rm - rf

1.1K posts

rm - rf banner
rm - rf

rm - rf

@56bit

Security enthusiast/#solorider /Fitness /Traveler/ Vasudhaiva Kutumbakam/#OneGod/#Yogi/ #InfoSec /Not the view of my employer.

Down at God's feet Se unió Temmuz 2010
501 Siguiendo190 Seguidores
rm - rf retuiteado
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114 by @rapid7 rapid7.com/blog/post/tr-c…
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
Florian Roth ⚡️@cyb3rops

This is bad. Putty level bad. notepad-plus-plus.org/news/hijacked-…

English
33
548
2.2K
417.5K
rm - rf retuiteado
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Someone going by "wwwiesel" on GitHub picked up @securitymeta_’s tradition this year and dropped a full list of #BlackFriday deals in the #InfoSec space Online Courses & Training - 8kSec Academy - AI Security Professional Course - Altered Security - Belkasoft - Blu Raven Academy - Career Hacking Quest - CloudBreach - Cyber Plumber's Lab - CyberWarFare Labs - DevSecOps Pro - DNS for Developers - Evilginx Mastery - Hack The Box Pro Labs - HackSmarter - HackTricks Training - Hexordia - Invictus IR Academy - Invictus CloudLabs - LetsDefend - Mobile Hacking Lab - OffSec Learn One - OPSWAT Academy - Pluralsight - Practical DevSecOps - Practical TLS - http://pwn[.]guide - CyberNow (SOC Analyst) - TCM Academy - TheXero - Vantage Point / Enciphers - White Knight Labs - WiFiChallenge Academy - ZeroPoint Security Exams - The SecOps Group Mini Courses - SecDim Books - The CloudSec Engineer Hardware - Hak5 - KSEC Labs Professional Services - Wortell Tools - Burp Bounty Pro - Burp Bounty Go - FullStro - Grammarly Pro - PortDroid - Proton Mail / VPN / Pass / Drive - HTTP Toolkit - http://SEOengine[.]ai - SubtitleBee - WebsiteVoice Services - Grayhat Warfare - AirVPN - CyberGhost VPN - Proton (second listing in file) - NordVPN - Tuta Mail - InMotion Hosting - IPVanish VPN Misc - Neato Stickers URL: github.com/wwwiesel/InfoS…
English
9
122
564
65.5K
rm - rf retuiteado
Nozomi 🍂
Nozomi 🍂@NozomiCodes·
Naval Ravikant: Everyone can be rich.
English
65
693
6K
94.7K
rm - rf retuiteado
Neo Kim
Neo Kim@systemdesignone·
If you want to become a world-class software engineer (in 6 months), read these 12 books:
English
52
538
3.9K
514.7K
rm - rf retuiteado
Traceix
Traceix@usetraceix·
Today we are releasing our FREE educational course: "Intro to Exploit Dev"! This course is perfect for those trying to start exploit dev and covers: - Tooling - Fuzzing - Exploitation techniques - And more! You can take the course here: bible.malcore.io/readme/the-beg…
Traceix tweet media
English
21
183
603
47.2K
rm - rf retuiteado
Moonlock Lab
Moonlock Lab@moonlock_lab·
Moonlock 2024 macOS Threat Report is here! 🧠AI-powered malware makes advanced attacks accessible to anyone. 💻 Malware-as-a-Service starts at $1,500/month. 📈 Stealer malware surges, targeting Keychain & crypto wallets. Dive into the full report: moonlock.com/moonlock-2024-…
English
0
15
35
10.8K
rm - rf retuiteado
nyxgeek
nyxgeek@nyxgeek·
IP addresses can also be represented as numbers in decimal, hexadecimal, or octal. This is not new information, but it's neat.
nyxgeek tweet media
English
76
236
3.5K
203.7K
rm - rf retuiteado
Alessandro Di Carlo
Alessandro Di Carlo@samaritan_o·
🚨 #DFIRtips 🚨 Today, during an investigation, I found a registry key that proved to be extremely useful in identifying the execution of a malicious executable: HeapLeakDetection! You can find it in the Software hive, specifically at HKLM\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications. This registry key is interesting because its subkeys refer to all the executables that have been detected by RADAR technology for real-time memory leak detection. Each subkey has its own LastDetectionTime which tells us the last time a memory leak occurred and which executable was affected. Even though it is not particularly well-known, this artifact could sometimes turn your investigation around, especially when the threat actor tries to erase their tracks by deleting the most common artifacts (Prefetch files, evtx logs, etc.) [screenshots from my test machine]
Alessandro Di Carlo tweet mediaAlessandro Di Carlo tweet media
English
6
97
404
54.3K
rm - rf retuiteado
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
Anyone have anonymous stories about foreign fake employee WfH/VPN fraud and how it was detected?
English
59
62
908
198.3K
rm - rf retuiteado
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confus… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code from 1996
English
37
650
1.8K
214.2K
rm - rf
rm - rf@56bit·
@greathorn at least you should acknowledge the downtime and share it on whatever platform that works for you.
English
0
0
0
21
Keane Grivich
Keane Grivich@kgrivich·
@SJFriedl @greathorn I spoke with one of their engineers. They are having a problem with their DNS record and are working to resolve. The backend looks like it's still working. Their DNS record changed last night I see. I'm wondering if they lost control of their domain...
English
2
0
0
64
Steve Friedl
Steve Friedl@SJFriedl·
A customer of mine uses @Greathorn for email security, but their domain stopped working today, the office goes right to voicemail, and they aren't responding on Twitter. It seems odd that they are so firmly down but I can't find anybody talking about it.
English
2
0
3
206
rm - rf retuiteado
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
Hey, hackers! 👋🏻 I hope this note is bookmarked on your belt! It contains awesome pdfs including: - Red team Operations - Reverse engineering content - Red Team x Blue team - Practical social engineering - Windows Privilege escalation - AD, & Road to OSCP - JR to Specialist career - Many Offsec notes - & Many more Thanks to Joas A Santos drive.google.com/drive/mobile/f… (I recommend you to follow his profile on Linkedin) #cybersecurity #Pentesting #Hacking #bugbountytips #infosec #cybersecuritytips #redteam #coding #100DaysOfHacking #vulnerabilities #BugBounty #100DaysOfCyberSecurity #CyberSecurityAwareness
7h3h4ckv157 tweet media
English
9
404
1.3K
135.6K
rm - rf retuiteado
Mike Takahashi
Mike Takahashi@TakSec·
Google Dork - File Upload 📁 (site:example[.]com | site:example[.]org) & intext:"choose file”
Mike Takahashi tweet mediaMike Takahashi tweet media
English
5
115
590
52.5K