Gleb Gritsai

1.3K posts

Gleb Gritsai

Gleb Gritsai

@repdet

参加日 Eylül 2009
222 フォロー中440 フォロワー
Gleb Gritsai がリツイート
0xDesigner
0xDesigner@0xDesigner·
5/
GIF
84
1.2K
40.3K
2.2M
Gleb Gritsai がリツイート
Josh Kamdjou
Josh Kamdjou@jkamdjou·
This works on Windows 11 and both Gmail and MSFT will let it through to the inbox. Confirmed by @amitchell516 and @samkscholten New detection/hunt rule is live for this, which looks for UNC paths inside URL file attachments (h/t @amitchell516!): github.com/sublime-securi…
Josh Kamdjou tweet media
David. 🏴󠁧󠁢󠁳󠁣󠁴󠁿@fuzz_sh

@awakecoding .url is great. The file doesn't even need to be opened, if you can get a user to download it and they go to delete it, just opening the Downloads folder sends the hash :D

English
2
56
112
42K
Gleb Gritsai がリツイート
Georgi Gerganov
Georgi Gerganov@ggerganov·
You still need to "train" it on the specific keyboard and you need to have sort of "ideal" conditions, but yeah -- it's a fun tool :) Give it a try if you have a mechanical keyboard. There are examples you can run directly in your browser via WASM
f4mi ‼️@f4micom

github.com/ggerganov/kbd-… this tool lets you extract text from an audio recording of keyboard strokes, right now, for free i am not making this shit up, you can potentially steal a password from an audio recording in an office

English
2
15
181
46.6K
Gleb Gritsai がリツイート
Zion Leonahenahe Basque
Zion Leonahenahe Basque@mahal0z·
I'd like to publicly introduce BinSync, a cross-decompiler collaboration tool and suite. With BinSync, you can finally share reversing data, like Types, across all your favorite decompilers (IDA, Binja, Ghidra, angr) on-the-fly. github.com/binsync/binsync. See thread for demos.
English
4
83
262
31.7K
Gleb Gritsai がリツイート
Prof. Feynman
Prof. Feynman@ProfFeynman·
There are two rules in life: 1) Never give out all the information.
English
339
3.8K
25.7K
3.6M
Gleb Gritsai がリツイート
IAM!ERICA
IAM!ERICA@EricaZelic·
🧵Some of my favorite LDAP queries. I let you all infer which tools to use them with. Most of these are from places around the web, nothing new. Just a list. 1. Find all DCs: (&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))
English
8
112
455
65.1K
Gleb Gritsai がリツイート
Nicolas Krassas
Nicolas Krassas@Dinosn·
Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes github.com/Ciphey/Ciphey
English
19
254
928
118.5K
Gleb Gritsai がリツイート
MDSec
MDSec@MDSecLabs·
We've just published a quick write up on CVE-2023-23397, which allows a remote adversary to leak NetNTLMv2 hashes: mdsec.co.uk/2023/03/exploi… by @domchell
MDSec tweet media
English
9
410
816
302.7K
Gleb Gritsai がリツイート
Beau
Beau@wirebytes·
Zero Trust is a security strategy. It is not a product or a service, but an approach in designing and implementing the following set of security principles: - Verify explicitly - Use least privilege access - Assume breach Updated Information here: lnkd.in/g5UmGgEm
Beau tweet media
English
0
18
62
3.8K
Gleb Gritsai がリツイート
Grzegorz Tworek
Grzegorz Tworek@0gtweet·
Need an almost invisible, post-exploitation, persistent, fileless, LPE backdoor? There are many, but this one looks really beautiful for me: type "sc.exe sdset scmanager D:(A;;KA;;;WD)" from an elevated command prompt.
Grzegorz Tworek tweet media
English
39
367
1.3K
302.4K
Gleb Gritsai がリツイート
Timur Yunusov
Timur Yunusov@a66ot·
Check out the latest articles from the Payment Village blog paymentvillage.org/blog : 1. How I used deepfakes to bypass security verifications in a bank. My first experience with hacking ongoing due diligence checks using deepfake and ML.
English
0
6
10
2.5K
Gleb Gritsai がリツイート
Adam Sawicki
Adam Sawicki@Reg__·
"Hello World under the microscope" - an article we wrote together with @gynvael and @j00ru! Originally published in issue 100 (1/2022) of the Programista magazine, now available online in Polish and English. asawicki.info/articles/Hello…
English
2
64
264
0