x0rz Profile Banner
x0rz Profile
x0rz

@x0rz

Followers
97,907
Following
422
Media
3,226
Statuses
24,986

Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓

France
Joined September 2009
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@x0rz
x0rz
7 years
Writing to /dev/null
53
3K
5K
@x0rz
x0rz
5 years
Tweet media one
35
924
3K
@x0rz
x0rz
2 years
This is sad, actually
Tweet media one
111
288
3K
@x0rz
x0rz
4 years
Holy shit, Jeff Bezos is not *rich*, he is... owning us all.
Tweet media one
54
1K
3K
@x0rz
x0rz
3 years
if (score <= 85) { printf("FAILED"); } if (score >= 85) { printf("PASSED"); } 🤦‍♂️
@rSoftwareGore
Software Gore
3 years
CHOOSE A SIDE!
Tweet media one
13
68
637
57
463
3K
@x0rz
x0rz
2 years
(Source )
Tweet media one
13
478
3K
@x0rz
x0rz
6 years
Obfuscating IPv4 addresses is fun, try: $ ping 0177.1 $ ping 134744072 $ ping 0x8080808 $ ping 010.0x0000008.00000010.8 $ ping 8.0x0000000000000080808 That works both on Linux and Windows 👌
43
1K
2K
@x0rz
x0rz
7 years
Company X: we only store secure passwords hashes Me:
Tweet media one
78
913
2K
@x0rz
x0rz
7 years
The Mother of All Skimmers 😲 #infosec #carders
60
3K
2K
@x0rz
x0rz
6 years
Opsec protip: don’t tell the NSA how many unique passwords you’re using
@NSAGov
NSA/CSS
6 years
How many unique passwords do you use? (password=pwd)
421
186
305
39
787
2K
@x0rz
x0rz
8 years
Tweet media one
20
2K
2K
@x0rz
x0rz
6 years
apt-get install python
@motherboard
Motherboard
6 years
A man tried to smuggle a python onto a plane inside a hard drive
Tweet media one
22
85
176
39
751
2K
@x0rz
x0rz
4 years
How it started How it’s going
Tweet media one
Tweet media two
22
538
2K
@x0rz
x0rz
5 years
Shit just got real with fake profiles: generate fake faces in one click - endless possibilities #Fake #MachineLearning
Tweet media one
Tweet media two
Tweet media three
89
984
2K
@x0rz
x0rz
5 years
How to fight against facial recognition, or how to steal an ID 😳
38
640
2K
@x0rz
x0rz
6 years
Why use P2P when you can use Google and the full speed of other people's servers 😏 intitle:"Index of" {MOVIE_TITLE} mkv 1080p
29
436
2K
@x0rz
x0rz
5 years
100 random bug bounty kids vs. 3 professional pentesters (jk jk)
25
429
2K
@x0rz
x0rz
5 years
Cisco patches bug by... denying access to "Curl" User-Agents 🤦‍♂️
@RedTeamPT
RedTeam Pentesting
5 years
@info_dox @TheHackerNews @bad_packets @hrbrmstr We were also quite surprised to find this /etc/nginx.conf in 1.4.2.20
Tweet media one
48
417
1K
41
712
2K
@x0rz
x0rz
3 years
Tweet media one
28
162
2K
@x0rz
x0rz
6 years
Nginx off-by-slash vulnerability, cool trick presented by @orange_8361 at #hacklu
Tweet media one
Tweet media two
Tweet media three
Tweet media four
15
773
2K
@x0rz
x0rz
5 years
I need this in my life: a terminal user-interface for tshark
16
499
2K
@x0rz
x0rz
5 years
Good old time
Tweet media one
83
268
1K
@x0rz
x0rz
2 years
If you want GPS algorithms to avoid going through your street, here is a nice tip
Tweet media one
24
251
1K
@x0rz
x0rz
6 years
This is the Shodan of open Amazon S3 buckets, you can expect anything and everything 👌 #OSINT #redteam
Tweet media one
Tweet media two
Tweet media three
19
691
1K
@x0rz
x0rz
5 years
This website is absolutely awesome when it comes to DNS analysis, really cool graphs too #DNS #OSINT
Tweet media one
18
515
1K
@x0rz
x0rz
5 years
I am speechless 😶
Tweet media one
139
353
1K
@x0rz
x0rz
6 years
| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄|               Hackers        You’re all awesome |___________|                 \ (•◡•) /                   \       /                     ---                     |   |
14
326
1K
@x0rz
x0rz
7 years
Retrieve saved #WiFi passwords on Windows: > netsh wlan show profiles > netsh wlan show profile name=<profile> key=clear #pentest #redteam
22
608
1K
@x0rz
x0rz
7 years
1960's vs. now
Tweet media one
12
837
1K
@x0rz
x0rz
5 years
Isn't this great?
Tweet media one
44
330
1K
@x0rz
x0rz
6 years
Researchers, beware of impostors trying to get information out of you with false pretexts (fake journalists, researchers, etc.). Here is most likely some Iranian dude working me... Next time, try something better than that, "kevin" #osint #cyber #counterintelligence
Tweet media one
Tweet media two
Tweet media three
Tweet media four
54
433
1K
@x0rz
x0rz
6 years
Really cool #vulnerability /exploit search engine, using multiple source feeds 👍 #exploitdb #pentest #redteam
Tweet media one
10
637
1K
@x0rz
x0rz
5 years
I don't know if this is the future or anything, but hot damn 😳
56
482
1K
@x0rz
x0rz
7 years
Did former director of the NSA and CIA just tweeted his password? 🤔
Tweet media one
84
692
1K
@x0rz
x0rz
7 years
How I see IT certification hoarders ie. John Doe (CISSP, CISA, CGEIT, ITIL, CEH) 👌
Tweet media one
Tweet media two
73
594
1K
@x0rz
x0rz
5 years
Military grade 2048-bit RC4 key
Tweet media one
23
243
1K
@x0rz
x0rz
5 years
When you suddenly realize you're out of scope 🙈
@Louisitaa
L0u!5e
5 years
47
2K
3K
12
365
1K
@x0rz
x0rz
6 years
Photon: fast web crawler which extracts URLs, files, intel & endpoints from a target #pentest #pentesting #redteam
Tweet media one
19
425
1K
@x0rz
x0rz
6 years
Darknet OSINT is a thing, and it's pretty awesome: check out #FreshOnions at zlal32teyptf4tvi[.]onion #darknet #tor #osint
Tweet media one
15
477
1K
@x0rz
x0rz
4 years
Watch out for these fake news outlets. They typically: - Don't link to any article/source - Don't have any website - Use embedded media w/o links - Use extensively hashtags to spread (such as #BREAKING #NEWS ) - Use generic "news" stock images - Are authorless/anonymous
5
922
1K
@x0rz
x0rz
5 years
Oh man, this is pure evil right there
26
596
1K
@x0rz
x0rz
4 years
This is deeply disturbing
31
449
1K
@x0rz
x0rz
6 years
Curated list of Unix binaries that can be exploited to bypass local security restrictions 👍 #LOLBins #unix #pentest #redteam
Tweet media one
6
575
1K
@x0rz
x0rz
5 years
Using the computing power of Google to defeat Google, noice
@FGRibreau
Francois-Guillaume Ribreau
5 years
This projet defeat ReCaptcha with 91% accuracy 🤩. How? You might ask. They ask for the audio challenge, dl the mp3, forward it to Google Speech2Text API and submit the answer back... and it works 🤦🏻‍♂️
Tweet media one
74
3K
6K
9
517
1K
@x0rz
x0rz
7 years
what? 🤔😂
Tweet media one
Tweet media two
47
645
1K
@x0rz
x0rz
6 years
CoffeeMiner: Hacking WiFi to inject cryptocurrency miner to HTML requests #WiFi #MITM #cryptominner
11
544
1K
@x0rz
x0rz
5 years
Dear follower, I appreciate you reading my tweets. Just wanted to give you my appreciation. Always glad to hear my (re)tweets can help you. Good vibes in this community, share knowledge when you can and don’t feel stupid for asking questions 👌
37
69
1K
@x0rz
x0rz
6 years
Hospital security: unsupervised & unlocked computers sitting in an open hallway. Screens showed names + medical data of patients... yuck 😷
Tweet media one
Tweet media two
67
419
1K
@x0rz
x0rz
6 years
Adblocking saves lives
18
470
1K
@x0rz
x0rz
6 years
Amazingly, this book written in 1987 covers all the core concepts of modern #DFIR : network monitoring, traps, honeypots, 0days & espionage. Nothing has fundamentally changed since, except the complexity of it all. Great read in you’re working in the field.
Tweet media one
44
318
1K
@x0rz
x0rz
4 years
What using IRC feels like these days
Tweet media one
30
146
989
@x0rz
x0rz
5 years
Building an interactive map of cameras from Shodan #Shodan #OSINT
Tweet media one
19
434
987
@x0rz
x0rz
5 years
"No logs VPN"
@hn_frontpage
HN Front Page
5 years
FBI arrests PureVPN user with log data that was said to not exist L: C:
16
205
330
31
470
958
@x0rz
x0rz
7 years
Emoji in URLs are probably a bad idea... probably: 🤔 #phishing #unicode #emoji
Tweet media one
35
1K
967
@x0rz
x0rz
6 years
"Facebook announces new dating feature"
Tweet media one
19
262
924
@x0rz
x0rz
5 years
Guys, I made it! 😘 ⁦ @thugcrowd
Tweet media one
69
64
953
@x0rz
x0rz
6 years
Tweet media one
7
285
925
@x0rz
x0rz
5 years
If this isn’t cyberpunk I don’t know what is
@tomiogeron
Tomio Geron
5 years
Pretty sure I’ve read this plot line in sci-fi
Tweet media one
18
1K
3K
12
335
902
@x0rz
x0rz
7 years
Some infosec stock pics are just... I don’t know man 🤷‍♂️
Tweet media one
33
228
893
@x0rz
x0rz
2 years
When you open Wireshark to see what’s up on your LAN
@SwiftOnSecurity
SwiftOnSecurity
2 years
Caption this
237
118
615
13
135
916
@x0rz
x0rz
6 years
Someone just burned two 0days because some idiot uploaded the PoC that pop a calc.exe on VirusTotal: priceless 😂💸
Tweet media one
22
366
904
@x0rz
x0rz
3 years
The Internet is just a DARPA experiment that got way out of hand
19
165
903
@x0rz
x0rz
6 years
Windows 7 Meltdown patch opened up a new vulnerability (on Win7 & Win Serv 2008): arbitrary memory read & write 😱 #windows #vulnerability
Tweet media one
14
743
879
@x0rz
x0rz
6 years
What the fuck did I just read 🤦‍♂️
Tweet media one
93
264
879
@x0rz
x0rz
5 years
Infinite money trick: 1) Buy 0day RCE from Zerodium 2) Hack into Zerodium IT systems with that RCE and get all other 0days for free 3) Sell them to highest bidder 4) Go back to step 1 with another vuln vendor
24
224
873
@x0rz
x0rz
7 years
Shodan now live tracking ships via VSAT antennas exposing web services 🤦‍♂️ #OSINT #shodan
Tweet media one
Tweet media two
Tweet media three
23
757
843
@x0rz
x0rz
3 years
New rule: everything is compromised until proven otherwise.
36
171
851
@x0rz
x0rz
7 years
Getting command execution on MSWord without any Macros 😈 #windows #maldoc #malware
Tweet media one
Tweet media two
15
569
836
@x0rz
x0rz
3 years
If Elon Musk and Jeff Bezos could start investing money into what we already have (ie. planet earth) instead of super-rich-dudes mars projects, that would be cool.
59
132
827
@x0rz
x0rz
6 years
So FYI, "redteam" doesn't mean "above the laws". A CEO can't allow someone else to hack into your personal email address to prove a point. This is plain wrong, unethical and privacy invasive. IMO, company email address is fair game. Personal email: nope! 🙅‍♂️
Tweet media one
74
270
830
@x0rz
x0rz
7 years
Recovering a blurred QR Code to access a #bitcoin wallet private key 👌 #crypto #cryptocurrency #fail
Tweet media one
Tweet media two
18
521
804
@x0rz
x0rz
9 months
It's totally crazy, after all these years, simply detecting `whoami' activity during non-working hours can spot the most sophisticated APT.
@memechaotic
chaotic memes
9 months
What is he saying?
4K
1K
27K
10
115
838
@x0rz
x0rz
3 years
👀
Tweet media one
11
218
816
@x0rz
x0rz
6 years
Could you imagine the cable management needed to use these... 😱 yep, that’s a sliced phone trunk cable
Tweet media one
47
253
798
@x0rz
x0rz
5 years
20 years behind the competition, but it’s really cool to see this happening! ;)
@TheHackersNews
The Hacker News
5 years
Microsoft today unveils "Windows Terminal" — a new, powerful, and productive terminal application for command-line lovers.
66
960
2K
19
199
799
@x0rz
x0rz
4 years
So many new domains with (corona|covid|virus), probably something to look out for #phishing attempts. Stay safe!
Tweet media one
29
450
800
@x0rz
x0rz
5 years
For those interested about propaganda. Let me introduce you to this story from WW2 and why what’s currently happening (on a small scale) is not something new, or even remotely state-of-the-art. Thread (1/17) 👇 #psyops #WW2
Tweet media one
15
459
778
@x0rz
x0rz
7 years
Spoofing e-mail is easy, here is how to break DKIM signature #phishing #DKIM
Tweet media one
Tweet media two
7
544
802
@x0rz
x0rz
6 years
Wireless rubber ducky ಠ‿ಠ
5
260
789
@x0rz
x0rz
7 years
This has to stop.
Tweet media one
36
322
742
@x0rz
x0rz
6 years
The ssh-decorator package from Python pip had an obvious backdoor (sending ip+login+password to ssh-decorate[.]cf in cleartext HTTP)
Tweet media one
9
608
759
@x0rz
x0rz
5 years
That's why I use the good old KeePass. No browser extension. Not an online password manager either. Just an encrypted file that stores my passwords with a simple GUI to manage them. It covers my threat model and I don't need more. Less is more 👌
@ProjectZeroBugs
Project Zero Bugs
5 years
lastpass: bypassing do_popupregister() leaks credentials from previous site
7
306
637
54
190
765
@x0rz
x0rz
6 years
The one bug to bring them all down - CVE-2018-1000136 (including, but not limited to: Signal Desktop, Slack, Discord, Atom, Visual Studio Code, Github Desktop) #electron #vulnerability
13
567
761
@x0rz
x0rz
6 years
When I open my DMs (and yes it's a real DM I got, except for the mixed case) 😩
Tweet media one
30
127
746
@x0rz
x0rz
4 years
Everytime I read "POS malware" I can only think of "piece of shit malware" (when it really means Point-of-sale malware). Am I the only one? 🤣
56
48
743
@x0rz
x0rz
6 years
Microsoft manually patching a binary, did they lost the source code? 🤔 #legacy #vulnerability
Tweet media one
21
461
749
@x0rz
x0rz
5 years
That’s not how it works
@CNN
CNN
5 years
$400,000 was found in this man's washing machine. He was arrested on suspicion of money laundering.
Tweet media one
581
5K
17K
25
200
720
@x0rz
x0rz
6 years
Nice trick, if you don't have netcat on a box, you can use `whois' to upload/download arbitrary file to a remote server 🤩
Tweet media one
8
306
741
@x0rz
x0rz
5 years
Fuck off
@TheEconomist
The Economist
5 years
A technology company has created an electronic badge that can monitor workers’ conversations, posture and even time spent in the toilet. This type of office surveillance raises concerns about workers’ rights and privacy
220
785
834
51
204
699
@x0rz
x0rz
6 years
Look at suspect #1 distracting the employee behind the cash register while #2 is covering the POS machine, these aren't amateurs #skimmer #carding #cybercrime
18
414
683
@x0rz
x0rz
6 years
Source code repositories (like Git) are most definitely targets of choice. Here is a way to hide arbitrary code (could be some bugdoor) content from Git logs/diff 👏 #SupplyChainAttack
7
389
698
@x0rz
x0rz
6 years
Always leave one or two secret directories in robots.txt #IAmEnlighten
Tweet media one
Tweet media two
16
208
692
@x0rz
x0rz
11 months
Tweet media one
@vxunderground
vx-underground
11 months
Here is the full video of the Polish CBZC (Central Bureau for Combating Cybercrime) arresting individuals associated with DDoS as a Service providers. Viewer discretion is advised. The levels of dorkiness are off of the charts.
42
98
523
11
79
689
@x0rz
x0rz
7 years
Once you see it
Tweet media one
25
286
687
@x0rz
x0rz
5 years
Typical illustration of how bad the internet is centralized nowadays: Cloudflare is down, most websites & services being disrupted by this.
28
245
670
@x0rz
x0rz
5 years
Facebook, Snapchat and other US companies have been doing so for years. Pretty sure TikTok (Chinese company) has been gathering tons of data as well, and millions of Americans have probably used it too. Users deserve privacy no matter the origin of the company.
@SenSchumer
Chuck Schumer
5 years
BIG: Share if you used #FaceApp : The @FBI & @FTC must look into the national security & privacy risks now Because millions of Americans have used it It’s owned by a Russia-based company And users are required to provide full, irrevocable access to their personal photos & data
Tweet media one
Tweet media two
568
3K
3K
16
330
679
@x0rz
x0rz
5 years
Delivering your custom payload to the target
8
177
680