Lost my phone at the office and spent 30 minutes turning the place over. Find My was disabled by MDM.
Out of ideas, I asked Claude how I could find it. It suggested tracking the Bluetooth signal strength, then wrote me a meter in about a minute.
I walked around watching the number climb. Found it.
Apparently you can just make the tool you need now.
Code: https://t.co/fmnISzHfZ2
HExHTTP - Header Exploitation HTTP
HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors.
https://t.co/d9KR9dukJi
Dumping SAM from a live Kali Linux in 2022 🔽
1⃣ cd Windows/System32/config
2⃣ pypykatz registry --sam SAM SYSTEM
Tools like chntpw, bkhive, pwdump, samdump2 are not working on latest Windows 10 👀
https://t.co/LyHlBnvcCX
🚨 ALERT 🚨
Python's ctx library and a fork of PHP's phpass have been compromised. 3 million users combined.
The malicious code sends all the environment variables to a heroku app, likely to mine AWS credentials.
Able to access Million+ emails $:
API Implementation:
/organization/:id => only org name shown
/organization/:id/users => 403 typical response
/organization/:id/users?get=newfolder => 403 with response & error msg (auth)
/organization/:id/users?get=users::metadata => BOOM
El Lago Groom mide 1300 metros y se extiende aproximadamente unos 6 kilómetros desde el Norte hasta el Sur, y unos 5 kilómetros de Este a Oeste en su parte más amplia.
New XML technique! Encode any DTD/XML inside an internal entity, and fly under WAF radars!
💥 XXE WAF Bypass
💥 Works when there is no XXE, but there is a vuln in the XML body, e.g. SQL Injection
#ptswarmTechniques