cwinfosec's profile picture. Profile pic by @infosecart

All interactions on this platform are my personal opinions.

cwinfosec

@cwinfosec

Profile pic by @infosecart All interactions on this platform are my personal opinions.

Pinned

youtube.com/watch?v=tn3xd9… Hot off the card! Today we take on the high difficulty blind SQL injection challenge on DVWA and discuss the concepts of binary search

cwinfosec's tweet card. Blind SQL Injection 0x3a - DVWA (High)

youtube.com

YouTube

Blind SQL Injection 0x3a - DVWA (High)


cwinfosec reposted

Just pushed my latest BYOVD read and write primitive PoCs to GitHub. The repo includes proof of concept code for evading different types of defenses. github.com/0xJs/BYOVD_rea…


415-344-0333 is the number to call if @Nextdoor somehow got your data, they absolutely LOVE phone support


cwinfosec reposted

"humans cannot do more than 5 hours of creative work a day" i cannot believe how many people believe this statement. absolute lemming behavior


cwinfosec reposted

I'm happy to finally release NovaHypervisor! NovaHypervisor is a defensive hypervisor with the goal of protecting AV/EDR vendors and crucial kernel structures that are currently uncovered by VBS and PatchGuard. Full explanation below 1/6. github.com/Idov31/NovaHyp…


👇 I can personally confirm that @0xTib3rius has given me excellent career advice that helped me navigate the job market, and this seems like a really cool opportunity to get plugged in with him while you're at DEFCON

If you're at DEF CON and new to the industry or looking for early career advice, make sure you come to this panel I'm part of! 👀

0xTib3rius's tweet image. If you're at DEF CON and new to the industry or looking for early career advice, make sure you come to this panel I'm part of! 👀


Hello @OpenAI I had an expectation when I click "Delete" that my account would be deleted, not deactivated. I want my account deleted, not deactivated. Please ensure that when customers click something that says "delete" that it actually does what it says.

cwinfosec's tweet image. Hello @OpenAI I had an expectation when I click "Delete" that my account would be deleted, not deactivated. I want my account deleted, not deactivated. Please ensure that when customers click something that says "delete" that it actually does what it says.

Devs really need to stop baking in annoying, incessant, nuisance ass pop-ups into every god damn app


cwinfosec reposted

Just released a WinDbg extension to read the IDT :) github.com/winterknife/EV…

_winterknife_'s tweet image. Just released a WinDbg extension to read the IDT :)
github.com/winterknife/EV…

It's the weekend...PUT. THE KEYBOARD. DOWN!


cwinfosec reposted

🔥 BYPASS WINDOWS DEFENDER XOR-obfuscate a Sliver C2 payload on Kali, forge a stealth C++ loader, and drop a reverse shell on Win10 in seconds. OUT NOW: youtu.be/lC9zh3_S-zg

Cyb3rMaddy's tweet image. 🔥 BYPASS WINDOWS DEFENDER

XOR-obfuscate a Sliver C2 payload on Kali, forge a stealth C++ loader, and drop a reverse shell on Win10 in seconds.

OUT NOW: 
youtu.be/lC9zh3_S-zg

cwinfosec reposted

🧵How to get into the RF world: a short thread for beginners. As promised, here’s my tips to get into RF as a hobbyist/beginner. Disclaimer: RF/Radio are my hobbies, but I'm not a professional RF engineer (My profession is “security”, and I studied computer science; I use RF/SDR…

MehdiHacks's tweet image. 🧵How to get into the RF world: a short thread for beginners.
As promised, here’s my tips to get into RF as a hobbyist/beginner.
Disclaimer: RF/Radio are my hobbies, but I'm not a professional RF engineer (My profession is “security”, and I studied computer science; I use RF/SDR…

I've got too many DMs asking about how to get into the RF world, and also how to get started with hardware security. I always replied individually, but then noticed that a major part of the answer is duplicated and common, so I will now work on 2 threads on these 2 topics.



cwinfosec reposted

Ancient pentest wisdom.

0xTib3rius's tweet image. Ancient pentest wisdom.

cwinfosec reposted

No

ffmpeg is old and outdated. is there a good alternative?



cwinfosec reposted

I often get asked what tools I use for web app pentesting, and people are surprised when I say it's 99% Burp Suite Pro. Here's why... 🧵👇

0xTib3rius's tweet image. I often get asked what tools I use for web app pentesting, and people are surprised when I say it's 99% Burp Suite Pro. Here's why...

🧵👇

cwinfosec reposted

I've released a blog series about modern Linux kernel exploitation, where you can learn some advanced techniques used in real-world kernel exploits. Enjoy! r1ru.github.io/categories/lin…

ri5255's tweet image. I've released a blog series about modern Linux kernel exploitation, where you can learn some advanced techniques used in real-world kernel exploits. Enjoy!

r1ru.github.io/categories/lin…

cwinfosec reposted

It doesn’t matter if people have AI. They’re still lazy af and lack confidence. You could give most people every advantage in the world and they will still stay where they are


cwinfosec reposted

Every once in a while it hits me how objectively awesome my job is. I get paid well to write super cool malware and do stuff that otherwise lands you in jail. Good to keep perspective on things!


cwinfosec reposted

A new module has been merged into NetExec: change-password🔥 Accounts with STATUS_PASSWORD_EXPIRED aren't a problem anymore, just reset their password. You can also abuse ForceChangePassword to reset another user's password. Made by @kriyosthearcane, @mehmetcanterman and me

al3x_n3ff's tweet image. A new module has been merged into NetExec: change-password🔥

Accounts with STATUS_PASSWORD_EXPIRED aren't a problem anymore, just reset their password.
You can also abuse ForceChangePassword to reset another user's password.

Made by @kriyosthearcane, @mehmetcanterman and me

cwinfosec reposted

hOw Do I lEaRn MaLwArE StUfF If you're new to malware stuff, and want to learn malware stuff, go to our paper collection. If you read 10% of our malware analysis paper collection (took notes, seriously understood it), you'd be a fuckin' monster. If you know how to code…

Malware paper statistic breakdown: Windows malware development papers: 721 papers Malware analysis papers: 12,293 papers Linux malware development papers: 65 papers ICS/SCADA malware papers: 94 papers



Loading...

Something went wrong.


Something went wrong.