Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile
Ophir Harpaz ๐ŸŽ—๏ธ

@ophirharpaz

Security researcher. Vegan for life.

ID: 375246970

linkhttp://ophirharpaz.com calendar_today17-09-2011 19:36:58

3,3K Tweet

12,12K Followers

569 Following

Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

Nice finding: here's how an attacker can spoof multiple DNS records and make them all point at the same machine (not trivial as you'll see!)

Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

A "sweet" attack campaign caught in our honeypot :) Spreads over SSH, mines crpytocurrency to a private pool and has a P2P malware module previously seen and analyzed by Unit 42. NoaBot is now uncovered and broken down by Stiv Kupchik >>

Akamai Security Intelligence Group (@akamai_research) 's Twitter Profile Photo

๐Ÿธ Ready for some ribbeting research? The FritzFrog botnet has found a new home in Log4Shell - or as we like to call it, Frog4Shell. See details on how this botnet hops around in our latest blog: akamai.com/blog/security-โ€ฆ

๐Ÿธ Ready for some ribbeting research?

The FritzFrog botnet has found a new home in Log4Shell - or as we like to call it, Frog4Shell. 

See details on how this botnet hops around in our latest blog:
akamai.com/blog/security-โ€ฆ
Tomer Peled (@tomerpeled92) 's Twitter Profile Photo

Very happy and excited to finally publish this blogpost! This blog is about a command injection vulnerability in Kubernetes. The vulnerability is with the local volumes feature and it will allow for RCE over all windows nodes in the cluster with SYSTEM privileges.

Ori David (@oridavid123) 's Twitter Profile Photo

Excited to share my third blog covering Microsoft DHCP! This time we go into the DHCP Administrators group, while exploring the question: Can a DHCP admin become a Domain admin? (Spoiler alert: Pretty often!) Get the full details here: akamai.com/blog/security-โ€ฆ

Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

I forgot (and now recall) how tedious it is to try to understand functions with big logic and how satisfying it is when you finally do

Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

it's the third time today that my build fails because in some miraculous way (i.e. vim) I managed to corrupt the source code. redundant lines added at the end of the file, endifs disappearing, you name it. I just wish I knew the keyboard shortcuts that made this happen

Gil Dickmann | ื’ื™ืœ ื“ื™ืงืžืŸ (@gildickmann) 's Twitter Profile Photo

ื‘ื•ืงืจ ื˜ื•ื‘ ืžื”ื›ื ืกืช. ื™ืฉ ืคื” ื™ื•ืชืจ ื‘ื ื™ ืžืฉืคื—ื•ืช ืฉืœ ื—ื˜ื•ืคื™ื ืžื—ื‘ืจื™ ื›ื ืกืช. ืœื ื• ืื™ืŸ ืคื’ืจื”.

ื‘ื•ืงืจ ื˜ื•ื‘ ืžื”ื›ื ืกืช. 
ื™ืฉ ืคื” ื™ื•ืชืจ ื‘ื ื™ ืžืฉืคื—ื•ืช ืฉืœ ื—ื˜ื•ืคื™ื
ืžื—ื‘ืจื™ ื›ื ืกืช. 

ืœื ื• ืื™ืŸ ืคื’ืจื”.
Iddo Yadlin (@iddoyadlin) 's Twitter Profile Photo

ืžื“ืจื™ืš ืœืขื‘ื•ื“ื” ืขื ื—ื™ืœื•ื ื™ื ื—ืœืง 1:

Adam Chester ๐Ÿดโ€โ˜ ๏ธ (@_xpn_) 's Twitter Profile Photo

To all you newbies out there getting into this industry and being worried about not knowing enough.. Unfortunately I'm here to tell you that imposter syndrome never stops! Enjoy what you do and stay humble, because you'll always doubt your skillz... That is all.

Amir Tibon ืืžื™ืจ ืชื™ื‘ื•ืŸ (@amirtibon) 's Twitter Profile Photo

ื”ืฉืขื” ืื—ืจื™ ื—ืฆื•ืช ื‘ื•ื•ืฉื™ื ื’ื˜ื•ืŸ. ื›ืœ ืฆืžืจืช ื”ืžืžืฉืœ ื›ื•ืœืœ ื”ื ืฉื™ื ื‘ื™ื™ื“ืŸ ืขืฆืžื• ืคืจืกืžื• ืชื’ื•ื‘ื•ืช ืงื•ืจืขื•ืช ืœื‘ ื‘ื ื•ืฉื ื”ื—ื˜ื•ืคื™ื ืฉื ืจืฆื—ื•. ื”ืฉืขื” 7:45 ื‘ื™ืฉืจืืœ. ืจืืฉ ื”ืžืžืฉืœื” ื™ื•ื“ืข ืžืื– ืืชืžื•ืœ ื‘ืœื™ืœื” ืขืœ ื”ืืกื•ืŸ, ื•ื”ื•ื ืฉื•ืชืง. ืžืฉืื™ืจ ืืช ื”ื‘ืฉื•ืจื” ื”ืงืฉื” ืœื“ื•ื‘ืจ ืฆื”"ืœ. ื”ืื™ืฉ ื”ื–ื” ืœื ืจืื•ื™ ืœื›ืœื•ื. ืคื—ื“ืŸ.

Gil Dickmann | ื’ื™ืœ ื“ื™ืงืžืŸ (@gildickmann) 's Twitter Profile Photo

ืกืœื™ื—ื”, ื›ืจืžืœื™. ืกืœื™ื—ื” ืฉืœื ืขืฆืจื ื• ื›ืฉืขื•ื“ ื”ื™ื” ืืคืฉืจ. ืกืœื™ื—ื” ืฉื ืชื ื• ืœื”ื ืœื”ืจื•ื’ ืื•ืชืš. ื”ืœื•ื•ืื™ ืฉืจืื™ืช ื•ืฉืžืขืช ืื•ืชื ื•. ื”ืœื•ื•ืื™ ืฉืœืžืจื•ืช ืฉืจืื™ืช ื‘ืขื™ื ื™ื™ื ืืช ื”ืจืฆื— ื”ื ื•ืจื ืฉืœ ืืžื ื›ื ืจืช, ื’ื™ืœื™ืช ืฉืื‘ื ืืฉืœ ื•ืื—ื™ื™ืš ืืœื•ืŸ ื•ืื•ืจ, ื”ื’ื™ืกื” ืฉืœืš ื™ืจื“ืŸ ื•ื”ืื—ื™ื™ื ื™ืช ืฉืœืš ื’ืคืŸ, ืฉืจื“ื•. ื”ืœื•ื•ืื™ ืฉืจืื™ืช ืื™ืš ื”ื—ื‘ืจื•ืช ืฉืœืš ื ืื‘ืงื• ื›ื“ื™ ืฉืชื—ื–ืจื™

ืกืœื™ื—ื”, ื›ืจืžืœื™. 

ืกืœื™ื—ื” ืฉืœื ืขืฆืจื ื• ื›ืฉืขื•ื“ ื”ื™ื” ืืคืฉืจ. 
ืกืœื™ื—ื” ืฉื ืชื ื• ืœื”ื ืœื”ืจื•ื’ ืื•ืชืš. 

ื”ืœื•ื•ืื™ ืฉืจืื™ืช ื•ืฉืžืขืช ืื•ืชื ื•. ื”ืœื•ื•ืื™ ืฉืœืžืจื•ืช ืฉืจืื™ืช ื‘ืขื™ื ื™ื™ื ืืช ื”ืจืฆื— ื”ื ื•ืจื ืฉืœ ืืžื ื›ื ืจืช, ื’ื™ืœื™ืช ืฉืื‘ื ืืฉืœ ื•ืื—ื™ื™ืš ืืœื•ืŸ ื•ืื•ืจ, ื”ื’ื™ืกื” ืฉืœืš ื™ืจื“ืŸ ื•ื”ืื—ื™ื™ื ื™ืช ืฉืœืš ื’ืคืŸ, ืฉืจื“ื•. ื”ืœื•ื•ืื™ ืฉืจืื™ืช ืื™ืš ื”ื—ื‘ืจื•ืช ืฉืœืš ื ืื‘ืงื• ื›ื“ื™ ืฉืชื—ื–ืจื™
chompie (@chompie1337) 's Twitter Profile Photo

VR is tough psychologically. Often asked if it's a good discipline to get into, given that the difficulty is always increasing. Hacking will always exist, in one form or another. The right question - are u ok w repeated failure/uncertainty without it influencing your self worth?

Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

Blue Hat IL's CFP is now open and I'm lucky to have been asked to join the committee again! I'd love to help those who are thinking about submitting a talk, send me a DM if I can assist. Excited to read some abstracts!

BlueHat IL (@bluehatil) 's Twitter Profile Photo

One week to go! If your plan is to submit your abstract to BlueHat IL 2025 at the very last second โ€“ we kind of respect that, but why not get it done now and save usย allย theย stress? microsoftrnd.co.il/bluehatil/confโ€ฆ

One week to go! If your plan is to submit your abstract to BlueHat IL 2025 at the very last second โ€“ we kind of respect that, but why not get it done now and save usย allย theย stress? microsoftrnd.co.il/bluehatil/confโ€ฆ
Ophir Harpaz ๐ŸŽ—๏ธ (@ophirharpaz) 's Twitter Profile Photo

Hexacon CFP is open until July 14th! Don't miss the chance to submit a talk - being a speaker is currently the only way to get a ticket to the sold-out event ;)

Mari0n (@pinkflawd) 's Twitter Profile Photo

Blackhoodie will be back at Hexacon this year, and we're currently looking for former BlackHoodies who would be willing to give a training, between Oct 6 and 9! blackhoodie.re/Hexacon2025/