Étienne Ducharme

32 posts

Étienne Ducharme banner
Étienne Ducharme

Étienne Ducharme

@b13bs_

Offensive security enthusiast | Pentester @ Desjardins

Katılım Kasım 2015
324 Takip Edilen50 Takipçiler
Étienne Ducharme
Étienne Ducharme@b13bs_·
Didn't see much noise around this, but is IP rotation through AWS API Gateway now being detected and blocked? I never had an issue with Fireprox before, but I'm definitely hitting some walls now. This might be why Flareprox and OmniProx were released in the past few months.
English
2
0
2
343
Étienne Ducharme
Étienne Ducharme@b13bs_·
How's your M365 password spraying game in 2024 ? On my side, it's harder than ever. For instance, after 6 rounds each 6 hours apart, starting to lock out accounts more and more each round, to the point where impact is noticeable. Rounds performed using the great #TeamFiltration
English
0
1
0
236
Étienne Ducharme
Étienne Ducharme@b13bs_·
Getting back into bug bounty. Is the HackerOne CTF for private invites still a thing ? I haven't receive anything for days, which seems different from a few years ago #bugbounty #hackerone
English
0
0
0
109
Étienne Ducharme
Étienne Ducharme@b13bs_·
@ShitSecure Great article, thanks! I'm currently hosting different versions of my phishing page with different entropy levels and obfuscators, including a custom one as you recommend. Good results so far, but TrustWave appears to be the most thorough regarding the entropy. @OffenseTeacher
English
0
0
1
147
Étienne Ducharme
Étienne Ducharme@b13bs_·
I fail to see how subdomain takeover could still work for azurewebsites.net. Validation through asuid prevents the Custom Domain from being configured, hence it should block the attack. Does it not ?
English
0
0
1
86
Étienne Ducharme
Étienne Ducharme@b13bs_·
Almost done with RTO course and I learned a lot, it is very complete and up-to-date. However, one *key* material is not covered... Which MX switches is @_RastaMouse using ! We hear them in the background during the demo videos, I'm loving the sound.
English
1
0
10
2.5K
Étienne Ducharme
Étienne Ducharme@b13bs_·
Hard to break good old habits, I'm still using the deprecated tool Aquatone for subdomain web flyover. Any suggestions for a replacement ? I especially liked Aquatone's grouping feature for similar-looking pages.
English
1
0
1
135
Étienne Ducharme
Étienne Ducharme@b13bs_·
Almost forgot to #brag for our podium (3rd place) at the CTF, with my colleagues from @OKIOKdata! The CTF was truly challenging and rewarding
English
0
2
1
219
Étienne Ducharme
Étienne Ducharme@b13bs_·
Before post-event depression settles in, I'd like to thank @NorthSec_io organization and volunteers! Had an awesome couple of days
English
1
0
4
116
Étienne Ducharme
Étienne Ducharme@b13bs_·
@NahamSec Still planning on doing it ? This content got me to sub to your Twitch channel
English
0
0
0
0
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I’m thinking about reviewing some recon frameworks during my stream tomorrow. Which ones would you like to see?
English
17
4
129
0
Étienne Ducharme
Étienne Ducharme@b13bs_·
@mpgn_x64 I just got what you meant. Your uncracked NT hashes are the wordlist for hashcat -m 27100 on your captured NetNTLMv2 hashes. Althought performance is not optimal, it would still be a good idea to run it without a rulefile and with uncracked NT hashes. Nice find!
English
0
0
1
0
Étienne Ducharme
Étienne Ducharme@b13bs_·
@mpgn_x64 I meant, I am not able to crack 5600 hashes with 27100 even thought it looks like the exact same format. How would you find hashes that could be cracked with 27100 ?
English
1
0
0
0
mpgn
mpgn@mpgn_x64·
hashcat -m 27100 👀 I'm thinking about all the ntds i've deleted ...
mpgn tweet media
English
5
1
47
0
Brandon Rossi
Brandon Rossi@0xConda·
I just launched a new pentesting lab using @snaplabsio! Patrons have early access to the lab template starting NOW! A public release will be available later this week. This is going to be a lot of fun 😉
Brandon Rossi tweet media
English
7
19
71
0