Internetwache.org
@internetwache
Followers
3K
Following
921
Media
152
Statuses
3K
IT Security, Bugbounties & Whitehats - Helping companies to find bugs. A project by @gehaxelt & @TimPhSchaefers.
Earth, Europe, Germany, Berlin
Joined June 2012
8 years ago we started tweeting with this twitter handle and with responsible disclosure & bug bounty hunting as @internetwache. ... an amazing ride so far - let's see how it continues. //cc: @gehaxelt & @TimPhSchaefers
19
4
7
Since portions of the web directory were protected, I had to use a tool to download all the `git objects` from the server. ⚠️ I used GitTools "Dumper" to dump the available objects, from @internetwache
https://t.co/TDA63L39Mc
1
5
59
If you're interested in the vulnerability at hand, check out this great article by @internetwache on exposed git repositories: https://t.co/MYXaIKkmZE
en.internetwache.org
Sebastian participated in a CTF (capture the flag) a couple of months ago. One challenge he faced was the task of restoring a git repository from a directory listing enabled webserver. With directory...
1
1
1
I started my blog in 2014, inspired by great security bloggers like @bitquark and @internetwache. The best platform to build up a blog at at that was Google Blogger. They provide a clean dashboard for writing posts, managing comments, understanding stats, and security features.
1
1
0
Im "Dialog für Cyber-Sicherheit - Denkwerkstatt" von @BSI_Bund, @iRightslab & @nexus_Institut haben wir heute am "Konzept zur Ausbildung digitaler Katastrophenschützer*innen" mitgewirkt. Es wird Zeit für "digitale Ersthelfer*Innen"! 💻 //cc: @ijonberlin @HonkHase @AG_KRITIS
Heute vertrete ich die @AG_KRITIS in dieser spannenden Runde! Gestern war der @HonkHase für uns dabei. Ich bin total gespannt welche Projekte ausgewählt werden!
0
6
13
Im "Dialog für Cyber-Sicherheit - Denkwerkstatt" von @BSI_Bund, @iRightslab & @nexus_Institut haben wir heute am "Konzept zur Ausbildung digitaler Katastrophenschützer*innen" mitgewirkt. Es wird Zeit für "digitale Ersthelfer*Innen"! 💻 //cc: @ijonberlin @HonkHase @AG_KRITIS
Heute vertrete ich die @AG_KRITIS in dieser spannenden Runde! Gestern war der @HonkHase für uns dabei. Ich bin total gespannt welche Projekte ausgewählt werden!
0
6
13
News about hackers who attacked "Water Supply" in the US ... Also a big problem in Germany - in 2018 we gained access ~7 local water supply stations in Germany. Also mentioned with another case of us in the official @BSI_Bund / @certbund report. https://t.co/fz7Mfct8x3 ^ts
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)
0
1
2
Git Happens - I have just completed this room! Used Git Dumper and Extractor from @internetwache's GitTools to get all the source code and then went looking for passwords in old commits. Check it out: https://t.co/MuxOzrlul8
#TryHackMe #git #githappens via @RealTryHackMe
tryhackme.com
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
0
2
4
A session by @TimPhSchaefers & @gehaxelt at @sitberlin 2018: Handling security bugs with responsible disclosure and bug bounty programs https://t.co/Zdi8dCwEVY
#Security
opensit.net
All SAP Inside Track Sessions in one place.
0
2
2
@stokfredrik @LiveOverflow We are Hackers! We want to spread the words and share our knowledge. We like copyleft, not copyright. If we had claimed all our RCE and XSS payloads and techniques since 2005 all of you new bug bounty hunter should pay to us researchers from the early days! That said: keep calm!
2
2
11
Our GitTools are featured in @_johnhammond "Git Happens" video ;-) https://t.co/9qEFys9TnU ^sn
github.com
A repository with 3 tools for pwn'ing websites with .git repositories available - internetwache/GitTools
Git Happens -- discovering a public-facing Github repository and pulling it down to look through website source code! A very quick and simple showcase. Premieres 2:00 PM EST. #ctf #git #tryhackme #pentest #infosec
0
2
5
4 years ago we had a video shoot about our project @internetwache and Bug Bounty Hunting. A lot of things have changed since that - but still a lot of fun to watch. Our Favorite scene has to do something with extreme sport 😂 - take a look. https://t.co/Pm5cS8hBTI ^ts
0
1
3
@Jhaddix Did you try to use these tools? https://t.co/tuI0vAt4hQ It will make your life simpler ;)
github.com
A repository with 3 tools for pwn'ing websites with .git repositories available - internetwache/GitTools
1
8
15
Heute Abend in der ARD um 21:45 Uhr sind wir (@gehaxelt und @TimPhSchaefers) kurz bei Report Mainz zum Thema "kritische Infrastrukturen & IT-Sicherheitsgesetz 2.0" zu sehen - also schaltet gern ein. https://t.co/HVkF5mzA3D
0
3
1
In dem Artikel wird auch unsere Arbeit kurz erwähnt. Mehr dazu gibt es heute Abend in #ReportMainz ^ts
Kritische Infrastruktur - Hacken leicht gemacht https://t.co/pL41SuLmyj
#Hacker
0
3
4
It happened again! @Bugcrowd changed the status of a *valid* bug submission from 2015 to N/A just yesterday... ^sn
2
1
1
Dass das Szenario im Bereich "Wasserversorgung" von @ijonberlin keinesfalls aus der Luft gegriffen ist, zeigen unsere Erfahrungen aus den letzten Jahren. #defensivecon Siehe bspw.: https://t.co/sWd6bTjZrZ Live-Stream / Programm für Interessierte: https://t.co/MpurFOyx1r
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)
0
5
9
Excited to announce that we @Dynatrace are running a bounty promo on our @Hacker0x01 program. 100% bounty increase until January 31st To all invited - Make sure not to miss out 😇 To all uninvited - First 25 people to comment their h1 nick and share this issue will get an invite
59
27
94
I've talked to @maksumuto from @SZ, one of Germany's most reputable newspapers about my life as a full-time #BugBounty hunter. You can find the article online and also in today's print version of the newspaper! (both only in German) https://t.co/F3JiqRMNo9
#security
sueddeutsche.de
Julien Ahrens ist Hacker, für Unternehmen sucht er nach Fehlern im System. Ein Gespräch über lange Nachtschichten und moralische Grenzen.
1
4
51