Tony

7.8K posts

Tony banner
Tony

Tony

@TJ_Null

Blue Teamer in Disguise. Blog at https://t.co/spa33ybIVL. SANS Netwars Champion. Former community manager and founder of the Offsec community for @offsectraining

Katılım Mart 2013
489 Takip Edilen23.3K Takipçiler
Sabitlenmiş Tweet
Tony
Tony@TJ_Null·
As Promised! I have decided to update my guide for preparing for OSCP. The guide is full of new updates and information to help you prepare for PEN-200/PWK 2.0. If anyone wants to read it here it is: netsecfocus.com/oscp/2021/05/0…
English
31
341
965
0
Tony
Tony@TJ_Null·
Your support will help us expand our team and our opportunity to contine playing the sport we love as we want to compete in other leagues in the future.
English
0
0
2
318
Tony
Tony@TJ_Null·
I know this is outside of Infosec, but I figured I ask. I run the Charm City Cannons Box Lacrosse team and we are looking for support to help fund our team to compete in the NABLL region. If you are interested in supporting us please let me know. instagram.com/charmcitycanno…
Tony tweet media
English
1
2
3
571
Tony
Tony@TJ_Null·
If you are using @kalilinux you should update to the latest kernel 6.19.14 that just rolled out. This version contains the patch for CopyFail
Tony tweet media
English
1
2
22
1.6K
Tony
Tony@TJ_Null·
@_nwodtuhs Totally agree with you about using VMs and containers for situations like this. However, I am a mad man that uses Kali Linux on bare metal 😂
English
0
0
2
86
Charlie Bromberg « Shutdown »
I've seen pentesters run Kali bare-metal. Please please please, use VMs or containers and/or Exegol. Short-lived, scoped and least-privilege environments. But please stop being a security consultant and applying the worst security practices at the same time 🙏
🕳@sekurlsa_pw

If you are wondering if Kali is vulnerable to copy-fail LPE, yes it is. You can monitor the changes for the Linux kernel package: pkg.kali.org/pkg/linux Debian testing has it patched in version 6.19.13-1 security-tracker.debian.org/tracker/CVE-20…

English
4
9
64
8.2K
Tony
Tony@TJ_Null·
@sekurlsa_pw The Kali Linux team is already aware about this. I have notified them when the POC was released.
English
0
0
6
467
Tony retweetledi
rootsecdev
rootsecdev@rootsecdev·
I too woke up and choose violence today as the fail-copy POC dropped. Made a clean exploit including fixing the UID post exploitation without rebooting the target server. Smoke those CTF’s in hack the box. github.com/rootsecdev/cve…
English
4
117
560
33.7K
Tony retweetledi
Bad Sector Labs
Bad Sector Labs@badsectorlabs·
CopyFail (CVE-2026-31431) in Go. In case you want to get root from a static binary without Python as a dependency. github.com/badsectorlabs/…
Bad Sector Labs tweet media
English
16
226
1.1K
77.3K
Tony
Tony@TJ_Null·
@me_irl Did you fix your glibc and musl issues?
English
1
0
0
17
the government man
the government man@me_irl·
glibc static version is working, futzing around with musl version
English
2
0
3
1.2K
the government man
the government man@me_irl·
Hello here is a cross-platform version of the CVE-2026-31431 proof-of-concept. The original was a Python script with an x86_64 payload. This is pure C with a cross-platform payload. github.com/tgies/copy-fai… Here it is running on aarch64. Have fun be safe
the government man tweet media
English
5
17
89
26.1K
Tony retweetledi
ClaudeDevs
ClaudeDevs@ClaudeDevs·
Over the past month, some of you reported Claude Code's quality had slipped. We investigated, and published a post-mortem on the three issues we found. All are fixed in v2.1.116+ and we’ve reset usage limits for all subscribers.
English
1.9K
2.6K
40K
6.4M
Tony
Tony@TJ_Null·
@Raman_Mohurle Yeah I don't know if 2-3 days is going to happen
Tony tweet media
English
1
0
0
48
Raman_MG
Raman_MG@Raman_Mohurle·
@TJ_Null I think it mostly take 2-3 days only My friend faced this so he re filled the form and it worked.
Raman_MG tweet media
English
1
0
0
102
Tony
Tony@TJ_Null·
First time testing out Opus 4.7 on AI CTF Challenge and of course I get hit with this notification in five mins...
Tony tweet media
English
9
0
28
4.3K
Tony
Tony@TJ_Null·
@Raman_Mohurle I already put an a submission in and I have not heard back so we shall see what happens now lol
English
1
0
0
156
Raman_MG
Raman_MG@Raman_Mohurle·
@TJ_Null you can opt for this claude.com/form/cyber-use… after this it probably won’t gives you issue in this stuffs. In my case it won’t even stopped after finding an RCE 😂😂 so i think it helps alott
English
1
0
2
295
Tony retweetledi
Het Mehta
Het Mehta@hetmehtaa·
Be Anthropic > Give people Opus 4.6 > People love it. > For 2 months you degrade Opus 4.6 > You give back normal Opus 4.6 and call it Opus 4.7. > People love it. That's the business model.
English
255
698
16K
592.3K
Tony
Tony@TJ_Null·
@4p0hk Yep this is what they built in 4.7
English
1
0
0
286
4p0hk
4p0hk@4p0hk·
@TJ_Null is this with the safeguard pass for offsec cyber use?
English
1
0
0
300
Tony
Tony@TJ_Null·
@Hultoko How do I prompt harder when it won't let me respond to continue you the conversation 😭
English
0
0
1
246