Erwan

898 posts

Erwan

Erwan

@erwan_lr

Security geek. Security Engineer. Self-educated. Vegan. @_WPScan_ / Jetpack / Automattic

Katılım Temmuz 2012
117 Takip Edilen682 Takipçiler
Erwan retweetledi
Jetpack
Jetpack@jetpack·
Jetpack is acquiring WPScan, a WordPress vulnerability database used across the WordPress ecosystem to learn about new vulnerabilities. Read more about how we're planning to make malware data and APIs more open source for all. jetpack.com/2021/11/04/jet…
English
4
14
29
0
Erwan
Erwan@erwan_lr·
RIP Mr Sean Lock, damn your craziness will be missed :(
English
0
0
1
0
Erwan retweetledi
WPScan - WordPress Security
We're giving away a free @offsectraining OCSP (PEN-200) certification course for WPScan's 10th Birthday! 🥳 Worth $999! We will be picking one security researcher who submitted a valid vuln during 2021 via our website submission form at random on June 16th! HACK THE PLANET!!!
GIF
English
2
23
111
0
Erwan
Erwan@erwan_lr·
@Bugcrowd Something attackers don't have ;D
English
0
0
2
0
bugcrowd
bugcrowd@Bugcrowd·
How would you define "scope" in just 4 words?
English
145
10
179
0
Erwan
Erwan@erwan_lr·
When you report a Stored XSS (with privilege escalation risk) and vendor replies "It's not a security issue, you can install a role manager plugin." o_O
Erwan tweet media
English
0
0
2
0
Erwan retweetledi
Ryan Dewhurst
Ryan Dewhurst@ethicalhack3r·
We're very excited to finally be able to assign CVE numbers for WordPress core, plugin and theme vulnerabilities.
CVE Announcements@CVEannounce

WPScan is now a CVE Numbering Authority (CNA) assigning CVE IDs for WordPress core, plugins, and themes #January122021_WPScan_Added_as_CVE_Numbering_Authority_CNA" target="_blank" rel="nofollow noopener">cve.mitre.org/news/archives/… #cve #cna #cveid #vulnerability #vulnerabilitymanagement #wordpress #WPScan

English
2
6
20
0
Erwan
Erwan@erwan_lr·
@jpgninja @ethicalhack3r @_WPScan_ @firefart Really depends what your goal is: find 0-day, make stats of attacks etc. Easiest part is to create the HP, all the management behind is very time consuming (especially to filter already known exploits). Can continue via dm if you wish, the tweet limit is killing me already xD
English
0
0
1
0
Chris Mewhort (Hort)
Chris Mewhort (Hort)@jpgninja·
@erwan_lr @ethicalhack3r @_WPScan_ @firefart Re: Approach, is it a game of: ☝🏻 False-flagging requests (ie. sending back 200's on timthumb.php reqs), or planting (presumably patched) files? ✌🏻 Logging everything (full requests, files, and all), or sifting through access_logs for novel requests?
English
1
0
0
0
Chris Mewhort (Hort)
Chris Mewhort (Hort)@jpgninja·
@ethicalhack3r @_WPScan_ @firefart @erwan_lr Ok, very cool. Thanks! Missed this before responding by dm, so if it will answer any of those questions feel free to ignore. Just trying to get a big picture understanding of the most efficient way of managing. Cheers!
English
1
0
0
0
Erwan
Erwan@erwan_lr·
Hey @Burp_Suite, I can not reply to the support agent on the thread. Tried in FF 77.0.1 and Safari 13.1.1 :x
Erwan tweet media
English
1
0
0
0
Erwan retweetledi
François MOCQ - F1GYT - framboise314 🌈
Fermeture de COVID3D... Après 190000 visières fournies et sans doute s'apercevant qu'il y a du fric à se faire en vendant la visière 15€ alors que les makers les offrent nos premiers de cordée ont décidé que ces visières gratuites, c'était de la merde... #OnNoublieraPas
François MOCQ - F1GYT - framboise314 🌈 tweet mediaFrançois MOCQ - F1GYT - framboise314 🌈 tweet media
Français
17
119
116
0
Erwan
Erwan@erwan_lr·
@avorion That's amazing!. However, those factory's goods do not appear in the trading overview (I've sent a report about that a few days ago ;))
English
0
0
0
0
Avorion
Avorion@avorion·
Missing just a few of the ingredients for your new awesome Turret? Look for Turret Factory Suppliers. These handy merchants always have a variety of items needed for turret crafting in stock! More expensive, but all in one place! #indiegames #indiedev #gamedev #Avorion #Boxelware
Avorion tweet media
English
1
0
12
0
Erwan
Erwan@erwan_lr·
@syed__umar @digininja @pentestmatt @PortSwigger Just put whatever (like test) in the first field, select the Encode as Base64, then click on the Smart decode next to the generated base64 encoded text. I don't recall any time this feature worked
Erwan tweet media
English
1
0
1
0
Robin
Robin@digininja·
@adriendb I'm glad I'm not the only one who finds that @PortSwigger Burp Suite "Smart Decode" isn't really that smart.
English
3
1
4
0
Erwan
Erwan@erwan_lr·
@darryllane101 Nah, thing is WP tries to access localhost:8000 which is not opened (WP docker runs on :80, bound to :8000 of the host). Only way so far is to bind 80 from the host to the 80 of the docker container, but not ideal :/
English
0
0
0
0
Erwan
Erwan@erwan_lr·
Anyone managed to get the WordPress Cron working with a wordpress docker image locally ? keep getting 'Your site could not complete a loopback request' and this is driving me crazy
English
0
1
1
0