SkelSec

6.8K posts

SkelSec banner
SkelSec

SkelSec

@SkelSec

CEO and Co-Founder of Octopwn

Katılım Haziran 2014
444 Takip Edilen11.7K Takipçiler
SkelSec
SkelSec@SkelSec·
@abdo_mhanni @lowercase_drm @0x64616e Nah man, don't try to make my projects mainstream. After the fifth time I'm sure they'll get it right and they won't have to credit me again...
English
1
0
1
27
Abdul Mhanni
Abdul Mhanni@abdo_mhanni·
@lowercase_drm @0x64616e I don’t see why impacket isn’t moving to @SkelSec msldap. They mentioned in response to someone’s PR that they are moving away from ldap3 and improving their own. Kinda weird to reinvent the wheel when msldap already does it all very well
English
1
0
0
28
drm
drm@lowercase_drm·
The conclusion of my last post (offsec.almond.consulting/ldap-authentic…) is « Since a lot of impacket’s examples are based on ldap3, it seems easy to adapt them to work against hardened domain controllers ». Good job @0x64616e!
drm tweet media
English
2
12
48
5.3K
SkelSec retweetledi
Simone Margaritelli
Simone Margaritelli@evilsocket·
Duuuude VulDB is the worst, they made public all 3 of my original disclosures that include the fully working root shell exploits ....
English
3
4
40
11.1K
FooSecn00b
FooSecn00b@foosecn00b·
@SkelSec You’re gonna need a van or a trench coat.
English
1
0
1
68
SkelSec
SkelSec@SkelSec·
Pssst! Hey, kid! Wanna buy SOC2?
English
1
0
27
1.7K
Marcello
Marcello@byt3bl33d3r·
The answer is yes*. Most pentests are for web apps and compliance driven anyway. If you think companies won't jump at the opportunity of cheaper pentests to satisfy their compliance requirements you're deluding yourself (regardless of the AI component). "AI driven" Internal network pentests I'd imagine will be a harder pill to swallow, but it's doable at a technical level with the current generation of LLMs . Red Teaming is a different story.
Medusa@medusa_0xf

Will pentesting be replaced by AI? 🤔

English
17
6
81
15.2K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
@daveaitel We’ve all had infinitely growing backlogs with no incentive to address them. Whatever we were doing wasn’t comprehensive, many things swept under the rug. All of this is inevitable, almost nothing to do with AI. But 14 year olds being able to report bs makes it more annoying.
English
1
1
33
1.2K
Dave Aitel
Dave Aitel@daveaitel·
Fwiw the problem was never that AI slop was going to overwhelm security teams: the problem was that having their hidden technical debt all called in at once was going to overwhelm them. Chrome having as many bugs as it still does is the perfect case example.
English
9
32
178
15.5K
SkelSec
SkelSec@SkelSec·
Ohh... you have reached the API limits, so we replaced your coder with a mental patient who will use half a crayon to randomly change values in your code. (he already ate the other helf)
English
0
0
1
488
SkelSec
SkelSec@SkelSec·
Research workflow: 1. Idea 2. discussions with peers 3. chatting with LLMs 4. feasibility check 5. Airbus guys already did that 5 years ago I'm.... eeehhhh.... (Airbus people doing some really underrated research btw, props to them!)
English
0
1
6
749
SkelSec
SkelSec@SkelSec·
@HackingLZ We have something interesting in this topic but stuck with explaining it to investors in EU so... :(
English
0
0
2
405
Justin Elze
Justin Elze@HackingLZ·
I’m really interested in what happens as places take a lot of investment money to build commodity OffSec LLM backed products, even as the barrier to entry keeps dropping. You eventually end up with what actually matters novel research, deep domain expertise, and humans.
English
9
3
53
5.2K
SkelSec retweetledi
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
WSUS fake updates for LPE or RCE when HTTP is being used? This one took many days and troubleshooting with claude but now we have a C2-Capable tool for the full stack including poisoning plus fake update delivery - the only thing we need is a low privileged C2 session! 🔥
S3cur3Th1sSh1t tweet media
English
5
40
210
13.4K
CDROM
CDROM@CDROM_99·
@SkelSec I mean we need more context first… lol.😂
English
1
0
0
57
SkelSec
SkelSec@SkelSec·
I did a thing, but dunno what to name the project. pls halp
English
2
0
2
1K
SkelSec
SkelSec@SkelSec·
@HackingLZ Change per-token pricing to per-working code pricing
English
0
0
0
259
SkelSec
SkelSec@SkelSec·
@IceSolst My PRs contain two projects worth of changes because I'm financially responsible
English
0
0
2
616
SkelSec retweetledi
Mayfly
Mayfly@M4yFly·
🔥🐉 New GOAD Lab: DRACARYS I’ve just released a new free lab environment on GOAD: DRACARYS. The challenge includes 3 VMs and the objective is simple: Start with no authentication and work your way up to Domain Admin. Have fun exploiting it! 🔥🐉 mayfly277.github.io/posts/Dracarys…
English
9
99
288
16.8K
SkelSec
SkelSec@SkelSec·
That is indeed hilarious...
SkelSec tweet mediaSkelSec tweet media
English
0
0
0
818
SkelSec retweetledi
Richard Johnson
Richard Johnson@richinseattle·
Spread the word! @phrack CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :) phrack.org
Richard Johnson tweet media
English
6
134
250
39.2K
SkelSec retweetledi
OtterSec
OtterSec@osec_io·
We recently achieved guest-to-host escape by exploiting a QEMU 0day. We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive. Writeup coming next week.
English
36
189
1.5K
72.1K
Josh
Josh@passthehashbrwn·
🚨🚨 TOOL 🚨🚨 NMAP is an ADVANCED port scanning tool used by AI HACKING FRAMEWORKS and PENTESTERS alike 🤓 Can scan ALL of YOUR ports 🤖🤖 Generates XML AND greppable REPORTS! 🔥🔥🔥
English
31
12
164
126.6K