If you find a bypass for a 10-year old Windows EoP vulnerability fix, does it mean it's a 0-day? 🤪
You can read this new blog post and make your own opinion.
👉 https://t.co/4skL8K9xLe
Big thanks to @cesarcer who has been an inspiration to me, among a few other researchers.
@shanto12 @securethisworld @elonmusk In order to ? Destroy the world economy ? Those conspirationists' bs make no sense.
The "let me out and let people dies" stance at least is honnest : selfish interest first
@msftsecurity What's the point of having MFA on the Outlook public Webmail if you only need one factor to authenticate (validation through the Authenticator App without providing a password) ? Is it possible to disable this behaviour ?
@hellfestopenair Hello, est-il possible d'avoir l'URL a refresh compulsivement pour le EasyCamp ? A défaut quelle est la source d'information à surveiller pour être prévenu dès l'ouverture ?
@Asmodee_fr@GaleForceNine Quand pensez-vous publier le planning de sorties ? On était plus bien avec BBE, au final on va encore prendre du retard sur les sorties VO...
Nouvel article permettant de mettre au clair le "Pass the hash".
Cette technique est utilisée dans énormément de tests, et pourtant elle n'est pas toujours complètement comprise. Voici alors un petit retour sur l'une des techniques les plus populaires. 🙃
https://t.co/meX3XvctKI
@ropnop No success with Go Plugins and virtual filesystems ? Last time I checked it looked like a viable solution but I didn't dig due to the lack of Windows support for plugins
I'm publishing some 🔥 research today, a major design flaw in Windows that's existed for almost *two decades*. I wrote a blog post on the story of the discovery all the way through to exploitation.
https://t.co/1DFW2VGQRb
Good to know: 11-characters passwords are safe* from 448x Nvidia RTX 2080, even when stored using unsalted MD5
__
*ᴹᵘˢᵗ ᵇᵉ ᵃ ᵖˢᵉᵘᵈᵒʳᵃⁿᵈᵒᵐ ˢᵗʳᶦⁿᵍ ⁽ʷ/ᵒ ᵖᵃᵗᵗᵉʳⁿˢ ᵒʳ ᵈᶦᶜᵗᶦᵒⁿⁿᵃʳʸ ʷᵒʳᵈˢ⁾