drm

249 posts

drm

drm

@lowercase_drm

@AlmondOffSec but mostly shilling for #pywerview

Katılım Mart 2022
87 Takip Edilen771 Takipçiler
Sabitlenmiş Tweet
drm
drm@lowercase_drm·
Choose your poison 🦋 bsky.app/profile/lowerc… 🐘 @drm" target="_blank" rel="nofollow noopener">mastodon.social/@drm (still posting here too)
English
0
0
1
2K
drm
drm@lowercase_drm·
Please, be advised that someone is using a forked repo of my KingCastle python script to spread LUA malware. What a time to be alive. User: Ramdhankola Repo: KingCastle 🌻
drm tweet mediadrm tweet media
English
0
0
0
103
drm
drm@lowercase_drm·
@SipeedIO Will it be open sourced ?
English
1
0
0
50
drm
drm@lowercase_drm·
Asked Claude to code a small site for the @NoobieDog repo about TPM sniffing. It was a fun exercice (even with a free tier claude account haha). vmk.lol
drm tweet media
English
0
0
7
281
drm
drm@lowercase_drm·
Dell Pro 14 Plus - PB14250: VMK sniffed on the WSON flash (UC2) hidden under the anti static (?) sticker.
drm tweet media
English
0
0
1
100
drm
drm@lowercase_drm·
Dell Pro 16 Plus - PB16250: TPM (green square, U712) and BIOS (red square, UH8) are on the back of the motherboard. But it boots on a desk!
drm tweet mediadrm tweet media
English
2
0
0
174
drm
drm@lowercase_drm·
Recently sniff a SPI bus for the first time (with and without PIN) on a Lenovo T470. It's quite fun, event with a DSLogic! s/o @en4rab for SPITkey.
drm tweet mediadrm tweet media
English
4
8
22
2.6K
drm retweetledi
MDSec
MDSec@MDSecLabs·
In our latest post, researcher @craigsblackie documents attacks against the Dell UEFI firmware that enable DMA attacks against TPM-only bitlockered devices mdsec.co.uk/2026/03/disabl…
MDSec tweet media
English
3
51
157
12.6K
drm retweetledi
Almond OffSec
Almond OffSec@AlmondOffSec·
A private @Burp_Suite Collaborator instance is an essential for pentesting sensitive environments, but managing TLS for it can be a pain. Today we release a Certbot plugin that automates Let’s Encrypt wildcard certificate renewals for private instances. github.com/AlmondOffSec/c…
English
0
3
11
527
drm
drm@lowercase_drm·
@vendetce No, problem, it's nothing fancy, but it helps (me, at least 🙂)
English
0
0
0
30
drm
drm@lowercase_drm·
I was bored to type the same commands each time I started a new internal pentest. So here comes KingCastle. This script does not perform any attacks, consider it as a cheat sheet, to quickly see low hanging fruits. github.com/ThePirateWhoSm…
drm tweet media
English
3
69
307
16.9K
drm
drm@lowercase_drm·
The Sword made its way to France 🗡️ @GiliYankovitch
drm tweet media
English
1
0
1
226
andrew danis
andrew danis@andrewdanis·
@lowercase_drm tweet is easier than opening a github issue, but looks like line 102 has a typo "dnshostame" which causes the script to fail
English
1
0
6
448
drm
drm@lowercase_drm·
@al3x_n3ff @Defte_ I have just experienced that behavior with a STATUS_PASSWORD_EXPIRED error
English
0
0
1
45
Alex Neff
Alex Neff@al3x_n3ff·
@Defte_ I have experienced that wrong credentials result in these timeouts, correct credentials still work as expected with NTLM. In your case there might be a bug with the long username? If anyone knows the reason for these timeouts please share your knowledge✌️
English
1
0
4
555
Aurélien Chalot
Aurélien Chalot@Defte_·
Anyone know wtf is happening ? Authenticating via NTLM on DC2025 seems a bit broken while working completely fine with Kerberos:
Aurélien Chalot tweet media
English
6
4
47
7.4K
drm
drm@lowercase_drm·
@en4rab @SipeedIO Nice hardware but sigrok can't handle a 15s capture at 800Mhz without crashing and it is barely usable at 400Mhz... I used the plugin from DSview (github.com/DreamSourceLab…), do you know a better one?
English
1
0
0
63
Robin Bradshaw
Robin Bradshaw@en4rab·
I finally tested the @SipeedIO SLogic16U3 with TPM sniffing. Their build of sigrok doesnt have Ghecko's plugin included but it is simple to add. I had some issues with it not liking my usb-c port but I got a trace and found out my sigrok2pcap script was rubbish and needed fixing
Robin Bradshaw tweet media
English
2
0
4
175
drm retweetledi
Almond OffSec
Almond OffSec@AlmondOffSec·
Team member @myst404_ identified a privilege escalation in WAPT caused by a DLL hijacking issue, which was promptly fixed by the vendor. Patched in version 2.6.1. Changelog: #wapt-2-6-1-17705-2026-02-04" target="_blank" rel="nofollow noopener">wapt.fr/fr/doc/wapt-ch…
Almond OffSec tweet media
English
0
5
22
1.2K
drm
drm@lowercase_drm·
@GiliYankovitch Can't wait to receive it! What about the ENIG coating version for the golden challenge winners?
English
1
0
1
36
Gili Yankovitch
Gili Yankovitch@GiliYankovitch·
The Sword of Secrets is shipping worldwide ⚔️ What started as a small hardware CTF turned into PCB spins, custom jigs, packaging chaos, and 250 units doing a surprise customs round trip. Every sword made it back. Now they’re finally on their way. Worth it. #Hardware #Embedded
Gili Yankovitch tweet media
English
4
2
6
325