@LOCASHmusic snagged this the other night at CCMF. Been a hell of a year and a half battling stage 4 cancer, but I beat it so far and living my best life. I made sure I could make CCMF this year after missing out on everything last year. Hell of a show!
@CarMax even though I didn’t have the best experience, i care deeply about people experiencing hard times. Unfortunately the managers wife has triple negative breast cancer. I the mail today was this. So much love.
Huge shoutout to @MedUnivSC. Thanks to a cancellation, they got me scheduled for my ileostomy reversal in under 48 hours. Faced some complications, but their care and skill went above and beyond. Home and recovering!
So thankful for @MedUnivSC for my temporary ileostomy and tumor removal. I have some amazing people on my care team. Just 4 days ago I was in surgery. Today I was able to be back to work. Happy that I will be able to enjoy Thanksgiving. Still a long road ahead.
Been having a little fun with AI lately for how to improve password cracking.
#hashcat#passwordcracking
https://t.co/7Xe0TeU3Xd
https://t.co/y9ECMgpGx6
Been a hell of a year battling cancer. Wife surprised me with the @steelers crucial catch hoodie. So far this year…4 colonoscopies, port surgery, radiation with chemo pills, 8 chemo infusions (4 more in my future) and waiting to schedule surgery. Enjoying a short break.
Earlier this year I was credited with CVE-2024-25693 for arcgis with base CVSS of 9.9. This vulnerability was a lot of fun as it chained several vulnerabilities together resulting in unauthenticated access to a web shell.
I was asked to show more than an alert for XSS in Sharepoint. I was able to access the user’s private/public files, delete and upload files to their drive. The XSS I reported was patched. The scripts used with the XSS is in the code of the repo. https://t.co/eaiq10QDgL
We ended up snagging a pick at @CCMFLive with Duddy and @SublimeWithRome. Was not expecting to sing happy birthday to Rome or the vibe they brought to the venue.
@NahamSec Definitely. Have you had a dupe of a vulnerability you submitted, never released to the public of a specific payload, where the platform leaked your payload to everyone and when you submit the next vuln you are the dupe even though it is your exact payload just on a dif endpoint?
I apologize, the example 14 isn’t real world since it relies on fetch and a string. The concept is worth learning. Using what is in the JavaScript to exploit XSS without actually typing a normal payload. It is an interesting exercise. Encountered a few times but not this easy.
Have a way to go. Some allow payloads that aren’t the intended solution (need to code checks for things burp discovers). Trying to create XSS that happens in the real world. The intended payloads are based on alert and document.domain unless specified. https://t.co/v4tyDZABAM