Joined July 2021
1,798 Photos and videos
Pinned Tweet
14 Dec 2023
Down memory lane we go, #hackrf one with a OnePlus Nord N100 (Rooted with nethunter and some added kernel functions.) #sdr #nethunter
🐸🐴💀😎🐄
8
4
36
11,006
I'm not much of a chef but sometimes it happens 😎
23
Heh, what a coincidence this pops up tonight. Great work and super. Obfuscation - keep up the good work world ᕙ⁠(⁠ ⁠ ⁠•⁠ ⁠‿⁠ ⁠•⁠ ⁠ ⁠)⁠ᕗ
firewalls can't stop this. A developer just open sourced a tunnel that smuggles your entire internet through port 53 the port every router on earth is forced to leave open. It's called MasterDnsVPN. It hides your traffic inside DNS queries, the one type of packet no network can block without breaking itself. Every firewall on earth has to allow DNS. Schools, airports, hotels, hotel WiFi, entire countries running ISP-level censorship all of them keep port 53 open or nothing on the network resolves. This repo turns that loophole into a full encrypted tunnel. Here's what makes it different from every other DNS tunnel that came before: → Custom ARQ layer gives you TCP-level reliability over UDP DNS, so nothing drops even on garbage networks → Sends every packet through up to 12 different resolver paths at the same time, if 11 fail the packet still arrives → Auto probes the maximum DNS payload your path can handle, then locks in the fastest MTU possible → AES-256-GCM, ChaCha20, AES-128, AES-192 all built in, pick your encryption → SOCKS5 proxy on 127.0.0.1:1080 point any browser or app at it and you're through Killed: $12/mo Mullvad, $10/mo NordVPN, $15/mo Astrill, every commercial DNS tunnel charging monthly fees for the exact same idea. Pre-built binaries for Windows, Linux AMD64, Linux ARM64, macOS ARM64. No Python install needed. Configure two DNS records, drop in the encryption key, run the executable. Works in environments where every other VPN protocol is dead on arrival. MIT License. 100% Opensource.
114
This old project in python came back to me, now this is just a simple GUI inspired by @ACEResponder, I do wonder 🤔, if pulling a port for each event and listing them as well might be a new feature. Hmm 🧐
Ty for a great list, @ACEResponder Had some weekend fun and made a super simple automated UI to look for the events listed. #DFIR #ThreatHunting #Python 😇
64
𒐪Z.A.P𒐪 retweeted
Hacking embedded systems using cheap hardware and LLMs: a How-to from @bl4sty [finally!]. 👨🏻‍💻🏭🔨💸🏆 More details: LinkedIn: linkedin.com/posts/dlaskov_c… Substack: it4sec.substack.com/p/hackin…
15
85
2,698
Hmmm 🤔
Rootless Android screen mirroring and device control github.com/barry-ran/QtScrcp…
46
𒐪Z.A.P𒐪 retweeted
10
97
511
18,181
𒐪Z.A.P𒐪 retweeted
Brute-forces hidden web paths using custom wordlists github.com/maurosoria/dirsea…
2
17
84
5,173
Keep it off ¯⁠\⁠_⁠(⁠ツ⁠)⁠_⁠/⁠¯
OMG
46
𒐪Z.A.P𒐪 retweeted
🚨 A threat actor known as welcometonightbrother is sharing source code that allegedly bypasses Cloudflare's Turnstile challenge, the bot-detection and CAPTCHA system used to protect websites. The actor says the tool works in a browser-based context, has posted a link to the code, and claims a reCAPTCHA v2 bypass may follow. Claim is unverified. 💥 Stop guessing what's redacted. Paid subscribers see everything: darkwebinformer.com/pricing
4
16
153
18,822
𒐪Z.A.P𒐪 retweeted
Microsoft has identified a npm supply chain compromise impacting 90 redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, frontend-components 7.7.2, and others. The payload is a self-propagating worm that infects other npm packages and self-publishes. Each compromised package adds a malicious preinstall hook, embedding an index.js script in the package.json that silently executes “node index.js” during installation, downloads Bun, and runs a payload that steals secrets from npm, GitHub, Amazon Web Services (AWS), and Secure Shell (SSH). The added code bloats index.js from ~8KB to ~4.3MB, acting as a heavily obfuscated ROT-9 eval loader. If any of the compromised packages are installed, users and organizations should assume compromise, rotate credentials, revert to a previously trusted version, and block compromised packages. Identified compromised npm packages have been taken down, and we continue to work with the npm team. Microsoft continues to investigate this attack and will publish updates as more information is available.
35
181
622
112,000
𒐪Z.A.P𒐪 retweeted
Hacking the Sensors: A playbook for hackers on what sensors are and how to attack them. 🏭🌡️🔦😱💥 More details on: LinkedIn: linkedin.com/posts/dlaskov_c… Substack: it4sec.substack.com/p/hackin…
20
108
3,242
It's a slow day, so a walk it is.
1
25
(⁠◔⁠‿⁠◔⁠)
NappyNoel004 - (Prank Phone Tap) You Could Be In Grave Danger
23
𒐪Z.A.P𒐪 retweeted
May 29
A new era of PC. 25.0528, 121.5990
8
205
1,833
58,624
(⁠⊙⁠_⁠◎⁠)\⁠(⁠°⁠o⁠°⁠)⁠/
NappyNoel004 - (Prank Phone Tap) - DJ From The Past 😄 🤣.
15
𒐪Z.A.P𒐪 retweeted
May 29
What’s your favorite scary movie?
310
472
10,412
8,241,276
𒐪Z.A.P𒐪 retweeted
Hugging Face security analysis: ~70,000 live secrets and API keys, private repos, and leaky pics! 🤖🤗💦🔑😈 More details on: LinkedIn: linkedin.com/posts/dlaskov_a… Substack: it4sec.substack.com/p/huggin…
14
37
1,954
𒐪Z.A.P𒐪 retweeted
Mirror Man... How many years bad luck do you score for breaking that?
114
505
9,891
1,579,665