Tweet ghim
Crypt0s
9K posts

Crypt0s
@Crypt0s
Application security guy who dabbles in radios, networking, protocols…pretty much anything anyone puts in front of me to hack!
Maryland, USA Tham gia Temmuz 2009
897 Đang theo dõi2.1K Người theo dõi
Crypt0s đã retweet
Crypt0s đã retweet
Crypt0s đã retweet

OST cannot be stopped. Here is a technique we tested internally 9 months ago: blocking EDR telemetry by leveraging the Windows Filtering Platform. Considered it so evil that we didn't publish it that time. It was pointless, now here it is by @netero_1010: github.com/netero1010/EDR…
English
Crypt0s đã retweet

Discovered and exploited an arbitrary file delete vulnerability that lead to SYSTEM level privileges.
Thanks to the goat @filip_dragovic.

English
Crypt0s đã retweet


If you are a 'redteamer' that doesn't open source your offensive tools, consider that your undisclosed techniques may be used by Russia against Ukraine. Think how hard it will be to stop something they know nothing about. Consider the ethical implications of that.
Steve Eckels@stevemk14ebr
If you are a 'redteamer' that open sources your offensive tools, consider that your malware may be used by Russia against Ukraine. And the ethical implications of that. In case writing open source malware was 'grey' for you.
English

@greybrimstone I have no idea but people are saying you’re either a lawyer or a boomer if you do it and I’m like…..???
GIF
English

@Crypt0s Right? When did this become a thing and why?!
English
Crypt0s đã retweet

Red, Blue, and Purple LDAP Queries.
Quite useful.
politoinc.com/post/ldap-quer…
English
Crypt0s đã retweet

New blog: Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust
I teased this a bit during my Windows Hello talks, now found some time to write about this interesting technique. Also contains defenses and detection opportunities.
dirkjanm.io/obtaining-doma…
English

Sorry GreyNoise is down right now! We're experiencing one of the shittiest, most mickey mouse DDoS we've ever seen, but sadly it's working. We'll be back up soon, promise 🫡
status.greynoise.io


English

A certificate reseller bypassed the HTTP verification of the ACME cert protocol by using a remote code injection in ACME.sh to write their own
When called out they are surprised Pikachu and say they didn’t know what an RCE was before this.
😬
Ryan Castellucci@ryancdotorg
🍿🍿🍿 CA dId NoThInG wRoNg (they built a product around an 0day in a certificate management tool, got caught, and I'm hoping this results in a root CA being incinerated because that would be funny) groups.google.com/a/mozilla.org/…
English
Crypt0s đã retweet
















