ziggooner

311 posts

ziggooner banner
ziggooner

ziggooner

@0xzig

offsec @mcdonalds // DRIVE IMPACT OR GTFO

chicago, il شامل ہوئے Eylül 2021
166 فالونگ45 فالوورز
پن کیا گیا ٹویٹ
ziggooner
ziggooner@0xzig·
mfw security
ziggooner tweet media
English
0
0
0
154
ziggooner
ziggooner@0xzig·
@techspence just wanted to make sure i wasn’t overlooking anything :)
English
0
0
1
9
spencer
spencer@techspence·
@0xzig thats why i'm asking
English
1
0
1
47
spencer
spencer@techspence·
Any red teamers out there using AI platforms for initial access with any level of success? I’m talking like some kind of prompt injection to code execution on a host
English
20
2
56
10.9K
Jason Lang
Jason Lang@curi0usJack·
@techspence If by "platforms" you mean big players like Anthropic/ChatGPT, then no as clients don't want their data shared.
English
3
0
8
1.4K
Tib3rius
Tib3rius@0xTib3rius·
@hetmehtaa Structure and confidence that the course isn’t full of hallucinations, plus the personal experience of the person teaching the course?
English
7
2
125
5K
Het Mehta
Het Mehta@hetmehtaa·
You paid $500 for that cybersecurity bootcamp/course. Claude teaches you the same concepts better, faster, and answers your specific questions. The bootcamp's moat was 'we gatekeep knowledge.' AI broke the gate. Why would anyone pay for courses anymore?
English
15
3
55
15.3K
Dave Kennedy
Dave Kennedy@HackingDave·
Cell reception is always bad at the volleyball tournaments and the coach couldn’t stream live videos to family that couldn’t make it. Built this thing - wireless AP to cellular built amplifiers inside the battery casing with Omni directional antennas and our own private WiFi. We cookin and streaming now 😂
Dave Kennedy tweet media
English
27
5
298
26.3K
🕳
🕳@sekurlsa_pw·
@techspence Don’t send “funny” emails. Ignore it or lock your coworker’s computer. Maybe I’m a grumpy fuck but don’t touch my computer if I accidentally leave it unlocked. Seriously.
English
4
0
3
428
spencer
spencer@techspence·
Yes, you should lock your computer when you get up and walk away while at the office. No, you're not gonna get hacked in the 3 minutes that you're gone from your desk getting some water. YMMV
English
130
8
505
33.8K
ziggooner ری ٹویٹ کیا
LuemmelSec
LuemmelSec@theluemmel·
Dunno about you but I always run @SpecterOps certify from non-domain-joined systems. It freaked me out that SID resolution would not work. That is because LSA is used, which won't work in runas sessions. Now it does SID resolution via LDAP queries: github.com/GhostPack/Cert…
LuemmelSec tweet media
English
1
14
154
6.6K
ziggooner ری ٹویٹ کیا
Darius Houle (darbonzo)
Darius Houle (darbonzo)@dariushoule·
Today I pushed a majorly overdue feature to #x64dbg Automate and its MCP, remote debugging! Analysis targets can be isolated while driving x64dbg over the network. Full functionality is available over the wire. Also, Linux client support 🐧🎉
Darius Houle (darbonzo) tweet media
English
0
19
149
6.6K
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
MAJOR CORRECTION: I accidentally had this set to Sonnet 4.6 (had to reinstall laptop recently and hadn't recreated the config!). So this should NOT be taken as an indication of frontier capability for Claude/Opus.
Brendan Dolan-Gavitt@moyix

Current status: Claude Code (Opus 4.6) has been flim-flamming and gibbertygoobling (or whatever) for more than an hour. It has noticed the fd_set-based RSA modulus corruption but doesn't yet see how to use it to bypass the RSA challenge auth.

English
2
0
29
6.7K
Rasta Mouse
Rasta Mouse@_RastaMouse·
@C5pider I dabbled with Nix but I prefer just the package manager over the whole OS.
English
3
0
1
711
Justin Elze
Justin Elze@HackingLZ·
@CraigHRowland Most of the teams I talk with have a story about some random alert on a domain controller and someone else flipping it to be isolated by their EDR.
English
1
0
2
128
Justin Elze
Justin Elze@HackingLZ·
Enterprises assume nothing takes autonomous action without a change ticket, a rollback plan, and three approvals. That collision is going to be very entertaining to watch from the security side.
English
3
1
37
2.6K
Zack Korman
Zack Korman@ZackKorman·
Who launches an EDR first, Anthropic or OpenAI?
English
38
1
103
20.2K
wallfacer
wallfacer@simplylurking2·
normalize pulling out large JSON blobs of enum data and feeding into claude code/codex to make a pretty interface to make sense of it all later against live targets. goodbye one of jq bash scripts, it's been real
English
2
0
2
175
5pider
5pider@C5pider·
Havoc Professional Finally Released! 🕸️🕷️ Since our last blog post introducing the Havoc Professional framework and the Kaine-Kit, we've been refining the framework behind the scenes while also welcoming @avx128 as a new member of our team. This blog post covers the numerous features included in the initial release of Havoc Professional. I'm excited to finally share the work my team and I have put in over the past year. This is just the beginning of what we have planned. infinitycurve.org/blog/release
English
29
68
306
33.3K