ProOfConcept9's profile picture.

Mr-PMillz

@ProOfConcept9

Mr-PMillz reposted

⚠️⚠️ CVE-2025-54236: Critical 9.1/10 Flaw in Magento / Adobe Commerce Enables Unauthenticated File-Upload & Account Takeover 🔥Deep Dive: slcyber.io/assetnote-secu… 🎯131k+ Results are found on the en.fofa.info nearly year. 🔗FOFA Link: en.fofa.info/result?qbase64… FOFA Query:…

fofabot's tweet image. ⚠️⚠️ CVE-2025-54236: Critical 9.1/10 Flaw in Magento / Adobe Commerce Enables Unauthenticated File-Upload & Account Takeover
🔥Deep Dive: slcyber.io/assetnote-secu…
🎯131k+ Results are found on the en.fofa.info nearly year.
🔗FOFA Link: en.fofa.info/result?qbase64…
FOFA Query:…

Mr-PMillz reposted

love the name, love the technique. going to check this out

I just released Flareprox 🔥 A Cloudflare based Fireprox alternative that allows you to route HTTP traffic through Cloudflare, to gain mostly unique IP Addresses, to avoid detection and blocks.

TurvSec's tweet image. I just released Flareprox 🔥

A Cloudflare based Fireprox alternative that allows you to route HTTP traffic through Cloudflare, to gain mostly unique IP Addresses, to avoid detection and blocks.
TurvSec's tweet image. I just released Flareprox 🔥

A Cloudflare based Fireprox alternative that allows you to route HTTP traffic through Cloudflare, to gain mostly unique IP Addresses, to avoid detection and blocks.
TurvSec's tweet image. I just released Flareprox 🔥

A Cloudflare based Fireprox alternative that allows you to route HTTP traffic through Cloudflare, to gain mostly unique IP Addresses, to avoid detection and blocks.


Mr-PMillz reposted

Hey folks, THURSDAY - BHIS Webcast Join our free, beginner-friendly one-hour BHIS webcast with security analyst Dale Hobbs. He’ll teach how NetExec tests credentials, finds users and shares, and runs techniques like Pass-the-Hash — no advanced skills required. Whether you’re…

BHinfoSecurity's tweet image. Hey folks,

THURSDAY - BHIS Webcast

Join our free, beginner-friendly one-hour BHIS webcast with security analyst Dale Hobbs.

He’ll teach how NetExec tests credentials, finds users and shares, and runs techniques like Pass-the-Hash — no advanced skills required.

Whether you’re…

Mr-PMillz reposted

Okay folks, the first release of the new #AADInternals OSINT tool requiring authentication is out now: osint.aadinternals.com It is still ugly as hell but should do the trick. To use the tool, you need an Entra ID account with a non-default (.onmicrosoft.com) domain name.

DrAzureAD's tweet image. Okay folks, the first release of the new #AADInternals OSINT tool requiring authentication is out now:
osint.aadinternals.com

It is still ugly as hell but should do the trick.

To use the tool, you need an Entra ID account with a non-default (.onmicrosoft.com) domain name.

As some dipsh*t is again enumerating the whole universe using #AADInternals #OSINT tool, the service is now closed until further notice.

DrAzureAD's tweet image. As some dipsh*t is again enumerating the whole universe using #AADInternals #OSINT tool, the service is now closed until further notice.


Mr-PMillz reposted

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…


Mr-PMillz reposted

frankensteined some code together to make a couple BOFs that set shadowcreds/rbcd for when proxying was acting up...maybe they're useful to you they dont clean up at the moment so that'll have to get added at some point...ops not done yet lol github.com/garrettfoster1…


Mr-PMillz reposted

We've come full circle :) First we had Entra in the Azure portal, and now we have Azure in the Entra portal 🙃

NathanMcNulty's tweet image. We've come full circle :)

First we had Entra in the Azure portal, and now we have Azure in the Entra portal 🙃

Mr-PMillz reposted

hashcat v7.1.0 released! This update includes important bug fixes, new features, and support for new hash-modes, including KeePass with Argon2. Read the full write-up here: hashcat.net/forum/thread-1…

hashcat's tweet image. hashcat v7.1.0 released!

This update includes important bug fixes, new features, and support for new hash-modes, including KeePass with Argon2.

Read the full write-up here: hashcat.net/forum/thread-1…

Mr-PMillz reposted

Workshop happening THIS THURSDAY: ✔️ Pay What You Can ✔️ Collaborative interaction with instructor & fellow students ✔️ Access to course slides for future reference ✔️ Tips, tools, & techniques that can be applied immediately antisyphontraining.com/product/worksh…

Antisy_Training's tweet image. Workshop happening THIS THURSDAY: 

✔️ Pay What You Can
✔️ Collaborative interaction with instructor & fellow students
✔️ Access to course slides for future reference
✔️ Tips, tools, & techniques that can be applied immediately

antisyphontraining.com/product/worksh…

Mr-PMillz reposted

I’m an Incident Responder on the AWS Customer Incident Response Team (CIRT). And I get asked a lot of questions, like: “Where do I even start with incident response in the cloud?” Here’s a beginner-friendly thread on AWS IR tips — with a few lessons I learned 🧵👇


Mr-PMillz reposted

Join us this Friday, July 18th, 11 AM–4 PM ET for the SOC Detection Engineering Crash Course with Hayden Covington from BlackHills Info Security! No experience needed, just bring your curiosity! Register now: antisyphontraining.com/course/worksho…

BHinfoSecurity's tweet image. Join us this Friday, July 18th, 11 AM–4 PM ET for the SOC Detection Engineering Crash Course with Hayden Covington from BlackHills Info Security! No experience needed, just bring your curiosity! Register now: antisyphontraining.com/course/worksho…

Chatbots and Skill Development chatgpt.com/share/6866a6c0…


Mr-PMillz reposted

Join Jennifer Shannon from Secure Ideas for this 2-day training course and by the end, you will be able to conduct a basic API pen test using a systematic approach & industry best practices! Grab your spot here: antisyphontraining.com/course/profess…

BHinfoSecurity's tweet image. Join Jennifer Shannon from Secure Ideas for this 2-day training course and by the end, you will be able to conduct a basic API pen test using a systematic approach & industry best practices!

Grab your spot here: antisyphontraining.com/course/profess…

Mr-PMillz reposted

Did you know that Antisyphon Training is part of the BHIS Family of Companies? Check out all of the Pay-Forward-What-You-Can offerings they have coming up next month! Which one are you most looking forward to? antisyphontraining.com/live-training-…

BHinfoSecurity's tweet image. Did you know that Antisyphon Training is part of the BHIS Family of Companies? 

Check out all of the Pay-Forward-What-You-Can offerings they have coming up next month!

Which one are you most looking forward to?

antisyphontraining.com/live-training-…

Mr-PMillz reposted

Join us for a FREE one-hour Antisyphon Anti-cast with Dorota Kozłowska, on the human side of hacking. Learn how attackers exploit trust through elicitation, pretexting, and manipulation—and how to protect against it. For more information! 👇 antisyphontraining.com/event/anti-cas…...

BHinfoSecurity's tweet image. Join us for a FREE one-hour Antisyphon Anti-cast with Dorota Kozłowska, on the human side of hacking. Learn how attackers exploit trust through elicitation, pretexting, and manipulation—and how to protect against it.
 
For more information! 👇
antisyphontraining.com/event/anti-cas…...

Mr-PMillz reposted

Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d. synacktiv.com/publications/n…


Mr-PMillz reposted

Pentesters: What's the coolest thing you've done with Burp Suite? 💥🖋️ New to the industry? You'll want to make sure you're comfortable with it and BB King has got you covered! THIS Friday, June 13th: antisyphontraining.com/course/worksho…

Antisy_Training's tweet image. Pentesters: What's the coolest thing you've done with Burp Suite? 💥🖋️

New to the industry? You'll want to make sure you're comfortable with it and BB King has got you covered! 

THIS Friday, June 13th: antisyphontraining.com/course/worksho…

Loading...

Something went wrong.


Something went wrong.