evantobac Profile Banner
Evan Tobac Profile
Evan Tobac

@evantobac

Followers
1K
Following
670
Media
26
Statuses
170

Security Researcher, Maker | Co-Founder, Head of Research & Tech at @SocialProofSec | @BSidesSF Review Committee | He/him | https://t.co/usxjnTc0oZ

San Francisco, CA
Joined January 2018
Don't wanna be here? Send us removal request.
@evantobac
Evan Tobac
3 years
We just hacked @donie (with his consent) and here's a breakdown of how we cracked his password. At a high level, we used a data breach site, the password cracking tool @hashcat, and a custom wordlist and ruleset. This is how it went down.
9
80
245
@evantobac
Evan Tobac
7 days
RT @0xTib3rius: Be me. Get invited by @RachelTobac & @evantobac to play craps. Side note: when the Tobacs invite you to gamble, you go. Th….
0
5
0
@evantobac
Evan Tobac
11 days
RT @RachelTobac: One of my favorite people in the @defcon universe is @_MG_ .Go buy his hacking tools, you’ll have a blast. .
0
17
0
@evantobac
Evan Tobac
11 days
RT @RachelTobac: The @socialproofsec @defcon 33 Clue Hunt in ON!.This challenge is short, it’s just 1 clue. Coin & sticker will both be of….
0
15
0
@evantobac
Evan Tobac
10 months
RT @RachelTobac: I just live hacked @ArleneDickinson (Dragons' Den star - Canada's Shark Tank) by using her breached passwords, social medi….
0
108
0
@evantobac
Evan Tobac
11 months
Very cool, portable tool to get insight into USB cables from @alvaroprieto .
Tweet media one
0
0
5
@evantobac
Evan Tobac
1 year
Great writeup of reversing and troubleshooting a malfunctioning Beaglebone Black. Lots of tools and techniques used (UART, JTAG, Saleae, EMIF Tuning, tinySA, ARM Reversing, etc.).
@analog_sam
Sam Gallagher
1 year
Finally published my writeup of my reverse engineering the TI AM335x boot ROM. (At least, as far as it served to help me get the boards to boot.) This is the processor at the core of the Beaglebone Black board.
Tweet media one
0
0
1
@evantobac
Evan Tobac
1 year
For anyone who wanted a key but didn't get one. Now you can print your own!.
@RsThrive
Chris O'Rourke
1 year
I've uploaded the keymaster key for the @socialproofsec clue hunt, for the few that asked for it. Looks best with various exotic @ fun PLA filaments. I recommend @Proto_pasta and @Polymaker_3D.
Tweet media one
0
1
6
@evantobac
Evan Tobac
1 year
What's the fair market value on goon money these days?
Tweet media one
1
0
4
@evantobac
Evan Tobac
1 year
RT @RachelTobac: Are you ready to play a game, @defcon? Our 1st Clue Hunt clue is ready for you. Winners get the challenge coin that screws….
0
13
0
@evantobac
Evan Tobac
1 year
RT @socialproofsec: Our @defcon Clue Hunt is starting soon & it’s bigger than ever before!.1st clue & Keymasters at @sec_defcon starting Fr….
0
10
0
@evantobac
Evan Tobac
2 years
RT @RachelTobac: *Sizzle Reel + Ransomware Song Debut!*.We just hit 500,000+ users for our @socialproofsec security awareness training vide….
0
20
0
@evantobac
Evan Tobac
2 years
RT @RachelTobac: Here’s how I used AI to clone a 60 Minutes correspondent’s voice to trick a colleague into handing over her passport numbe….
0
6K
0
@evantobac
Evan Tobac
2 years
RT @60Minutes: 60 Minutes hired an ethical hacker to show how easy it is to be scammed. She conned our unsuspecting colleague using artific….
0
2K
0
@evantobac
Evan Tobac
2 years
RT @RachelTobac: *Our Music & Spoken Security Awareness Videos are now on (almost) every continent🤯 - Demo/Update*.Here are more sample sni….
0
24
0
@evantobac
Evan Tobac
3 years
RT @clintgibler: Great overview of the dangers of password reuse due to data breaches by @RachelTobac, @evantobac . * Find email addresses….
0
7
0
@evantobac
Evan Tobac
3 years
So putting it all together, we found a password hash for Donie on a data breach site, made a Donie-specific wordlist of previously-used passwords and personal info, and fed it to Hashcat with a modified version of Dive ruleset. Hashcat cracked the password in under 15 seconds.
2
1
10
@evantobac
Evan Tobac
3 years
Example Hashcat rules might be adding special characters to the beginning or end, incrementing numbers, or converting words to leetspeak (e.g. p4ssw0rd). Rules can basically automate most of the superficial changes many people make to their old passwords.
1
1
6
@evantobac
Evan Tobac
3 years
Hashcat is a tool that creates password guesses and hashes them to see if they match the target. It takes as input a wordlist of potential password guesses and a list of rules for all the modifications of each password to try.
1
1
7
@evantobac
Evan Tobac
3 years
I took all the old passwords that we knew Donie used in the past and added them to a list of personal details about Donie we found on social media. This was our wordlist. I used this wordlist with a password cracking tool called Hashcat.
1
1
7