akmalhisyam_'s profile picture.

Akmal Hisyam

@akmalhisyam_

Akmal Hisyam reposted

Silence broken. WGMY CTF 2024 is coming soon! 🚩 #WGMY2024

wargamesmy's tweet image. Silence broken. WGMY CTF 2024 is coming soon! 🚩
#WGMY2024

Akmal Hisyam reposted

Tag si Akmal cepat-cepat! Ada burger free di TPCB Cyberjaya Shaftsbury Square @Twt_Cyberjaya

TpcBurger's tweet image. Tag si Akmal cepat-cepat! Ada burger free di TPCB Cyberjaya Shaftsbury Square @Twt_Cyberjaya
TpcBurger's tweet image. Tag si Akmal cepat-cepat! Ada burger free di TPCB Cyberjaya Shaftsbury Square @Twt_Cyberjaya

Akmal Hisyam reposted

I like the project, but I’m not sure everyone remembers what LOL stands for - do people think it stands for ‘Lollection of Lools’?

New LOL project, LOLAD a collection of Active Directory techniques! 👇 lolad-project.github.io

fr0gger_'s tweet image. New LOL project, LOLAD a collection of Active Directory techniques! 👇

lolad-project.github.io


Akmal Hisyam reposted

weak

SaleemUsama's tweet image. weak

Akmal Hisyam reposted

PHP have released a line of sunglasses and they are hilarious 😂 php.net/sunglasses


Akmal Hisyam reposted

In today's WTF?!?!? moment When a ESXi server is domain-joined, it assumes any "ESX Admins" group & its members should have full admin rights. So.... anyone who can create & manage a group in AD, can get full admin rights to the VMware ESX hypervisors! microsoft.com/en-us/security…

PyroTek3's tweet image. In today's WTF?!?!? moment

When a ESXi server is domain-joined, it assumes any  "ESX Admins" group & its members should have full admin rights.

So.... anyone who can create & manage a group in AD, can get full admin rights to the VMware ESX hypervisors!
microsoft.com/en-us/security…

Microsoft has uncovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085, being exploited by threat actors to obtain full administrative permissions on domain-joined ESXi hypervisors and encrypt critical servers in ransomware attacks. msft.it/6012lbTai



Akmal Hisyam reposted

Since I'm 6 drinks in for 20 bucks, let me tell you all about the story of how the first Microsoft Office 2007 vulnerability was discovered, or how it wasn't. This was a story I was gonna save for a book but fuck it, I ain't gonna write it anyways.


Akmal Hisyam reposted

I forked Go's net/http & net/url, and then hot-swapped them in my forked ffuf code. If you're an advanced ffuf user, this will solve some of the limitations you may have run into such as header canonization, invalid URL hex values, and more github.com/sw33tLie/uff #bugbounty

sw33tLie's tweet image. I forked Go's net/http & net/url, and then hot-swapped them in my forked ffuf code.  

If you're an advanced ffuf user, this will solve some of the limitations you may have run into such as header canonization, invalid URL hex values, and more  github.com/sw33tLie/uff

#bugbounty

Akmal Hisyam reposted

Huk aloh, Elon ore Kelate ruponyo

Demo made me cringe



Akmal Hisyam reposted

FOSS moment

BushidoToken's tweet image. FOSS moment

Akmal Hisyam reposted

So i was bored and develop this! lekirframework.com Vulnerable by design to help people learn about web security Choose your flavour Source code - deploy yourself Vm image - minimal setup Docker - minimal setup

Firdaus_Khai's tweet image. So i was bored and develop this!

lekirframework.com

Vulnerable by design to help people learn about web security

Choose your flavour
Source code - deploy yourself
Vm image - minimal setup
Docker - minimal setup
Firdaus_Khai's tweet image. So i was bored and develop this!

lekirframework.com

Vulnerable by design to help people learn about web security

Choose your flavour
Source code - deploy yourself
Vm image - minimal setup
Docker - minimal setup

Akmal Hisyam reposted

Discover LEKIR Framework Your Playground for Understanding and Defending Against Web Vulnerabilities lekirframework.com


Akmal Hisyam reposted

Tenang. Trust me, it's not PADU 😅

xanda's tweet image. Tenang. Trust me, it's not PADU 😅

Akmal Hisyam reposted

holy fuck there's a list of victims too

AzakaSekai_'s tweet image. holy fuck there's a list of victims too

Akmal Hisyam reposted

Okay but this version is exponentially better

22 years ago today, vanessa carlton released ‘a thousand miles’. a classic.



Akmal Hisyam reposted

In 1631, a Dutch guy published a book about his travels to SE Asia and it brought the word "orangutan" into Western languages. Its description of orangutans is amazing

depthsofwiki's tweet image. In 1631, a Dutch guy published a book about his travels to SE Asia and it brought the word "orangutan" into Western languages. Its description of orangutans is amazing

And RED Team

Been in penetration testing for 12 years. Still don't know what a "PEN Test" is.



akmalhisyam_'s tweet image.

You're looking at the first direct image of another planetary system located about 300 light-years away around a star like our Sun.

MAstronomers's tweet image. You're looking at the first direct image of another planetary system located about 300 light-years away around a star like our Sun.


Akmal Hisyam reposted

Sorry guys. Me and my big mouth😅 github.com/GhostPack/Rube…

Found a funny way to detect Rubeus. There's a typo in the process name used when calling LsaRegisterLogonProcess, which shows up in the Windows audit logs. Not sure if that was intentional given the code comment right next to it.

_RastaMouse's tweet image. Found a funny way to detect Rubeus. There's a typo in the process name used when calling LsaRegisterLogonProcess, which shows up in the Windows audit logs. Not sure if that was intentional given the code comment right next to it.
_RastaMouse's tweet image. Found a funny way to detect Rubeus. There's a typo in the process name used when calling LsaRegisterLogonProcess, which shows up in the Windows audit logs. Not sure if that was intentional given the code comment right next to it.


Loading...

Something went wrong.


Something went wrong.