r3s1n

68 posts

r3s1n banner
r3s1n

r3s1n

@ResinSec

ethical hacker, student, coder. working on many projects i’ll never finish. my kung fu is stronger than yours

New York, USA Katılım Ekim 2021
152 Takip Edilen20 Takipçiler
r3s1n
r3s1n@ResinSec·
Working on researching AD/windows exploitation. Lots of things to learn!
English
0
0
0
24
r3s1n retweetledi
Flipper Devices
Flipper Devices@flipper_net·
Amazing story🥲: A guy from our Discord found a poor cat in the garden. The cat had an animal RFID tag implant (FDX-B 134kHz), so he scanned it with Flipper, found the cat's owner via the local animal ID database, and they were reunited Turned out that 🐈 was missing for 2 years!
Flipper Devices tweet media
English
82
930
7.5K
0
r3s1n retweetledi
Nihad
Nihad@navilla_eth·
How bypass HTML to Reflected XSS I using KNOXSS payload to bypass it KNOXSS Payload👇👇 "--!><Svg/Onload=confirm`cookie`>"
Nihad tweet media
English
4
73
241
0
r3s1n retweetledi
Brandon Rossi
Brandon Rossi@0xConda·
Here's a mind map I made to help you with Linux privilege escalation
Brandon Rossi tweet media
English
13
265
1.1K
0
r3s1n retweetledi
David Colombo
David Colombo@cyber_colombo·
So, I now have full remote control of over 20 Tesla’s in 10 countries and there seems to be no way to find the owners and report it to them…
English
302
950
6K
0
r3s1n retweetledi
Ilios Labs
Ilios Labs@IliosLabs·
Monad is on ProductHunt! Check it out at producthunt.com/posts/monad and make sure to upvote + share the link so we can get a great launch on the 23rd!
English
0
1
1
0
r3s1n
r3s1n@ResinSec·
Just wanted to let you all know, @IliosLabs is working on a new project called Monad, which lets you share your own code snippets with a really intuitive tagging system. I'd definitely suggest checking them out when it releases! #infosec #bugbountytips
English
0
2
2
0
r3s1n retweetledi
Ilios Labs
Ilios Labs@IliosLabs·
Shoutout to @ResinSec for hacking Monad and alerting us to many vulnerabilities!
English
0
1
3
0
r3s1n retweetledi
The Tor Project
The Tor Project@torproject·
Privacy is a human right.
English
49
775
3.8K
0
r3s1n retweetledi
Roberto Nunes
Roberto Nunes@0x_Akoko·
If the main endpoint is forbidden we can also check for the backup file. /blog/wp-config.php => 403 Forbidden /blog/wp-config.php.bkp => 200 OK #bugbountytips #bugbounty #infosec
Roberto Nunes tweet media
English
5
106
305
0
r3s1n retweetledi
mr.d0x
mr.d0x@mrd0x·
Bypass Defender AV static detection: If you name a malicious file DumpStack.log Defender doesn't scan it.
mr.d0x tweet media
English
37
982
3.2K
0
r3s1n retweetledi
Youstin
Youstin@iustinBB·
Cache Poisoning at Scale: Identifying and Exploiting over 70 Cache Poisoning Vulnerabilities youst.in/posts/cache-po…
English
24
620
1.4K
0
r3s1n
r3s1n@ResinSec·
@rootxyash Biggest security risk to most WordPress sites is plugins/themes. Fingerprint the versions being used and try to see if a CVE exists. If so, how easy would it be to make a PoC? Is there an existing exploit on github/exploit-db?
English
0
0
5
0
r3s1n
r3s1n@ResinSec·
@rootxyash Most of the time SSRF via xmlrpc.php will be closed as N/A or informational. Usually cited on the basis that HTTP and DNS requests aren't valid vulnerabilities unless you could exfiltrate information, which you can't do here
English
3
0
9
0
Yash Devkate 🇮🇳
Yash Devkate 🇮🇳@rootxyash·
A thread all about Common Vulnerabilities in WordPress Websites. Retweet this and let others to know about this (•‿•)
English
13
305
567
0
r3s1n retweetledi
Prof. Feynman
Prof. Feynman@ProfFeynman·
You are under no obligation to remain the same person you were a year ago, a month ago, or even a day ago. You are here to create yourself, continuously.
English
103
4.7K
22.3K
0