Gladstomych

10 posts

Gladstomych

Gladstomych

@gladstomych

From saving kids to popping shells

Katılım Nisan 2022
43 Takip Edilen139 Takipçiler
Gladstomych
Gladstomych@gladstomych·
@rootsecdev ah the metadata endpoint, one of the best REST APIs to have graced the web
English
0
0
1
473
Gladstomych
Gladstomych@gladstomych·
@BritishImpact @BSidesLondon I heard chatters in Bsides that canary tokens via custom CSS might be unsupported soon-ish due to MS side changes? Not 100% positive though or whether that affects the Thinkst canaries
English
0
0
0
130
Barry
Barry@BritishImpact·
@gladstomych @BSidesLondon You should add something that strips out Thinkst Canary Tokens from the custom CSS. Although I think they use really random domains
English
1
0
0
212
Octoberfest7
Octoberfest7@Octoberfest73·
@gladstomych @BSidesLondon Nice work! Forgive me as I’m not super familiar with AiTM && Entra ID, would this work when client certificates and/or passkeys are used?
English
1
0
0
219
Gladstomych
Gladstomych@gladstomych·
Huge thanks to @BSidesLondon for the platform. Genuinely some of the best community vibes I've experienced. And thank you to @JumpsecLabs gang for the journey - you know who you are!
English
1
0
5
876
Gladstomych
Gladstomych@gladstomych·
What makes it different? - No infra - just `tokenflare.py deploy` - Free tier Cloudflare Workers - Built-in bot blocking - Webhook notifications on cookie capture - Sub-minute setup vs hours for alternatives
English
1
0
9
1.1K
Gladstomych
Gladstomych@gladstomych·
@rootsecdev Hey there, author of TokenSmith here - yeah we never intended people to use that directly for phishing - landing someone at /nativeclient a pretty odd UX
English
1
0
1
240
rootsecdev
rootsecdev@rootsecdev·
It looks like Microsoft is shutting down some of the shenanigans I have been using with TokenSmith URL's to bypass device code flow scenarios... and bypassing some CA policies. For Example I have been using the ZTNA Network Access Client client ID for some know bypass fun with Entra Scopes >> entrascopes.com/?appId=038ddad… RIP #Azure #Pentesting #Cloud
rootsecdev tweet media
English
2
9
133
17.1K