Ryan Elkins

354 posts

Ryan Elkins banner
Ryan Elkins

Ryan Elkins

@ryanelkins

cloud | security | hacking | automation | emo music | faith | family | opinions are my own

Indiana Katılım Ağustos 2009
499 Takip Edilen730 Takipçiler
Ryan Elkins
Ryan Elkins@ryanelkins·
@Andrew___Morris @pdiscoveryio @ipinfo @4A4133 I did this a while back and also put this URL into many of the SaaS products I use such as a url in a draft email not being sent to see if it was accessed (it was), sending them in private messages, etc. Would be an interesting expansion to your project related to privacy.
English
0
0
4
928
Andrew Morris (afk)
Andrew Morris (afk)@Andrew___Morris·
For kicks, I set up an interactsh server with authoritative DNS, wrote a bit of code that gens a random UUID dot mydomain dot com at runtime, resolves DNS+grabs a web page, compiled it into an exe, and uploaded it to a few malware sandboxes. Results are wild. Here are some stats:
Andrew Morris (afk) tweet mediaAndrew Morris (afk) tweet mediaAndrew Morris (afk) tweet mediaAndrew Morris (afk) tweet media
English
19
74
410
85.5K
Ryan Elkins
Ryan Elkins@ryanelkins·
@ofjaaah I have some updated code that will work across many of the functions and I’ll work on developing the cdk and deployment guide this week. I’d be happy to share more details once I get the infrastructure code published.
English
2
0
1
78
👑 OFJAAAH 👑
👑 OFJAAAH 👑@ofjaaah·
@ryanelkins If you can help me build this structure I'd be very happy, or have a step-by-step guide on how we can execute it, and if you release it I can talk more about her here in Brazil to my students and followers:?
English
1
0
0
67
Ryan Elkins
Ryan Elkins@ryanelkins·
@HackingDave 💯 agree. I would have driven over for this one if I knew this group was going to be there! Lots of great memories!
English
0
0
1
464
Dave Kennedy
Dave Kennedy@HackingDave·
Reunited with my old Diebold team and co-workers 12 years later... My peers. This team right here was hands down the best team ever assembled. We did so much high-speed and revolutionary stuff for the time and had the best security program ever made for that time. We had buy-off through the entire business including the board..friends with IT, friends with each executive in the group - we could get anything done at anytime. Not because we forced security - because we always had the right intentions for the organization to reduce risk in a way that was reasonable. Love this crew and the entire team we had. One of the best experiences I ever had, and one that I cherish everyday on how smart of folks I get to work with that teach me something new everyday. So many good stories, laughs, and accomplishing something special that forged who I am today. I am a better person due to them, and Scott Angelo who brought us all together. Scott was/is my mentor and someone I learned more from than anyone in my entire career. Not on hacking, but how to talk, how to present, how to run a business - but most importantly how to be a leader and believe in people.
Dave Kennedy tweet media
English
2
3
125
15K
Ryan Elkins
Ryan Elkins@ryanelkins·
@infosec_au Agreed. From an enterprise perspective, the challenge is trying to balance limited resources to maintain hygiene scores for app security reported by the insurers and 3rd parties which heavily score on client side visibility while also prioritizing high impact server side.
English
0
0
1
1.4K
shubs
shubs@infosec_au·
For the first 3-4 years that i was working in infosec, I found client side security so exciting. I stayed on top of every new technique and studied new techniques closely. After this, I took a step back and realised that all of my work on client side security felt helpless, useless, to some extent. The reason why companies were being breached was not due to client side security issues (for the most part). I analysed the reasons companies faced great hardship, and most of the time it was not because of client side security issues but rather server side issues that led to critical impact on their infrastructure. A part of me thought that client side security issues still had impact to the end users (and they still do), but I couldn't cite a single example where a company had lost so much due to a client side issue. It really shaped my mindset and perspective for what to be looking for when auditing an application, and is the reason why I became so deeply invested in server side security. I still try and stay on top of client side security exploitation techniques, but they don't really excite me any more. Might be that my perspective is wrong, and I'm open to feedback, but spending more time on server side issues makes more sense to me from a security perspective. From a bug bounty perspective, do whatever you need to do to make money (it is a game after all), but a 7 step client side chain doesn't really appeal to me from a security impact perspective.
English
23
54
493
140.8K
Ryan Elkins
Ryan Elkins@ryanelkins·
@cdasmktcda @Jhaddix @stokfredrik Very cool! I assume it is a controller that can manage the IaC? It would be neat to integrate hardwired and wireless iot devices into the RPi4 to send telemetry and interception data to the infra for bug hunting iot (i.e. network traffic to find src/dst endpoints, beacons, etc).
English
0
0
1
36
Ryan Elkins
Ryan Elkins@ryanelkins·
@hakluke 1 AirPod in the ear when cooking, chores, getting kids back to sleep with playlist of content. I do YouTube red for conference talks. That age is rough for hands on keyboard. Night is still my main time but at ages 8 and 5, I’m past the all the time exhaustion. It gets easier.
English
1
0
2
642
Ryan Elkins
Ryan Elkins@ryanelkins·
@adrien_jeanneau It should be fixed now. Thanks again for the heads up! A weird react routing issue.
English
1
0
1
56
Ryan Elkins
Ryan Elkins@ryanelkins·
@RayRedacted @RayRedacted When you posted this, I signed up and was selected in the lottery. I can’t DM you but if you want my slot, let me know. Timeslot details are: From 21/02 11:00 (CET) to 23/02 11:00 (CET)
English
0
0
1
53
Ray [REDACTED]
Ray [REDACTED]@RayRedacted·
Hello friends! The ticket lottery to the Paris 2024 Olympics is now open! There is no cost to enter the lottery, & I am hoping that one of you might be get an opportunity to buy tickets to Speed Climbing; I would absolutely love to watch that event live. tickets.paris2024.org/en/
English
2
2
17
0
Ryan Elkins
Ryan Elkins@ryanelkins·
☁️ This has always been one of my favorite and most valuable security resources since the original release. The approach is relevant even if you do not use AWS. Great job on the updates and the entire document is worth the time to read and implement!
Anna McAbee@amcabee13

Check out the new AWS Security Incident Response whitepaper! It has been completely re-written from previous versions. For details on the update and a link to the whitepaper, see this blog: aws.amazon.com/blogs/security…

English
0
0
2
531
Ryan Elkins
Ryan Elkins@ryanelkins·
@kburakmavzer Let me know if you build something cool with step functions. I have unfinished code using similar approach for automated staging and completion of static analysis/vuln discovery which I think is a gap in this space and something I’d like to see more of.
English
1
0
0
70
Ryan Elkins
Ryan Elkins@ryanelkins·
@JackRhysider Already adding a bunch of new podcasts from other shared lists. Thank you for such a great podcast that I always look forward to!
Ryan Elkins tweet media
English
0
0
3
0
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
Show me your Spotify Wrapped top #5 podcasts you listened to. Maybe we'll discover other good shows to listen to.
English
100
6
155
0
Ryan Elkins retweetledi
Moxie Marlinspike
Moxie Marlinspike@moxie·
One unique thing about software as an engineering discipline is that it offers abstractions which allow ppl to start contributing in the field w/o having to understand the whole field. To be great, though, imo understanding what’s under the abstractions is really important: 1/
English
31
135
749
0
Ryan Elkins
Ryan Elkins@ryanelkins·
The prompt# zine is always so cool and well-done! Thank you @BHinfoSecurity for such a unique resource! My bear vs bear chase card went straight into the card saver. Now to determine where to send it to have it authenticated and graded🥇!
Ryan Elkins tweet mediaRyan Elkins tweet media
English
1
0
2
0