Chris Hatton

2.6K posts

Chris Hatton banner
Chris Hatton

Chris Hatton

@hattonsec

Cyber Security Consultant and Researcher. ex @dmuhackers chairman. OSCP, CSTL INF

Cheltenham Katılım Ocak 2014
345 Takip Edilen852 Takipçiler
Chris Hatton
Chris Hatton@hattonsec·
The post also covers what happened once it became public, how quickly things escalated, and why linpeas.sh didn’t stay up for long after that.
English
0
0
0
148
Chris Hatton
Chris Hatton@hattonsec·
Remember the linpeas.sh saga from about a year ago? I’ve finally written it up. The findings include LinPEAS being run as root, during active pentests, on compromised web servers, and even on live production systems. hattonsec.com/a-linpeas-saga/
Chris Hatton tweet media
English
1
0
2
308
Chris Hatton
Chris Hatton@hattonsec·
@yaelBro56836079 Very true, but those boxes don't have outbound Internet access so I never would have known if the script was ran on those.
English
0
0
0
948
_yBz
_yBz@yaelBro56836079·
@hattonsec Most are probably on htb and thm platforms
English
1
0
1
853
Chris Hatton
Chris Hatton@hattonsec·
@MaddStep The hundreds of people a week that ran the script I hosted on the domain thinking it was the real script says different.
English
1
0
171
6.2K
spencer
spencer@techspence·
There’s a popular Linux privilege escalation script (linpeas) that’s had a copycat create nefarious linpeas[.]sh. Linpeas (a great tool) has 0 association with linpeas[.]sh (bad) To all pentesters and cybersecurity folks who run tools and scripts as part of their job, be careful Know your tools!
English
5
17
95
80.5K
Chris Hatton
Chris Hatton@hattonsec·
@ippsec @bravesalad1021 Correct, that was everything I was collecting. And you're right, it was a bit of research for a talk at a conference.
English
0
0
6
677
ippsec
ippsec@ippsec·
@bravesalad1021 @hattonsec Am I missing something? I don't see it sending environment variables. Random UUID, MachineUUID, isroot, hostname, current user, kernel is what I see.
English
1
0
7
481
Chris Hatton
Chris Hatton@hattonsec·
When doing HackTheBox and searching for linpeas I used to type linpeas.sh into my browser intending to search google for it, however it would take me to an unregistered domain. I registered the domain in December and I am now getting 1.8k unique hits a month.
English
5
3
35
0
Chris Hatton
Chris Hatton@hattonsec·
@maccamudwood @Wrexham_AFC What are you on about, no one says that, he has been League Two player of the season and got the League Two golden boot before 😂
English
1
0
0
678
Macca
Macca@maccamudwood·
@Wrexham_AFC Get in mullin !! 1 season wonder an can only do it in the national league apparently 🙄
English
1
0
0
1.7K
Wrexham AFC
Wrexham AFC@Wrexham_AFC·
MULLIN YOU BEAUTYYYYYY 47’ | Wrexham AFC 2-2 Crewe Alexandra 🔴⚪️ #WxmAFC
Wrexham AFC tweet media
English
22
38
1.8K
1.6M
Chris Hatton
Chris Hatton@hattonsec·
Passed CSTL INF, happy days! Onwards and upwards 😁
English
0
1
9
0
Chris Hatton
Chris Hatton@hattonsec·
@cyberethical_me @carlospolopm When typing linpeas.sh into your URL bar with the intent to search it on Google it goes straight to my site, so I believe 99% of them are accidental. That's why I registered the domain, because I used to do the same and get a 404.
English
2
0
0
0
CyberEthical.Me @cyberethical_me@infosec.exchange
@hattonsec @carlospolopm I hoped it is an awareness campaign and not some impersonation attack attempt, didn't see that popping out from search before. Seeing you collect statistics, how many people were trying to use that?
English
1
0
0
0
Chris Hatton
Chris Hatton@hattonsec·
@cyberethical_me @carlospolopm I own the domain. If you try to copy and paste the script it will warn you that it's not the real site and display my twitter handle. Not malicious, more to make people aware that they're copying a random script.
English
1
0
7
0
CyberEthical.Me @cyberethical_me@infosec.exchange
@hattonsec @carlospolopm Are you the owner of linpeas[dot]sh? And if so, what is the reason behind this site? Why expose outdated linPEAS script? Is this for malicious intends? Is this honeypot? Why @carlospolopm is not aware of this when it pops up in top 5 google search results? So many questions.
English
1
0
0
0
Chris Hatton
Chris Hatton@hattonsec·
It's been a week now and I can confirm robot vacuum cleaners are 100% worth it. The place has never looked so consistently clean, it's insane. I welcome our cleaning robot overlords.
GIF
English
0
0
12
0
Chris Hatton
Chris Hatton@hattonsec·
There is a conspiracy around dishwasher salt at the moment, 4 shops and all out of stock for weeks?? #SaltGate #BigSalt
English
0
0
1
0
Chris Hatton retweetledi
Jesse McLaren
Jesse McLaren@McJesse·
WOW. Jaw dropping. FBI says Ned’s School Survival Guide was never formally declassified.
English
31
4K
63.2K
0