dois dos melhores resultados da carreira 🔗 Acesse o Brasil Zero Grau! brasilzerograu.com.br/2026/04/prisci…
Português
0
2
6
233
Daniel Cid
Daniel Cid@danielcid·
Pretty much every site on our network has been scanned and attempted to be exploited so far. If you didn't patch over the weekend, it might be safe to consider it compromised. First attempt I see on the logs was on: 2025-12-03 21:00:24 18.182.x.z 403 "POST /_next/static/chunks/react-flight HTTP/1.1" "-" "Mozilla/5.0 (CVE-2025-55182 PoC)" Before most people were even aware of it.
Daniel Cid@danielcid

One of the best explanations for CVE-2025-55182 / React2Shell. Recommended reading.

English
1
1
2
381
Daniel Cid
Daniel Cid@danielcid·
@leomarciano Your email seems to be bouncing. Do you have a different one?
English
1
0
1
61
Daniel Cid
Daniel Cid@danielcid·
@leomarciano Oh, what's going on? DM me here so I can investigate.
English
1
0
0
62
Daniel Cid
Daniel Cid@danielcid·
@riper81 Pretty cool project. Adding to my list of sites to use.
English
1
0
1
61
Daniel Cid
Daniel Cid@danielcid·
@0x6rss Pretty cool tool. Would be interesting to integrate with dnsarchive.net as well (if you want, can give you full access there).
English
1
0
15
985
Daniel Cid
Daniel Cid@danielcid·
@riper81 Yeah, same here... The interesting part was 4 days before the public disclosure.
English
0
0
1
26
Daniel Cid
Daniel Cid@danielcid·
Interesting.. First scan for CVE-2025-53771 (latest Sharepoint vuln) on our logs was on July 16th, a few days before public disclosure. 172.174.82.132 16/Jul/2025:07:31:10 +0000 "GET /_layouts/15/ToolPane.aspx HTTP/1.1" "http://localhost" "Mozilla/5.0" From a Microsoft IP address...
English
1
2
9
650
Daniel Cid أُعيد تغريده
Trunc Project
Trunc Project@logwithtrunc·
Have you noticed this "?slince_golden=test" requests on your logs? It is for a WordPress Backdoor. We wrote a small summary about it here: trunc.org/learning/slinc… Seeing it on your logs too?
English
0
3
4
333
Daniel Cid
Daniel Cid@danielcid·
We put up a list with the top domains (most visited) via our DNS intelligence: dnsarchive.net/top-domains top 100 top 1,000 top 10,000
English
1
0
2
190
Daniel Cid أُعيد تغريده
noc.org
noc.org@noc_org·
Have you looked at our DNS database? DNS Archive has over 200m domains, IP addresses and historical DNS data: dnsarchive.net
English
0
2
4
202
Daniel Cid
Daniel Cid@danielcid·
First thing I do on any of my new ubuntu servers: apt install net-tools Just so I can have my old ifconfig back.
English
0
0
2
209
Daniel Cid
Daniel Cid@danielcid·
Nothing more useful than searching through over 1TB of logs in less than a sec with the Trunc terminal for some threat hunting... Both via the terminal and web. It makes finding issues so quick.
Daniel Cid tweet mediaDaniel Cid tweet media
English
0
0
5
245