Nicocha30 Profile Banner
Nicolas Chatelain Profile
Nicolas Chatelain

@Nicocha30

Followers
365
Following
275
Media
29
Statuses
588

Security researcher | Ligolo/Ligolo-ng/Chashell author

Paris
Joined March 2014
Don't wanna be here? Send us removal request.
@NecromancerLabs
Necromancer Labs
7 months
There are likely Ligolo servers on the Internet that you can connect to with a Ligolo agent. 1. Ligolo has 3 JARM signatures. 2. Ligolo-MP's JARM is the same as Sliver C2. 3. We do not advise or condone connecting to potential Ligolo servers. https://t.co/IYCIFmwEy5
1
2
4
@_atsika
Atsika
8 months
ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments πŸ”’ 🌐 https://t.co/KO4AYUDTmb Blog post for more details right below ⬇️
Tweet card summary image
github.com
SOCKS5 proxy tool that uses Azure Blob Storage as a means of communication. - quarkslab/proxyblob
@quarkslab
quarkslab
8 months
Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out @_atsika's article on how it came to exist after an assumed breach mission ‡️ πŸ‘‰ https://t.co/ApZloWD3hl
3
45
112
@dcgparis
DEFCON GROUP Paris
1 year
πŸ‡¬πŸ‡§ DEFCON Paris on NOV-04 πŸ‡«πŸ‡· DEFCON Paris le 04/11 - "New cyber visualisation tool", by Adem Ali Cherif - "RedTeaming and Tunneling – Stop using Raspberry Pi!", by Nicolas Chatelain (@Nicocha30) πŸ“ Le Carlie, 177 rue Saint Martin, Paris πŸ•– 19:00 🎟️
0
11
22
@quarkslab
quarkslab
1 year
Wireless hacking doesn't have to be a mess of dongles and ad-hoc code anymore. Yesterday @virtualabs and @CayreRomain from @Eurecom released WHAD, a set of open source tools, libraries and firmware to make wireless security research easier. The code repo: https://t.co/KtacDBecg7
1
26
62
@vxunderground
vx-underground
1 year
How to fix the Crowdstrike thing: 1. Boot Windows into safe mode 2. Go to C:\Windows\System32\drivers\CrowdStrike 3. Delete C-00000291*.sys 4. Repeat for every host in your enterprise network including remote workers 5. If you're using BitLocker jump off a bridge
493
7K
51K
@Nicocha30
Nicolas Chatelain
1 year
πŸ’ͺ🏻
1
1
2
@haxrob
HaxRob
2 years
Plans to literally "hack the planet" foiled due to 500ms of latency that Andres instinctually investigated. The latency was due how the malicious code parsed symbol tables in memory. https://t.co/WNExkhVbTx
37
714
6K
@mubix
Rob Fuller
2 years
β€œIt’s almost like people are making more money teaching hacking than actually doing it.” -- @assume_breach https://t.co/2OIGpqk7hS ^ 100% true statement, and most don't teach good habits, they teach run and gun cowboy BS.
Tweet card summary image
link.medium.com
Hi all! So, this is going to be a different type of post. I’ve tried to stay a little off the radar personally with my blogs and Twitter account for a lot of reasons. It’s not hard to find out who I…
12
73
315
@daveaitel
Dave Aitel
2 years
Lol?
@rwincey
b0yd
2 years
GitLab CVE-2023-7028 POC user[email][]=valid@email.com&user[email][]=attacker@email.com - PWNED
0
1
7
@ollieatnowhere
Ollie Whitehouse
2 years
A fun little canary for you all in cyber defence to help detect breaches/data theft. QT & MP4 files can reference external urls via 'rdrf' sections. These can be URLs and thus you can get a DNS resolution and/or HTTP request on open. Have an MP4 working example in VLC...
6
40
151
@bagder
daniel:// stenberg://
2 years
CVE-2020-19909 is everything that is wrong with CVEs Another 9.8 CRITICAL curl problem. All made up. https://t.co/iiWAnJHCYh
32
367
1K
@tnpitsecurity
TNP IT Security
4 years
We can confirm that VMWare vCenter is affected by the Log4j vulnerability. #log4j #vcenter #Log4Shell
17
361
747
@tnpitsecurity
TNP IT Security
4 years
Our IT Security Lab discovered several critical vulnerabilities affecting Cobbler <= 3.2.1 https://t.co/YUbnROJDDR We would like to thank @cobblerproject and @SUSE for seriously and quickly handling this vulnerability. #oss #vulnerability #security
0
5
8
@tnpitsecurity
TNP IT Security
4 years
In 2020, we discovered a vulnerability in Sonos speakers and worked with them following a Responsible Disclosure policy. Very smooth and kind collaboration, thanks @Sonos! https://t.co/VRMuq3zavr #Hardware #Hacking #Infosec #IoT #pcileech
0
6
5
@tnpitsecurity
TNP IT Security
4 years
We released our first public tool, Ligolo-ng : An advanced, yet simple, tunneling tool that uses a TUN interface. https://t.co/RdaXbSW2FW #redteam #pentesting #pentest #infosec #golang
Tweet card summary image
github.com
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. - nicocha30/ligolo-ng
1
12
15
@CorelliumHQ
Corellium
5 years
The Corellium Cloud has been updated to support the latest iOS 14.5! βœ¨πŸ“± Want to start testing your apps without the need to jailbreak your device? Corellium makes it possible for as little as $0.50/hour, with fully integrated security testing tools! https://t.co/XpMpAUcfFa
6
51
249