Rambo

437 posts

Rambo

Rambo

@R44MB00

OSCP, CRTE, Hacker, Researcher

Medellín, Colombia Katılım Ekim 2016
449 Takip Edilen107 Takipçiler
Sabitlenmiş Tweet
Rambo
Rambo@R44MB00·
Real interesting stuff. "When everything you can want to know about a program’s behaviour can be found by RE, then source code for software becomes more like blueprints for a building: a record at best of what was intended or specified, but not necessarily of what got built."
English
0
16
21
0
Rambo retweetledi
MalDev Academy
MalDev Academy@MalDevAcademy·
As promised, today we released DumpBrowserSecrets a tool which extracts passwords, tokens, cookies and other data from several browsers. github.com/Maldev-Academy…
MalDev Academy tweet media
English
7
195
1.1K
66K
Rambo retweetledi
eversinc33 🤍🔪⋆。˚ ⋆
Dumbest AMSI bypass I know so far, but it works: sideloading a fake amsi.dll to a copied version of powershell which simply return S_OK / AMSI_RESULT_CLEAN for every command. I would have thought that there was some kind of signature check upon loading amsi.dll but apparently not
eversinc33 🤍🔪⋆。˚ ⋆ tweet media
English
18
262
885
105.7K
Rambo
Rambo@R44MB00·
The burnout is real! 🥴🔥🔥🥴 Friendly reminder to do something for yourself today.
English
0
0
0
31
Rambo retweetledi
Sonatype
Sonatype@sonatype·
.@Sonatype's Juan Aguirre (@R44MB00) gets back to the basics on how to research and identify threats. ⏪ Juan dives into the waters 🌊 of malware analysis and provides best practices for analyzing Python malware 🐍 bit.ly/3GU6c74
Sonatype tweet media
English
1
2
2
244
Rambo retweetledi
vx-underground
vx-underground@vxunderground·
Surprise! Another ChatGPT tweet! Except this time it is people making ChatGPT punch itself in the face *Images via @Kevin2600
vx-underground tweet mediavx-underground tweet mediavx-underground tweet media
English
22
187
1.4K
0
Rambo retweetledi
MalwareHunterTeam
MalwareHunterTeam@malwrhunterteam·
Very legit IP address, right? 😂
MalwareHunterTeam tweet media
English
116
184
1.7K
0
Rambo retweetledi
PT SWARM
PT SWARM@ptswarm·
🔥 A tip for getting RCE in Jetty apps with just one XML file!
PT SWARM tweet media
English
5
238
720
0
Rambo retweetledi
shubs
shubs@infosec_au·
A few months ago, I collaborated with @HusseiN98D to find critical vulnerabilities in a bank. It involved finding a 0day in dotCMS. You can read about the discovery and exploitation process here: blog.assetnote.io/2022/05/03/hac…
English
10
177
582
0
Rambo retweetledi
Corben Leo
Corben Leo@hacker_·
Authorization. Easy to understand. Critical if implemented incorrectly. Want to see an example? (dumb question Corben, yes, why not) Last month, I found an auth bypass that lead to a full account takeover. Here's how I found it:
English
37
226
809
0
Rambo retweetledi
Ax Sharma
Ax Sharma@Ax_Sharma·
For anyone puzzled by strange stuff on NPM lately 🤔 Random #opensource packages, each with HUNDREDS OF 'security placeholder' versions but no malicious code are being published daily. cc @R44MB00
Ax Sharma tweet mediaAx Sharma tweet mediaAx Sharma tweet media
English
1
2
6
0
Rambo
Rambo@R44MB00·
@mcipekci @SynackRedTeam 393 bugs ~ 300k 82 bugs ~ 200k Now that's growth and improvement! Looks like a lot of effort and time put in to the example sqli , but a clear reward can be seen in the numbers. Awesome stuff!
English
1
0
4
0