@SymoneBeez maybe if they were worthless. That’s not the case here, they’ve got the OSEP, OSED, and OSWE - that combination alone is a gold for most appsec roles and red team roles. Most cleared IC roles would pay near 300-400k for malware researchers, red team operators and roles alike.
@kobi_hk how would you trigger a bypass if the status will always return 429’s? I get there’s not rate-limiting, but is the bypass an actual bypass or just that there’s no rate-limiting imposed?
@muddletoes@IceSolst that’s a pretty flawed statement. You can be generating mrr from users of your product that highlights value and some growth so that investors feel more confident about investing in your startup
@tyler_agg How would you best incorporate this from input coming from for instance a Twilio response webhook? Then sending output back through Twilio or SMS in general?
@I_Am_Jakoby Curious on ways to create detections around this. Maybe decoding the ASCII and looking for specific cmdlets? Or querying for specific instances of anomalous chars in the PS command history? Trying to find a catch all detection.
That epic Microsoft moment❤️#cve20200601#curveball
Recently worked on #mimikatz and ECC, so yes, 10 and 2016/2019 only.
Previous versions like Windows 7 did not support personnal EC curves (only few NIST standard ones)
I made Silver public, mass vulnerability scanner 🔥
Github: https://t.co/jGZSPSFqnT
- Scans are resumable by default
- Get notified on Slack if a vulnerability is found
- Designed for large volume scans
- Caches vuln. data to improve performance over time
- Shodan integration