Nicolas Chatelain
@Nicocha30
Followers
365
Following
275
Media
29
Statuses
588
Security researcher | Ligolo/Ligolo-ng/Chashell author
Paris
Joined March 2014
There are likely Ligolo servers on the Internet that you can connect to with a Ligolo agent. 1. Ligolo has 3 JARM signatures. 2. Ligolo-MP's JARM is the same as Sliver C2. 3. We do not advise or condone connecting to potential Ligolo servers. https://t.co/IYCIFmwEy5
1
2
4
ProxyBlob is alive ! Weβve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments π π https://t.co/KO4AYUDTmb Blog post for more details right below β¬οΈ
github.com
SOCKS5 proxy tool that uses Azure Blob Storage as a means of communication. - quarkslab/proxyblob
Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out @_atsika's article on how it came to exist after an assumed breach mission β€΅οΈ π https://t.co/ApZloWD3hl
3
45
112
π¬π§ DEFCON Paris on NOV-04 π«π· DEFCON Paris le 04/11 - "New cyber visualisation tool", by Adem Ali Cherif - "RedTeaming and Tunneling β Stop using Raspberry Pi!", by Nicolas Chatelain (@Nicocha30) π Le Carlie, 177 rue Saint Martin, Paris π 19:00 ποΈ
0
11
22
Wireless hacking doesn't have to be a mess of dongles and ad-hoc code anymore. Yesterday @virtualabs and @CayreRomain from @Eurecom released WHAD, a set of open source tools, libraries and firmware to make wireless security research easier. The code repo: https://t.co/KtacDBecg7
1
26
62
How to fix the Crowdstrike thing: 1. Boot Windows into safe mode 2. Go to C:\Windows\System32\drivers\CrowdStrike 3. Delete C-00000291*.sys 4. Repeat for every host in your enterprise network including remote workers 5. If you're using BitLocker jump off a bridge
493
7K
51K
Plans to literally "hack the planet" foiled due to 500ms of latency that Andres instinctually investigated. The latency was due how the malicious code parsed symbol tables in memory. https://t.co/WNExkhVbTx
37
714
6K
βItβs almost like people are making more money teaching hacking than actually doing it.β -- @assume_breach
https://t.co/2OIGpqk7hS ^ 100% true statement, and most don't teach good habits, they teach run and gun cowboy BS.
link.medium.com
Hi all! So, this is going to be a different type of post. Iβve tried to stay a little off the radar personally with my blogs and Twitter account for a lot of reasons. Itβs not hard to find out who Iβ¦
12
73
315
LocalPotato - When Swapping The Context Leads You To SYSTEM
localpotato.com
Here we are again with our new *potato flavor, the LocalPotato! This was a cool finding so we decided to create this dedicated website ;)
0
10
37
A fun little canary for you all in cyber defence to help detect breaches/data theft. QT & MP4 files can reference external urls via 'rdrf' sections. These can be URLs and thus you can get a DNS resolution and/or HTTP request on open. Have an MP4 working example in VLC...
6
40
151
CVE-2020-19909 is everything that is wrong with CVEs Another 9.8 CRITICAL curl problem. All made up. https://t.co/iiWAnJHCYh
32
367
1K
Our team released a new PoC of the recently discovered Nerftoken antivirus bypass technique, written in Golang! https://t.co/Mq1sHE1j6r
#golang #nerftoken #pentest #avbypass #infosec #redteam
github.com
Nerftoken implemented in Golang. Contribute to tnpitsecurity/nerftoken-go development by creating an account on GitHub.
0
5
7
We can confirm that VMWare vCenter is affected by the Log4j vulnerability. #log4j #vcenter #Log4Shell
17
361
747
Our IT Security Lab discovered several critical vulnerabilities affecting Cobbler <= 3.2.1 https://t.co/YUbnROJDDR We would like to thank @cobblerproject and @SUSE for seriously and quickly handling this vulnerability. #oss #vulnerability #security
0
5
8
We released our first public tool, Ligolo-ng : An advanced, yet simple, tunneling tool that uses a TUN interface. https://t.co/RdaXbSW2FW
#redteam #pentesting #pentest #infosec #golang
github.com
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. - nicocha30/ligolo-ng
1
12
15
The Corellium Cloud has been updated to support the latest iOS 14.5! β¨π± Want to start testing your apps without the need to jailbreak your device? Corellium makes it possible for as little as $0.50/hour, with fully integrated security testing tools! https://t.co/XpMpAUcfFa
6
51
249
New Post: The Universal Loader for Go
symbolcrash.com
This Golang library provides a consistent interface for loading shared libraries from memory, without using CGO, on OSX M1/amd64, Linux and Windows.
1
8
27