This video changed how I used vim forever. And I’m super thankful for it. @TomNomNom@stokfredrik. Tomorrow I’ll be posting a (very small) follow-up use case of some tricks in this video combined with ai. https://t.co/EIgm8vcYCx
One cool thing I didn't mention in the presentation is that you can also use the single-packet attack via Burp Repeater, even in the free edition. This should make testing & creating replication steps for triagers a bit easier!
Attention @BlackHatEvents attendees! 🚨
@2600AltF4 and David Vargas from Bishop Fox present their #security research TODAY; don’t miss “Badge of Shame: Breaking into Secure Facilities with #OSDP” starting at 11:20 AM today in South Seas CD, Level 3. https://t.co/MK1iZebjFi
A deep dive into crypto vulnerabilities my team discovered that enabled @bishopfox's security research + exploit development in FortiGate firewalls 🔥🧱 https://t.co/GKNeSpHB4h
We are over the moon to announce that Senior Security Engineer Tom Hudson (@tomnomnom), the mastermind behind popular #opensource gems like jsluice and gron, is gracing our #DEFCON 31 edition of #BFLive! 🚀
Get ready to dive into the secrets of his exceptional #hacking tools and uncover the methodologies fueling them – and hear his unique #offensivesecurity perspective as well. https://t.co/59JMzUmwFT
🛠️ jsluice
A command-line tool for extracting URLs, paths, secrets, and other interesting data from JavaScript source code
By @bishopfox's @tomnomnom#bugbountytips#pentesting
https://t.co/aRBKx6X2fH
One week until this talk. I got a preview of Jon's section on building an exploit for a FortiGate CVE and it will be great. Plus, hear the tale of how I accidentally found vulns in Windows and InTune while looking for the same type of issue in a product we assessed.
My brilliant team at @bishopfox developed a safe, no-crash vulnerability check for the recent CVE-2023-27997 heap overflow in FortiGate firewalls allowing RCE. You can try the tool out yourself at https://t.co/X8Fg73RQgF. Check out the blog, too! Clever technique, worth a read.
@TomNomNom I like Usage, because it sort of fleshes out what the tool does. Then, when you've had a chance to see whether it meets your needs, install instructions