disassembler of gubbins, builder of awful things, breaker of worse things, herder of cats. father of drones.

Joined May 2023
157 Photos and videos
There are ways and means to get around this, but they are vaguely effort-intensive and sufficiently annoying to not be worthwhile. Like, what is there to gain anyway.
Another reason public wifi is fine: client isolation. Each device is basically on its own vlan.
1
1
549
one of my strongly held opinions in the game of "red teaming" is that you should try stupid, low effort, "an intern could do this/this will never work" shit right off the rip. I mean. It works all the goddamn time in the wild. Obsession with "evasions" is brainworms.
5
3
60
2,809
just fucking have someone make a yandex or gmail or whatever free-email and start sending low effort shit out on day 1 of the engagement. while your coworkers are busy faffing around with indirect syscalls or sleep masks or whatever, you will probably get a shell, statistically
2
7
404
red team protip: just repeatedly spam them barely convincing emails linking to a page that serves an executable file and you will probably land a shell in an embarrassingly large number of engagements.
2
12
1,793
the amount of wins I get with ${off the shelf C2} in stock config or minimal alteration probably outweighs the amount of wins I get where I spend a shitload of effort making something extra super duper speshul for the engagement. If you know, you know.
31 Jul 2025
Same thing goes for C2s, but y’all aren’t ready for that conversation 🙈
1
5
468
there should be a measurement for "billable hours wasted on unnecessary R&D" honestly for red team work. Often just fucking going full send with the most bullshit solution you did in 5 minutes beats spending weeks of work on "evasion" and Big Red Team doesn't want to admit this.
1
3
167
Something I am looking for since forever is a old copy of "H1N1 Loader" by Slayer616 that was published on an old forum (OpenSC, and some others). I wonder if any other VX archivist types have it? Or the Func-In RAT demos by DeadlyVermillion? cc: @vxunderground
3
2
269
also related: original copies of "Dangerous Kitten" or "/i/kit" or similar. Needed for a history project a friends doing.
1
105
Pretty much all these interceptor "aerodynamic shell" designs are based on race drones. A lot of wheels are being busily reinvented by those who care not for looking at prior art and it is honestly fucking depressing.
3D printed German interceptor drone looks suspiciously similar to the Ukrainian ones. This American football looking little goblin can go 400 km/hr. Someone has been collaborating 🤝
Community note
Video was taken from a hobbyist drone builder, quadmovr. Creator's accounts: x.com/quadmovr youtube.com/@quadmovr/shor… Original video: youtube.com/shorts/Jcc51Ov…
1
3
299
As an example... Anyone with much experience would probably have put the motors in a pusher config instead of a tractor/puller config to put less load on the ESC.
1
90
I nearly was an Internet Arsehole and replied with "skill issue", but Dmitry is about 90001x more talented than me at literally everything and I actually agree with him somewhat here. The User Experience of F/OSS networking honestly fucking sucks and saying "skill issue" is cope.
Do not use OpenWRT if you want anything to actually work. Pay Cisco or ubiquiti. Spent hours trying to get something as trivial as hairpin NAT to work. Nope. The Internet is full of people with the same problem. No solutions. Going back to my EdgeROUTER. At least it works.
1
3
348
the big question is how many floors is the aeroflot ceo gonna fall from when he gets shoved out a expired window.
1
2
314
EasyAccess==EasyAccess again,again,again :D
Stack overflows, heap overflows, and existential dread - it must be an SSLVPN. labs.watchtowr.com/stack-ove…
1
3
475
the first drone taken out in this video is a Forpost UCAV which allegedly costs around 5-7 million dollars a pop, turned into scrap by a sub-1k$ FPV drone made using mostly off the shelf components. A second one gets hit at ~19 seconds.
In two weeks, SBU Alpha unit destroyed 16 tanks, 21 armored vehicles, 75 artillery systems, 22 air defense systems, 17 EW assets, 577 vehicles, 80 drones, 308 antennas, 789 enemy positions, 15 ammo depots, and 7 fuel storage sites using strike drones and other weapons.
1
1
3
2,170
At 22 seconds you can see an Orion UCAV get hit. Those fuckers are absolutely enormous and must cost a frankly absurd amount of money.
1
110
These are Gerbera drones, not Geran. I have no idea how "OSINT" accounts keep making this mistake.
Another 5 Russian Geran drones downed by the GARPUN unit using Ukrainian interceptor drones.
1
187
I did a little digging around Github this morning and it seems someone has actually been working on an embeddable i2p implementation in Rust. This is awesome, and opens up a whole host of possibilities for privacy focussed p2p networked applications. Or C2 channels. Link below
2
3
249
Between this and Arti (the embeddable Tor implementation in Rust), there is a lot of potential going forward for some Really Cool Things to be built, offloading the networking layer of your decentralised application to these networks, nifty cross-network shenanigans, etc
2
184
Gutted to be missing @BSidesBSK this year, but they do have a fun CTF on that you can play remotely.
1
2
4
338