f1rstm4tter Profile Banner
Ryan Roth Profile
Ryan Roth

@f1rstm4tter

Followers
318
Following
1K
Media
57
Statuses
786

InfoSec | Hacker | Saltwater Fly Fisherman 🦈 | Gamer | Amateur Malware Analyst | Former Web Dev

Philadelphia, PA
Joined August 2016
Don't wanna be here? Send us removal request.
@f1rstm4tter
Ryan Roth
2 months
A single 1.4GB file exposed credentials for 110+ universities. Terra Dotta incident included encode keys enabling complete auth bypass, plus LDAP, SMTP, and API credentials across their entire client base. Credentials remain active months after disclosure.
Tweet card summary image
ryanmroth.com
I discovered a critical Terra Dotta data exposure affecting hundreds of universities: publicly accessible credentials, SEVIS immigration data, and authentication bypasses. The vendor removed file...
0
2
1
@f1rstm4tter
Ryan Roth
4 months
I started a blog. Because what the world really needed… was another cybersecurity professional with a website. The first post is live: "CVE-2024-50960: Exploiting Extron SMP Command Injection".
Tweet card summary image
ryanmroth.com
I recently stumbled upon a command injection vulnerability in Extron SMP streaming media processors—one that lets an authenticated web admin execute arbitrary OS commands as root. This post breaks...
0
0
0
@f1rstm4tter
Ryan Roth
1 year
RT @hopeconf: Marjorie Taylor Greene (@RepMTG) has a warning for the American people. HOPE XV will take place from July 12-14, 2024 at St.….
0
32
0
@f1rstm4tter
Ryan Roth
3 years
RT @mfts0: When your PR is finally accepted and merged
Tweet media one
0
1K
0
@f1rstm4tter
Ryan Roth
3 years
RT @ctrlshifti: idea: a gameshow called Imposter Syndrome where you take 10 senior developers and tell them that one of them is actually ju….
0
4K
0
@f1rstm4tter
Ryan Roth
3 years
RT @hAPI_hacker: The @NahamSec Hacking APIs book giveaway! .Giving out 10 signed print copies and I'll ship them anywhere 🌎🌍🌏. One entry pe….
Tweet card summary image
nostarch.com
Learn how to test APIs for security vulnerabilities so you can uncover high-payout bugs and improve the security of web apps.
0
856
0
@f1rstm4tter
Ryan Roth
3 years
RT @thezdi: Here's a quick demonstration of the #Microsoft Teams 0-click exploit demonstrated by @starlabs_sg during #Pwn2Own last week. h….
0
46
0
@f1rstm4tter
Ryan Roth
3 years
hxxp://23[.]95[.]52[.]191/onye/.hxxps://gg-l[.]xyz/BlZch.198[.]199[.]122[.]148.@ColoCrossing malware hosted .@digitalocean ns for domain.@GoDaddyHelp registrar.
app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
1
0
0
@f1rstm4tter
Ryan Roth
3 years
RT @rootsecdev: Lsass dumps. 😁.
0
3
0
@f1rstm4tter
Ryan Roth
3 years
RT @IAmMandatory: It's time to up our infosec shitposting game (listen with audio)
0
889
0
@f1rstm4tter
Ryan Roth
3 years
RT @hardwaterhacker: Today I learned CrowdStrike's ML AV component looks at total entropy in an executable and will block it if the entropy….
0
145
0
@f1rstm4tter
Ryan Roth
3 years
RT @philly2600: Philly 2600 meets this Friday at 30th Street Station around 6pm! We don't know if the food court will be open yet now that….
0
2
0
@f1rstm4tter
Ryan Roth
3 years
Tweet media one
0
23
0
@f1rstm4tter
Ryan Roth
4 years
RT @tunguz: Painting:.“The arrival of the AWS bill.”.Oil on canvas.
Tweet media one
0
736
0
@f1rstm4tter
Ryan Roth
4 years
RT @zebpalmer: Cisco is offering Splunk $20 billion. Unclear if they're trying to buy the company, or just renew their subscription for a….
0
1K
0
@f1rstm4tter
Ryan Roth
4 years
RT @BentleyAudrey: Seriously.
Tweet media one
0
41
0
@f1rstm4tter
Ryan Roth
4 years
Are FCC filing's internal device images always such poor quality? Maybe I just happened upon a particularly bad set. Seems like it would be in their best interest to get clear ones. But probably not the orgs in providing huh?.
0
0
0