nullpwn's profile picture. ʙᴏʀᴇᴅ sᴇᴄᴜʀɪᴛʏ ᴇɴɢɪɴᴇᴇʀ, sᴇɴᴅ ᴛʜᴏᴛs ᴀɴᴅ ᴘɪᴢᴢᴀ

uʍdןןnu

@nullpwn

ʙᴏʀᴇᴅ sᴇᴄᴜʀɪᴛʏ ᴇɴɢɪɴᴇᴇʀ, sᴇɴᴅ ᴛʜᴏᴛs ᴀɴᴅ ᴘɪᴢᴢᴀ

uʍdןןnu reposted

BADBOX: a firmware backdoored trojan found in 74,000 Chinese Android phones, tablets, and TV boxes in 227 counties and territories There are confirmed 8 devices with backdoors installed — seven TV boxes, the T95, T95Z, T95MAX, X88, Q9, X12PLUS, and MXQ Pro 5G, and a tablet J5-W.…

androidmalware2's tweet image. BADBOX: a firmware backdoored trojan found in 74,000 Chinese Android phones, tablets, and TV boxes in 227 counties and territories

There are confirmed 8 devices with backdoors installed — seven TV boxes, the T95, T95Z, T95MAX, X88, Q9, X12PLUS, and MXQ Pro 5G, and a tablet J5-W.…

ChamelDoH: New Linux Backdoor Utilizing DNS-over-HTTPS Tunneling for Covert CnC thehackernews.com/2023/06/chamel… via @TheHackersNews


Want to get a job in cybersecurity? Save $5 on a premium TryHackMe subscription using my referral link below! Level up your skills with interactive challenges, virtual labs, and real-world scenarios. Let's hack together! tryhackme.com/signup?referre… #tryhackme #cybersecurity


Haven't tweet in a while here's what changed : new web changed from .ro to .com added blog function via jekyll new article about facebook cookie stealer incoming more junky scamming pages for @DNSC_RO to check


uʍdןןnu reposted

8 pieces of free software for cybersecurity enthusiasts: 1. Training: Hack The Box 2. Curated News: Feedly 3. Web Hacking: Burp Suite 4. Data Modification: Cyber Chef 5. Port Scan: Nmap 6. Operating System: Kali Linux 7. Debugging: Ghidra 8. Email Security: DeHashed


uʍdןןnu reposted

OSINT.SH - All in one Information Gathering Tools osint.sh


uʍdןןnu reposted

Can’t believe YouTube doesn’t have a basic New Device Access verification when session token was used from another IP+User Agent This would prevent @LinusTech from running across a home butt-naked at night, dealing with social engineering attack, that hijacked YT session tokens

therceman's tweet image. Can’t believe YouTube doesn’t have a basic New Device Access verification when session token was used from another IP+User Agent

This would prevent @LinusTech from running across a home butt-naked at night, dealing with social engineering attack, that hijacked YT session tokens

uʍdןןnu reposted

Now and for a period of time, my Python basics course is free. Course: bit.ly/37cmhlx


uʍdןןnu reposted

🤷‍♂️

malwrhunterteam's tweet image. 🤷‍♂️

uʍdןןnu reposted

1/ THIS IS BAD!!! Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱 All part of a new #Rhadamanthys stealer campaign with new tricks and mainly targeting streamers.

1ZRR4H's tweet image. 1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new #Rhadamanthys stealer campaign with new tricks and mainly targeting streamers.
1ZRR4H's tweet image. 1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new #Rhadamanthys stealer campaign with new tricks and mainly targeting streamers.
1ZRR4H's tweet image. 1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new #Rhadamanthys stealer campaign with new tricks and mainly targeting streamers.
1ZRR4H's tweet image. 1/ THIS IS BAD!!!

Search for "OBS" in Google and you get, not 1, but 5 (❗️) malicious ads in the first links/results 😱

All part of a new #Rhadamanthys stealer campaign with new tricks and mainly targeting streamers.

uʍdןןnu reposted

Only 8?

InfosecMemes_'s tweet image. Only 8?

uʍdןןnu reposted

Time for another giveaway! We are going to send a t-shirt and a few goodies to one person who follows @PentesterLab and retweets this tweet!! And we are going to give a 12-month voucher to someone who follows @PentesterLab and likes this tweet!!


uʍdןןnu reposted

Bug Bounty Hint Don't forget to check for the /_wpeprivate/config.json endpoint on a website for information disclosure. P.S. WPEngine is a provider of managed WordPress hosting. It creates a folder named _wpeprivate that contains the config.json with highly sensitive info.


uʍdןןnu reposted

🤷‍♂️

malwrhunterteam's tweet image. 🤷‍♂️

uʍdןןnu reposted

This is sad, actually

x0rz's tweet image. This is sad, actually

uʍdןןnu reposted

The person responsible for the Rockstar & Uber breach has angered a group of ransomware Threat Actors They state he initiated conversations on selling access, but in the midst of negotiations burned access He claimed to have access to Kone, Bank of Brasil, Take2Games & DoorDash

vxunderground's tweet image. The person responsible for the Rockstar & Uber breach has angered a group of ransomware Threat Actors

They state he initiated conversations on selling access, but in the midst of negotiations burned access

He claimed to have access to Kone, Bank of Brasil, Take2Games & DoorDash
vxunderground's tweet image. The person responsible for the Rockstar & Uber breach has angered a group of ransomware Threat Actors

They state he initiated conversations on selling access, but in the midst of negotiations burned access

He claimed to have access to Kone, Bank of Brasil, Take2Games & DoorDash
vxunderground's tweet image. The person responsible for the Rockstar & Uber breach has angered a group of ransomware Threat Actors

They state he initiated conversations on selling access, but in the midst of negotiations burned access

He claimed to have access to Kone, Bank of Brasil, Take2Games & DoorDash
vxunderground's tweet image. The person responsible for the Rockstar & Uber breach has angered a group of ransomware Threat Actors

They state he initiated conversations on selling access, but in the midst of negotiations burned access

He claimed to have access to Kone, Bank of Brasil, Take2Games & DoorDash

uʍdןןnu reposted

Illustrating security concepts: sure you have integrity and availability, but without confidentiality, does it really matter?

MalwareJake's tweet image. Illustrating security concepts: sure you have integrity and availability, but without confidentiality, does it really matter?

uʍdןןnu reposted

You're in their inbox, I'm in the production servers. We aren't the same.


Loading...

Something went wrong.


Something went wrong.