drm

242 posts

drm

drm

@lowercase_drm

@AlmondOffSec but mostly shilling for #pywerview

Katılım Mart 2022
85 Takip Edilen777 Takipçiler
Sabitlenmiş Tweet
drm
drm@lowercase_drm·
Choose your poison 🦋 bsky.app/profile/lowerc… 🐘 @drm" target="_blank" rel="nofollow noopener">mastodon.social/@drm (still posting here too)
English
0
0
1
1.9K
drm retweetledi
Almond OffSec
Almond OffSec@AlmondOffSec·
A private @Burp_Suite Collaborator instance is an essential for pentesting sensitive environments, but managing TLS for it can be a pain. Today we release a Certbot plugin that automates Let’s Encrypt wildcard certificate renewals for private instances. github.com/AlmondOffSec/c…
English
0
1
5
225
drm
drm@lowercase_drm·
@vendetce No, problem, it's nothing fancy, but it helps (me, at least 🙂)
English
0
0
0
25
drm
drm@lowercase_drm·
I was bored to type the same commands each time I started a new internal pentest. So here comes KingCastle. This script does not perform any attacks, consider it as a cheat sheet, to quickly see low hanging fruits. github.com/ThePirateWhoSm…
drm tweet media
English
3
68
305
16.6K
drm
drm@lowercase_drm·
The Sword made its way to France 🗡️ @GiliYankovitch
drm tweet media
English
1
0
1
211
andrew danis
andrew danis@andrewdanis·
@lowercase_drm tweet is easier than opening a github issue, but looks like line 102 has a typo "dnshostame" which causes the script to fail
English
1
0
6
440
drm
drm@lowercase_drm·
@al3x_n3ff @Defte_ I have just experienced that behavior with a STATUS_PASSWORD_EXPIRED error
English
0
0
1
44
Alex Neff
Alex Neff@al3x_n3ff·
@Defte_ I have experienced that wrong credentials result in these timeouts, correct credentials still work as expected with NTLM. In your case there might be a bug with the long username? If anyone knows the reason for these timeouts please share your knowledge✌️
English
1
0
4
552
Aurélien Chalot
Aurélien Chalot@Defte_·
Anyone know wtf is happening ? Authenticating via NTLM on DC2025 seems a bit broken while working completely fine with Kerberos:
Aurélien Chalot tweet media
English
6
4
47
7.3K
drm
drm@lowercase_drm·
@en4rab @SipeedIO Nice hardware but sigrok can't handle a 15s capture at 800Mhz without crashing and it is barely usable at 400Mhz... I used the plugin from DSview (github.com/DreamSourceLab…), do you know a better one?
English
1
0
0
61
Robin Bradshaw
Robin Bradshaw@en4rab·
I finally tested the @SipeedIO SLogic16U3 with TPM sniffing. Their build of sigrok doesnt have Ghecko's plugin included but it is simple to add. I had some issues with it not liking my usb-c port but I got a trace and found out my sigrok2pcap script was rubbish and needed fixing
Robin Bradshaw tweet media
English
2
0
4
155
drm retweetledi
Almond OffSec
Almond OffSec@AlmondOffSec·
Team member @myst404_ identified a privilege escalation in WAPT caused by a DLL hijacking issue, which was promptly fixed by the vendor. Patched in version 2.6.1. Changelog: #wapt-2-6-1-17705-2026-02-04" target="_blank" rel="nofollow noopener">wapt.fr/fr/doc/wapt-ch…
Almond OffSec tweet media
English
0
6
22
1.2K
drm
drm@lowercase_drm·
@GiliYankovitch Can't wait to receive it! What about the ENIG coating version for the golden challenge winners?
English
1
0
1
35
Gili Yankovitch
Gili Yankovitch@GiliYankovitch·
The Sword of Secrets is shipping worldwide ⚔️ What started as a small hardware CTF turned into PCB spins, custom jigs, packaging chaos, and 250 units doing a surprise customs round trip. Every sword made it back. Now they’re finally on their way. Worth it. #Hardware #Embedded
Gili Yankovitch tweet media
English
4
2
6
304
drm retweetledi
RedTeam Pentesting
RedTeam Pentesting@RedTeamPT·
Originally, Microsoft did not enforce their own specs for validated writes at all and only checked if a KeyCredentialLink is already present. Now they require a CustomKeyInformation field with the "MFA Not Required" flag to be present and the last logon timestamp to be absent.
English
2
3
16
1.9K
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Today I had an ldap ntlmrelayx.py socks connection but all tools failed to query LDAP via socks5 except from certipy. But certipy only queries certificate information. Well, so I let claude code something which worked 🧐 github.com/S3cur3Th1sSh1t…
S3cur3Th1sSh1t tweet media
English
4
61
244
13.7K
drm
drm@lowercase_drm·
@Defte_ Seems ok on my DC2025s😕
drm tweet media
English
1
0
0
556
drm
drm@lowercase_drm·
@Blurbdust Does anyone have benchmark? What cracking speed I can expect on a modern hardware?
English
1
0
1
474
drm
drm@lowercase_drm·
@SipeedIO @ico_TC How can I test it ? Is there a pull request ?
English
1
0
0
155
drm retweetledi
car leak
car leak@DruzheKarlik·
@ghidraninja gang watching the logic analyzer output
car leak tweet media
English
0
4
17
3.3K