Jon Aubrey Profile
Jon Aubrey

@SecurityJon

Followers
2K
Following
947
Media
354
Statuses
3K

UK
Joined January 2014
Don't wanna be here? Send us removal request.
@SecurityJon
Jon Aubrey
6 years
Finally got a few mins to finish off some projects. First up ‘the dancing car’ - a stand-alone car cluster which ‘dances’ along with music. #CarHacking
8
21
188
@SecurityJon
Jon Aubrey
4 months
This. We said it was a bad idea from the start and it is. Privacy nightmare and easily bypassed
@tautology0
ẗäüẗöl̈ög̈ÿ
4 months
@ScottMcGready Watching companies come out with stupid ways of doing age verification which are all easily bypassed just shows that it was misguided from the start. It just needs to be scrapped in favour of better education.
0
0
1
@SecurityJon
Jon Aubrey
9 months
Got a new gym bag for Valentine’s Day. This is going to amuse me for months. #wehackhealth
0
0
1
@SecurityJon
Jon Aubrey
9 months
Spot on. Anyone that says ‘security isn’t hard’ has never had to deal with pre-existing conditions
0
0
3
@SecurityJon
Jon Aubrey
10 months
Hey @LGUK Your recent firmware upgrade for the G1 TV just broke ARC support, and with no firmware downgrade permitted I now have no sound. Perhaps having a rollback feature or even a downgrade feature might not make for salty users..
0
0
0
@SecurityJon
Jon Aubrey
11 months
Train tickets booked - see you all @BSidesLondon next weekend!
0
0
1
@bb_hacks
0xBB
1 year
Fancy retrieving plaintext user credentials, deactivation passcodes and uninstall passwords for Palo Alto Global Protect VPN? Thank goodness Palo Alto make that easy for you ... Full write up here : https://t.co/6T65cHCi9n Tooling available here :
Tweet card summary image
github.com
Tool to extract username and password of current user from PanGPA in plaintext - t3hbb/PanGP_Extractor
2
71
201
@SecurityJon
Jon Aubrey
1 year
I downloaded my Amazon Music data to try to figure out what song I was listening to, and included in the data is the amount of times they've tried to upsell me something recently. A paid service tried to sell me something over 500 times in the last few months...
0
1
1
@SecurityJon
Jon Aubrey
1 year
For the first time in many years I tried to connect an iPhone to a Windows PC to do a backup. 1 hour in and I'm still no closer to getting either device to 'trust' the other - how did Apple mess this up so badly?!
0
0
1
@bb_hacks
0xBB
1 year
Cortex XDR full bypass with stock meterpreter payload. Screenshot from tooling demo, apologies for quality.
0
12
102
@SecurityJon
Jon Aubrey
1 year
Broken PCB trace/pad repair. I need some enamel wire me thinks….
0
0
1
@bb_hacks
0xBB
1 year
Just a brief article showing how easy it is to figure out where the canary files are kept on systems using Cortex XDR and how to avoid them. Issue was reported to Palo Alto, but it was determined to be a non-issue, so … here you go 😊 https://t.co/n1nLXruVT8
Tweet card summary image
shells.systems
Estimated Reading Time: 6 minutesA post exploring how to enumerate and avoid Cortex XDR ransomware files/folders and avoid getting caught
4
43
127
@SecurityJon
Jon Aubrey
1 year
Can confirm. I got the nerve up to talk to Dave in a queue for Blackhat many years ago. He was in a cast for a broken foot and was with friends and yet still was willing to have a chat for a few moments about random stuff.
@HackingDave
Dave Kennedy
1 year
Flying out Sat for BlackHat! Look forward to seeing you amazing folks. I'll be around our #BinaryDefense booth and our #TrustedSec training class. Always happy for a hug, fist bump, or handshake. I promise, while I might look big, but I'm a teddy bear and very approachable! 😂
0
0
1
@SecurityJon
Jon Aubrey
1 year
We still do staged updates for our operating systems, small batches to confirm there are no issues before we push out globally. Is anyone doing the same for every other app on their machines? Today showed you need to be.
0
0
1
@SecurityJon
Jon Aubrey
1 year
Electrical people, please help settle an argument over how long a car battery could power a gaming console for: Console uses 210W and needs 110v, battery is 12v@55ah capacity(660W?) Battery CCA is 440, with a step up transformer can the battery power the console for 3 hours?
0
0
0
@SecurityJon
Jon Aubrey
2 years
It took me many years to get password policies changed in every org and the changes were made around this premise. Stop enforcing complexity, length and patterns and just prevent common themes
@cybergibbons
Cybergibbons 🚲🚲🚲
2 years
(yes, I know both exceed the policy, but it's what people do) The solution isn't to make passwords better - it's to make the damage of compromising one password limited. MFA. Principle of least privilege. Stop blaming the users.
0
0
2
@SecurityJon
Jon Aubrey
2 years
Some power is being used though, although none of the ICs are getting warm at all
0
0
0
@SecurityJon
Jon Aubrey
2 years
I was interested in what killed all of the equipment, this is the Pi 400 Desktop. Interestingly there is a large burn mark next to the HDMI connector and not the power or USB connectors where I would expect it to be.
1
0
0
@SecurityJon
Jon Aubrey
2 years
*Erg*. Hardware testing failure this morning led to a Pi Desktop, Monitor, 2x USB Hubs and a few other bits getting fried when main voltage jumped into my testing machine from a USB connection. Thankfully it wasn't my laptop getting hit but it still scared the life out of me :(
1
0
2
@SecurityJon
Jon Aubrey
2 years
Wow @NetflixUK - that’s a jump. Currently it’s £8 a month, now it’s jumping to £11 a month or forcing Ads on me. That’s a 37.5% price increase.
0
0
2
@SecurityJon
Jon Aubrey
2 years
Cake and a new book, looking forward to this afternoon @drjessicabarker
1
1
3