Adrian

228 posts

Adrian banner
Adrian

Adrian

@mr_mitm

Mostly left for bsky Hacking, Basketball, Cosmology, Whisky, Pizza, Guitar

Tübingen, Deutschland Katılım Mart 2019
91 Takip Edilen183 Takipçiler
Adrian
Adrian@mr_mitm·
@techspence What are you thoughts on PAWs? In my experience, literally all orgs draw the line there and use bastion hosts instead. Admins refuse to do office tasks in a VM or separate workstation.
English
1
0
1
160
spencer
spencer@techspence·
I’ve always thought (wrongly) that tiered administration for Active Directory was widely known and accepted. It seems like it’s one of those things that many feel is “for big companies” and is more effort than it’s worth. But I disagree.. Maybe should do a podcast on this topic what do you think?
English
21
9
128
16K
Adrian retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
It's been quiet for a while around bloodhound Python, however I'm happy to share that I am now maintaining the project at my personal GitHub. The latest version fixes many bugs/issues, also thanks to the many PRs that were submitted (thanks all!). github.com/dirkjanm/blood…
English
11
197
626
60.8K
Adrian
Adrian@mr_mitm·
Linux: Password-based remote auth is a big no-no, especially for root! Use public keys and sudo instead. Windows: Or we can just enable it by default. Let's call it SMB. Oh and the hash is also the password, because why not.
English
1
0
5
353
Adrian
Adrian@mr_mitm·
@_dirkjan @bookingcom Same for me. Was contacted via WhatsApp, but they had all details. Very convincing. This has been going on for years and booking claims it's an issue with the hotels. Yet I never had this issue with hotels[.]com. Made a one-time exception for booking - instantly almost scammed.
English
1
0
1
552
Dirk-jan
Dirk-jan@_dirkjan·
Hey @bookingcom , I'm getting scammed via your official message system on a real booking. Sounds like you're having some security troubles.
Dirk-jan tweet media
English
39
69
496
144.7K
Adrian retweetledi
n00py
n00py@n00py1·
The craziest BloodHound art I've made yet (password sharing clusters)
n00py tweet media
English
8
19
203
25K
Adrian
Adrian@mr_mitm·
@friggelei @cirosec Die wollen nur Leute, die kaputte TLS certs diagnostizieren können
Deutsch
0
0
1
145
friggelei
friggelei@friggelei·
@cirosec echt jetzt, die Subdomain nicht im SAN?
Deutsch
2
0
3
589
Adrian
Adrian@mr_mitm·
@two06 A bit dramatic, no?
English
0
0
2
1.2K
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿
Choose no life. Choose no career. Choose no family. Choose a fucking big mess with laptops, mobile devices, fully encrypted flash drives and tens of VMs. Choose no sleep, high caffeine and mental insurance. Choose no friends. Choose combats and matching trekking shoes. Choose chairs for your office in a range of fucking fabrics. Choose Burp, Kali, hipster scripting languages, toolkits, debuggers, and wondering why the fuck you‘re writing a report on a Sunday morning. Choose sitting in that swivel chair, looking at mind-numbing, spirit-crushing applications and infrastructures, stuffing fucking junk food into your mouth. Choose rotting away at the end of it all, pishing your last on some miserable cons, nothing more than an has-been technical resource to the non-sentient, fucked up AI DARPA spawned to replace the computer-literate.  Choose your future. Choose to pentest.
English
8
31
197
44.9K
Jean
Jean@Jean_Maes_1994·
Has anyone ever pentested wireless keyboards? Seems to me like free keylogging lol
English
22
8
66
24K
Adrian
Adrian@mr_mitm·
@florianaigner When people thought the world was flat, they were wrong. When people thought the earth was spherical, they were wrong. But if you think that thinking the earth is spherical is just as wrong as thinking the earth is flat, then your view is wronger than both of them put together
English
1
0
2
137
Florian Aigner
Florian Aigner@florianaigner·
Ich schrieb gestern, die Erde sei eine Kugel. Und natürlich kam dann wieder: "Stimmt doch nicht! Wie kannst du nur! Die Erde ist ein Geoid, ein Rotationsellipsoid, kartoffelförmig!" Ein paar Zeilen dazu, weil ich das wirklich für ein problematisches Missverständnis halte: (🧵)
Deutsch
88
237
1.5K
257.3K
Adrian
Adrian@mr_mitm·
@ShitSecure Or just rerun bloodhound for each new set of creds
English
0
0
0
20
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Do manual verifications for each credentials found. Back to the roots and steps needed before BH was released :P
English
1
0
16
1.7K
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
Pentest/Red-Team tip: Never trust in BH-Information if you didn't enumerate them with an administrative user. Session infos are not complete, Local Group information may be missing. Low priv users cannot enumerate that anymore for updated systems. 🧐
S3cur3Th1sSh1t tweet media
English
6
44
221
34.7K
Merill Fernando
Merill Fernando@merill·
It's 2023 and your IT team is still forcing the entire company to change their passwords every few months 🤦 PS. I work at Microsoft, and we stopped doing this nearly four years ago. Send the link below to your IT team 👇
Merill Fernando tweet media
English
167
576
3.2K
725.5K
Adrian retweetledi
Tib3rius
Tib3rius@0xTib3rius·
OK, I have no idea how long this series of tweets will be, but I've heard from several people associated or previously associated with NCC. While I've verified the association, bear in mind that a lot of this is from single sources. To start with, here's some backstory on the original round of layoffs in February: A North America-wide all-hands meeting was scheduled with only a few days notice, which was unusual. On that day, the British press were reporting that NCC was forecasting lower growth than expected and were going to lay off ~8% of its global workforce. The all-hands meeting confirmed layoffs would be coming. Managers would be notified that same day, and the layoffs would start at 12PM EST on the next day (a Friday). The layoffs were described by one source as a "bloody massacre". Employees were locked out of their computers before their manager had a chance to contact them and tell them the bad news. Several of these employees were onsite at customers in the middle of engagements. Several employees were locked out by mistake and only found out hours later that they were still employed. The actual number of employees laid off ended up being significantly higher than the 7-8% they were told in the all-hands meeting. One source estimated that between 10-15% of all North American employees were let go. Mismanagement was blamed by one source for the layoffs, as the North American side of the business was heavily dependent on work from big west coast tech firms and startups, which was a shift from a lot of east coast financial customers. When these big tech firms started their own layoffs, they reduced the number of services being bought from NCC, resulting in the February layoffs.
English
4
26
107
111.4K
Adrian
Adrian@mr_mitm·
@peter4logo @florianaigner Sämtliche Publikationen von Clausen beziehen sich auf Quantenphysik. Dadurch kann man weder auf das sachliche Argument eingehen, noch hat er irgendeine besondere Autorität auf dem Gebiet. Soll er sein Modell doch Peer Reviewen lassen. scholar.google.com/citations?hl=e…
Deutsch
1
0
0
9