sysop_host's profile picture. Hacker, security geek, climber, spanner monkey, and occasional builder of rally cars

sysop_host

@sysop_host

Hacker, security geek, climber, spanner monkey, and occasional builder of rally cars

sysop_host 已轉發

Phorion Threat Report: a backdoored Cursor extension was used to deploy the Paradox Stealer infostealer into macOS developer workflows. The post breaks down the full infection chain, detection opportunities and why IDE extensions have become a reliable point of initial access.…

PhorionTech's tweet image. Phorion Threat Report: a backdoored Cursor extension was used to deploy the Paradox Stealer infostealer into macOS developer workflows.

The post breaks down the full infection chain, detection opportunities and why IDE extensions have become a reliable point of initial access.…

sysop_host 已轉發

🍎☕️ A new LPE for macOS Tahoe. 100% reliable, instant root. <3 Shared work with @gergely_kalman . That coffee shop was awesome 😎


sysop_host 已轉發

😂

malwrhunterteam's tweet image. 😂

sysop_host 已轉發

Worked with @sysop_host. A file can show a benign script but runs the hidden payload when executed through osascript. It seems that when a compiled AppleScript exists in the resource fork, osascript will run this and ignore the contents of the data fork.

I wrote a thing about some recent dabbling with AppleScripts 0x626c6f67.xyz/posts/hiding-c…



I wrote a thing about some recent dabbling with AppleScripts 0x626c6f67.xyz/posts/hiding-c…


sysop_host 已轉發

Calling all London #redteam and cyber crew! Save the date 23 Nov 23 for #Beacon23: a hacker-run microcon for discussions and talks on all things around #offensivesecurity with informal drinks and music til 10pm, near Old Street. Register on Eventbrite at l.ocalho.st


sysop_host 已轉發

A standalone tweet; I have made my book fully free for those that want it, and it's also available to pay some money for if you want to support my blog/work: Free: blog.zsec.uk/ltr101-copies-…​ Paid: leanpub.com/ltr101-breakin…#ltr101 #CyberMonday #BlackFriday #InfosecStudents


sysop_host 已轉發

Say it with me: Telegram is not private mastodon.technology/@rysiek/109160…


sysop_host 已轉發

WIP: the ability to update Athena comms type during execution. Example Situation: You want to run a SOCKS proxy, but don't want to send a billion HTTP requests, you can switch to the websocket c2 profile and run your proxy in a stealthier way

checkymander's tweet image. WIP: the ability to update Athena comms type during execution. 
Example Situation:
You want to run a SOCKS proxy, but don&apos;t want to send a billion HTTP requests, you can switch to the websocket c2 profile and run your proxy in a stealthier way

This

If your entire enterprise security model crumbles because a user fell for a phish, that's not the user's fault.



sysop_host 已轉發

Ever wondered how a QR code works? No, me neither but it's low-key fascinating. (Warning, there is some extremely nerdy shit here.👇 )

DanHollick's tweet image. Ever wondered how a QR code works?  
No, me neither but it&apos;s low-key fascinating.

(Warning, there is some extremely nerdy shit here.👇 )

sysop_host 已轉發

ANNOUNCEMENT: We are very happy to announce that Security BSides Sydney Conference 2022 will be held on 27th November this year - lock the date in! #bsides #bsidessyd CFP opening soon!


sysop_host 已轉發

Join @psychsecurity in his talk on Sun at 10:05am "A brief guide to outflanking TCC" as he discusses design flaws within the macOS TTC and demonstrate techniques to access privacy features during offensive operations. He will also present his OSS Tool. bsidesmelbourne.com/2022-tcc.html


sysop_host 已轉發

🆕 Update(s): 🐛 Bug assigned CVE-2022-28756 🩹 Patch now available, in Zoom v5.11.5 (9788) See Zoom's security bulletin: explore.zoom.us/en/trust/secur… Mahalos to @Zoom for the (incredibly) quick fix! 🙌🏽 🙏🏽

patrickwardle's tweet image. 🆕 Update(s):
🐛 Bug assigned CVE-2022-28756
🩹 Patch now available, in Zoom v5.11.5 (9788)

See Zoom&apos;s security bulletin: 
explore.zoom.us/en/trust/secur…

Mahalos to @Zoom for the (incredibly) quick fix! 🙌🏽 🙏🏽

Hey @1Password the 1Pass 8 SSH agent is great, but it would be nicer still if it prompted to unlock other accounts when no matching key is found in any of the currently unlocked one. I have multiple account with separate master passwords so they don’t all unlock together.


sysop_host 已轉發

[BLOG] Fun post on how to combine evilginx by @mrgretzky and BITB by @mrd0x. rastamouse.me/evilginx-meet-…


sysop_host 已轉發

We are releasing #BloodHound 4.2 soon. In the meantime, check out the difference between the design of BloodHound 1.0's graph and BloodHound 4.2's graph:

_wald0's tweet image. We are releasing #BloodHound 4.2 soon. In the meantime, check out the difference between the design of BloodHound 1.0&apos;s graph and BloodHound 4.2&apos;s graph:
_wald0's tweet image. We are releasing #BloodHound 4.2 soon. In the meantime, check out the difference between the design of BloodHound 1.0&apos;s graph and BloodHound 4.2&apos;s graph:

Dear CAPTCHA makers, please include a gravy boat with “select all boats” challenges.


“Innovative”

If your entire enterprise security model crumbles because a user fell for a phish, that's not the user's fault.



Loading...

Something went wrong.


Something went wrong.