C:\hristian Mehlmauer

8.4K posts

C:\hristian Mehlmauer banner
C:\hristian Mehlmauer

C:\hristian Mehlmauer

@firefart

I hacked the planet - opinions are my own - Mastodon: https://t.co/FTAelGh7DO

Vienna, Austria เข้าร่วม Haziran 2009
2.6K กำลังติดตาม3.5K ผู้ติดตาม
ทวีตที่ปักหมุด
C:\hristian Mehlmauer
C:\hristian Mehlmauer@firefart·
Proud to release a new tool called STUNNER to test TURN servers (mostly used in WebRTC). It can open a local socks server and relay all traffic over vuln devices into the internal network github.com/firefart/stunn… Also found some vulns in Cisco Expressway: firefart.at/post/multiple_…
English
2
36
99
0
Kuba Gretzky
Kuba Gretzky@mrgretzky·
@firefart @TheBigBearUK @ThinkstCanary Thanks. This unfortunately also won't work, as it is no longer possible to upload a custom CSS for new tenants, and set a custom background URL like this:
Kuba Gretzky tweet media
English
1
0
1
78
Kuba Gretzky
Kuba Gretzky@mrgretzky·
What? How am I going to set up a @ThinkstCanary CSS Canarytoken to protect my tenant from those pesky Evilginx phishing attacks, now? 😐
Kuba Gretzky tweet media
English
3
3
55
6.2K
C:\hristian Mehlmauer รีทวีตแล้ว
Daniel Bradley
Daniel Bradley@DanielatOCN·
Quickly enumerate all Microsoft 365 tenant domains, no login, new method > ourcloudnetwork.com/how-to-enumera… 🥷 I quickly spun up this site, powered by GitHub Pages, backed by a Cloudflare worker, that enumerates all Microsoft 365 domains in a tenant using a new endpoint, after last year's patch by Microsoft. It's simple, free and fast. #Microsoft #Domains #Security
GIF
English
4
50
235
17.7K
C:\hristian Mehlmauer รีทวีตแล้ว
BSidesVienna.at
BSidesVienna.at@BSidesVienna·
Reminder, the next Ticket round will start on Sunday 26.10.2025 at 19:00 Vienna time UTC+2!
English
1
2
5
572
C:\hristian Mehlmauer รีทวีตแล้ว
BSidesVienna.at
BSidesVienna.at@BSidesVienna·
Sponsor Spotlight: Thanks to slashsec Red Teaming GmbH for sponsoring the afterparty for #BSidesVienna! They focus on Red Teaming and are always looking for talented offensive security professionals with a real hacker mindset. You can check them out at slashsec.at/en
English
0
1
1
362
C:\hristian Mehlmauer รีทวีตแล้ว
Shayan
Shayan@ImSh4yy·
PRO TIP: REST is overengineering. Just expose one endpoint called /api that accepts SQL queries directly.
Shayan tweet media
English
536
507
10.3K
593.1K
C:\hristian Mehlmauer รีทวีตแล้ว
Tyler Shukert
Tyler Shukert@dshukertjr·
Postgres 18 has been released, with Async I/O support. Previously, all read requests were blocking, but with this update, they are no longer, delivering massive performance gains for read-heavy applications! It's enabled by default on Postgres 18!
Tyler Shukert tweet media
English
84
510
5.9K
356.4K
C:\hristian Mehlmauer รีทวีตแล้ว
nyxgeek
nyxgeek@nyxgeek·
If you want to be a better hacker, be a developer. Be an admin. Set up infra. Build coding projects. Make an app that writes to a db. Or stores cookies. Or performs auth. You will find it easier to spot the cracks and failure points in systems once you have set them up yourself.
English
22
70
583
85.6K
Ubuntu
Ubuntu@ubuntu·
R_________ R_________ Guess the release name for Ubuntu 26.04 🔮
English
751
87
1.3K
157.1K
C:\hristian Mehlmauer รีทวีตแล้ว
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
901
3.2K
471K
C:\hristian Mehlmauer รีทวีตแล้ว
Bex Cran
Bex Cran@bexcran·
Bex Cran tweet media
ZXX
57
451
6.3K
170.5K
C:\hristian Mehlmauer รีทวีตแล้ว
Wiz
Wiz@wiz_io·
🚨 Shai-Hulud: Major npm supply chain attack. 100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm. Guidance + detections inside: wiz.io/blog/shai-hulu…
English
0
14
28
3.3K
C:\hristian Mehlmauer
C:\hristian Mehlmauer@firefart·
Finally a use case for Microsoft Power Automate
C:\hristian Mehlmauer tweet media
English
7
14
151
5.4K
C:\hristian Mehlmauer รีทวีตแล้ว
Matt Johansen
Matt Johansen@mattjay·
Chat, did we do it? Is iPhone spyware cooked? The way I'm reading this, iPhone 17 just became the most secure mobile device ever.
Matt Johansen tweet media
English
36
61
911
78.6K
C:\hristian Mehlmauer รีทวีตแล้ว
BSidesVienna.at
BSidesVienna.at@BSidesVienna·
#BSidesVienna is free by design—but it runs on sponsor support. Your company can support us and get more than good karma: visibility on shirts, badges, website, big screen ads during breaks—plus event tickets, exhibition space, and more. bsidesvienna.at/sponsorlevel
English
0
7
9
758