mRr3b00t Profile Banner
mRr3b00t Profile
mRr3b00t

@UK_Daniel_Card

Followers
92,540
Following
7,326
Media
66,509
Statuses
351,232

真理的揭露者 Quis custodiet ipsos custodes fella in cyberspace #nafo undercover #FVEY Lovely Horse #fella #meme #farm #appreciator #cyber #specialist

London, Vauxhall
Joined April 2009
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@UK_Daniel_Card
mRr3b00t
28 days
Finally this MacBook Pro has a good OS installed on it 🫡
Tweet media one
906
404
11K
@UK_Daniel_Card
mRr3b00t
27 days
ur old if u have ever used one of these :P
Tweet media one
685
226
5K
@UK_Daniel_Card
mRr3b00t
2 months
You connect a device (Bluetooth) on a Mac and it pings an http server at Apple…
Tweet media one
111
230
5K
@UK_Daniel_Card
mRr3b00t
12 days
god look at what they make you aspire to.... 4 hours in a fucking coffee shop.. Seriously I can't think of anywhere worse to work. 1) it's not private 2) it's noisy 3) Tea at the cyber bunker is > anywhere else 4) mouse, keyboard + screen 5) xbox/consoles 6) family 7)
@al3rez
Alireza Bashiri
14 days
What stops you from working 4 hours straight in a coffee shop?
Tweet media one
2K
107
3K
153
141
4K
@UK_Daniel_Card
mRr3b00t
1 month
they LIED! Macs are not MORE secure!!!!!!!!
Tweet media one
89
243
4K
@UK_Daniel_Card
mRr3b00t
4 months
Wait till people see what runs on planes/submarines 🤣 Be careful, elite cyber seals hide everywhere! Like the hordes of hackers on trains they lurk everywhere ;)
@timheuer
Tim
4 months
I think I found out why the ride keeps stopping Disney.
67
32
715
56
183
3K
@UK_Daniel_Card
mRr3b00t
29 days
Are the FBI in Baltimore smoking crack?
113
87
2K
@UK_Daniel_Card
mRr3b00t
2 months
USA frens did someone unplug the router?
Tweet media one
125
122
2K
@UK_Daniel_Card
mRr3b00t
2 years
Launching devastating cyber attack!!!! Pew pew
Tweet media one
205
163
2K
@UK_Daniel_Card
mRr3b00t
1 month
reminder when you install windows it instantly has ERRORS in the event log... this is no different in Server 2025
Tweet media one
40
82
2K
@UK_Daniel_Card
mRr3b00t
6 months
twitter have rolled out audio calls on twitter using STUN. Be warned if you call someone the recipient (and anyone in the traffic path) can see your egress IP. Apple private relay does not cover this.
Tweet media one
56
572
2K
@UK_Daniel_Card
mRr3b00t
9 months
################################ CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent ################################ now.. first questions... how many devices in your enterprise do you have running a vulnerable version of SSH? How many of these are internet
35
298
1K
@UK_Daniel_Card
mRr3b00t
10 months
Ok today we are inside the perimiter We have options: > LDAP/ADDS (TCP 389,636,3268,3269) > Find the printers and continue the human printer war! TCP 9100,9101 > Look for network devices (SSH, HTTP and TELNET) 22,80,443,8443,23) > Look for services like email (SMTP TCP 25) >
Tweet media one
44
231
1K
@UK_Daniel_Card
mRr3b00t
27 days
you wonder why no one takes security seriously?? it's because dick heads run around telling people shit like this... what the fuck is wrong with people....
Tweet media one
67
59
1K
@UK_Daniel_Card
mRr3b00t
9 months
wanna see how most networks are? we have found an exposed RDP server on the public internet.... we are going to fire a load of authentication attempts at the server! hydra -l administrator -P /usr/share/wordlists/rockyou.txt -t 4 -I rdp://target how long till we get caught?
Tweet media one
42
166
1K
@UK_Daniel_Card
mRr3b00t
4 months
*looks at pineapple default guest address range*
@SecurityTrybe
Security Trybe
4 months
Tweet media one
55
158
2K
13
44
1K
@UK_Daniel_Card
mRr3b00t
19 days
Mac life is odd 🤣 I basically have to RDP into a windows box to actually do actual work. The Mac is like the most expensive thin client in the fucking world 🤣
Tweet media one
119
61
1K
@UK_Daniel_Card
mRr3b00t
1 month
XZ Uitls backdoor TLDR: 1) we don' know who did it (from a human pov) - we know the GitHub account that was used. 2) this was caught by a ninja and it didn't deploy to loads of stuff. Some linux distros like KALI managed to get infiltrated (the backdoor works on x86/x64 Linux
43
132
1K
@UK_Daniel_Card
mRr3b00t
1 year
Office 365 Security Testing Tools
Tweet media one
18
307
962
@UK_Daniel_Card
mRr3b00t
10 months
oh no.. the NDR server caught me... oh no wait it didn't because there isn't one in ~>90% of networks and even when there is people don't seem to respond to alerts much ( based on BEC and ransomware incidents where something like D @RKTR @CE is deployed) this however is a noisy
Tweet media one
28
121
945
@UK_Daniel_Card
mRr3b00t
1 year
Let's learn some computer hacking skills!
Tweet media one
30
127
926
@UK_Daniel_Card
mRr3b00t
2 months
COBALT STRIKE SERVER IP LIST ############################ 139.9.41.156 39.105.4.90 115.159.50.50 141.98.81.98 192.227.234.140 106.54.228.198 159.203.67.15 20.163.176.140 119.91.195.178 106.52.244.189 124.223.200.131 80.85.154.37 107.173.15.230 123.60.74.61 40.77.86.17
53
133
942
@UK_Daniel_Card
mRr3b00t
12 days
Ok gang shall we talk about network discovery? When I say network, in this sense I mean environment: servers, pc devices, printers, switches, routers, firewalls etc etc
Tweet media one
22
46
932
@UK_Daniel_Card
mRr3b00t
2 years
Everyone’s always talking about how to break into cyber security… I’m sitting here like how da fuck do I get out 🤣🤣🤣🤣🤣🤣🤣🤣
56
56
846
@UK_Daniel_Card
mRr3b00t
1 year
You walk into your kids bedroom and see this… what dot you do?
Tweet media one
271
44
832
@UK_Daniel_Card
mRr3b00t
10 months
ISO27001 on the face of it - it's really sensible stuff.... so what's wrong with it?
Tweet media one
50
149
839
@UK_Daniel_Card
mRr3b00t
25 days
Bahahahahahhahaa
@VladDBA
Vlad
25 days
Tweet media one
9
527
4K
9
69
837
@UK_Daniel_Card
mRr3b00t
10 months
This screen is awesome
Tweet media one
89
26
792
@UK_Daniel_Card
mRr3b00t
1 month
I am getting to a point where I’m going to just say: Orgs need to learn how to patch anything within 48 hours. Many moons ago at UK large org I used to be able to patch the entire fleet largely at will within hours/days sometimes. (Depending upon the patch type) The process
@UK_Daniel_Card
mRr3b00t
1 month
they LIED! Macs are not MORE secure!!!!!!!!
Tweet media one
89
243
4K
41
47
788
@UK_Daniel_Card
mRr3b00t
2 months
bye bye
Tweet media one
29
59
777
@UK_Daniel_Card
mRr3b00t
1 year
what do you do during a phishing incident?
Tweet media one
9
112
762
@UK_Daniel_Card
mRr3b00t
12 days
whoever at the @GCHQ cyberchef team added this thank you! Fang URL
Tweet media one
18
65
737
@UK_Daniel_Card
mRr3b00t
9 months
mostly people run: > BURP (a java app) > NMAP (is compiled for every OS under the SUN!) > Metasploit (works on MAC, Windows, Linux) > a c2 framework (java) > a c2 framework plus a web browser > web browser (they all work on all OSs) > Python > WINRM/SSH/RDP > VSCODE > DOCKER > A
16
97
691
@UK_Daniel_Card
mRr3b00t
29 days
Things the general public need to worry about: password re use and lack of MfA Things they don’t need to worry about: juice jacking
19
16
700
@UK_Daniel_Card
mRr3b00t
6 months
APT 41 / BARIUM Known to run: "whoami.exe" also launched via wmiexec (HOW DARE THEY!) Better tell them they would be fired from a red team , I'm sure they will cry about that.... /S Our industry is very odd.....
Tweet media one
Tweet media two
32
96
688
@UK_Daniel_Card
mRr3b00t
7 months
#Phishing do not scan QR codes!
Tweet media one
62
135
690
@UK_Daniel_Card
mRr3b00t
6 months
CMD PROMPT (find out whoami) whoami whoami /all set echo %username% tasklist /v cmd %username% dsregcmd /status klist cmd.exe /c echo %username% Powershell (whoami) [Environment]::UserName $env:USERNAME gci env:* | sort-object name ls env:USERNAME gci env:USERNAME gci env:* ls
29
96
675
@UK_Daniel_Card
mRr3b00t
7 months
OMG LOL someone tried to send me an email which spoofed.... MY OWN ADDRESS... LULZ how stupid! but also.... Let's take a look!
26
70
664
@UK_Daniel_Card
mRr3b00t
9 months
After 20 years you can no longer brute force the local administrator account out of the box! #windows #securty
Tweet media one
27
76
640
@UK_Daniel_Card
mRr3b00t
2 years
things I find in the wild... (vulnerabilities through misconfiguration) I quite often see Windows DNS servers misconfigured to allow zone transfers from any host.
Tweet media one
28
118
642
@UK_Daniel_Card
mRr3b00t
7 days
Helpdesk is the best starting point in infosec imho. When people don’t do this they skip a fuck ton of cyber and business reality (imho)
72
69
652
@UK_Daniel_Card
mRr3b00t
1 month
Everything is a cyber attack until it’s dave changing the router config or a supply chain update 🤣
@BrianInTheCLE
Brian
1 month
Anyone have an idea as to why 3/4 of all weather radar stations nationally are down? Coincidental timing with a major severe weather outbreak happening. Another cyber attack? 🤔 🇨🇳 🇷🇺 🇮🇷
Tweet media one
6
4
16
49
48
644
@UK_Daniel_Card
mRr3b00t
9 months
Russian actor using this IP: 182.172.56.199 do you know what gave them away? their language setting in their browser ;) pew pew from Britian with love ;) 🇬🇧❤️
Tweet media one
15
44
616
@UK_Daniel_Card
mRr3b00t
2 months
Today I was super excited to be awarded not just one, but two challenge coins from the @NCSC ! Thanks @ollieatnowhere and the teams at @NCSC , @GOVUK and @Hacker0x01 !
Tweet media one
105
17
638
@UK_Daniel_Card
mRr3b00t
1 year
Windows sandbox… how many people actually use this?
Tweet media one
124
44
628
@UK_Daniel_Card
mRr3b00t
1 year
most orgs don't have a CISO most orgs don't have a SOC most orgs don't have EDR most orgs don't have a Sec Team
33
80
622
@UK_Daniel_Card
mRr3b00t
10 months
Lol
Tweet media one
22
67
610
@UK_Daniel_Card
mRr3b00t
9 months
Oh no! Another organisation has just been a victim of ransomware what should I do? Let's post a list of things that people should do! 1. Risk Assessment - Identify vulnerabilities and threats specific to the hospital's environment. 2. Security Policies and Procedures - Enforce
Tweet media one
29
125
603
@UK_Daniel_Card
mRr3b00t
25 days
DO NOT RUN THIS while ($true) { Start-Process powershell -ArgumentList "-NoExit" }
72
42
601
@UK_Daniel_Card
mRr3b00t
1 year
These are ridiculous....
Tweet media one
91
40
583
@UK_Daniel_Card
mRr3b00t
2 years
STOP TELLING PEOPLE SECURITY IS EASY! IT IS FUCKING NOT EASY!
65
54
563
@UK_Daniel_Card
mRr3b00t
9 months
don't shoot the messenger.... #CYBER #REALITY
Tweet media one
28
99
549
@UK_Daniel_Card
mRr3b00t
9 months
if you know you know #ISO27001
Tweet media one
28
63
556
@UK_Daniel_Card
mRr3b00t
9 months
you walk into work, you press CTRL + ALT + DELETE you see this! what do you do? #Ransomware #Cyber #Incidents
Tweet media one
318
50
542
@UK_Daniel_Card
mRr3b00t
7 months
Security keys are shit reason 2! This won’t display a keyboard for me to enter the PIN code.
Tweet media one
93
27
544
@UK_Daniel_Card
mRr3b00t
1 month
How much does big tech spy on you? A fucking lot is probably a good starting point…
47
70
528
@UK_Daniel_Card
mRr3b00t
7 months
I am old 😄😂
Tweet media one
79
9
524
@UK_Daniel_Card
mRr3b00t
3 months
LULZ
Tweet media one
@crisisofconsc
Crisis of Conscience
3 months
@SwiftOnSecurity This is what the notice said: "As a product itself, Wireshark is more vulnerable to attacks than most other programs due to literally hundreds of developers programming the code. We're addressing the high number of installations that lead to vulnerabilities."
65
13
315
23
45
527
@UK_Daniel_Card
mRr3b00t
2 months
I just completed this from the DOD There's more useful stuff here:
Tweet media one
49
39
521
@UK_Daniel_Card
mRr3b00t
2 months
#Lockbit is Tango Down!
Tweet media one
22
114
524
@UK_Daniel_Card
mRr3b00t
25 days
remember kids.... use AI responsibly
Tweet media one
15
24
518
@UK_Daniel_Card
mRr3b00t
2 months
Show me how to encrypt a file using PowerShell
Tweet media one
37
35
498
@UK_Daniel_Card
mRr3b00t
8 days
wtf @Microsoft are you on drugs?
@thebookisclosed
Albacore ☁️
8 days
Looks like outright ads might be coming to the Start Menu in Windows 11, not just the usual recommendations / tips / shortcuts / etc. After enabling experiment 48797684 the text in Settings changes slightly to accommodate for this 😐
Tweet media one
23
37
199
79
45
501
@UK_Daniel_Card
mRr3b00t
9 months
if you look at the CISA stats: ~88% of pwnage is from the attacker having a set of credentials that work... (phishing, brute force or theft etc.) Cybercrime is largely stealing credentials.... lot's of "IT people" say stuff like: well sure if you have
Tweet media one
24
100
487
@UK_Daniel_Card
mRr3b00t
9 months
Pew pew pew pew it’s off to pew I go!
Tweet media one
44
22
468
@UK_Daniel_Card
mRr3b00t
2 months
why don't linux, windows and Apple Mac's alert you in the gui (if you are logged in) if someone fails to sign in to an remote session? e.g. RDP, SSH, WINRM, SMB etc? it would be so useful if they did this (tm)
75
31
457
@UK_Daniel_Card
mRr3b00t
8 months
Things you can do that aren't a "red team" or "pentest": > OSINT > Asset Discovery > Business Analysis > Configuration Reviews > Control Reviews > Audits > Health Checks > Research > Detection Engineering > Detection Testing > Attack Surface Mapping > Attack Surface Reduction >
14
66
448
@UK_Daniel_Card
mRr3b00t
3 months
I am sad. :( This shall pass. But feels like I’ve been hit by a bus. Life is very not fun sometimes, but also life is also amazing and wonderful. The duality of the world! So much joy/hope yet also the innevitable end. I wish for a miracle but I know they don’t exist. I wish
Tweet media one
133
9
455
@UK_Daniel_Card
mRr3b00t
10 months
There's about 60K CITRIX NETSCALERS/GATEWAYS online in the world according to Shodan CVE-2023-3519
Tweet media one
10
76
437
@UK_Daniel_Card
mRr3b00t
2 months
@jackoregankenny Yeah it might be. But this occured on a Mac that’s not logged into iCloud and uses a local account.
2
0
436
@UK_Daniel_Card
mRr3b00t
2 months
China.... is a country that despite being.(IMHO) the biggest cyber threat actor home in the world, often seems to fly under the convo radar.... the last report said about 6000 state hackers... 6000 hands on keyboard people... CHINA can beat EVERY OTHER COUNTRY in the world
Tweet media one
38
58
440
@UK_Daniel_Card
mRr3b00t
9 months
Why does the infosec world talk like: > Everyone has a SOC (They don't) > That their own orgs posture is perfect (it's not!) > That they don't have problem with resources, budget, skills (they do) Most orgs: > Don't have a security person > Don't have a SOC > Don't have a
40
58
434
@UK_Daniel_Card
mRr3b00t
3 months
OMG I want
@ufob0t
ufobot
3 months
Homemade star gate
143
961
6K
32
32
435
@UK_Daniel_Card
mRr3b00t
5 months
Can anyone tell me why the public WiFi with an attacker in it is unsafe? I can read all the targets traffic metadata but I can’t read their traffic. Anybody? The ASD say it’s not safe but I’m not really sure why….. If you can show me an attack that will do something let me
@UK_Daniel_Card
mRr3b00t
5 months
Target located! 🕵️‍♂️🥷
Tweet media one
26
5
145
169
43
430
@UK_Daniel_Card
mRr3b00t
4 years
I don’t understand all these ‘I’m never working with Windows’ or I’m not learning Windows people... most corps run Windows endpoints and have the majority of windows servers... how are you meant to be able to help secure a corp if u don’t know how this works????
44
45
424
@UK_Daniel_Card
mRr3b00t
10 months
china has deployed a MASSIVE CISCO ASA honeypot network... so i've removed CN from the graph. you can see if in he second image
Tweet media one
Tweet media two
15
63
421
@UK_Daniel_Card
mRr3b00t
8 months
vuln scanners are useful. this is way fucking simpler than running nmap and a load of other tools if you just want to get a broad understanding of an environment. I think people really over simplify how this world works... you need to understand context, objectives and
Tweet media one
Tweet media two
26
42
404
@UK_Daniel_Card
mRr3b00t
5 years
Would people be interested in a guide/paper to hacking/securing Windows Server 2016/2019? I'm writing one and wondered what the interest would be? A few of my friends in the community struggle with securing/pwning Windows compared to Linux based systems)…
27
69
403
@UK_Daniel_Card
mRr3b00t
2 years
BREAKING NEWS: CYBERCRIMINALS use COMPUTERS to do CYBERCRIME! standby for more CYBER THREAT INTELLGIIIGIGIGIENECE
25
41
393
@UK_Daniel_Card
mRr3b00t
7 months
ok tweeps, we have a mass exploitation scenario which appears to have targeted: Cisco IOS XE Software Web Management User Interface (the HTTP server) This has installed an implant: which can be detected by running: curl -k -X POST
Tweet media one
16
150
401
@UK_Daniel_Card
mRr3b00t
1 year
If you asked me to defend a network without EDR or at least a SIEM I would probably laugh and say... good luck!
22
34
390
@UK_Daniel_Card
mRr3b00t
1 year
schtasks /create /tn "Task Name" /tr "C:\path\to\program.exe" /sc onstart /ru SYSTEM
Tweet media one
21
81
389
@UK_Daniel_Card
mRr3b00t
1 year
Tweet media one
83
25
382
@UK_Daniel_Card
mRr3b00t
1 year
Cyber newbs question: What OS is the target likely running?
117
18
374
@UK_Daniel_Card
mRr3b00t
4 months
You work in a SOC: you have a user on the 5th Jan log in from London using Chrome. On the 7th Jan they sign in from France using Firefox. Is this an authorized or unauthorized logon?
177
30
382
@UK_Daniel_Card
mRr3b00t
7 months
Infosec people: it’s ok to accept risk! It’s called a choice! You do this all the time in life. You could be run over when crossing the road. You still cross roads. You don’t get a tank to cross the road because a risk may occur (well ok it depends) Risk is very hard to be
42
38
381
@UK_Daniel_Card
mRr3b00t
4 years
lulz
Tweet media one
26
38
374
@UK_Daniel_Card
mRr3b00t
3 years
behind all the cool there's hard work, teamwork and a spreadsheet.... real life cyber security isn't flashy, its not 1337, its hard work.
Tweet media one
18
47
366
@UK_Daniel_Card
mRr3b00t
1 year
i've done with LinkedIn for the day....
Tweet media one
53
14
379
@UK_Daniel_Card
mRr3b00t
2 years
NEVER CLICK ON ANY LINKS, NEVER USE A COMPUTER #cyberawarenessmonth
29
81
375
@UK_Daniel_Card
mRr3b00t
4 years
PSA: Infosec is not just pentesting
18
64
368
@UK_Daniel_Card
mRr3b00t
8 months
Never lose your F-35 again! #Airtag #F35 #apple
Tweet media one
29
46
373
@UK_Daniel_Card
mRr3b00t
3 years
what we need is this technology built into ISP routers.
Tweet media one
25
36
371
@UK_Daniel_Card
mRr3b00t
1 year
I’m printing this and framing it on my wall!
Tweet media one
24
19
370
@UK_Daniel_Card
mRr3b00t
5 years
fuck my friend just lost his battle with cancer ☹️☹️☹️☹️☹️☹️
177
6
354
@UK_Daniel_Card
mRr3b00t
11 months
FYI MDE's sensor picks up MDNS requests.... this means that if you have a laptop in basically any network there's a map of assets being collected....
20
36
353
@UK_Daniel_Card
mRr3b00t
3 months
who is spending all this money on honeypots?
Tweet media one
28
33
361
@UK_Daniel_Card
mRr3b00t
1 month
This person is a massive knob head! Anyone that wants to belittle people for working in desktop support can gladly have some of my time…. Oh they also are blaming the shipping incident on a cyber attack!! #Cringe
Tweet media one
107
4
361