nulllzero's profile picture. spaceyyyy
@nullcat@defcon.social

#000000

@nulllzero

spaceyyyy @[email protected]

Pinned

static in a cube 🤔

nulllzero's tweet image. static in a cube 🤔

#000000 reposted

About the #Signal outage: In information security we look at three principles: secrecy, integrity, and availability. Signal’s outage affected only one of them: availability. The relay servers were down, so messages couldn’t move. But nobody could read them. Signal is open…


#000000 reposted

Now Playing UwU Underground Wanna Buy My Zero Days? 3:03 ------------|------ 4:26 ↻ ◁ || ▷ ↺ @opzero_en @SonicWall @MSFTResearch SLSH Track Progress: ▓░░░░░░░░░ 10%


#000000 reposted

Hey guise I’m a Threat Actor about to do illegal shit, can anyone recommend a good DLP and maybe remote device management tools to install on my machine? Does Palantir have an agent I could install?


#000000 reposted

In April this year, @grafana had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks. How were they discovered? Canarytokens.. Check out their (super transparent) post¹ on how they use our tokens at scale.. __ ¹ link follows

ThinkstCanary's tweet image. In April this year, @grafana had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks.

How were they discovered? Canarytokens..

Check out their (super transparent) post¹ on how they use our tokens at scale.. 

__
¹ link follows

#000000 reposted

Thai Buddhist monk: I .....will.....keep..... praying....


#000000 reposted
cyb3rops's tweet image.

It's the whole Internet

cyb3rops's tweet image. It's the whole Internet
cyb3rops's tweet image. It's the whole Internet
cyb3rops's tweet image. It's the whole Internet
cyb3rops's tweet image. It's the whole Internet


#000000 reposted

Name a more iconic duo... I'll wait

sshell_'s tweet image. Name a more iconic duo... I'll wait
sshell_'s tweet image. Name a more iconic duo... I'll wait

#000000 reposted

Can a DHCP administrator become a domain administrator? Well, as it turns out, sometimes it sure can. 🥴 In our latest blog post, see how Akamai researchers discovered a new PrivEsc technique affecting Active Directory. Full write-up: akamai.com/blog/security-…

akamai_research's tweet image. Can a DHCP administrator become a domain administrator? Well, as it turns out, sometimes it sure can. 🥴

In our latest blog post, see how Akamai researchers discovered a new PrivEsc technique affecting Active Directory.

Full write-up:
akamai.com/blog/security-…

#000000 reposted

HUGE UPDATE TO THE CAT STREAM @uwukko and @schlizzawg have spent the last month cooking an entire overhaul of the meow.camera site. You can now watch the Hello Street Cat streams on just about any device! (even firefox) meow.camera/viewer/

archer_uwu's tweet image. HUGE UPDATE TO THE CAT STREAM

@uwukko and @schlizzawg have spent the last month cooking an entire overhaul of the meow.camera site.

You can now watch the Hello Street Cat streams on just about any device! (even firefox)

meow.camera/viewer/

#000000 reposted

Today 70,000,000+ records from an unspecified division of AT&T were leaked onto Breached. No information is available to indicate whether it is a 3rd party compromise, or which 'division' this data is from. Regardless, upon review we can confirm the stolen data is legitimate.


#000000 reposted

So GPS jamming requires line of sight between the jammer and the target. Accounting for mountains, that is almost a perfect shape around Kaliningrad (Max of 270 ish miles for an at altitude plane, 220 ish for decent like over Sweden). Russia isn't even trying to hide it.

Last 46 hours Baltic Jammer has been running in south Baltics. At least 873 unique aircrafts has had their navigation equipment jammed. Each one a passenger jet filled with civilians. E.g. Ryanairs SP-RKS has been without GPS for at least 2 hours going in and out of Vilnius.

auonsson's tweet image. Last 46 hours Baltic Jammer has been running in south Baltics. 

At least 873 unique aircrafts has had their navigation equipment jammed. Each one a passenger jet filled with civilians.

E.g. Ryanairs SP-RKS has been without GPS for at least 2 hours going in and out of Vilnius.


"Prosecutors told the court on Friday that Kivimäki's whereabouts were discovered after he posted a picture of a bottle of champagne on the Ylilauta website, which led police to his location."

Last 46 hours Baltic Jammer has been running in south Baltics. At least 873 unique aircrafts has had their navigation equipment jammed. Each one a passenger jet filled with civilians. E.g. Ryanairs SP-RKS has been without GPS for at least 2 hours going in and out of Vilnius.

auonsson's tweet image. Last 46 hours Baltic Jammer has been running in south Baltics. 

At least 873 unique aircrafts has had their navigation equipment jammed. Each one a passenger jet filled with civilians.

E.g. Ryanairs SP-RKS has been without GPS for at least 2 hours going in and out of Vilnius.


#000000 reposted

My detailed analysis report of SolarWinds Security Event Manager AMF Deserialization RCE (CVE-2024-0692), with two methods to achieve RCE exp10it.io/2024/03/solarw… xz.aliyun.com/t/14044


#000000 reposted

I am becoming the Joker

SwiftOnSecurity's tweet image. I am becoming the Joker

#000000 reposted

I recently found two very interesting Linux binaries uploaded to Virustotal. I call this malware 'GTPDOOR'. GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunnelling Protocol), silently listening on the GRX network (1/n) 🧵

haxrob's tweet image. I recently found two very interesting Linux binaries uploaded to Virustotal. 

I call this malware 'GTPDOOR'.

GTPDOOR is a 'magic/wakeup' packet backdoor that uses a novel C2 transport protocol: GTP (GPRS Tunnelling Protocol), silently listening on the GRX network (1/n) 🧵

#000000 reposted

Mogilevich ransomware claims to have targeted 1. Gaming Giant - Epic Games 🇺🇸 2. Ireland’s Department of foreign affairs 🇮🇪 #Ransomware #Threatintel

FalconFeedsio's tweet image. Mogilevich ransomware claims to have targeted 

1. Gaming Giant - Epic Games 🇺🇸
2. Ireland’s Department of  foreign affairs 🇮🇪 

#Ransomware #Threatintel
FalconFeedsio's tweet image. Mogilevich ransomware claims to have targeted 

1. Gaming Giant - Epic Games 🇺🇸
2. Ireland’s Department of  foreign affairs 🇮🇪 

#Ransomware #Threatintel

#000000 reposted

🧵 A collection of my favorite pieces from the Windows XP source code. \windows\core\ntgdi\test\teff\poo.txt

endermanch's tweet image. 🧵 A collection of my favorite pieces from the Windows XP source code.

\windows\core\ntgdi\test\teff\poo.txt

#000000 reposted

.@lozaning is a nuisance to society. We gotta stop them. They've created the Toothbrush Botnet!

vxunderground's tweet image. .@lozaning is a nuisance to society. We gotta stop them. They've created the Toothbrush Botnet!

#000000 reposted

Developed this when I encountered a sophisticated sample using `%=exitcodeascii%` with subshells for obfuscation, and it works like a charm so far! Give it a look and share any thoughts, I'm opening to adding any missing functionality.

Revamped a batch deobfuscation script to add a lot of additional functionality, check it out here to help make sense of detected malware! github.com/TargetPackage/…



Loading...

Something went wrong.


Something went wrong.