Thanks everyone who attended my keynote presentation at @bsidesahmedabad.
I've published my slides here: https://t.co/nX774nrEbU
I hope that the keynote was informative and inspiring :)
I was recently featured in the American Banker for my work in bug bounties targeting financial institutions. You can read about it here:
Article: https://t.co/eCdLRueUuj
Bypass paywall: https://t.co/USikKdvj7F
Our security research team @assetnote discovered a critical pre-authentication RCE vulnerability affecting Aspera Faspex. There are still thousands of unpatched instances on the internet. Pretty crazy bug. You can read about the finding here: https://t.co/FT8D7WeF0V
Our security research team at @assetnote discovered a critical RCE vulnerability in Avaya Device Services. This vulnerability has affected our customers and has also led to over $60k of findings in bug bounties. You can read the writeup of this issue here: https://t.co/qXmof1oLML
Huge thanks to all CSECcon 2022 attendees, speakers, sponsors, volunteers, DUCTF, MQ MACS, ActivateUTS and UTS:CSEC!
Link in bio to leave feedback and view photos! Check emails to see if you’re a CTF winner/your prizes, and reach out if you missed out on collecting your merch!
Shoutout to @utscsec for organising such a wonderful infosec conf! It had everything: cool venue, excellent and diverse speakers, a sweet lighting setup, a ctf room, a quiet room, rad artwork. Oh and this was their *first* conference. I'm in awe. Much ❤️❤️
1/3
New video! In this video we walk through the first Azure attack workshop by @Mandiant
https://t.co/Y7DWjSKXkI
We cover:
- Resetting app credentials and logging in as the service principal
- Listing Azure key vaults, listing secrets and showing secret values
I am quite often asked if there are sites, training, and/or books that I would recommend to get into DFIR and of course, continue to learn. So I have created a sub-page Resources with my recommendations. I will continue to update this page over time.
https://t.co/M7WN5yaWaG
🔥Get keen and block out the 23rd-25th September in your calendars as CTF days cause DUCTF 3.0 is coming!
See y'all there hackers! 💻
https://t.co/2pQFJvCBEQ
#cybersecurity#ctf#infosec#ductf
The second episode of Bug Bounty Redacted is out now! https://t.co/bfZxFtbztv
This episode covers third party subdomain takeovers and exposed administration panels.
There's also a free @PentesterLab 1-month subscription code in the video. I wonder who will find it first?
I've released the first episode of Bug Bounty Redacted today (Exposed Redis & HAProxy):
https://t.co/AA0xlUE1k2
This series walks you through real bug bounty reports that were rewarded, and explains the discovery process, and reporting process in detail.
New episodes Monthly!
Other day I asked for large repos of detection rules here is the running list of responses.
Elastic - https://t.co/OwVwhHU3nZ
Sigma - https://t.co/LygEgGSBeB
Chronicle - https://t.co/4QqDyzJCWC
Splunk - https://t.co/csHzWFCpLE
Falcon Force -https://t.co/9cOd5elj3U
We've released a new blog post and a tool called Ghostbuster which eliminates dangling elastic IPs by performing analysis on your resources within all your AWS accounts. You can read about this here: https://t.co/Y2owuFj4wI
Our CFP is up! Sign up, whether you're old or new to the field, if you have something to talk highly technical or more social or functional, or even if it's only adjacent to cyber!
https://t.co/26eqIldYHF
Our team took apart Solarwinds Web Help Desk to discover some serious issues (hardcoded credentials, arbitrary HQL evaluation) - CVE-2021-35232 - we explain the discovery and exploitation process in our blog post:
https://t.co/AIiTIohBzh