
Ryan Roth
@f1rstm4tter
Followers
318
Following
1K
Media
57
Statuses
786
InfoSec | Hacker | Saltwater Fly Fisherman 🦈 | Gamer | Amateur Malware Analyst | Former Web Dev
Philadelphia, PA
Joined August 2016
A single 1.4GB file exposed credentials for 110+ universities. Terra Dotta incident included encode keys enabling complete auth bypass, plus LDAP, SMTP, and API credentials across their entire client base. Credentials remain active months after disclosure.
ryanmroth.com
I discovered a critical Terra Dotta data exposure affecting hundreds of universities: publicly accessible credentials, SEVIS immigration data, and authentication bypasses. The vendor removed file...
0
2
1
I started a blog. Because what the world really needed… was another cybersecurity professional with a website. The first post is live: "CVE-2024-50960: Exploiting Extron SMP Command Injection".
ryanmroth.com
I recently stumbled upon a command injection vulnerability in Extron SMP streaming media processors—one that lets an authenticated web admin execute arbitrary OS commands as root. This post breaks...
0
0
0
RT @ctrlshifti: idea: a gameshow called Imposter Syndrome where you take 10 senior developers and tell them that one of them is actually ju….
0
4K
0
RT @hAPI_hacker: The @NahamSec Hacking APIs book giveaway! .Giving out 10 signed print copies and I'll ship them anywhere 🌎🌍🌏. One entry pe….
nostarch.com
Learn how to test APIs for security vulnerabilities so you can uncover high-payout bugs and improve the security of web apps.
0
856
0
RT @InfoSecTogether: To celebrate the launch of this new course from @mttaggart and @TCMSecurity we want to give away (1) voucher!. To ente….
academy.tcm-sec.com
TCM Security Academy offers practical, job-focused cybersecurity training designed by industry-leading instructors that doesn't break the bank.
0
235
0
RT @thezdi: Here's a quick demonstration of the #Microsoft Teams 0-click exploit demonstrated by @starlabs_sg during #Pwn2Own last week. h….
0
46
0
hxxp://23[.]95[.]52[.]191/onye/.hxxps://gg-l[.]xyz/BlZch.198[.]199[.]122[.]148.@ColoCrossing malware hosted .@digitalocean ns for domain.@GoDaddyHelp registrar.
app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
1
0
0
RT @Prof_Rege: This just broke my heart. This is @TU_CARE's dataset. All of it. Please acknowledge us for the….
securityweek.com
A Temple University research project that tracks ransomware attacks on critical infrastructure has documented more than 1,100 incidents to date.
0
116
0
RT @hardwaterhacker: Today I learned CrowdStrike's ML AV component looks at total entropy in an executable and will block it if the entropy….
0
145
0
RT @philly2600: Philly 2600 meets this Friday at 30th Street Station around 6pm! We don't know if the food court will be open yet now that….
0
2
0
RT @zebpalmer: Cisco is offering Splunk $20 billion. Unclear if they're trying to buy the company, or just renew their subscription for a….
0
1K
0