Script0mAn's profile picture.

AN

@Script0mAn

AN reposted

Apple released a hearing aids feature for the AirPods Pro a while ago. I bought a pair for grandma, but then realized that the feature was geoblocked in India So we at @_lagrangepoint decided to unblock it. It ended up involving a leaky microwave and building a Faraday cage:

thel3l's tweet image. Apple released a hearing aids feature for the AirPods Pro a while ago. I bought a pair for grandma, but then realized that the feature was geoblocked in India

So we at @_lagrangepoint decided to unblock it. It ended up involving a leaky microwave and building a Faraday cage:

AN reposted

🚨Outlook Zero-Click🚨TLDR; Recommended Steps for Microsoft 365 Admins can be seen in this blog post. ironscales.com/blog/zero-clic… The CVE-2024-30103 vulnerability leverages a flaw in how Microsoft Outlook handles specific types of email content. An attacker can embed malicious…


AN reposted

Lock down those ADCS servers folks! Even templates with just the Server Authentication EKU can cause problems. Enroll for the targets Okta login portal DNS hostname and some DNS poisoning to your malicious server and you've got yourself a FastPass/Passwordless MitM

_EthicalChaos_'s tweet image. Lock down those ADCS servers folks!  Even templates with just the Server Authentication EKU can cause problems.  Enroll for the targets Okta login portal DNS hostname and some DNS poisoning to your malicious server and you've got yourself a FastPass/Passwordless MitM

AN reposted

Nothing fancy here but if you want to dump emails from an Azure tenant through a device code phishing this may help. github.com/Mr-Un1k0d3r/Ms… Bonus feature you can also push your payload on the target tenant and use the shareable link in your weaponized campaign.


AN reposted

CVEMAP Simple #go command line tool for getting information about CVEs: - by ID - by vendor - by product - by severity - by cvss score and much more. github.com/projectdiscove… Creator @pdiscoveryio

cyb_detective's tweet image. CVEMAP

Simple #go command line tool for getting information about CVEs:

- by ID
- by vendor
- by product
- by severity
- by cvss score

and much more.

github.com/projectdiscove…

Creator @pdiscoveryio

AN reposted

Abusing #AzureAD / #EntraID Domain Services part 2 from @Secureworks is out now: Dumping NTHashes from Microsoft Entra ID

Secureworks has discovered that stored Microsoft Entra ID NTHashes can be recovered and decrypted & then used in pass-the-hash attacks. Read our latest Threat Analysis to discover how this happens & how to detect it. scwx.us/cj #azure #cybersecurity

Secureworks's tweet image. Secureworks has discovered that stored Microsoft Entra ID NTHashes can be recovered and decrypted & then used in pass-the-hash attacks. Read our latest Threat Analysis to discover how this happens & how to detect it.
scwx.us/cj
#azure #cybersecurity


AN reposted

Nice catch !

S0ufi4n3's tweet image. Nice catch !

AN reposted

How I just got gained access to 22 unauthorized endpoints across 116 websites (260k endpoints) in about 10 minutes. Use what your comfy with. 👇


AN reposted

Scene in MGM Grand according to a TikTok user who said slots machines down and casino floor empty after cyber attack. She also says staff had to make and distribute physical room keys and an admin error caused her to walk in on another guest. Source: vm.tiktok.com/ZGJnKXd6R/


AN reposted

Microsoft Excel Python has the following registry key setting values HKCU\software\policies\microsoft\office\16.0\excel\security\PythonFunctionWarnings DWORD 0 = All Security Warnings Disabled 1 = Security Warning: Enable-Content 2 = Blocks all Python Execution


AN reposted

As promised, here is a blogpost on SharpSCCMs new AdminService/CMPivot capabilities. The creator of SharpSCCM, @_Mayyhem and I will be at the SpecterOps booth tomorrow @ 11am and ARSENAL @ 11:30am Thursday presenting SCCM takeover and post-ex techniques medium.com/@dlomellini/la…


AN reposted

Uncommon funny cyber related post on LinkedIn. The idea of CISO's doing press briefing post an incident 😂😂


AN reposted

#Moonlighter has reached the @Space_Station! This mini satellite from @AerospaceCorp is the world’s first & only hacking sandbox in space and will allow #cybersecurity professionals and some of the world’s best #hackers to do space-based cyber experiments: issnationallab.org/spx28-moonligh…

ISS_CASIS's tweet image. #Moonlighter has reached the @Space_Station! This mini satellite from @AerospaceCorp is the world’s first & only hacking sandbox in space and will allow #cybersecurity professionals and some of the world’s best #hackers to do space-based cyber experiments: issnationallab.org/spx28-moonligh…

AN reposted

Can't wait to see you get hacked, Moonlighter. ❤️ @defcon @hack_a_sat

#Moonlighter has reached the @Space_Station! This mini satellite from @AerospaceCorp is the world’s first & only hacking sandbox in space and will allow #cybersecurity professionals and some of the world’s best #hackers to do space-based cyber experiments: issnationallab.org/spx28-moonligh…

ISS_CASIS's tweet image. #Moonlighter has reached the @Space_Station! This mini satellite from @AerospaceCorp is the world’s first & only hacking sandbox in space and will allow #cybersecurity professionals and some of the world’s best #hackers to do space-based cyber experiments: issnationallab.org/spx28-moonligh…


100% agree It simply works and doesn’t get in the way.

This is a random reminder to anyone looking to get started in #Linux that I highly recommend @system76 Pop!_OS for stability and usability reasons. It also keeps...getting...prettier.



This account does not have any followers

United States Trends

Loading...

Something went wrong.


Something went wrong.