Pepijn
@xstplanet
Followers
80
Following
301
Media
12
Statuses
142
hacker at @hadriansecurity. volunteer at @divdnl. developer. foss lover. getting rid of nano since 2010
Netherlands
Joined October 2021
https://t.co/41EtihxSNx It's been well over 20 days to say a single f... word on the hackerone report I have with them. @Hacker0x01, @TMobile when can I publicly disclose?
wired.com
The mobile operator just suffered at least its fifth data breach since 2018, despite promising to spend a fortune shoring up its systems.
0
0
1
Zero to Hero: The process of reversing and exploiting complex vulnerabilities!
2
116
440
Here is why NetNTLMv1 should be disabled in prod networks ASAP. Besides cracking the hash back to NTLM (and then forging Silver Tickets) is straightforward, there is also a lesser known but immediate relay attack path by removing the MIC and doing RBCD abuse. Demo in screenshots.
26
342
1K
We are excited to announce our friend @corg_e will be the new manager of vx-underground merchandise. In the following days (or weeks?) we will have a new e-commerce domain. tl;dr kawaii merchandise, or something
21
23
363
I have like 50 RCE bugs on this BB target. But EVERY time I have submitted a bug to this company it's a dup. So I'm conditioned to not submit them. I think bug bounties are creating some type of bystander effect...
4
3
29
January 22, 2023 — AS21859 — ZEN-ECN [US] — leaked 1348 prefixes creating 1349 conflicts with 44 ASNs in 8 countries. Propagation: 100%. Duration: 1 hour 20 minutes.
0
6
19
When I see TikTok being used as C2, this is how I know I’m getting too old for this shit
11
43
425
It’s like I always say: “These sequence diagrams aren’t going to animate themselves!” CVE-2021-1732 (win32k kernel type confusion -> OOB-R/W) (Based on https://t.co/EmpEzw3nyq)
3
34
212
SANS (free) Workshop – NTLM Relaying 101: How Internal Pentesters Compromise Domains by @Jean_Maes_1994 This workshop requires a large local LAB (40+ GB zip file download). https://t.co/oN31HXf359
#infosec #pentesting #sans
1
99
266
New blog post on a recent collab with @UsmanMansha420 where I bypassed Akamai WAF to get RCE on a Java application with Spring EL injection. Spent some time writing about the process of constructing the custom payload. Hope you enjoy!
pmnh.site
Writeup of a collaborated bug on Bugcrowd where I was able to bypass Akamai WAF to exploit RCE on Spring Boot error page using SpEL
13
141
379
Fortinet heeft een kwetsbaarheid verholpen in FortiOS SSL-VPN. De kans/schade van de kwetsbaarheid met kenmerk CVE-2022-42475 beoordelen wij als high/high. Er is reeds beperkt actief misbruik waargenomen. Lees het beveiligingsadvies hier:
1
11
8
Often people read write ups and because they don’t understand them they assume that the writer must be very fucking smart, maybe it just wasn’t written well. On the flip side when something is written well and people understand, they fail to recognise the value of the author.
16
27
326
Voorstel, als een overheidsorganisatie zijn ligging niet op orde heeft. Stil leggen, tot dat het wel in orde is. https://t.co/XsqsOChJVL
security.nl
Dat systemen van de Belastingdienst de zoekopdrachten van personeel niet kunnen loggen hindert onderzoek naar corruptie, zo ...
1
1
2