odyssey

4.6K posts

odyssey banner
odyssey

odyssey

@CFCOdyssey

part time sec enjoyer

Katılım Ağustos 2020
1.4K Takip Edilen69 Takipçiler
Sabitlenmiş Tweet
odyssey
odyssey@CFCOdyssey·
odyssey tweet mediaodyssey tweet media
ZXX
0
0
6
520
odyssey
odyssey@CFCOdyssey·
Straight gas…none of this woke bullshit
English
0
0
0
5
odyssey retweetledi
vx-underground
vx-underground@vxunderground·
Good news everyone Shai-Hulud, that spoopy Git worm thingy everyones been yapping about, has been open-sourced. What does this mean? TeamPCP, or someone else, has released the fully weaponized worm for you. github.com/hmoreirar/Shai…
English
74
228
2.1K
224.7K
CFCDaily
CFCDaily@CFCDaily·
🚨JUST IN: Xabi Alonso has emerged as the front-runner for the Chelsea job in a move that indicates the club are willing to cede more power to the manager over recruitment. [@MsiDouglas] inews.co.uk/sport/football…
English
112
401
4.5K
448.2K
odyssey retweetledi
Craig Hope
Craig Hope@CraigHope_DM·
🚨 EXCLUSIVE: Spygate 2.0! 🕵️‍♂️ Middlesbrough catch suspected Southampton 1st-team analyst hiding in bushes at training ground! 👇 Full details 👇 dailymail.com/sport/football…
English
162
520
3.9K
1.6M
odyssey
odyssey@CFCOdyssey·
@gammaroneus @sith_lord_bane @vxunderground Procdump runs on my security context (CU) - which is trusted the same as Edge, so it can open it with PROCESS_VM_READ and read memory via normal APIs. But in enterprise world it would be like SOC Christmas if someone dumps memory.
English
0
0
1
25
vx-underground
vx-underground@vxunderground·
The initial proof-of-concept was released in C-sharp. Using this method to dump credentials is iffy because it requires administrative access and some security access tokens which can raise some flags. First, Edge is Chromium based. This is a Chromium thing but (if my memory serves me correctly) a unique attribute to Edge exclusively. However, because it is Chromium based this may impact other Chromium bases. It requires more investigation. Edge is a primary target because it's the default Windows browser and used in enterprise environments. Secondly, as far as malware goes, this is yet another method to potentially dump credentials on a home users machine. There are a few different ways. This method doesn't surprise me. However, successfully using this method is an enterprise environment would be difficult to use. It would require administrative access and some security access tokens which would immediately raise some flags. In other words, this method is interesting, I like the research performed, however it isn't something super super critical. If you're using this method in an enterprise environment then that company has been completely compromised down to the bone and they've got much larger issues. The code and research is really cool though. I just wish it wasn't written in C-sharp (I have an irrational disdain to .NET, especially lately).
International Cyber Digest@IntCyberDigest

‼️🚨 Microsoft calls this "intended behaviour," so here we go. How to dump the credentials of every user stored in Microsoft Edge: 1. Open Edge. Don't browse anywhere, just open it. 2. Flip to Task Manager, find Edge, expand the task. 3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump." 4. Open the dump file and look for credentials. The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking. Thanks to Rob VandenBrink at SANS: isc.sans.edu/diary/32954

English
37
69
814
83.7K
Ondřej
Ondřej@gammaroneus·
@sith_lord_bane @vxunderground Right, but that's task manager, malware would need to do it itself and to do that, it would require admin rights I guess that's how I understand it
English
1
0
0
80
odyssey retweetledi
mary ✧
mary ✧@marydocharlito·
mary ✧ tweet media
ZXX
4
800
3K
28.3K
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
NVIDIA's GeForce got owned by Shiny Hunters.
H4x0r.DZ 🇰🇵 tweet media
English
20
54
491
54.4K
Lippy
Lippy@LickshotLippy·
They’ve got down Manny. When I saw the dm I got gassed, I thought I was playing in one of those matches
Lippy tweet media
English
7
4
966
123.2K
odyssey retweetledi
ThePrimeagen
ThePrimeagen@ThePrimeagen·
It's beginning to look a lot like Christmas
ThePrimeagen tweet media
English
110
183
6.3K
119.8K
Saeed TV
Saeed TV@SaeedTV_·
I miss last night already.
English
77
117
2K
111K
odyssey retweetledi
Tom's Hardware
Tom's Hardware@tomshardware·
PS5 Linux loader goes public, turning ‘Phat’ consoles into full Linux PCs — build script includes bootable Ubuntu 24.04 image, can output 4K games at 60 FPS tomshardware.com/software/linux…
English
54
361
2.4K
163.5K
odyssey retweetledi
Tony/Humpty
Tony/Humpty@cyb3rjerry·
NPM packages mbt@1.2.48 and @\cap-js@2.2.2 got popped chat
Tony/Humpty tweet media
English
9
80
631
33.2K
odyssey retweetledi
Pys
Pys@CFCPys·
Tosin, Trev and GarNeto. Strap in folks.
English
118
214
3.1K
86K