Infosec House

162 posts

Infosec House banner
Infosec House

Infosec House

@InfosecHouse

Tools & Resources for Cyber Security Operations. | Admin @Lyphtur

Katılım Aralık 2016
20 Takip Edilen1K Takipçiler
Sabitlenmiş Tweet
Infosec House
Infosec House@InfosecHouse·
I’ve been getting tagged by @redbubble creators regarding takedowns of their artwork. It seems the word/term “infosec” is getting flagged and taken down with my name as the IP owner. This is false. Please speak with @InfosecEdu infosecinstitute.com/trademarks/
English
0
0
1
745
Intigriti
Intigriti@intigriti·
Getting started in mobile hacking? 😎 Check out Medusa by @Ch0pin! A framework to help you pentest Android & iOS mobile applications! 🔗 github.com/Ch0pin/medusa
Intigriti tweet media
English
5
52
260
16.1K
Infosec House retweetledi
sw33tLie
sw33tLie@sw33tLie·
I've recently put more work into my ffuf fork, uff, and I think every ffuf user should at least give it a try - and maybe even switch to it. Here's why, in a #bugbounty 🧵
sw33tLie tweet media
English
12
76
471
55.7K
sysxplore
sysxplore@sysxplore·
Stop distro hopping! just use Ubuntu.
sysxplore tweet media
English
169
50
883
49.3K
Infosec House
Infosec House@InfosecHouse·
@theluemmel Nope but you did just uncover a tool we are missing on our site! Will get to adding this one! Appreciate it! 🤙
English
0
0
1
120
Infosec House
Infosec House@InfosecHouse·
@NahamSec What I can say is, you show the things that most courses never teach us but stop pumping self help. Appreciate it Top 0xG! 😂
English
0
0
1
161
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
There are two types of people in my comments section:
Ben Sadeghipour tweet media
English
17
6
147
11.6K
Infosec House
Infosec House@InfosecHouse·
@intigriti 👀 Looks like a new tool we can add to the site. Thanks for sharing!
English
0
0
2
193
Infosec House
Infosec House@InfosecHouse·
@fr0gger_ This is awesome going to add your site to our tool/resources! 🤙
English
0
0
1
162
Thomas Roccia 🤘
Thomas Roccia 🤘@fr0gger_·
🤓 A friend of mine shared me an article published today about a clever and interesting concept called LargeLanguageC2. Let me break it down simply 👇 It is a steganographic Command & Control channel that hides commands inside natural language text. Here’s how it works: 👾 Encoding: Each byte becomes two parts. One picks a word, the other repeats it. Filler words make it look natural. 🛸 Decoding: The 13th word gives part of the byte. The 14th word’s repetition gives the rest. 👽 Execution: The server decodes, runs the command, and replies using the same trick. The author claim there is currently no detection. No YARA. No security product to catch this pattern. Until now. 🤓 I reviewed the POC and spotted several detection opportunities: ・Unnatural repetition of specific words ・Predictable placement of dictionary words (13th word) ・Repetitive vocabulary (~40 words) ・No punctuation or casing, looks like a stream ・Consistent three-word filler sequences repeated four times per byte Based on that, I built a simple NOVA rule. NOVA is the open-source prompt pattern matching engine I created (like YARA, but for natural language and LLM content). Guess what, It works well to spot these kinds of text-based C2 channels. Depending on how the attacker implements the C2, you might need to adjust your rule, but the detection logic would still work. ➡️ Blog: @tomer2138/large-language-command-control-8552154fa167" target="_blank" rel="nofollow noopener">medium.com/@tomer2138/lar… ✨ Nova: novahunting.ai
Thomas Roccia 🤘 tweet mediaThomas Roccia 🤘 tweet media
English
9
52
188
18.8K
vx-underground
vx-underground@vxunderground·
We are now 6 years old. In 6 years this account, and website, went from small and obscure to one of the largest information security related Twitter profiles. Twitter and Telegram combined, vx-underground has over 400,000 people who follow our content and discussions. It is very surreal feeling seeing a small personal project, dedicated to saving stuff that I thought was cool, becoming so large and popular. Sometimes I find it hard to believe what I say matters to anyone, because at the end of the day I'm just some stinky nerd who likes spamming cat pictures. As I've said for the past 6 years: nothing will change. We will continue to provide free malware source, samples, and papers. That's all I've got to say right now. Thank you for all the love and support. I look forward to continually serving all of you. - smelly smellington
English
46
55
989
41.4K
TCM Security
TCM Security@TCMSecurity·
Looking for quality #OSINT resources? We've put together this handy guide based on the tools we recommend in our OSINT course, organized by category to make things easy, like: ✅ Sock puppet resources ✅ Search engine #OSINT tools ✅ Image analysis tools ✅ Website OSINT tools Whether you're just starting out or sharpening your skills, the selected resources should help you out! Want to go even deeper? Check out our Practical OSINT Research Professional (PORP) certification! tcm.rocks/porp-x
TCM Security tweet mediaTCM Security tweet mediaTCM Security tweet mediaTCM Security tweet media
English
4
17
88
16.7K
Infosec House
Infosec House@InfosecHouse·
Doing some switch-a-roos on hosting. Expect some 404 errors.
English
0
0
0
134
Infosec House
Infosec House@InfosecHouse·
Happy Mother’s Day to the original system architect. All love, no bugs! 💕
English
0
0
1
70
vx-underground
vx-underground@vxunderground·
@RachelTobac ive got my setup muted so idk what ur saying but ur teeth are white as cocaine wtf rachel stop being so healthy
English
2
0
44
3.7K
Rachel Tobac
Rachel Tobac@RachelTobac·
Let’s break down 2 types of scams happening to folks right now to help keep your loved ones safe. 1st, scammers are capitalizing on fears of a recession to trick folks into: - Making bogus investments to “get rich quick” - Joining "investment coaching" groups w/ expensive fees
English
6
32
132
11.7K
Infosec House
Infosec House@InfosecHouse·
// Comm silence broken Life.exe crashed. Work spawned endless threads. But the lab lights stayed on — brewing new ops. > New tools added soon > New content creation besides only a website > Maybe... physical drops? Encrypt Everything. Hack the planet.
English
0
0
0
122