Stephen Sims Profile Banner
Stephen Sims Profile
Stephen Sims

@Steph3nSims

Followers
20,404
Following
605
Media
415
Statuses
3,429

Perpetual Student | SANS Fellow | Musician | Braggart Hater | Gray Hat Hacking | VR | 🏂 | deadcode |

Berkeley, CA
Joined February 2014
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@Steph3nSims
Stephen Sims
2 years
Once I finally hit 10K followers I’m going to give away 10 copies of Gray Hat Hacking 6th edition to likes on this tweet. They’ve been hanging out in my office and I want them to go to good homes!
Tweet media one
110
298
3K
@Steph3nSims
Stephen Sims
4 months
Introduction to Reverse Engineering and Debugging
10
348
1K
@Steph3nSims
Stephen Sims
1 year
A Look at Modern Windows Kernel Exploitation
11
268
931
@Steph3nSims
Stephen Sims
1 year
Introduction to Linux Heap Exploitation
8
230
864
@Steph3nSims
Stephen Sims
3 years
Exploit dev tip in 1998: grep memcpy Exploit dev tip in 2021: grep memcpy
6
145
784
@Steph3nSims
Stephen Sims
3 years
During a webcast last week to announce the new Offensive Operations curriculum at SANS we gave away a free course. I made mention that we would give away a few copies of Gray Hat Hacking 5th ed. as well. Tomorrow, @SANSOffensive will randomly select 5 people who like this post.
Tweet media one
12
42
637
@Steph3nSims
Stephen Sims
2 years
I’m going to randomly pick 3 people who retweet this to receive a copy of the book. I’ll tweet out the winners tomorrow. I’ll also be giving away two more copies later this week complements of @RayRedacted ! …and maybe a couple more next week just for university students
Tweet media one
30
1K
582
@Steph3nSims
Stephen Sims
2 years
Browser Exploitation Introduction
3
183
590
@Steph3nSims
Stephen Sims
2 years
That happened way faster than expected. I’m en route to the airport to fly to Vegas to teach. I’ll use the time on the plane to pick 10 random names and @ them in my next tweet. I’ll ship when home after the weekend. Thanks!
Tweet media one
@Steph3nSims
Stephen Sims
2 years
Once I finally hit 10K followers I’m going to give away 10 copies of Gray Hat Hacking 6th edition to likes on this tweet. They’ve been hanging out in my office and I want them to go to good homes!
Tweet media one
110
298
3K
71
43
579
@Steph3nSims
Stephen Sims
2 years
Introduction to Linux Heap Internals
5
134
518
@Steph3nSims
Stephen Sims
1 year
Debugging the Windows Kernel and Undocumented Structures
6
133
507
@Steph3nSims
Stephen Sims
1 year
Zero to Hero: The process of reversing and exploiting complex vulnerabilities!
2
122
467
@Steph3nSims
Stephen Sims
2 months
Reverse Engineering Malware with Ghidra
3
118
432
@Steph3nSims
Stephen Sims
2 years
Just got the physical copies of Gray Hat Hacking 6th ed. in the mail! A few people were asking about the ToC. Here it is... I'm going to think of a way to give a couple copies away soon. I'll tweet when I figure that out!
Tweet media one
Tweet media two
Tweet media three
33
54
431
@Steph3nSims
Stephen Sims
11 months
Active Directory Certificate Services: The Latest Attacks - with Tim Medin
0
147
413
@Steph3nSims
Stephen Sims
2 years
Tomorrow, I am presenting to a group of 12 girl scouts about infosec and hacking. For some reason I am more nervous about this than teaching a roomful of MIT PhD’s. 🙈
30
9
391
@Steph3nSims
Stephen Sims
6 months
Windows Exploit Mitigation Bypass - Isolated Heaps
3
97
377
@Steph3nSims
Stephen Sims
1 year
Modern Windows Command & Control / Implants
3
100
356
@Steph3nSims
Stephen Sims
7 months
Reverse Engineering a tcpip.sys DOS Vulnerability
5
82
331
@Steph3nSims
Stephen Sims
1 year
Join me on the Off By One Security stream this Friday with @chompie1337 , to watch her walk through the process of reversing and exploiting complex vulnerabilities! This one will answer a lot of great questions commonly asked about exploit development!
Tweet media one
12
75
327
@Steph3nSims
Stephen Sims
1 month
Low-Level x86-64 Architecture, Linking & Loading, Memory Management, etc...
2
84
323
@Steph3nSims
Stephen Sims
2 years
Modern Binary/Patch Diffing!
2
89
312
@Steph3nSims
Stephen Sims
11 months
Browser Exploitation Introduction: Part 2 - Use After Free Against IE 11, Bypassing MemGC and Isolated Heaps
0
73
293
@Steph3nSims
Stephen Sims
2 years
Useful IDA Pro scripts/plugins: IDACode - IPyIDA - Karta - IDA PyCharm - # Thanks @Void_Sec SARK - There are more, but those are some good ones! @ilfak
1
74
285
@Steph3nSims
Stephen Sims
4 months
I get a lot of DM's, etc... from people saying that they "feel dumb," "..too far behind to get good at reversing," "..should probably change professions," "..are too late to the game." You're wrong! We all start somewhere. Would anyone be interested in a stream on how to start?
39
23
285
@Steph3nSims
Stephen Sims
9 months
I had to delete an earlier tweet, sorry. I just found 10+ vulns so far in the pdf previewer used by Outlook, etc....Crazy part is that it was by doing some basic things from @DidierStevens tools here: with an interesting corpus (which was the hard part)...
2
74
282
@Steph3nSims
Stephen Sims
1 year
Reverse Engineering Exploit Mitigations Series - Do Not Allow Child Processes
0
65
283
@Steph3nSims
Stephen Sims
1 year
Reversing a Windows Exploit Mitigation (Exploit Guard)
4
87
279
@Steph3nSims
Stephen Sims
4 months
Windows Exploit Mitigation Series thus far: - Do Not Allow Child Processes: - Stack Pivot Protection: - Isolated Heaps: - High level look at CFG and Heap Spraying:
0
100
273
@Steph3nSims
Stephen Sims
5 months
Cobalt Strike from a Blue Team Perspective
1
70
269
@Steph3nSims
Stephen Sims
2 years
I’m down to teach the retired section from SEC760 on browser Use After Free exploitation during a couple public streams if folks would be interested. Would be against IE11, but the bug class and technique is still very relevant. Thoughts?
25
26
265
@Steph3nSims
Stephen Sims
3 months
Upcoming Off By One Security Streams: 2-Feb - @Steph3nSims on IDA Pro 9-Feb - @psifertex on Reversing with Binja 16-Feb - @_hugsy_ on GEF Unleashed! 23-Feb - @asoni on Reversing with Ghidra 1-Mar - @mrgretzky on What's new with EvilGinx!
10
67
252
@Steph3nSims
Stephen Sims
2 months
Debugging Windows Internals with x64dbg!
0
58
253
@Steph3nSims
Stephen Sims
1 year
Understanding Exploit Mitigations for Defenders
5
53
235
@Steph3nSims
Stephen Sims
3 months
Reverse Engineering with Binary Ninja (Binja)
3
49
231
@Steph3nSims
Stephen Sims
6 years
Gray Hat Hacking 5th ed. is out! Just back from London to get my author copies. I need to figure out a good way to give away a couple copies
Tweet media one
35
59
221
@Steph3nSims
Stephen Sims
1 year
Breaking into Hacking as a Career!
1
80
218
@Steph3nSims
Stephen Sims
10 months
Hacking Google Cloud Platform (GCP) with Kat Traxler!
1
50
219
@Steph3nSims
Stephen Sims
4 years
Stoked! My first (sadly)browser 0-day of the year was approved for purchase and responsible disclosure. Info leak + RCE + SBX. Brutal. Side-note: Why no matter where I live am I literally on the last USPS stop of the day?
17
11
216
@Steph3nSims
Stephen Sims
4 months
Windows Exploit Mitigation Series - Reversing Export Address Table Filtering (EAF)
1
54
214
@Steph3nSims
Stephen Sims
7 months
Web Bug Bounties: Tactics to Hunt for Logic Vulnerabilities
0
56
215
@Steph3nSims
Stephen Sims
3 months
Would anyone be interested in a short(ish) session on intro to IDA Pro tomorrow (Friday at 11AM PT)? Even if you use ghidra, you'll still learn some things. I'll set an arbitrary number of 250 likes. Not because I care about ratio, but to make sure people are interested! haha
11
15
209
@Steph3nSims
Stephen Sims
18 days
Windows Device Drivers Internals and some Reversing
3
44
206
@Steph3nSims
Stephen Sims
9 months
The History of Heap Spraying
3
48
198
@Steph3nSims
Stephen Sims
1 year
Writing CTF challenges just became a whole lot easier!
Tweet media one
7
19
196
@Steph3nSims
Stephen Sims
5 months
Off By One Security streams are back! Join me Thursday, the 7-DEC at 11AM PST with the amazing @DidierStevens , who will give us awesome insight (and likely some new tools) on Cobalt Strike from a Blue Team Perspective! AKA: Improve your red team chops!
Tweet media one
2
48
184
@Steph3nSims
Stephen Sims
2 years
Someone on LinkedIn sent a DM asking if I’d be interested in writing a “PERL for Kids” book. How could someone dislike children so much?
9
13
178
@Steph3nSims
Stephen Sims
1 year
On January 20th, @chompie1337 will be on the Off By One Security Stream to share knowledge on the process she uses to reverse and exploit complex vulnerabilities! I'll be giving away a Proxmark3 during the stream! YT: LinkedIn:
Tweet media one
4
44
167
@Steph3nSims
Stephen Sims
5 years
I'm gauging interest in a possible course offered under my curriculum at SANS. Could you like this tweet if you'd be interested in a 2-day lab heavy course on bug bounties / vuln discovery & disclosure, written by someone with cred from LinkedIn, Etsy, Facebook, ATT, & many more
11
14
167
@Steph3nSims
Stephen Sims
2 years
Available for presale! I believe it ships in March. I’ll be giving some copies away as well when I get them. All proceeds for my portion are going to @CAL_FIRE !
Tweet media one
7
45
166
@Steph3nSims
Stephen Sims
2 months
IDA Pro and Hex-Rays Decompiler Giveaway! One lucky person will win by being the first to solve a challenge! Join me this Friday at 11AM PT on the Off By One Security stream where I'll dive into Scripting with IDA Pro and static analysis for bug hunting!
Tweet media one
2
38
167
@Steph3nSims
Stephen Sims
9 months
Return Oriented Shellcode (ROP Shellcode)
1
48
162
@Steph3nSims
Stephen Sims
7 years
Based on requests, I've posted my BSidesCharm slides on MS Patch Diffing for Exploitation to
2
85
159
@Steph3nSims
Stephen Sims
2 months
I plan to do a series of short videos covering various Windows Internals components. Members helping with our tuition assistance and charity goals will get first access and then public to all in the days after. What is the _CONTEXT structure
3
29
154
@Steph3nSims
Stephen Sims
4 years
I’m recording SANS SEC760 “Advanced Exploit Dev” at home over the next week with @jgeigerm for OnDemand. Thinking about streaming/webcasting the module on IDA Pro while I’m recording this Saturday at 1PM Pacific Time if there’s an interest. Worth it?
12
18
153
@Steph3nSims
Stephen Sims
3 months
I plan on doing a new Windows Internals stream, as people often ask for one, but here are a couple of existing videos on the topic: from @mrexodia from @alexsotirov
2
36
153
@Steph3nSims
Stephen Sims
11 months
If you haven't had a chance to watch the chat between @davidbombal & myself, talking about getting into exploit development, check it out here: David has a lot of great content! I'm looking forward to catching up with him again to talk about new topics!
Tweet media one
2
14
151
@Steph3nSims
Stephen Sims
19 days
Join me tomorrow on the Off By One Security stream with special guest Pavel Yosifovich @zodiacon for a session on Windows Device Drivers Internals, ...and Some Additional Reversing! 19-April at 11AM PT. Looking forward to this one!
Tweet media one
3
34
153
@Steph3nSims
Stephen Sims
3 years
So, I’m thinking about doing a weekly stream where I have guests & we talk all things red, purple, exploit dev, etc.... Content focused. Certainly not a new concept by any means, and I’m not the streaming type, but I’m down if you all think it would be cool and useful. Yay? Nay?
24
7
148
@Steph3nSims
Stephen Sims
2 months
Join us tomorrow (15-Mar at 11AM PT) on the Off By One Security stream with guest @mrexodia , creator of x64dbg, as we take a look at debugging Windows internals and such with this amazing debugger! Come with your questions!
Tweet media one
2
26
144
@Steph3nSims
Stephen Sims
4 years
To all of those waiting for SANS SEC760 "Adv Exploit Dev" to go live in OnDemand, sorry for the delay. I JUST got done re-recording book two on advanced Linux exploitation. It is finally done! Remote labs are done! So much work. Very excited and thanks for your patience.
Tweet media one
4
32
146
@Steph3nSims
Stephen Sims
16 days
One of my finer slides over the past 10+ years... haha
Tweet media one
4
16
146
@Steph3nSims
Stephen Sims
4 years
SANS SEC760 IDA Pro Challenge Binary: Target: nc 5760 To win: DM me a screenshot of target compromise, your source IP, & exploit code. First one to do this wins the IDA license! I will post when a winner is identified. Good luck!
2
79
141
@Steph3nSims
Stephen Sims
1 year
AIRaaS (Artificial Intelligence Ransomware as a Service)
Tweet media one
0
31
140
@Steph3nSims
Stephen Sims
11 months
Tomorrow's Off By One Security stream will be my attempt to do another browser exploitation session. My very first stream was browser exploitation against IE 7. This one will be IE 11, and a mem-disclosure bug. I'm a bit rusty, but we'll try! Yay?
Tweet media one
4
23
140
@Steph3nSims
Stephen Sims
4 months
Join me on tomorrow's Off By One Security stream at 11AM PT, as we cover a bit on getting started with reverse engineering and debugging. This will be a series to help those of you preparing for your self-learning journey or an upcoming course!
Tweet media one
@Steph3nSims
Stephen Sims
4 months
This Friday's Off By One Security stream will be on the topic I've "Quote Retweeted." We're going to start with the introduction to reverse engineering. It will be technical, but introductory, and then we'll ramp up through a series over the coming months. Come with questions!
5
11
71
2
32
138
@Steph3nSims
Stephen Sims
9 months
Exploiting Off By One Vulnerabilities
0
33
136
@Steph3nSims
Stephen Sims
2 years
Any interest in a Blockchain and Crypto Security Summit? Would you attend? Would be virtual. Security has been lacking in that space.
33
9
133
@Steph3nSims
Stephen Sims
2 years
In case you missed it, I did a 2 hour webcast on Use After Free exploitation here: Subscribe to my YouTube channel to find out when future streams will run and on what topics!
2
40
126
@Steph3nSims
Stephen Sims
5 months
Tough question to summarize. Gray Hat Hacking is at the point where we'd normally start working on the next edition. Questions: - Know any universities who use it? - Are printed books still desired? - Would you want a 7th edition? The replies will help determine the outcome.
Tweet media one
29
23
128
@Steph3nSims
Stephen Sims
4 years
The most important slide in the updated version of SEC760. 😂
Tweet media one
5
16
127
@Steph3nSims
Stephen Sims
4 months
To all of those who track my posts, you need to check out @ale_sp_brazil work. He publishes so much quality research on reversing and more! Reading his work will save you countless hours. Thank you, Alexandre!
@ale_sp_brazil
Alexandre Borges
4 months
To date I've already written 644 pages to help the security community and, hopefully, more articles will be released in the coming months: 9. 8. 7. 6. 5. 4.…
Tweet media one
10
278
898
2
26
125
@Steph3nSims
Stephen Sims
3 years
Would anyone be interested in webcast sessions on exploit dev course content that is being retired to make room for other material? Still good stuff, but perhaps showing its age. I’d be happy to do some if it’s useful.
23
12
127
@Steph3nSims
Stephen Sims
4 years
IDA Pro giveaway challenge #1 ! The SANS Pen Test curriculum is giving away one IDA Pro license by way of a binary challenge created with @htejeda . I will tweet out the link to the binary & remote system to pwn this Thursday at UTC-08:00. Hint: Polish off your Linux heap skills
5
76
124
@Steph3nSims
Stephen Sims
2 months
Scripting with IDA pro - IDA Pro and Hex-Rays Giveaway!
1
26
125
@Steph3nSims
Stephen Sims
1 month
We'll see how this one goes!! I'll be "attempting" to stream a module from a class I'm teaching on OS architecture, linking & loading, etc.... I'm not sure if it will turn out well as it's a "rogue" stream. haha. 9AM EST, 27-March... Off By One Security
Tweet media one
0
24
125
@Steph3nSims
Stephen Sims
3 months
On the Off By One Security Discord server, I was asked to post some questions I'd ask a potential candidate applying for a vulnerability researcher position. I'm sure some will not agree with the questions, but they work for me! Feel free to use them.
Tweet media one
1
20
123
@Steph3nSims
Stephen Sims
3 months
Identifying Library Versions When Remotely Hacking Linux Vulnerabilities
0
31
119
@Steph3nSims
Stephen Sims
3 years
My CA plate is Ox9O & has been for over 10 yrs. I rarely get questions or comments on it. I was thrilled today to get approached by a high school kid today while taking my daughter to the park, who asked “Is that a NOP plate? I’ve used that hacking vid games.” She made my day! 🙌
4
8
118
@Steph3nSims
Stephen Sims
8 years
meh...
Tweet media one
7
96
118
@Steph3nSims
Stephen Sims
4 years
I'm very excited to announce the release of the highly anticipated SANS SEC588 - Cloud Penetration Testing course. Congratulations to @mosesrenegade on completing it. Watch for the beta announcement date soon: @SANSPenTest
7
45
117
@Steph3nSims
Stephen Sims
1 year
That was a fun stream to do. If you're interested in seeing how an exploit mitigation works in Windows Defender Exploit Guard, you can see the recorded stream here: In the image is a simple function that validates that the stack pointer hasn't been stolen
Tweet media one
0
34
117
@Steph3nSims
Stephen Sims
25 days
Hello! There will not be an Off By One Security stream today, but check out some of the upcoming streams with @zodiacon , @cutaway , @haxorthematrix , @yarden_shafir , and @jstrosch ! More to announce soon! Have a great weekend!
Tweet media one
2
16
116
@Steph3nSims
Stephen Sims
1 year
I’m going to leak a bit of cool news out about Hackfest Hollywood in Nov! Day 1 Keynote: @chompie1337 Day 2. keynote: @inversecos This event is gonna be 🔥🔥🔥! We also have comfirmed talks from @FuzzySec and @33y0re CFP is dropping soon. Get your submissions ready!
10
28
114
@Steph3nSims
Stephen Sims
4 years
I should really pay more attention to how big things are before using all of my credit card points to buy something. 🤦‍♂️
Tweet media one
23
2
114
@Steph3nSims
Stephen Sims
3 years
About to start the SANS Offensive Operations webcast! Thought I’d sport my lucky binary shirt. Can’t take a selfie for the life of me.
Tweet media one
Tweet media two
8
4
111
@Steph3nSims
Stephen Sims
4 years
If we were to do a Gray Hat Hacking 6th edition, what topics do you think should be covered, or just update it to be current?
Tweet media one
20
26
108
@Steph3nSims
Stephen Sims
2 months
Getting Started with Debugging Hyper-V for Vulnerability Research
1
28
105
@Steph3nSims
Stephen Sims
2 years
Monday, August 29th will be my first stream. This one will just be me. I will teach content on Use After Free browser exploitation. I plan to do it weekly with lots of guests. Majority technical content. Minimal BS! More details soon! .
2
35
109
@Steph3nSims
Stephen Sims
3 months
Just came across this silly image I made a long time ago when taking a mental break from reversing. It would be amazing if someone made a plugin to turn any recursive descent function view in IDA Pro into a Donkey Kong game!
Tweet media one
5
8
106
@Steph3nSims
Stephen Sims
2 years
Most CVE's are privately disclosed. Exploit framework vendors, and many others, want to have the most exploits for non-public vulns. Weaponization of n-day vulns has decreased over the years. It can be very time consuming and lead to non-exploitable bugs, but you learn a ton. 🧵
2
25
106
@Steph3nSims
Stephen Sims
4 months
Check out the latest chat that I had with @davidbombal ! I share my own journey a bit, as well as some considerations that might be useful to you, depending on your path.
@davidbombal
David Bombal
4 months
Mind blowing 🤯 $20 million USD bounties! Zero to Hero Money Hacking Roadmap with the amazing @Steph3nSims who shares his years of experience with us! Watch and learn 😀 YouTube video: #ios #android #apple #cyber #cybersecurity #windows #macos
Tweet media one
6
26
153
4
13
105
@Steph3nSims
Stephen Sims
3 months
Find the bug....
Tweet media one
15
16
104
@Steph3nSims
Stephen Sims
3 months
GEF Unleashed: Tips and Tricks for Efficient Exploit Crafting
1
27
102
@Steph3nSims
Stephen Sims
5 years
Probably only the 3rd or 4th selfie I’ve ever taken in my life, but proud of my 10 yr old boy for making it out of surgery to remove a mast cell tumor. Grade 2 thankfully!
Tweet media one
9
6
104
@Steph3nSims
Stephen Sims
3 months
New stream added to the Off By One Security calendar. March 22nd with @ergot86 , one of my coauthors of Gray Hat Hacking 6th ed., as he takes us through "Getting Started with Debugging Hyper-V for Vulnerability Research!" This will be a good one!
Tweet media one
3
24
105
@Steph3nSims
Stephen Sims
2 months
Join me this Friday at 11AM PT with guest @ergot86 for a session on Getting Started with Debugging Hyper-V for Vulnerability Research!
Tweet media one
1
22
103
@Steph3nSims
Stephen Sims
6 years
Any interest in a webcast walking through a browser memory disclosure bug? Would be advanced of course...
34
13
102
@Steph3nSims
Stephen Sims
3 years
Twitter puts me in a bad mood way too often, so I’m just going to say something positive. I appreciate all of you who bring value to the platform. I look forward to seeing you in person again at conferences soon and to grabbing a coffee or a beer. So long to COVID-19. 😊
3
7
103