I have been putting lots of time learning Golang lately. As a part of this learning experience, I decided to put my knowledge to test and rewrite BruteSpray from Python to Golang! It's much faster and no longer utilizes Medusa for bruteforce. #brutespray
https://t.co/bK1b3EN2Gb
Finally finished building and testing all of the hands-on hardware hacking exercise units for @defcon@IoTvillage . Next step is to write-ups the training manual for the lab.
Currently working to find and build out a new hands on exercise for @defcon 30 @IoTvillage. Hope to create a new learning opportunity for those attending this year. Will keep everyone updated as it progresses. Currently just destroying tons of gear i have been buying on eBay
You like NTLM relays to LDAP? Same. There's a unique error that will identify whether LDAP EPA (channel binding) is enforced, and it can be determined from an unauthenticated perspective.
Here's a PoC to check for both channel binding and server signing:
https://t.co/s7qGACH4DY
Log4j2 < 2.17.0 sensitive data leakage , if it’s configured like pattern="${ctx:userAgent}" and put User-Agent to MDC, forged header 'User-Agent: ${hostName}' will output hostname of server. This security issue has been fixed in Log4j2 2.17.0😄
to add, the original flights had generous layovers to give my infant son a break as this is his first time flying, now our layovers are down to the wire, thanks for nothing #AmericanAirlines
@AmericanAir shame on you... You move my flight over 2 hours but will not provide a cancellation refund, and won't let me switch to a flight similar to my original because of the cost difference. Lousy customer service, this is the final straw for me to switch to Delta
Another new podcast episode with @sho_luv and @t1d3nio as they tell us about a social engineering engagement that started on the roof, went into the vault and earned them swag!
https://t.co/tQochFIOlk