
@strawp
Followers
818
Following
4K
Media
576
Statuses
13K
Principal security consultant @nettitude_labs. CHECK Team Leader (Applications). Frequently uninjured snowboarder. @[email protected]
document.location
Joined April 2008
If you miss Twitter back in pre-2010 days when it was just full of geeks sharing cool stuff, then get on Mastodon. is where I'll be now. 👋.
0
0
1
I did a thing.
Popular document storage solution, ONLYOFFICE, affected by multiple vulnerabilities. Our latest post by @strawp shows how to exploit this for unauthenticated remote code execution.
3
0
8
RT @Nettitude_Labs: Popular document storage solution, ONLYOFFICE, affected by multiple vulnerabilities. Our latest post by @strawp shows h….
lrqa.com
About 18 months ago, I was conducting a pentest of a document management platform. It was designed with the goal of providing a secure document storage and sharing solution for some high impact use...
0
10
0
RT @saajanbhujel: Hey everyone👋,. Read my blog about "How I Got $10,000 From GitHub For Bypassing Filtration oF HTML tags". @GitHubSecurity….
infosecwriteups.com
Hey everyone👋, I hope you’re having an A+ week🚀! In today’s blog, I am going to tell you that, “How I Got $10,000 From GitHuB”.
0
219
0
A year ago I would not have bothered attempting to get into an account with MFA, but last week I used this same technique and got 8 accounts in an org over 2 days on a remote SE test. MFA is snake oil.
grahamcluley.com
Uber has suffered a security breach which allowed a hacker to break into its network, and access the company’s internal documents and systems. How did they do it? By bombarding an employee with a…
0
0
0
RT @gentilkiwi: Always fabulous to see editors low the Windows Security level. When Citrix SSO is enabled. passwords are stored in *user….
0
296
0
RT @Nettitude_Labs: Learn four of the most effective network relaying attacks against Windows domains. Defenders - learn how to mitigate ag….
lrqa.com
Network relaying abuse in the context of a legacy Windows authentication protocol is by no means a novel vector for privilege escalation in a domain context.
0
45
0
RT @mubix: This is something you should watch. These two individuals know more about scanning than a very large majority of Infosec combine….
0
73
0