Off By One Security

137 posts

Off By One Security banner
Off By One Security

Off By One Security

@offby1security

New streams every Friday! All channel proceeds go back to the community! Check out https://t.co/um6KVfwMFJ for our AI-powered offensive security testing platform!

California, USA Katılım Haziran 2024
2 Takip Edilen1.5K Takipçiler
Off By One Security
Off By One Security@offby1security·
Happy to share that we sponsored a K9 Officer's Bullet Proof Protective vest for Axel who works for the Mississippi Department of Corrections!
Off By One Security tweet media
English
1
1
11
986
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
Five years from now the state of the AI-era cybersecurity industry will have resulted in:
English
5
1
10
3.1K
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
Automated Reverse Engineering with LibGhidra, GhidraSQL, and AI Agents x.com/i/broadcasts/1…
Română
1
35
155
14.1K
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
With the low barrier to entry for vulnerability research due to AI, that used to require advanced and niche skills, I'm seeing that exploit mitigation bypasses are still difficult for AI. Weaponizing vulnerabilities still requires advanced knowledge. Disclosure != Skill...
English
8
14
141
14.5K
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
We at @offby1security saw an interesting defense against AI-powered offensive agents recently. Fingerprinting of the agents performing the testing resulted in misleading, honeypot-like responses, attempting to distract or redirect them. It didn't work but worth noting.
English
3
2
21
1.9K
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
Would you be interested in a stream on the @offby1security channel covering the costs between using different Frontier models to discover the same vulnerabilities and the changes to the prompts and testing methodologies to find them?
English
7
4
56
3K
Off By One Security retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
Offensive Security in Web3 from Exploit Mindset to DeFi Precision Bugs with Josselin Feist x.com/i/broadcasts/1…
English
1
3
12
852
Off By One Security retweetledi
Kuba Gretzky
Kuba Gretzky@mrgretzky·
I'm very excited to announce that last Friday, I had the privilege of making the first public reveal of the upcoming Phishlets 2.0 update for Evilginx on the Off By One Security stream. 🪝🐟 The live demos consisted of: - Examples of how the new Phishlets 2.0 format allows for modifying every part of reverse proxied HTTP traffic during a phishing attack. - FIDO MFA downgrade phishing attack against a Microsoft account, through live modification of MFA configuration in JSON format. - Reveal of the entirely new "Reverse Input Proxy" phishing technique, involving Evilpuppet and a background browser to perform a FIDO MFA downgrade phishing attack against a Google account (without the need to reverse proxy the targeted website). I strongly hope the Phishlets 2.0 update will be a game-changer for phishing attack simulation, and that red teams will finally have all the tools they need to simulate the most advanced attacks in the wild. If you have any suggestions, criticisms, or general feedback, this is the best time to let me know. I would love everyone, especially Evilginx Pro users, to share their opinions, as my priority is to make the red team's job easier and more fun! And yes, I plan to release a batch of ready-to-use phishlets in the new format, with the Phishlets 2.0 update coming first to Evilginx Pro, in the upcoming months, to get everyone up and running. Enjoy the watch! Video: youtube.com/watch?v=eeauoO… Learn more about Evilginx Pro: evilginx.com
YouTube video
YouTube
English
0
30
108
16.5K