Théo Louis-Tisserand (@0hexit) 's Twitter Profile
Théo Louis-Tisserand

@0hexit

ID: 1178597365810438144

calendar_today30-09-2019 09:08:17

92 Tweet

57 Followers

289 Following

Hexacon (@hexacon_fr) 's Twitter Profile Photo

New year, new look! ✨ For this edition our visual identity gets a refresher : hexacon.fr ✨ As a reminder, our CFP is currently open until the 1st of June :  hexacon.fr/conference/cal… More things to be announced in the followings weeks, stay tuned! #HEXACON2023

BiereSecuTLS (@bieresecu) 's Twitter Profile Photo

📣Rappel pour celles et ceux qui auraient raté l'info 🗓️Un Bière&Sécu est prévu le jeudi 1er juin à 19h au Rooster and Beer à Toulouse. Inscrivez-vous 👉 framadate.org/71L2VK5zeaMxhl… En espérant vous voir nombreux !🍻

Synacktiv (@synacktiv) 's Twitter Profile Photo

A while ago during a security assessment, Théo Louis-Tisserand identified multiple vulnerabilities on the PRTG Network Monitor application version 21.3.69.1333, allowing an attacker to perform XSS attacks. Read the technical details in the advisory: synacktiv.com/sites/default/…

A while ago during a security assessment, <a href="/0hexit/">Théo Louis-Tisserand</a> identified multiple  vulnerabilities on the PRTG Network Monitor application version  21.3.69.1333, allowing an attacker to perform XSS attacks. Read the  technical details in the advisory: synacktiv.com/sites/default/…
Synacktiv (@synacktiv) 's Twitter Profile Photo

During a recent Active Directory intrusion test, @croco_byte was led to devise a new versatile attack vector targeting Group Policy Objects, allowing their exploitation through NTLM relaying. synacktiv.com/publications/g…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Bored of managing multiple proxychains configurations? Hugo Clout developed bbs, a swiss army knife proxy manager for red teamers! The project is available on our GitHub: github.com/synacktiv/bbs

BiereSecuTLS (@bieresecu) 's Twitter Profile Photo

Bonne année tout le monde 😄🎉 📣Prenez une bonne résolution et venez au premier Bière&Sécu 2024, le jeudi 8 février 🗓️ à 19h au Rooster and Beer 🐔🍺 Inscrivez-vous 👉 framadate.org/HlfuGIxo2u62Ws… Contactez-nous si vous avez des sujets à présenter via Twitter ou Discord 🗣️!

Hexacon (@hexacon_fr) 's Twitter Profile Photo

☁️ Whether it's on premises or in the cloud, a domain is a domain. 💪 Flex your intrusion muscles with @tiyeuse and Hugow's training! ➡️ hexacon.fr/trainer/vincen… 📆 30/09-03/10 2024 📍Espace Vinci, Rue des Jeuneurs, Paris

☁️ Whether it's on premises  or in the cloud, a domain is a domain.

💪 Flex your intrusion muscles with @tiyeuse and <a href="/hugow_vincent/">Hugow</a>'s training!

➡️ hexacon.fr/trainer/vincen…
📆 30/09-03/10 2024
📍Espace Vinci, Rue des Jeuneurs, Paris
Adam Chester 🏴‍☠️ (@_xpn_) 's Twitter Profile Photo

Thanks to Théo Louis-Tisserand's PR, DPoP auth support has now been added to CloudNine for Okta which is used in agent versions >3.18.0 \o/ github.com/xpn/OktaPostEx…

Synacktiv (@synacktiv) 's Twitter Profile Photo

GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas Alexis Danizan and Pierre Milioni analyzed the patch and wrote the exploit code! github.com/synacktiv/CVE-…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Oh, you didn't know? Cool kids are now relaying Kerberos over SMB 😏 Check out our latest blogpost by Hugow to discover how to perform this attack: synacktiv.com/publications/r…

Synacktiv (@synacktiv) 's Twitter Profile Photo

You can now use LDAP/LDAPs protocols with the SOCKS proxy of ntlmrelayx thanks to the PR from Pierre Milioni (now merged upstream). Here is an example with ldeep using relayed authentication from HTTP to LDAPs :

You can now use LDAP/LDAPs protocols with the SOCKS proxy of ntlmrelayx thanks to the PR from <a href="/b1two_/">Pierre Milioni</a> (now merged upstream).
Here is an example with ldeep using relayed authentication from HTTP to LDAPs :
Synacktiv (@synacktiv) 's Twitter Profile Photo

Following the release of IPSpinner last week, now is the time to unveil CaptainCredz! Perform advanced, fine-grained password spraying while remaining under the radar for your next Red Team engagement 🔥 github.com/synacktiv/capt…

Synacktiv (@synacktiv) 's Twitter Profile Photo

In our latest article, Quentin Roland and Scaum demonstrate a trick allowing to make Windows SMB clients fall back to WebDav HTTP authentication, enhancing the NTLM and Kerberos relaying capabilities of multicast poisoning attacks! synacktiv.com/publications/t…

Synacktiv (@synacktiv) 's Twitter Profile Photo

🚀 This week, Us3r777 & Pierre kick off our new Whitebox Vulnerability Research training! Students will dive into PHP, Java, and .NET, analyzing & exploiting 1-day vulnerabilities. Let’s get started! 💻🔍

🚀 This week, <a href="/us3r777/">Us3r777</a> &amp; <a href="/__pierreg/">Pierre</a> kick off our new Whitebox Vulnerability Research training! Students will dive into PHP, Java, and .NET, analyzing &amp; exploiting 1-day vulnerabilities. Let’s get started! 💻🔍
Synacktiv (@synacktiv) 's Twitter Profile Photo

Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by Guillaume André and Wil. synacktiv.com/publications/n…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Our ninja kalimero is now on stage at #x33fcon to talk about his journey from dissecting SCCM until the discovery of the critical CVE-2024-43468 and the post-exploitation opportunities🔥

Our ninja <a href="/kalimer0x00/">kalimero</a> is now on stage at #x33fcon to talk about his journey from dissecting SCCM until the discovery of the critical CVE-2024-43468 and the post-exploitation opportunities🔥