Sabitlenmiş Tweet
Luke Turvey
4.7K posts

Luke Turvey
@TurvSec
Professional Hacker. Founder of PenTest reporting tool https://t.co/wU45D4wCUG Collects infosec tools like Pokémon cards at: https://t.co/HUC8oTdRCo
Buckinghamshire Katılım Mayıs 2009
379 Takip Edilen7.7K Takipçiler

@ZackKorman This is hilarious because I was going to comment Darktrace but then my experience of them was from like 10 years ago.
So they're still terrible? 💀
English

It turns out people really don’t like Darktrace.
Zack Korman@ZackKorman
Which cybersecurity companies have the worst sales and marketing tactics? And follow up question: Do you / your company use their products anyway?
English

@IceSolst I cant prove it but honestly, I don't believe this. There's no way that Azerbaijan IDOR was a false positive.
English

For years, Google API keys (AIza...) had little to no real-world impact.
But recently, many of them unexpectedly gained access to Google Gemini.
curl "generativelanguage.googleapis.com/v1/models?key=…"
This appears to be a widespread misconfiguration that can be hunted in the wild.

English

@TurvSec Color scheme is on point and that’s all that matters.
English

Which cybersecurity companies have the worst sales and marketing tactics? And follow up question: Do you / your company use their products anyway?
solst/ICE of Astarte@IceSolst
infosec has a sales problem: bias, lies, lack of nuance, manipulation, extortion, spam, harassment, kicking you out for handing out anti-drink-spiking covers…
English

@Ross_Starkey_ @robprogressive Completely agree. Can’t be having money just appear out of nowhere. Much better when it slowly appears via an ISA instead.
And in fact, I actually make a point of asking for a pay cut whenever I’m offered a raise. Got to stay humble and grind as hard as possible.
English

I don't play the lottery. Never have.
Not even because of the odds. I just think if I ever built real wealth, I'd want to know I earned it. Winning it would feel like cheating.
£58.70 a week, invested into an ISA for 20 years, would change someone's life. And they'd actually understand how they got there.
English

A lady in front of me in the queue spent £58.70 on the lottery
3 people before her all bought lottery tickets, spending £2 to £12
The odds of winning the lottery in the UK are 1 in 45,057,474
This highlights everything that is wrong with how people are taught about money in this country
That £2 or £5 or £10 a week, if invested & compounded over decades, could meaningfully contribute to their future financial security
English

@IAMERICAbooted I just finished an engagement where user accounts are just UN00001 to UN99999 and they have an AD connected login portal externally facing.
They have a 5 wrong password and manual unlock policy 💀
English

@ZackKorman @j2k3k Well now I know its up for grabs, I'm considering making a cybersecurity start up that uses AI.
English

My new company now has a name: Embroidery.
Might even launch an actual product at some point.
embroidery.io
English

@UK_Daniel_Card I think i use Claude almost everyday now. Coding, making gym routines, helping organise things, research. My life has improved considerably lol
English

@UK_Daniel_Card For real though, how incredible is it that we can just make basically anything we dream of now.
Life is so easy
English

@UK_Daniel_Card Yeah but its irrelevant because you didnt code it yourself so its useless and vulnerable and slop.
English

@hetmehtaa This reminds me of when a client got mad at a colleague of mine.
He was using a common wordlist to find web paths and the wordlist contained a bunch of swear words that appeared in the clients logs.
English

spent 3 hours today doing a full penetration test on our production server
found nothing
very secure
went home proud
our client called at 11pm saying their website is showing a directory listing of every internal file including something called "salaries_real_final_2024.xlsx"
i told them that's actually a feature
it's called "transparency"
they did not agree with my interpretation
i have been asked to redo the pentest
i retried the same thing again
found nothing again
i think the issue is on their end honestly
English

@WebSecAcademy Get those alternative IP representations here
vulnsy.com/free-tools/alt…
English

Your SSRF filter blocks 127.0.0.1 and localhost. That's okay! Try these:
2130706433 (decimal)
017700000001 (octal)
127.1 (shorthand)
127.0.0.0 (with subnet tricks)
0x7f000001 (hex)
They all resolve to localhost. Many blacklists don't catch all of them.
Try this technique, and plenty of other SSRF techniques, in our free SSRF labs! portswigger.net/web-security/s…
English

@rezoundous I genuinely dont get why people can't just send each other concise emails to avoid the pointless small talk and other wasted time on calls
English








