cloudsecurityLT's profile picture.

mindesh

@cloudsecurityLT

You might like

If you have UDP 631 accessible from all internet: you probably have much bigger problems than the CUPS vulnerability.

🚨Make sure UDP port 631 is not exposed to the internet!🚨 To check: sudo netstat -tulpn | grep 631. If the output is empty you're good.



mindesh reposted

😂😂

Shefali__J's tweet image. 😂😂

mindesh reposted

Exfiltrating data through audio is not new (e.g. excellent code by @x86matthew) but doing it in pure #PowerShell was fun 😎 1. bin2wav.ps1 creates audio file to be played. 2. wav2bin.ps1 analyzes recorded audio file and re-creates original data. Enjoy: github.com/gtworek/PSBits…


mindesh reposted

7 killer sites that will reveal thousands of free resources (save them):


mindesh reposted

Be a Python Expert in 2023: A roadmap for absolute beginners


mindesh reposted

7 GitHub repositories will make you a standout developer from 99% of people:


mindesh reposted

Becoming a creator in 2023 will change your life. Here are 13 tips to make the switch from a consumer to a creator:


mindesh reposted

What are some tools you can't live without? Here are a few I use: 1. Bpytop: A better version of the Linux `top` command

GrahamHelton3's tweet image. What are some tools you can't live without? Here are a few I use:

1. Bpytop: A better version of the Linux `top` command

mindesh reposted

Do they know what this phrase means?

substitute's tweet image. Do they know what this phrase means?

mindesh reposted

6 GitHub repositories will make you a standout developer from 99% of people:


mindesh reposted

The new cs.github.com search allows for regex, which means brand **new** regex GitHub Dorks are possible! Eg, find SSH and FTP passwords via connection strings with: /ssh:\/\/.*:.*@.*target\.com/ /ftp:\/\/.*:.*@.*target\.com/ #BugBounty #bugbountytips #infosec

BrownBearSec's tweet image. The new cs.github.com search allows for regex, which means brand **new** regex GitHub Dorks are possible! 

Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/ 
/ftp:\/\/.*:.*@.*target\.com/ 

#BugBounty #bugbountytips #infosec

mindesh reposted

Dumping LSASS is such a 2020 move, let me introduce a new CrackMapExec module called Masky developed by @_ZakSec 🎉 If you have admin privilege, the module will impersonate all users connected -> ask a certificate (ADCS) -> retrieve the NT hash using PKINIT 🚀 Crazy module 🪂

mpgn_x64's tweet image. Dumping LSASS is such a 2020 move, let me introduce a new CrackMapExec module called Masky developed by @_ZakSec 🎉

If you have admin privilege, the module will impersonate all users connected -> ask a certificate (ADCS) -> retrieve the NT hash using PKINIT 🚀

Crazy module 🪂

mindesh reposted

1/ Perhaps a lesser known "feature" of Microsoft Authenticator, but the diagnostic data can be very helpful in investigating a compromised #Azure account where MFA is enabled but the user claims not to have confirmed the MFA Consent Prompt. 🧵


mindesh reposted

Free design websites that should be illegal to know - part 2 (mega thread):


mindesh reposted

In 1940, an illegitimate Russian referendum forced my country into decades of terror, subjugation and poverty. That's all I'm going to say about illegitimate Russian referendums.


mindesh reposted

Thanks to @vysecurity I've built for #PingCastleCloud a service to translate DNS to tenantID (no news here) but also from TenantID to a DNS record (exclusive!!!). 7M+ tenants are listed and this database is enriched after each search. tenantresolution.pingcastle.com


mindesh reposted

My top 3 go-to resources for every pentest I perform: cristivlad.substack.com/p/pentestbooks


United States Trends

You might like

Loading...

Something went wrong.


Something went wrong.