8 years ago we started tweeting with this twitter handle and with responsible disclosure & bug bounty hunting as @internetwache.
... an amazing ride so far - let's see how it continues.
//cc: @gehaxelt & @TimPhSchaefers
Since portions of the web directory were protected, I had to use a tool to download all the `git objects` from the server.
⚠️ I used GitTools "Dumper" to dump the available objects, from @internetwache
https://t.co/TDA63L39Mc
I started my blog in 2014, inspired by great security bloggers like @bitquark and @internetwache. The best platform to build up a blog at at that was Google Blogger. They provide a clean dashboard for writing posts, managing comments, understanding stats, and security features.
Im "Dialog für Cyber-Sicherheit - Denkwerkstatt" von @BSI_Bund, @iRightslab & @nexus_Institut haben wir heute am "Konzept zur Ausbildung digitaler Katastrophenschützer*innen" mitgewirkt.
Es wird Zeit für "digitale Ersthelfer*Innen"! 💻
//cc: @ijonberlin @HonkHase @AG_KRITIS
Im "Dialog für Cyber-Sicherheit - Denkwerkstatt" von @BSI_Bund, @iRightslab & @nexus_Institut haben wir heute am "Konzept zur Ausbildung digitaler Katastrophenschützer*innen" mitgewirkt.
Es wird Zeit für "digitale Ersthelfer*Innen"! 💻
//cc: @ijonberlin @HonkHase @AG_KRITIS
Heute vertrete ich die @AG_KRITIS in dieser spannenden Runde!
Gestern war der @HonkHase für uns dabei. Ich bin total gespannt welche Projekte ausgewählt werden!
News about hackers who attacked "Water Supply" in the US ...
Also a big problem in Germany - in 2018 we gained access ~7 local water supply stations in Germany.
Also mentioned with another case of us in the official @BSI_Bund / @certbund report. https://t.co/fz7Mfct8x3 ^ts
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)
Git Happens - I have just completed this room!
Used Git Dumper and Extractor from @internetwache's GitTools to get all the source code and then went looking for passwords in old commits.
Check it out: https://t.co/MuxOzrlul8
#TryHackMe#git#githappens via @tryhackme
A session by @TimPhSchaefers & @gehaxelt at @sitberlin 2018: Handling security bugs with responsible disclosure and bug bounty programs https://t.co/Zdi8dCwEVY #Security
@stokfredrik@LiveOverflow We are Hackers! We want to spread the words and share our knowledge. We like copyleft, not copyright. If we had claimed all our RCE and XSS payloads and techniques since 2005 all of you new bug bounty hunter should pay to us researchers from the early days! That said: keep calm!
Git Happens -- discovering a public-facing Github repository and pulling it down to look through website source code! A very quick and simple showcase. Premieres 2:00 PM EST. #ctf#git#tryhackme#pentest#infosec https://t.co/DV5Nd8HXx7
4 years ago we had a video shoot about our project @internetwache and Bug Bounty Hunting.
A lot of things have changed since that - but still a lot of fun to watch.
Our Favorite scene has to do something with extreme sport 😂 - take a look.
https://t.co/Pm5cS8hBTI ^ts
Heute Abend in der ARD um 21:45 Uhr sind wir (@gehaxelt und @TimPhSchaefers) kurz bei Report Mainz zum Thema "kritische Infrastrukturen & IT-Sicherheitsgesetz 2.0" zu sehen - also schaltet gern ein.
https://t.co/HVkF5mzA3D
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)
@nnwakelam Hi, thx for the message - we look into that.
Maybe this script helps you in the meantime:
https://t.co/3WWdgBGryE
Read also the background article on that:
https://t.co/LZyq77d6t5 ^ts
Dass das Szenario im Bereich "Wasserversorgung" von @ijonberlin keinesfalls aus der Luft gegriffen ist, zeigen unsere Erfahrungen aus den letzten Jahren. #defensivecon
Siehe bspw.: https://t.co/sWd6bTjZrZ
Live-Stream / Programm für Interessierte: https://t.co/MpurFOyx1r
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)