/teasing for French speakers
Après plus d'un an de boulot en parallèle des missions, on y arrive enfin !
Un livre sur la sécurité offensive (non, pas un énième bouquin d'ethical hacking ou autre sujet traité 100x)
* TTP et techniques d'évasion
* Découverte de vuln inconnues et construction de full chain exploitable
* Montage de C2 et d'infra offensive
* Des bypass utilisés en intrusion physique, redoutablement efficaces dans la vraie vie - testés et approuvés ;)
Mais aussi tout ce qu'on montre jamais et qui fais parti du taff:
threat modeling, phase de qualification/adaptation aux type de contraintes, reporting orienté impact métier pour tirer un max de valeur de chaque exercice...
Le fil rouge:
trouver, *comprendre* et exploiter reste un métier de réflexion.
Pas de scan ou d'automatisation qui pense à ta place.
Le "think out of the box", le vrai n'est pas mort.
-> À l'ère de l'IA c'est même notre plus grand atout !
Fiche dispo chez https://t.co/wkseByIewR
cc @EdicionesENI@ENIEcoleInforma
Sortie prévue juste après la rentrée , stay tuned 🔥
https://t.co/WfuFX8n5Lv
#OffSec #Pentest #RedTeam #InfoSec
I hadn’t planned to share this quite so soon, but you guys are observant.
Today was my final day at @FcpnchStds working on @playrust.
Nearly thirteen years ago, I discovered a game called Rust. Nearly eleven years ago, I was given the incredible opportunity to work on it by @garrynewman and @Helkus
I joined Facepunch from the community and worked my way up to COO and Executive Producer on Rust, originally from QA. Today, I’m stepping away and returning to where I started: as part of the community.
Rust and Facepunch have consumed a huge part of my life. I’ve loved it, fought for it and given it everything I had. Leaving has been one of the hardest decisions I’ve ever made, but I’m incredibly proud of what we’ve achieved. I've live my 10 year old dream.
Rust has one of the best development teams in the industry. For more than a decade, they’ve delivered monthly updates without fail, constantly improving, experimenting and pushing the game forwards. I’m proud of the culture we built and the legacy I leave behind.
Rust is currently reaching some of the highest numbers in its 13 year history across multiple platforms. Rust Mobile is also well underway, and I’m incredibly proud to have worked so closely with that team and helped bring Rust to an entirely new audience.
It's not always easy running a game of this scale, but I fucking loved it. Rust has made gaming history.
None of this would exist without the community. A game is nothing without the people who play it, support it, create content around it, run servers, make mods, report issues and continue play. You’ve challenged us, frustrated us, inspired us and helped shape Rust into what it is today. I’ll always be grateful for that.
Looking at you /r/playrust - you're a confusing bunch.
I don’t have another job or some big new adventure lined up, but I can't wait to see what next sparks my passion.
The years I dedicated to Rust inevitably took time away from other parts of my life. Now it’s time to give some of that time back into the areas I sacrificed.
Thank you to everyone at Facepunch, our partners, the creators, server owners, admins, modders, mappers, [you] and the tens millions of players who made this journey possible.
I’ll still be around. Just back in the community where it all began. 🫡
It's being a wild ride.
🩷🩷🩷
⚠️ Monero + Tor : une faille réseau vient d’être exposée !!
Le Monero Research Lab se réunit demain 29 juillet pour en discuter...
Monero est conçu pour cacher :
👉 qui envoie
👉 qui reçoit
👉 et combien
Pour protéger aussi l’adresse IP de l’utilisateur, beaucoup de gens (et de nœuds) font passer leurs transactions via Tor
Le paper montre qu’il existe une faille au niveau du réseau (pas dans la cryptographie de Monero elle-même) quand on utilise Tor avec Monero
Explication...
Quand un nœud Monero tourne derrière Tor :
➡️ Il crée une adresse oignon (hidden service)
➡️ Quand il veut envoyer une transaction, il ne la diffuse pas directement sur internet clair
➡️ Il l’envoie d’abord uniquement à deux nœuds Tor proxy (des hidden services sortants) avant que la transaction ne passe sur le réseau Monero normal (clearnet)
C’est une particularité de la façon dont Monero gère les connexions Tor
Un attaquant peut :
👉 Prendre la place de ces deux connexions sortantes du nœud cible
👉 Capturer les transactions qui sortent de ce nœud
👉 Puis utiliser une technique appelée watermarking (marquage du trafic) pour lier l’adresse oignon Tor à la vraie adresse IP de la machine
Ils appellent leur méthode ProxyMark
Elle se déroule en trois étapes :
➡️ Identifier le rôle des nœuds (qui est un proxy, qui est un client, etc.)
➡️ Capturer les transactions qui originent du nœud cible
➡️ Dé-anonymiser la localisation (trouver l’IP réelle)
Les auteurs ont testé leur attaque sur :
👉 le réseau Tor réel
👉 le mainnet Monero
👉 et le testnet
Résultats rapportés :
Identification des adresses oignon : 100% de précision ‼️
Occupation des connexions sortantes :
Très efficace (7 à 11 sur 12 connexions selon les conditions)
Watermarking :
100% de précision et plus de 91-93% de rappel
Autrement dit, dans les conditions de leurs expériences, l’attaque fonctionne très bien !
👉 Ça ne casse pas les ring signatures, les stealth addresses ni RingCT
👉 Ça ne permet pas de lire le contenu des transactions Monero
👉 Ça ne dé-anonymise pas les utilisateurs qui n’utilisent pas Tor de cette façon (ou qui utilisent Tor correctement avec d’autres précautions)
C’est une attaque réseau... elle exploite la façon dont Monero et Tor interagissent ensemble, pas la crypto on-chain
Le Monero Research Lab en discute demain 29 juillet
Ils vont regarder s’il faut changer quelque chose dans le code
Bref... Dès que deux protocoles se rencontrent, un point faible apparaît souvent 😉
#Monero #Tor #Privacy
@Aykuro_@ssysyy7 Ta pas compris et c'est ok. Il a simplement dit que vous avez le droit de DEMANDER. Pas que c'est obligatoire de rembourser. Et en général si tu es pas trop chiant que tu abuses pas, se faire sauter quelques lignes de frais c'est tranquille
🚨 Q1 2026 Cyber Risk Report is out!
📷Based on 2.1 MILLION malware & phishing investigations, @anyrun_app reveals:
• +14.7% surge in credential theft
• +98.3% explosion in loader-based attacks
• +58.4% rise in LOLBAS living-off-the-land tactics The threat landscape is evolving fast.
Don’t miss these critical insights!
📷 Read the full report: #CyberSecurity #ThreatIntelligence #CyberRisk
Au final, j'ai décider de faire croquer tout le monde, pas juste ma communauté.
Déjà RT -> 250$ tirage cette semaine
Ensuite sur mon site https://t.co/HnW3LNSHsv c'est désormais 3000$ de cash pour tous. Tout le monde peut participer, n'importe ou dans le monde.
Pronostiquez, soyez le meilleur, gagnez du fric.
Analyzed a PowerShell malware loader that hides its second stage inside a seemingly legitimate MP3 file.
Key observations:
• Downloads result.mp3
• Extracts bytes from a fixed offset (12345)
• Decrypts the blob using an RC4-like stream cipher with key "ZHOPA"
• Attempts in-memory execution via VirtualAlloc + NtCreateThreadEx
This is a nice example of payload smuggling using non-executable media files.
https://lincdiiin[.]com/homework.txt
https://lincdiiin[.]com/Program.exe
https://lincdiiin[.]com/loader.hta
https://lincdiiin[.]com/result.mp3
The loader never directly executes the downloaded MP3.
Instead:
OFFSET = 12345
PAYLOAD_LENGTH = 23148
KEY = "ZHOPA"
The selected byte range is decrypted and copied into RWX memory:
VirtualAlloc(..., PAGE_EXECUTE_READWRITE)
Marshal.Copy(...)
NtCreateThreadEx(...)
If thread creation fails, the malware drops the payload as a temporary .exe and executes it from disk.
Classic fileless-first, disk-fallback behavior.
Un gros giveaway pour fêter notre victoire au Major Paris de Rocket League ça vous dit ? On dit merci Razer pour ce stuff de compétition 😁
À gagner :
🎧 1 casque Blackshark V3 Pro PS5
🎮 1 manette Raiju V3 Pro PS5
👕 1 maillot Eternals
Pour participer :
✅ RT + Like ce tweet
✅ Follow @KarmineCorp & @RazerFrance
🍀 TAS le 02/06, bonne chance à tous !
CIA and Mossad and pedo elite are running some kind of sex trafficking entrapment blackmail ring out of Puerto Rico and caribbean islands. They are going to frame me with a laptop planted by my ex gf who was a spy. They will torture me to death.
Check out the Winds of January:
📅Version 1.2 arrives Jan 8 (UTC)
🗺️New Region: Nine Mortal Ways Base
📖New Story: Kaifeng Campaign & Legacy Quests
🏆New Content: Jianghu Martial Games, Guild Battle Preseason, Hero's Realm, World Boss, and more!
Free-to-Play with Cross-Play and Cross-Progression across PC, PS5 and Mobile!
📱 Mobile: https://t.co/lU0p6oVpAo
💻 PC & PS: https://t.co/gNamN21zUA
#WhereWindsMeet