First @hashcat benchmarks on the new @nvidia RTX 4090! Coming in at an insane >2x uplift over the 3090 for nearly every algorithm. Easily capable of setting records: 300GH/s NTLM and 200kh/s bcrypt w/ OC! Thanks to blazer for the run. Full benchmarks here: https://t.co/Bftucib7P9
A quick writeup on my recent experience trying to disclose a vulnerability to the owners of a website and why you should encourage vulnerability disclosure in your business - https://t.co/MUQH02mxQC
The Conti ransomware leaks have unveiled Conti's primary Bitcoin address.
From April 21st, 2017 - February 28th, 2022 Conti has received 65,498.197 BTC
That is 2,707,466,220.29 USD.
I wrote about a blind SQL injection vulnerability I recently found during an engagement. I felt it was a bit unusual compared to the normal SQL injection vulnerabilities I find.
Let me know what you think.
https://t.co/X9StjH8ly7
#penetrationtesting#sqlinjection
An interesting read. It could be argued (and I’m sure it will) that these vulnerabilities make the data inadmissible as it could have been altered. Guess Cellebrite will be increasing their security spend. https://t.co/8EypZwO4M4
For newish pentesters: alt + printscreen will screenshot the active window only and for windows 10: windows key + shift + s will let you choose an area to capture (just like snipping tool without the extra steps). You're welcome :D
A surprisingly fun red vs blue team game on steam. While it has it's issues, it conveys the feeling that the other side has an unfair advantage regardless of which team you choose.
https://t.co/toQ1NOeRGd
An interesting view in opposition to the concept of "technical debt". Main point, well made: Technical people using business terminology incorrectly is just as amusing as business people using technical terms incorrectly.
Infosec is full of bad analogies. The absolute worse is "technical debt". People think it's a good analogy for communicating with "business types", but it isn't, because techies don't understand "debt". Techies think debt is bad, business types think debt is good.
According to google a new zero day is discovered on average every 17 days in the wild. This compared to the many many millions of unpatched machines that are vulnerable to known attacks every day. It's the heart attack that'll get you, not the shark! https://t.co/sDikOnrOPZ
We've confirmed exploitability of Windows Pre-Auth RDP bug (CVE-2019-0708) patched yesterday by Microsoft. Exploit works remotely, without authentication, and provides SYSTEM privileges on Windows Srv 2008, Win 7, Win 2003, XP. Enabling NLA mitigates the bug. Patch now or GFY!
WhatsApp hard to detect remote code execution vulnerability discovered by the internal security team even though it only took an (unanswered) call to exploit - Nice when the system works...kinda - https://t.co/FJnL3qVzuE