Alberto (@__ar0d__) 's Twitter Profile
Alberto

@__ar0d__

Infosec | Tech | Entrepreneur 👋. badsectorlabs.com | ludus.cloud

ID: 1160241353487474690

linkhttps://ar-infosec.com calendar_today10-08-2019 17:27:49

703 Tweet

443 Followers

1,1K Following

Bad Sector Labs (@badsectorlabs) 's Twitter Profile Photo

Dropped a new tool at DEF CON 32! Loot SCCM Distribution points via HTTP with github.com/badsectorlabs/… We've found credentials, certificates, custom apps, keystores, etc. What will you find?

Clint Gibler (@clintgibler) 's Twitter Profile Photo

D'oh, so you leaked your AWS credentials 🤦‍♂️ Does it matter 𝐰𝐡𝐞𝐫𝐞? It turns out there's a HUGE difference in how fast attackers will find them. Idan Ben Ari deployed canary tokens (fake AWS credentials) using Thinkst Canary to a number of different locations and analyzed:

D'oh, so you leaked your AWS credentials 🤦‍♂️ Does it matter 𝐰𝐡𝐞𝐫𝐞?

It turns out there's a HUGE difference in how fast attackers will find them.

Idan Ben Ari deployed canary tokens (fake AWS credentials) using <a href="/ThinkstCanary/">Thinkst Canary</a> to a number of different locations and analyzed:
vx-underground (@vxunderground) 's Twitter Profile Photo

The Record From Recorded Future News tl;dr it's cool and badass when your car parses your conversations to determine vehicle passengers, passengers name, locations, traveling speed, objects of interest around them, road conditions, traffic, etc. then sells it to advertisers and data collection groups

Marshall (@__mastadon) 's Twitter Profile Photo

I just released a tailscale deploy/remove role for Bad Sector Labs Ludus. Thank you to Chihuahua in charge NotMe for all the testing. Please let me know if you encounter any bugs or if you have any ideas for improvement. Feel free to submit a PR. github.com/NocteDefensor/… #Ludus #Tailscale

💻 gpiper (@greypiperr) 's Twitter Profile Photo

I’m building incredibly in-depth course work for Command and Control operations as well as detection engineering. This is NOT entry level. Live instruction + lifetime access to materials. Until it launches, once a week I will give away access to someone who retweets and follows

Anurag Bhagsain (@abhagsain) 's Twitter Profile Photo

Last week, we asked Devin to make a change. It added an event on the banner component mount, which caused 6.6M PostHog events in one week, which will cost us $733 Devin cost $500 + $733 = $1273 😢👍 Lesson - Review AI-generated code multiple times

Last week, we asked Devin to make a change. It added an event on the banner component mount, which caused 6.6M <a href="/posthog/">PostHog</a> events in one week, which will cost us $733 
Devin cost $500 + $733 = $1273 😢👍

Lesson - Review AI-generated code multiple times
Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

Happy to see that frack113 added an Ansible role for our Aurora agent in Ludus Ludus docs.ludus.cloud Ludus Roles docs.ludus.cloud/docs/roles/#lu… github.com/frack113/ludus… Aurora Agent (free) nextron-systems.com/aurora/

Happy to see that <a href="/frack113/">frack113</a> added an Ansible role for our Aurora agent in Ludus

Ludus
docs.ludus.cloud

Ludus Roles
docs.ludus.cloud/docs/roles/#lu…
github.com/frack113/ludus…

Aurora Agent (free)
nextron-systems.com/aurora/
Bad Sector Labs (@badsectorlabs) 's Twitter Profile Photo

Cobalt Strike for free!? Adaptix C2 (HackerRalf) is the best open source C2 I've used since Havoc (5pider). SOCKS5, remote and local port forwards, and BOF support! Now it's easy to install the server + client, especially on 🏟️Ludus with our new role: github.com/badsectorlabs/…

Cobalt Strike for free!? Adaptix C2 (<a href="/hacker_ralf/">HackerRalf</a>) is the best open source C2 I've used since Havoc (<a href="/C5pider/">5pider</a>). SOCKS5, remote and local port forwards, and BOF support! Now it's easy to install the server + client, especially on 🏟️Ludus with our new role:

github.com/badsectorlabs/…
Bad Sector Labs (@badsectorlabs) 's Twitter Profile Photo

This week's edition is packed full of great techniques and tools! One of the longest posts we've done; there's so much cool stuff being released. blog.badsectorlabs.com/last-week-in-s…