EBENEZER ADU-BITHERMAN

34 posts

EBENEZER ADU-BITHERMAN banner
EBENEZER ADU-BITHERMAN

EBENEZER ADU-BITHERMAN

@focus_furry

Cybersecurity Professional & Pentester. Focused on offensive security,CTF player, and training the next generation of security experts.

Accra, Ghana Beigetreten Mayıs 2026
12 Folgt964 Follower
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
From null session to AS-REP roast from scratch — unauthenticated guest access → RID brute-force → parsed AD user list → LDAP preauth targeting → domain hashes harvested ​This is what weak default permissions + missing Kerberos preauth look like in the real world.
English
0
4
15
3K
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
Beyond automated tools, true research demands patience. Take Wireshark—mastering packet analysis requires deep, manual filtering through network noise. Or Burp Suite—where tweaking requests and hunting logic flaws is a patient, iterative process.
English
1
3
16
677
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
Ever wondered how a network is brought to its knees? 📉 DHCP Starvation is a DoS technique where an attacker floods a server with spoofed requests to exhaust the IP pool. ​This creates a vacuum where nobody will be able to connect to the network.@elormkdaniel @RedHatPentester
English
0
6
33
1.6K
Kereste
Kereste@apoyusikenturk_·
@focus_furry Found sql vulnerabilities on many different websites using Zap, but its not working
English
1
0
1
35
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
Burp Suite vs. ZAP? 🛡️ Burp Suite is the gold standard for deep manual testing & OAST. ZAP is a powerhouse for automation, scripting, and CI/CD integration. The best pros use both: ZAP for the scan, Burp for the exploit. BUT I LOVE ZAP
EBENEZER ADU-BITHERMAN tweet mediaEBENEZER ADU-BITHERMAN tweet media
English
1
1
18
1.3K
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
NetHunter = limited by phone hardware & needs root. 📱❌ SSH + ngrok = full power of your rig, remotely. 💻🔥 I prefer the remote workflow for my terminal sessions —way more stable for complex tasks. Why settle for mobile limits? 🛡️ @RedHatPentester @elormkdaniel
EBENEZER ADU-BITHERMAN tweet mediaEBENEZER ADU-BITHERMAN tweet media
English
2
0
16
771
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
REST makes you beg for data in multiple trips. GraphQL lets you ask for everything in one. 💚 REST: server decides what you get 🟣 GraphQL: YOU decide what you get Not hype — just the right tool for the right job.@elormkdaniel @RedHatPentester
EBENEZER ADU-BITHERMAN tweet media
English
0
4
10
522
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
Building a CMS is easy. Securing it is the real game.The core framework rarely fails; it’s the sprawling third-party plugin ecosystem that’s a goldmine for bugs. One unpatched add-on can trigger privilege escalation or IDOR. @RedHatPentester @elormkdaniel
EBENEZER ADU-BITHERMAN tweet media
English
0
1
18
623
EBENEZER ADU-BITHERMAN
EBENEZER ADU-BITHERMAN@focus_furry·
Ever find a ForceChangePassword edge in BloodHound? ​It's a direct path to account takeover. Use net rpc password to reset the target's credentials and gain immediate access to their shares and privileges. Always map your attack vectors and check those ACLs!
English
1
9
23
1.5K
EBENEZER ADU-BITHERMAN retweetet
Elorm Daniel
Elorm Daniel@elormkdaniel·
How to turn your Phone into a Hacking Machine
English
2
27
107
3.7K
EBENEZER ADU-BITHERMAN retweetet
Nana Sei Anyemedu
Nana Sei Anyemedu@RedHatPentester·
NITA is an Agency and not an Authority. I took my time to read about them very well. What they planning to do falls under the powers of an authority. NITA is the agency responsible for implementing Ghana's IT policies. Its mandate includes identifying, promoting and developing innovative technologies. NITA plays a significant national role, its structure and mandate fit more within an implementation/coordination agency than an independent regulatory authority. It does not function as a fully independent national regulator with broad enforcement powers across the ICT sector in the same way an authority typically would. For example, a true authority often has powers to: a. independently regulate an industry, b. issue mandatory licenses, c. enforce compliance, d. impose sanctions or penalties, e. conduct formal investigations, f. operate with stronger statutory independence. This doesn’t fall into the powers of NITA but then they want to execute it. If laws work very well, NITA sef won’t get away. So the question is; why does an agency want to execute the powers of an authority and who is backing them do this? Charley we are tired😂😂.
English
11
65
153
5.8K
EBENEZER ADU-BITHERMAN retweetet
EBENEZER ADU-BITHERMAN retweetet
Elorm Daniel
Elorm Daniel@elormkdaniel·
Not sure what Cyber Security includes: This one image explains all
Elorm Daniel tweet media
English
0
12
55
1.5K
EBENEZER ADU-BITHERMAN retweetet
Nana Sei Anyemedu
Nana Sei Anyemedu@RedHatPentester·
Are you aware ECG was attacked with ransomware few years ago? The ransomware incident involving ECG a few years ago served as a critical wake-up call, highlighting the need to strengthen the national cybersecurity ecosystem. However, the organization responsible for handling the response did not release a public report detailing the incident. And also after rectifying the issue everybody go bed😂 While confidentiality agreements and operational sensitivities may limit disclosure, a basic level of transparency could have helped improve public awareness and trust. We have long way to go🤦🏾‍♂️🤦🏾‍♂️
English
8
39
131
4.6K
EBENEZER ADU-BITHERMAN retweetet
Nana Sei Anyemedu
Nana Sei Anyemedu@RedHatPentester·
SINDEL: SINDEL Shadow Intelligence Network & Data Extraction Laboratory Years ago, an IDOR vulnerability earned me my 3rd major bug bounty. Last year, I built an entire lab around it. SINDEL focuses exclusively on Insecure Direct Object Reference (IDOR) vulnerabilities, covering all 10 recognised IDOR attack categories across 18 unique endpoints. All 18 flags were captured across every difficulty level. The most advanced challenges involve hashed identifier IDORs and token-based IDORs, requiring deeper knowledge of cryptographic weaknesses and enumeration techniques beyond simple ID incrementing. Link: github.com/RedHatPenteste…
Nana Sei Anyemedu tweet mediaNana Sei Anyemedu tweet media
English
5
28
116
7.9K