François Reynaud

38 posts

François Reynaud

François Reynaud

@__fpr

Katılım Mayıs 2022
23 Takip Edilen39 Takipçiler
bitdecay
bitdecay@synbyte·
@Defte_ Can you not just run responder in a analyzer mode? I am sure you can see all the dns or other traffice, which will help you see all (I think) active hosts.
English
2
0
0
76
Aurélien Chalot
Aurélien Chalot@Defte_·
During internal assessments I realized that the most difficult part is to detect all subnets. Running nmap is good but long . So what if we let computers and servers talk to us instead and monitor incoming packets ? (1/2)
English
17
40
322
44.9K
JS0N Haddix
JS0N Haddix@Jhaddix·
Web Hacking Tip: When using ffuf change the user agent string as the default one "Fuzz Faster U Fool" is commonly blocked. -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
JS0N Haddix tweet media
English
2
27
205
15K
Alex Neff
Alex Neff@al3x_n3ff·
Made some improvements to Impacket's version enumeration for Windows. Now you have a much better idea of which Windows versions you are dealing with. Already available in NetExec, PR to the Fortra repository is open. Here is a before and after example:
Alex Neff tweet media
English
2
19
88
5.8K
Mick Douglas 🇺🇦🌻
Mick Douglas 🇺🇦🌻@bettersafetynet·
@0xTib3rius I mean just look at it... 0 is an oval. Why are we arguing this? If it were "Δ day" we'd call it triangle day. But it's "0 day". The oval is right there.
English
2
0
3
273
Matt Wensing 🐙
Matt Wensing 🐙@mattwensing·
GPT has definitely gotten more resistant to doing tedious work. Essentially giving you part of the answer and then telling you to do the rest. Imagine your database only giving you the first 10 rows when you run a query. The tide is going back in.
Matt Wensing 🐙 tweet media
English
388
230
4.7K
2M
François Reynaud
François Reynaud@__fpr·
@Waltuuh @ZephrFish tbf, they're not supposed to, cuz they're supposed to be aware that a pentest is going on. That's one of the main differences between a red team and a pentest
English
2
0
0
16
Andy Gill
Andy Gill@ZephrFish·
Now and again it’s good to have fun
Andy Gill tweet media
English
13
22
149
14.1K
François Reynaud retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
Are you new or getting started in pentesting? Is it hard to come by AD environments to practice on except when on an engagement? Check out: Game of Active Directory (GOAD): A vulnerable Active Directory environment for penetration testing practice. (link below)
JS0N Haddix tweet media
English
15
203
913
111K
N (\dev\ice)
N (\dev\ice)@_dev_ice·
@vim_tricks I would be great if visual move can move whole block selected
English
1
0
0
53
VimTricks
VimTricks@vim_tricks·
You can use ddp to move the current line down in Vim. But I use mappings for Ctrl-j and Ctrl-k to move one or more lines up or down quickly... 👉 Read the tip: bit.ly/3dhJuqn ✉️ Free weekly tips: bit.ly/vimtricks
GIF
English
2
10
39
5.2K
François Reynaud
François Reynaud@__fpr·
@0xTib3rius What's the app for ? What's are its most critical functionalities ? Is there a WAF ?
English
0
0
1
34
Tib3rius
Tib3rius@0xTib3rius·
Web #AppSec interview questions! Reply with your best answer (and/or share this post!), I'll post mine tomorrow. Question 45: What are some questions you would ask a customer during a web app pentest scoping call? #InfoSec #Cybersecurity #BugBounty #Hacking
English
4
3
21
7.4K
François Reynaud
François Reynaud@__fpr·
@mpgn_x64 Also, it saves results in cmedb 😊 But is the administrator password 'October2022' or 🦄🦄🦄🦄🦄🦄🦄🦄 ? xD
English
0
0
1
235
mpgn
mpgn@mpgn_x64·
A new module just landed on CrackMapExec called WCC by @__fpr 🚀 This module checks various configuration items on Windows machines, such as LSA cache, hash storage format, etc 🤿 You can also export the results for your pentest report ✍ Available on github.com/mpgn/CrackMapE…
mpgn tweet mediampgn tweet media
English
6
83
333
26.4K
Joseph Thacker
Joseph Thacker@rez0__·
1/ Read the javascript 2/ Be quick to collaborate 3/ Read new vulnerability reports 4/ Impact over argument 5/ Respectfully push back (against downgrading severities)
English
3
6
63
4.7K
Joseph Thacker
Joseph Thacker@rez0__·
10 (very) short tips for bug bounty:
English
11
73
279
44.5K
François Reynaud retweetledi
EDF Sport
EDF Sport@EDF_Sport·
🎁 JEU CONCOURS 🎁 C'est l'événement à ne pas rater 🔥 Vous avez envie d'y participer ? Tentez de gagner 2️⃣ places pour vivre les Jeux Olympiques de Paris 2024 🤩 Pour participer : ✅ Follow @energiedusport ✅ RT ce tweet
EDF Sport tweet media
Français
87
840
417
224.4K