Johnathan Norman

4.4K posts

Johnathan Norman banner
Johnathan Norman

Johnathan Norman

@spoofyroot

Security research and engineering lead at @microsoft. on mastodon: https://t.co/YfJkktByFv and @spoofy.bsky.social not posting here anymore.

Redmond, WA Katılım Aralık 2009
334 Takip Edilen4.5K Takipçiler
Johnathan Norman
Johnathan Norman@spoofyroot·
@decoder_it @splinter_code hrm... I reviewed a fix but perhaps they didn't roll it out yet or even pulled it back because it broke something.. give me a bit to dig.
English
1
0
1
314
Antonio Cocomazzi
Antonio Cocomazzi@splinter_code·
Very interesting post by Microsoft about the internals of the new Admin Protection feature It seems they have patched my SSPI UAC bypass based on NTLM as well as the Kerberos UAC bypass in which both were able to bypass AP as well More details here 👇 techcommunity.microsoft.com/blog/microsoft…
English
2
49
155
11.5K
Johnathan Norman retweetledi
Zack Bornstein
Zack Bornstein@ZackBornstein·
until the day i die i will never understand how this wasn’t the end of it
Zack Bornstein tweet media
English
9.2K
32.9K
296.3K
22.9M
Johnathan Norman retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
WILD: actual photo of Musk-hired door knockers being driven around #Michigan. This group of mostly-black workers were driven in the back of a truck with no seats. They say they were flown in, given unrealistic goals, and threatened with their lodging being cut off & being forced to pay their own way home if they couldn't meet them. Some didn't even know which candidate they were working for. Article by @JakeLahut wired.com/story/elon-mus…
John Scott-Railton tweet media
English
1.4K
10K
31.3K
3.2M
Johnathan Norman retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
NEW: @X is pushing partisan content, most of it supporting Trump & sowing election doubt. @WSJ reporters created new accounts with interests in things like crafts, then observed what content the accounts got recommended. Their "for you" feeds showed pro-Trump content at double the rate of pro-Harris content. By @jackgillum @AlexaCorse & Adrienne Tong wsj.com/politics/elect…
John Scott-Railton tweet mediaJohn Scott-Railton tweet mediaJohn Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
725
4.5K
11.8K
1.2M
Johnathan Norman
Johnathan Norman@spoofyroot·
@kryc_uk Yeah but I get a 3x performance increase by removing the check 🥴
English
2
0
4
263
Gareth Evans
Gareth Evans@kryc_uk·
Pro tip, check buffer length _before_ memmove
Gareth Evans tweet media
English
1
0
8
1.1K
Johnathan Norman retweetledi
Alex Ionescu
Alex Ionescu@aionescu·
It’s wonderful to see what @XenoKovah and his collaborators have built for the community. I always recommend OST2 for my new hires and other juniors, or just anyone trying to get started on a new topic. The courses are excellent. It’s an honor to sponsor the Windows Security Path
Alex Ionescu tweet media
OpenSecurityTraining2@OpenSecTraining

Thanks to Winsider Seminars & Solutions (@yarden_shafir & @aionescu) for Sponsoring #OST2 at the Gold🥇 level! Learn more about them here: windows-internals.com

English
0
16
113
16.4K
Johnathan Norman retweetledi
Ryan M
Ryan M@Grimdoomer·
Here's a time lapse video showing my 360 hypervisor exploit triggering in ~18.5 minutes. This is a pretty average time for the exploit with about 40% success rate. People asked if it works on winchester and I don't think there's any reason it won't but I don't have one to test on
English
36
134
948
73.4K
Harvester
Harvester@Harvesterify·
@spoofyroot Is it expected to be extended to other services in the future, or to be available to non-MSFT services ?
English
1
0
1
554
Johnathan Norman
Johnathan Norman@spoofyroot·
The new account type for services finally landed in WIP. Now when running Windows Protected Print (WPP) the service will run as "Restricted Service" and no longer SYSTEM. There will be a SYSTEM process, but it basically just launches the worker.
Johnathan Norman tweet media
English
2
18
99
27.5K
Johnathan Norman
Johnathan Norman@spoofyroot·
This update will land in non-WIP builds (GA) likely in January. Big thanks to @tiraniddo who gave us early feedback on the design... and shoutout to @Grimdoomer who did the prototype. It was really fun working with the Print team.
English
0
0
15
1.2K
Johnathan Norman
Johnathan Norman@spoofyroot·
@tiraniddo @decoder_it @bopin2020 @splinter_code I wont publicly share my view on sudo. Other than to say i'm glad there's a warning about security risk when enabling it. When Admin protection is enabled, certain sudo configurations simply don't work and return an error. But i hope people just dont enable it.
English
1
0
0
336
James Forshaw
James Forshaw@tiraniddo·
@spoofyroot @decoder_it @bopin2020 @splinter_code Ironically there was a perfect opportunity to remodel the concept of elevation in Windows, by introducing something like sudo. Unfortunately, something "like" sudo was introduced which was just a fancy wrapper around UAC :(
English
1
0
2
323
Andrea P
Andrea P@decoder_it·
Administrator Protection bypass using "Kerberos trick" by @tiraniddo
Andrea P tweet media
English
3
37
162
19.1K
Johnathan Norman
Johnathan Norman@spoofyroot·
@decoder_it @tiraniddo @bopin2020 @splinter_code This is where things get difficult. We fully expect usability challenges and it will take time to really refine the user experience. We're trying to fix decades of decision making around UAC, it will take some time to get right. But this direction is better than the alternative.
English
1
0
1
303
Johnathan Norman
Johnathan Norman@spoofyroot·
@decoder_it @tiraniddo @bopin2020 @splinter_code We wouldn't consider it a bypass if a user must click through a security prompt. We reviewed a large (~100?) number of auto elevated com interfaces, pretty sure ICMLua was one. You should get a prompt, if not we missed something.
English
1
0
1
237
Johnathan Norman retweetledi
Hayden Barnes
Hayden Barnes@unixterminal·
Microsoft has open sourced its new cross-platform virtual machine layer written in Rust: github.com/microsoft/open… From many of the same team who created WSL, including @benhillis.
English
12
473
1.9K
184.6K