John Jiang

20 posts

John Jiang banner
John Jiang

John Jiang

@SecurityThunder

Researcher/UCCU Hacker Co-founder/HackerPeanutJohn

Taiwan 가입일 Ekim 2017
213 팔로잉78 팔로워
John Jiang 리트윗함
EZ
EZ@IAMERICAbooted·
Here's my top 20 weaknesses in M365 based on experience consulting. I've seen most of these everywhere in varying mixtures. Public groups has been a problem in all but one org I've worked with. 1. Public Groups expose sensitive data 2. Upload from unmanaged devices 3. Download from unmanaged devices 4. Lack of CAPs to block device code phishing 5. Lack of CAPs and configurations to mitigate AITM 6. OneDrive sync allowed from unmanaged devices 7. Ability to sync cloud storage to other 3rd party drives and vice versa 8. Anyone links in OneDrive and SharePoint 9. Legacy SharePoint IRM on sites and document libraries and Teams (classic) sites 10. Non-existant App Governance 11. Lack of governance or data security on Power Platform Connectors 12. Lack of license by request for Power Platform Apps 13. Teams apps sprawl 14. Anon users allowed to chat in Teams 15. Excessive API permissions in vendor apps 16. Ungoverned 3rd party AI 17. Lack of DLP on Microsoft Cloud Services 18. Lack of Safelinks in office365 apps aside from email 19. Lack of safe attachments in m365 apps outside email 20. Lack of phishing resistant authn
English
7
34
226
11.4K
%TEMP%
%TEMP%@TEMP43487580·
@SecurityThunder learned how to make a meme from your talk at Troopers😂
English
1
0
3
460
John Jiang 리트윗함
%TEMP%
%TEMP%@TEMP43487580·
I just started a new blog, and this is my first post. I took a bit of PTO, so this is a little record of some fun I had playing around with Intune during that time. It's about enrollment restriction bypass😄 temp43487580.github.io/intune/bypass-…
English
14
69
245
48.7K
John Jiang
John Jiang@SecurityThunder·
Just wrapped up our talk at DEF CON 33 ! Wandering around after my talk, and people are still coming up to recommend listening to our research! It's the greatest affirmation for a researcher. #DEFCON
John Jiang tweet media
English
0
0
1
215
John Jiang 리트윗함
Kazma
Kazma@kazma_tw·
First international talk — at @WEareTROOPERS ! Saw views from my history textbook, and met legends I used to only see on the internet.🫡 Big thanks to my best research partner, my mentor @SecurityThunder , and everyone who showed up to hype me up 🔥
Kazma tweet media
English
0
1
4
178
John Jiang 리트윗함
CyCraft Technology
CyCraft Technology@cycraft_corp·
We observed an attacker #VPN directly into an internal network to bypass preventive security & then create a digital skeleton key to gain admin access across the entire network. Is your #remotework force secure? Read our full analysis >> ow.ly/mKa950zgD2c
English
0
2
6
0
John Jiang 리트윗함
x0rz
x0rz@x0rz·
This is exactly why recovery from APT is difficult: they have multiple vantage points to get inside your network once they're in, lateral mouvement is deadly slideshare.net/FrodeHommedal/… by @FrodeHommedal
x0rz tweet media
English
3
100
167
0
John Jiang
John Jiang@SecurityThunder·
@maridegrazia Thx , I'll let you know when the translation is published.
English
0
0
0
0
John Jiang
John Jiang@SecurityThunder·
@maridegrazia It's awesome. May I translate the post to Traditional Chinese? I want share it with more people.
English
1
0
0
0