George Noseevich

707 posts

George Noseevich

George Noseevich

@webpentest

Katılım Temmuz 2012
101 Takip Edilen736 Takipçiler
George Noseevich
George Noseevich@webpentest·
Hey @h2hconference, on your CFP page you have 2 deadlines - Oct 1 for proposals and Oct 17 for slides. Does that mean that you expect both proposals and slides before you make the decision about acceptance? Or only those who've received an acceptance note need to submit slides?
English
2
0
2
241
George Noseevich retweetledi
Xappy
Xappy@theXappy·
Thing I learned today: Decrypting arbitrary TLS sessions on Windows (for code utilizing schannel): #11-what-is-schannel" target="_blank" rel="nofollow noopener">b.poc.fun/decrypting-sch… Great explanation, and very easy to use code, by @webpentest
Xappy tweet media
English
0
1
1
190
George Noseevich
George Noseevich@webpentest·
@alterm4nn @alexx_mikh @annita_oreo @andrey_sitnik Понятно что почти всегда можно извернуться (обычно с потерей и в деньгах и во времени и в удобстве). Алсо, возвращаясь к исходной постановке вопроса - где ты щас валютный кэш найдешь?)
Русский
1
0
0
0
George Noseevich
George Noseevich@webpentest·
@alterm4nn @alexx_mikh @annita_oreo @andrey_sitnik Далеко не везде можно заплатить кешем есличо) Попробуй арендовать в европе машину за кеш, в большинстве мест это просто невозможно.
Русский
1
0
1
0
George Noseevich
George Noseevich@webpentest·
@SVSoldatov @rostov_prizrak Не трудитесь, знаю я такие "объяснения". Нацисты, кстати, уже пытались такое объяснять, только мир им в конце концов объяснил другое.
Русский
1
0
0
0
Sergey Soldatov
Sergey Soldatov@SVSoldatov·
@webpentest @rostov_prizrak Не путайте эволюцию и деградацию. Критерий очень прост: все, что ведёт к исчезновению Человечества - деградация, а то что к преувеличению и процветанию - эволюция, принципы которой вошли в этику, мораль, заповеди. Надо объяснять, что мужеложство ведёт к исчезновению Человечества?
Русский
1
0
0
0
George Noseevich
George Noseevich@webpentest·
@SVSoldatov @rostov_prizrak "Сегодня ты играешь джаз, а завтра родину продашь". Ксенофобия гораздо ближе к насилию, чем нестандартные сексуальные предпочтения.
Русский
1
0
0
0
Sergey Soldatov
Sergey Soldatov@SVSoldatov·
@rostov_prizrak Да, от мужеложства до насилия над детьми - один шаг
Русский
1
0
0
0
George Noseevich
George Noseevich@webpentest·
@Minions87705924 This might be because in win10 it is an experimental unsupported feature that you have to manually enable.
English
0
0
0
0
KrnObj
KrnObj@KrnObj·
@webpentest Yes, you are right.  But I see  #tls-protocol-version-support" target="_blank" rel="nofollow noopener">docs.microsoft.com/en-us/windows/…  This link is shown in the win11 official support, so more confused
English
1
0
0
0
George Noseevich
George Noseevich@webpentest·
Some time ago I had a task where I needed to extract TLS session keys from win apps that use schannel (i.e. mstsc). Did some reversing and ended up creating a frida script that hooks key creation in lsass. Feedback welcome! b.poc.fun/sslkeylog-for-…
English
3
1
5
0
George Noseevich
George Noseevich@webpentest·
@Minions87705924 Hi! Win10 also supports TLS1.3 starting from 1909. See #transport-layer-security-tls" target="_blank" rel="nofollow noopener">docs.microsoft.com/en-us/windows/…. Not sure about server versions though.
English
1
1
0
0
KrnObj
KrnObj@KrnObj·
@webpentest Hi, I read your article on "Decrypting Schannel TLS", I found that the part that wants to test Windows TLS1.3 can only be turned on on Windows 11 or Windows Server 2022?  Is that so?
English
1
0
0
0
George Noseevich
George Noseevich@webpentest·
@SVSoldatov "дальше - раскрутит" - если повезет =D По факту далеко не все и далеко не всегда "раскручивают". А еще можно специально шуметь не там, где реальная движуха, тогда пока будут "раскручивать" не с того конца, все уже закончится)
Русский
1
0
1
0
Sergey Soldatov
Sergey Soldatov@SVSoldatov·
Нас пугают, что атакующему для взлома достаточно успеха однажды, а защитнику надо быть успешным всегда Но на практике по-другому: атакующему надо оставаться незаметным на всех этапах атаки, а защитнику достаточно его обнаружить однажды на любом этапе, а дальше - раскрутит!
Русский
2
1
4
0
George Noseevich
George Noseevich@webpentest·
@c3c Awesome work, considering there are no docs for AD Explorer snapshots!
English
0
0
1
0
George Noseevich
George Noseevich@webpentest·
@exploitph @_nwodtuhs I have to say, for the work I do most of the time, your research is more important. As definitely more fun to repro and study! That said, the lifespan of the bug will be limited for most orgs due to updates, and log4j vuln in internal nets is likely to stay literally forever.
English
0
0
1
0
Charlie Clark
Charlie Clark@exploitph·
@_nwodtuhs log4j vuln had to happen at the same time I released my research :'-(
English
6
0
40
0
George Noseevich
George Noseevich@webpentest·
@a66ot @InfoSecDJ @Hacker0x01 @Bugcrowd I'm perfectly aware of that, but ppl from MC were like: google your name name => see the org name => nah fuck it we have a reason to not communicate and not lose face. So I understand their though process, but this doesn't make their decisions any less dumb
English
0
0
1
0
Timur Yunusov
Timur Yunusov@a66ot·
step 1. I Approached MasterCard using any possible channels to show them vulnerabilities in their tokenization services Step 2. MC had fixed these issues silently without informing me. Step 3. I decided to stretch myself and used @Bugcrowd to deliver my findings to MC
English
1
1
18
0
George Noseevich
George Noseevich@webpentest·
@a66ot @InfoSecDJ @Hacker0x01 @Bugcrowd Have any business with sanctioned ppl or orgs = suffer penalties and fines from govt, and also bad PR among potential clients. That is how sanctions are designed to work - 1% is legally prohibited from having business, other 99% just fear and don't want to bother.
English
1
0
0
0
Timur Yunusov
Timur Yunusov@a66ot·
@InfoSecDJ @Hacker0x01 @Bugcrowd Oh shit. Don't tell me that unicorns also don't exist 😂😂😂 But ok, practically, how the ban of bug submissions "due to sanctions" make any business more profitable?
English
1
0
0
0
Timur Yunusov
Timur Yunusov@a66ot·
After a conversation with @stamparm about passion and CTF and what drives whom, not being the biggest fan of CTFs I found a lot of similarities and key differences with my own passion - security research:
English
2
0
3
0
George Noseevich
George Noseevich@webpentest·
@a66ot Sincerely though, how do people use an 0day in an engagement without disclosing? What will go in the report as an entry vector? Or are 'private pentesters' just another name for criminals? So many questions.
English
0
0
0
0
George Noseevich retweetledi
Bushwhackers
Bushwhackers@BushwhackersCTF·
Thanks to @hackerdom and all participating teams for #ructf! It has been fun, as always.
English
0
2
6
0
Ed Targett
Ed Targett@editortargett·
@webpentest That's bouncing. I'm on ed at thestack dot technology...
English
1
0
0
0
Ed Targett
Ed Targett@editortargett·
@webpentest Hi George. I'd like to talk to you about '22005. Possible to pop me a DM please?
English
1
0
0
0