nyxgeek Profile Banner
nyxgeek Profile
nyxgeek

@nyxgeek

Followers
7K
Following
54K
Media
803
Statuses
11K

rebel scum, nerfherder, dogged and relentless. H/P/V/A/C Directory - https://t.co/qn0D9H7IIi

hacking gibsons
Joined June 2012
Don't wanna be here? Send us removal request.
@nyxgeek
nyxgeek
2 years
If anyone wants to check out my DEF CON talk about massive user enumeration, presence monitoring, and guest relationships in Azure, they posted the video a few days back. Track the Planet!.
Tweet media one
5
17
103
@nyxgeek
nyxgeek
4 hours
My PR for GraphRunner has been accepted! . You can now check for insecure Front Door WAF rules with Check-FrontDoorWAF!. . Shoutout and thanks to @dafthack and @424f424f ! Absolutely love GraphRunner!
Tweet media one
1
2
13
@nyxgeek
nyxgeek
4 hours
If you’re using Azure Front Door WAF, make sure you select the correct IP match variable or you’re gonna have a bad time. Here’s a standalone tool you can run from CloudShell to check for insecure Front Door WAF rules that utilize RemoteAddr.
Tweet media one
@TrustedSec
TrustedSec
5 hours
Does your WAF use IP restrictions, or are they more like IP recommendations? @nyxgeek reveals the difference between RemoteAddr and SocketAddr, a distinction that could create a 'sleeper' rule that looks secure but is easily bypassed.
3
22
65
@nyxgeek
nyxgeek
5 hours
RT @TrustedSec: Does your WAF use IP restrictions, or are they more like IP recommendations? @nyxgeek reveals the difference between Remote….
0
14
0
@nyxgeek
nyxgeek
1 day
RT @todayininfosec: 1982: The movie Tron was released. The story of a software engineer who tried to hack his old employer's mainframe to p….
0
21
0
@nyxgeek
nyxgeek
1 day
RT @HackingLZ: Really big fan of the post exploitation enumeration/discovery framework called ServiceNow.
0
52
0
@nyxgeek
nyxgeek
1 day
RT @TrustedSec: What started as casual poking around quickly revealed a serious privilege escalation. In our latest blog, @Oddvarmoe shares….
0
27
0
@nyxgeek
nyxgeek
1 day
RT @Oddvarmoe: The writeup about the CVE-2025-1729 I mentioned earlier this year is published. Fix from Lenovo should be out today.
0
9
0
@nyxgeek
nyxgeek
1 day
RT @thegrugq: It’s that time of the week again. Fortinet has an RCE.
0
73
0
@nyxgeek
nyxgeek
3 days
RT @TheCinesthetic: Since its release 11 years ago, just one hour and 31 minutes have passed on Miller's planet in Interstellar. https://t.….
0
27K
0
@nyxgeek
nyxgeek
3 days
RT @MerriamWebster: 'Vacations.' . The word is 'vacations.'
Tweet media one
0
9K
0
@nyxgeek
nyxgeek
3 days
Tweet media one
0
9K
0
@nyxgeek
nyxgeek
3 days
RT @Acyn: DOOCY: So what happened to the Epstein client list that the attorney general said she had on her desk? . LEAVITT: I think if you….
0
15K
0
@nyxgeek
nyxgeek
3 days
RT @coffeebreak_YT: 1 MINUTE IS MISSING FROM EPSTEIN SECURITY FOOTAGE 💀
0
2K
0
@nyxgeek
nyxgeek
3 days
RT @briantylercohen: Hey @MattWallace888, since you saw the leaked files back in February, why don't you tell us what the White House won't….
0
14K
0
@nyxgeek
nyxgeek
3 days
RT @TrustedSec: Check out this @CyberNews video featuring @HackingDave! They break down the story behind the mysterious hacker group the Sh….
0
5
0
@nyxgeek
nyxgeek
3 days
RT @0x64616e: Onboard yourself - PaloAlto Global Protect edition:.1. Become local admin.2. Export device cert from original workstation.3.….
0
103
0
@nyxgeek
nyxgeek
3 days
RT @elonmusk: 🤬
Tweet media one
0
102K
0
@nyxgeek
nyxgeek
3 days
RT @elonmusk: What’s the time? Oh look, it’s no-one-has-been-arrested-o’clock again …
Tweet media one
0
90K
0