ᅟ 리트윗함
ᅟ
821 posts

ᅟ
@_harleo
tl;dr hacker / infosec analyst & researcher. mostly lurking.
0.0.0.0/0 가입일 Ekim 2017
681 팔로잉330 팔로워
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English

@pentest_swissky @mod0 Thanks for sharing! Still perplexed at how Synology handled this. This could have been devastating.
English
ᅟ 리트윗함

When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365 - @mod0 / @_harleo
modzero.com/en/blog/when-b…
English
ᅟ 리트윗함
ᅟ 리트윗함
ᅟ 리트윗함




























