Dirk-jan

2.5K posts

Dirk-jan banner
Dirk-jan

Dirk-jan

@_dirkjan

Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.

Katılım Aralık 2017
205 Takip Edilen29.9K Takipçiler
Sabitlenmiş Tweet
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
139
903
3.2K
474.5K
rootsecdev
rootsecdev@rootsecdev·
So if you installed ROADtools fresh with @_dirkjan updates from today you might run into a fun mitm issue with selenium and roadtx. This is a known compatibility issue between selenium-wire (which bundles an old fork of mitmproxy) and modern pyOpenSSL. The bundled mitmproxy code calls X509.get_extension(), which was removed from pyOpenSSL in version 23.3.0+. So in short you are going to have TLS interception issues. Anyway this takes care of it if you are using ubuntu. Happy cloud hacking folks. pip install 'pyOpenSSL<23.3.0'
English
1
2
19
2.4K
Dirk-jan
Dirk-jan@_dirkjan·
@merill That's a big step! Excited for you!
English
1
0
7
1.7K
Merill Fernando
Merill Fernando@merill·
Hey folks, some personal news. I’m leaving Microsoft. It’s been a privilege to work here, and I’m incredibly grateful for the people I’ve worked with, the customers I’ve learned from, and the support so many of you have shown me along the way. I’m now starting out on my own and chasing a dream I’ve had for a long time: building software that makes security more practical, accessible, and useful for the people doing the work every day. Why now? With all the change happening around us, I feel like new possibilities are opening up. I want to spend this next chapter building things I care deeply about, solving problems that matter, and doing work that brings me joy. I’m excited. Nervous. Grateful. My newsletters, podcast, Maester and other tools will all be part of this next chapter, and I’ll share more in the coming weeks. Thank you for being part of the journey so far. I’m looking forward to building this next chapter with your support.
Merill Fernando tweet media
English
129
47
1.1K
51.1K
Dirk-jan
Dirk-jan@_dirkjan·
@mthcht2 Nah it's in my backlog of changes to polish up and push to GitHub.
English
0
0
5
762
mthcht
mthcht@mthcht2·
@_dirkjan Did you commit this arg? I’d like to test it. I think I’m already catching this behavior through request-count anomalies on a specific endpoint uri, in addition to the classic pattern of many distinct endpoints uris queried in a short time window
English
1
0
1
880
Dirk-jan
Dirk-jan@_dirkjan·
@Cyb3rMonk All are possibilities but I don't want my enumeration to take hours. If detection is such a huge concern you're better off requesting small pieces of data by hand.
English
1
0
8
411
Mehmet Ergene
Mehmet Ergene@Cyb3rMonk·
@_dirkjan Maybe add a delay between each request to slow it down? But it would be difficult to evade the volume based enumeration spread over a few hours. Do we really need to have all the data or can we just expand the enumeration scope slowly starting from the first compromised user?
English
1
0
1
428
Dirk-jan
Dirk-jan@_dirkjan·
@Cyb3rMonk Volume based detection still works 😉 but it's 1 endpoint in this mode.
English
2
0
9
1.2K
Mehmet Ergene
Mehmet Ergene@Cyb3rMonk·
@_dirkjan I just did the same 😅🤣 just 2 or 3 endpoints but I will see you 😉
English
1
0
5
1.3K
Dirk-jan
Dirk-jan@_dirkjan·
@_xpn_ Congrats dude, that's huge! 😀
English
0
0
1
531
Dirk-jan
Dirk-jan@_dirkjan·
@_xpn_ Nice write-up and thanks for the shout-outs! VS legacy was indeed removed as a foci client recently. I do have an updated list but I have a bit of a backlog of work in progress commits that I need to finalize before pushing things to GitHub.
English
1
0
2
1K
Dirk-jan retweetledi
Adam Chester 🏴‍☠️
If you came to SOCON, you may have seen the fireside chat on Ouroboros (if you weren't too busy counting my "urm"s 😝). The blog post is now live, detailing how we can use Dev-Tunnels for lateral movement, and allow pivoting from GitHub/Entra ID access. specterops.io/blog/2026/05/0…
English
6
49
186
26.7K
Dirk-jan retweetledi
Andrea P
Andrea P@decoder_it·
I published a new "security research" post, and for once, it’s not about Windows 😅 This time I took a look at the myAudi connected vehicle platform and its APIs..🤓 Curiosity drives security research, no matter the target Read it here 👇 decoder.cloud/2026/05/08/oh-…
English
2
11
29
3.9K
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
Mr. and Mrs. Johnson 04.25.2026
Jonny Johnson tweet media
English
25
1
91
6.6K
Dirk-jan
Dirk-jan@_dirkjan·
One month to go until the next public edition of my Entra ID course in The Hague. Working on some roadrecon and roadtx updates from my backlog, and new content on agent identities! Tickets are still available via events.outsidersecurity.nl/entra-26-07/
English
2
10
53
4.3K
Dirk-jan retweetledi
Area41 Security Con
Area41 Security Con@a41con·
🛸 👽 We have published this year's agenda with the talks for the AREA41 security conference 2026 🛸 👽 We are excited - hope you too! ➡️ Check them out at: #schedule" target="_blank" rel="nofollow noopener">a41con.ch/#schedule 📅 June 18-19. 2026, Zürich 🎫 Ticket sale May 5th @ 13:00 pretix.eu/DC4131tickets/…
Area41 Security Con tweet media
English
0
9
15
2K