This is super cool! (just catching up late after the weekend)
Is it possible to generate that passkey using the previously captured cookies or tokens, through phishing? (using browser cookies in general)
Discord announces that users will need to verify their age from early March onwards in-order-to access age restricted content.
All accounts will be set to a āteen-by-defaultā experience until otherwise verified as an adult.
(discord.com/press-releases/dā¦)
I came across a simple technique that abuses Fondue.exe, a native Windows binary, to execute a custom malicious APPWIZ.cpl file placed in the same directory.
PoC and More details on how it was discovered later!
#redteam#offsec
Wow this post really blew up! If you want to know more about the smallest possible files that do things, check out the 6th annual Binary Golf Grand Prix, happening now til January 18th!
x.com/binarygolf/status/1979ā¦
Would you like to be my colleague, and get to wear an awesome red hoodie? We are looking for a full-stack / offensive developer. Drop me a message or apply directly: job-boards.greenhouse.io/forā¦
We are giving away 1 free spot for level ZERO.
If you are a cyber pro or tech bro and want a full system reset - now is your chance.
To enter: š retweet
Bonus entry: š¬ comment below - 1 thing you want to fix in the new year.
Winner announced Friday.
#wehackhealth
Today I got RDOFF (.rdf) files working in nasm 2.15. I wrote my own lib bc nasm didn't generate properly. Also patched the 32-bit loader in `rdx` with mmap tricks (shoutout ixi). An executable RDOFF has likely never run on a 64 bit system before today. Writeup soon! #BGGP6
ALT gdb executing the rdx binary with the global.rdf file as the argument, returning 6 and exiting
ALT screenshot of a terminal with the rdx binary running global.rdf checking the return value, a hex dump of the file, and the output of the generator script that built it
New writeup for #BGGP6 !!
What's the smallest Wireshark dissector? What's the most annoying Wireshark dissector?
Find out here: n0.lol/bggp6-wireshark/
ALT Wireshark with a bunch of pop up windows that say "6"
Last month, @d_tranman and I gave a talk @MCTTP_Con called "COM to the Darkside" focusing on COM/DCOM cross-session and fileless lateral movement tradecraft.
Check out the slides here: github.com/bohops/COM-to-theā¦
Recording should be released soon.
Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ā¤µļø ghst.ly/4qtl2rm
Red Treat was incredible. Thank you so much to @domchell@StanHacked@MarcOverIP for your hard work making another successful year. The calibre of content shared the conversations was šand @max__grim thanks for another swanky badge