Francesco Enrietti (@not4nhacker) 's Twitter Profile
Francesco Enrietti

@not4nhacker

ID: 1484161274443448327

calendar_today20-01-2022 13:50:17

52 Tweet

54 Followers

218 Following

Shielder (@shieldersec) 's Twitter Profile Photo

Time to pop something out of our publication queue! Learn how Paolo Cavaglià found a way to combine #CodeBuild and #S3 privileges to escalate his privileges in a fairly complex #AWS environment. shielder.com/blog/2023/07/a…

Damion Schubert - @ZenOfDesign.com on bsky (@zenofdesign) 's Twitter Profile Photo

The last week on Twitter has been really an amazing string of WTF, even by the impressive standards of Elon. It's really funny when you put all the pieces together. it's important to start at the beginning. Twitter's pretty broke. (amusing thread)

The last week on Twitter has been really an amazing string of WTF, even by the impressive standards of Elon.  It's really funny when you put all the pieces together.

it's important to start at the beginning.  Twitter's pretty broke.

(amusing thread)
teej dv 🔭 (@teej_dv) 's Twitter Profile Photo

"I use Linux as my operating system," I state proudly to the unkempt, bearded man. He swivels around in his desk chair with a devilish gleam in his eyes, ready to mansplain with extreme precision. "Actually," he says with a grin, "Linux is just the kernel. you use GNU+Linux." I

Shielder (@shieldersec) 's Twitter Profile Photo

Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how TheZero 🍉 on BlueSky and Pit combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 shielder.com/blog/2024/01/h…

Shielder (@shieldersec) 's Twitter Profile Photo

We recently partnered with OSTIF Official to perform a security audit sponsored by Amazon Web Services on Bref. The audit resulted in 5 findings promptly addresses by Matthieu Napoli. The report is now public, check the details here: shielder.com/blog/2024/03/b…

Shielder (@shieldersec) 's Twitter Profile Photo

Back in December 2023 our researchers TheZero 🍉 on BlueSky Pit and Mindless performed an audit sponsored by Amazon Web Services and facilitated by OSTIF Official on boost. It resulted in 7 findings and 15 new fuzzers. The report is now public, check the details here: shielder.com/blog/2024/05/b…

Shielder (@shieldersec) 's Twitter Profile Photo

During a recent engagement Mindless hacked his way through Vtiger CRM which led to discover a privilege escalation and a SQL injection. Learn more in the dedicated advisories: - CVE-2024-42994 #sqli shielder.com/advisories/vti… - CVE-2024-42995 #privesc shielder.com/advisories/vti…

During a recent engagement <a href="/Mindlaess_/">Mindless</a> hacked his way through <a href="/vtigercrm/">Vtiger CRM</a> which led to discover a privilege escalation and a SQL injection.
Learn more in the dedicated advisories:
- CVE-2024-42994 #sqli shielder.com/advisories/vti…
- CVE-2024-42995 #privesc shielder.com/advisories/vti…
TumpiCon (@tumpiconit) 's Twitter Profile Photo

Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!

Shielder (@shieldersec) 's Twitter Profile Photo

In Lausanne for Insomni'hack? Don’t miss the chance to meet our very own Francesco Enrietti! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!

In Lausanne for <a href="/1ns0mn1h4ck/">Insomni'hack</a>? Don’t miss the chance to meet our very own <a href="/not4nhacker/">Francesco Enrietti</a>! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
Shielder (@shieldersec) 's Twitter Profile Photo

Last week Apple released MacOS 13.4 which contains a fix for a vulnerability Pit exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373

Last week <a href="/Apple/">Apple</a> released MacOS 13.4 which contains a fix for a vulnerability <a href="/suidpit/">Pit</a> exploited to escape the Sandbox. 
Update now and stay tuned for the technical details!
Ref: support.apple.com/en-us/122373
TheSAS2025 (@thesascon) 's Twitter Profile Photo

You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo Cavaglià (Paolo Cavaglià) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream" 🏰 His team spent

You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo Cavaglià (<a href="/Paupu_95/">Paolo Cavaglià</a>) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream"

🏰 His team spent
blasty (@bl4sty) 's Twitter Profile Photo

can we please get the libxml2 and ffmpeg people some cold cash, lambo's and decent quality blow as a token of appreciation for all the ASAN splats we throw over the fence and want to have fixed pronto? I know one man's trash (CVE's) is another man's treasure, but we gotta respect