Luke Turvey

4.7K posts

Luke Turvey banner
Luke Turvey

Luke Turvey

@TurvSec

Professional Hacker. Founder of PenTest reporting tool https://t.co/wU45D4wCUG Collects infosec tools like Pokémon cards at: https://t.co/HUC8oTdRCo

Buckinghamshire Katılım Mayıs 2009
379 Takip Edilen7.7K Takipçiler
Sabitlenmiş Tweet
Luke Turvey
Luke Turvey@TurvSec·
VULNSY - A Pentest Reporting Platform for Security Teams Built by pentesters, for pentesters.
English
1
2
16
47.5K
Luke Turvey
Luke Turvey@TurvSec·
@ZackKorman This is hilarious because I was going to comment Darktrace but then my experience of them was from like 10 years ago. So they're still terrible? 💀
English
1
0
2
139
Luke Turvey
Luke Turvey@TurvSec·
@IceSolst I cant prove it but honestly, I don't believe this. There's no way that Azerbaijan IDOR was a false positive.
English
0
0
6
1.2K
solst/ICE of Astarte
Claude is CRAZY here are all my hackerone payouts just from today
solst/ICE of Astarte tweet media
English
37
18
640
35.7K
Shad0w
Shad0w@Itx_Shad0w·
For years, Google API keys (AIza...) had little to no real-world impact. But recently, many of them unexpectedly gained access to Google Gemini. curl "generativelanguage.googleapis.com/v1/models?key=…" This appears to be a widespread misconfiguration that can be hunted in the wild.
Shad0w tweet media
English
9
17
212
5.8K
Zack Korman
Zack Korman@ZackKorman·
Niche post, but: Anthropic’s audit logs for Claude Code don’t tell you enough to detect misaligned / malicious behavior. You unfortunately need to use hooks instead to get the necessary data.
English
22
7
117
11.8K
Zack Korman
Zack Korman@ZackKorman·
@TurvSec Color scheme is on point and that’s all that matters.
English
1
0
4
1.1K
Luke Turvey
Luke Turvey@TurvSec·
@Ross_Starkey_ @robprogressive Completely agree. Can’t be having money just appear out of nowhere. Much better when it slowly appears via an ISA instead. And in fact, I actually make a point of asking for a pay cut whenever I’m offered a raise. Got to stay humble and grind as hard as possible.
English
0
0
0
43
Ross Starkey
Ross Starkey@Ross_Starkey_·
I don't play the lottery. Never have. Not even because of the odds. I just think if I ever built real wealth, I'd want to know I earned it. Winning it would feel like cheating. £58.70 a week, invested into an ISA for 20 years, would change someone's life. And they'd actually understand how they got there.
English
6
0
6
3.9K
Rob Moore
Rob Moore@robprogressive·
A lady in front of me in the queue spent £58.70 on the lottery 3 people before her all bought lottery tickets, spending £2 to £12 The odds of winning the lottery in the UK are 1 in 45,057,474 This highlights everything that is wrong with how people are taught about money in this country That £2 or £5 or £10 a week, if invested & compounded over decades, could meaningfully contribute to their future financial security
English
261
19
341
85.9K
Luke Turvey
Luke Turvey@TurvSec·
@IAMERICAbooted I just finished an engagement where user accounts are just UN00001 to UN99999 and they have an AD connected login portal externally facing. They have a 5 wrong password and manual unlock policy 💀
English
1
0
0
28
EZ
EZ@IAMERICAbooted·
Uncomfortable reminder: real attackers dont care about locking users out. They'll just wait until theyre reset and try again :p
English
2
1
19
682
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Science says: don’t get a job in cybersecurity 😅😆
mRr3b00t tweet media
English
10
2
51
2.4K
Luke Turvey
Luke Turvey@TurvSec·
@ZackKorman @j2k3k Well now I know its up for grabs, I'm considering making a cybersecurity start up that uses AI.
English
0
0
2
27
Zack Korman
Zack Korman@ZackKorman·
My new company now has a name: Embroidery. Might even launch an actual product at some point. embroidery.io
English
43
8
139
11.9K
Luke Turvey
Luke Turvey@TurvSec·
Read yesterday that @grok now analyses all posts to build a great timeline. Looks like its going well @elonmusk
Luke Turvey tweet media
English
1
0
2
106
Luke Turvey
Luke Turvey@TurvSec·
@UK_Daniel_Card I think i use Claude almost everyday now. Coding, making gym routines, helping organise things, research. My life has improved considerably lol
English
0
0
0
80
mRr3b00t
mRr3b00t@UK_Daniel_Card·
used claude to make a tool to extract and decrypt a unifi backup and then produce an html report.
mRr3b00t tweet media
English
4
2
35
5.3K
Sick
Sick@sickdotdev·
Prove me wrong: Vibe coding = security risks
English
152
3
104
9.3K
Luke Turvey
Luke Turvey@TurvSec·
@UK_Daniel_Card For real though, how incredible is it that we can just make basically anything we dream of now. Life is so easy
English
1
0
1
34
Luke Turvey
Luke Turvey@TurvSec·
@UK_Daniel_Card Yeah but its irrelevant because you didnt code it yourself so its useless and vulnerable and slop.
English
2
0
2
185
Luke Turvey
Luke Turvey@TurvSec·
@hetmehtaa This reminds me of when a client got mad at a colleague of mine. He was using a common wordlist to find web paths and the wordlist contained a bunch of swear words that appeared in the clients logs.
English
0
0
2
1.5K
Het Mehta
Het Mehta@hetmehtaa·
spent 3 hours today doing a full penetration test on our production server found nothing very secure went home proud our client called at 11pm saying their website is showing a directory listing of every internal file including something called "salaries_real_final_2024.xlsx" i told them that's actually a feature it's called "transparency" they did not agree with my interpretation i have been asked to redo the pentest i retried the same thing again found nothing again i think the issue is on their end honestly
English
4
0
82
13.6K
Web Security Academy
Web Security Academy@WebSecAcademy·
Your SSRF filter blocks 127.0.0.1 and localhost. That's okay! Try these: 2130706433 (decimal) 017700000001 (octal) 127.1 (shorthand) 127.0.0.0 (with subnet tricks) 0x7f000001 (hex) They all resolve to localhost. Many blacklists don't catch all of them. Try this technique, and plenty of other SSRF techniques, in our free SSRF labs! portswigger.net/web-security/s…
English
3
26
268
12.3K
Luke Turvey
Luke Turvey@TurvSec·
@rezoundous I genuinely dont get why people can't just send each other concise emails to avoid the pointless small talk and other wasted time on calls
English
0
0
0
45
Tyler
Tyler@rezoundous·
I genuinely don’t get why people use zoom over google meet
English
108
6
197
17.5K