Justin Bollinger (@bandrel) 's Twitter Profile
Justin Bollinger

@bandrel

hacker, finder of EKUwu (CVE-2024-49019) open.spotify.com/track/7ktbPtJN…

ID: 38090837

linkhttps://trustedsec.com/blog/ekuwu-not-just-another-ad-cs-esc calendar_today06-05-2009 02:27:00

21,21K Tweet

5,5K Followers

2,2K Following

Ryan M. Montgomery (@0dayctf) 's Twitter Profile Photo

Photos can now be located from within your house. Stay safe! - - I’d love to hear your thoughts on this. The goal is to put this in the hands of LE, and this will be very helpful for many cases.

mpgn (@mpgn_x64) 's Twitter Profile Photo

Based on the research of Akamai, I made a new module on netexec to find every principal that can perform a BadSuccessor attack and the OUs where it holds the required permissions 🔥 github.com/Pennyw0rth/Net…

Based on the research of Akamai, I made a new module on netexec to find every principal that can perform a BadSuccessor attack and the OUs where it holds the required permissions 🔥

github.com/Pennyw0rth/Net…
vx-underground (@vxunderground) 's Twitter Profile Photo

Hahahahhahahaha Unironically a good idea. It's so unbelievably stupid and it works. Depending on explorer layout, the .exe might not be visible. Filename.mp4 + ??? spaces + .exe Hahahahahaha UNC6032 is wild as hell

Hahahahhahahaha 

Unironically a good idea. It's so unbelievably stupid and it works. Depending on explorer layout, the .exe might not be visible.

Filename.mp4 + ??? spaces + .exe

Hahahahahaha UNC6032 is wild as hell
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.

Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.
TrustedSec (@trustedsec) 's Twitter Profile Photo

Registration for our #BlackHatUSA training on “Adversary Tactics and Threat Hunting” is open! Standard pricing ends July 18, so enroll now! Black Hat blackhat.com/us-25/training…

Registration for our #BlackHatUSA training on “Adversary Tactics and Threat Hunting” is open! Standard pricing ends July 18, so enroll now! <a href="/BlackHatEvents/">Black Hat</a> blackhat.com/us-25/training…