mosesrenegade
@mosesrenegade.bsky.social
📤 380
📥 76
📝 45
Hackerman. You can find out about me here.
https://linktr.ee/mosesrenegade
I was talking to a few students over the past few weeks, and it suddenly dawned on me. The SEC588 Cloud Pen Testing course has almost no reason not to come in person. Why is that? All students get the 4-month OnDemand Bundle with Lab access included with all classes!
3 months ago
1
0
0
Happy America Day for 2025.
8 months ago
0
1
0
I spend the last few days on a new project. Get IPv6 running in my homelab. The dual horned nature of my house made me hesitant. I learned a ton along the way. Probably will do a video or blog post soon.
#IPv6
#Homelab
9 months ago
0
3
0
I am speaking at the South Florida ISSA Meeting Tonight. It's in the same venue as the HackMiami conference. If you are in the area and want to hang out, here are the details:
www.meetup.com/south...
loading . . .
May SFISSA Meeting @ HackMiami XII, Thu, May 15, 2025, 6:00 PM | Meetup
We’re excited to be hosting this month’s meeting at the HackMiami Conference, one of South Florida’s most anticipated cybersecurity events. Location: Marenas Beach Resort
https://www.meetup.com/south-florida-issa-chapter/events/307512862/?eventOrigin=home_page_upcoming_events%24all&_gl=1*hs0yp*_up*MQ..*_ga*MTI4OTI1OTgxMS4xNzQ1NTI5MjEx*_ga_NP82XMKW0P*czE3NDczMjM0OTAkbzMkZzAkdDE3NDczMjM0OTAkajYwJGwwJGgw
9 months ago
0
0
0
I have not been active on social media for the last 45 days. My ability to share sharply declined. After some deep thinking and professional life changes, I can now share more freely—such a burden lifted from my shoulders. Videos are coming soon.
10 months ago
0
0
0
If you have ever taken #SEC588, I have always said that SAML needs to go away. Here is a nasty bug in a library where you can bypass it altogether mostly:
workos.com/blog/samlstorm Just s
#SEC588
nd a signed request, and you will be good to go.
loading . . .
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries — WorkOS
Any service using xml-crypto or a Node.js SAML implementation using it, should update immediately to the latest version. WorkOS customers are safe and were not impacted.
https://workos.com/blog/samlstorm
11 months ago
0
1
0
If you see the following header in your weblogs and your running next.js ... well... x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware
#CVE-2025-29927
11 months ago
0
0
0
I just wanted to go on record in saying if the internet ever went dark, it is truly when this website is gone....
www.zombo.com
11 months ago
0
1
0
This is an excellent writeup by the Objective See folks. I had to ensure I was still reading about an exploit halfway through the beginning because the build-up was so good. If MacOS and Exploiting MacOS is your thing, this is a great read:
bit.ly/4bTsGnZ
loading . . .
Leaking Passwords
...and more on macOS
https://bit.ly/4bTsGnZ
11 months ago
0
1
0
I'll more than likely discuss this at some point in a video. This Apache Tomcat bug is pretty bad. The POC is dead simple and it will probably be easy to work around firewalls. Patch!
www.darkreading.com/...
1/n
loading . . .
Apache Tomcat RCE Vulnerability Under Fire With Exploit
The researchers who discovered the initial assault warned that the simple, staged attack is just the beginning for advanced exploit sequences that will test cyber defenses in new and more difficult ways.
https://www.darkreading.com/vulnerabilities-threats/apache-tomcat-rce-vulnerability-exploit
11 months ago
2
1
2
Let me be crystal clear: the person who wrote the @watchtowrcyber blog is correct about deserialization gadgets. The video gives some thoughts, but I wanted to add context. Amazing work from @sinsinology 1/n
youtu.be/mJTo_YGwYzY
loading . . .
Infosec Drama of the Week?
I want to be clear that in the video, I'm talking about this post:https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in...
https://youtu.be/mJTo_YGwYzY
11 months ago
1
0
0
Is that Tomcat bug a non-issue? I'm hesitant to say so, primarily because of the many horror show bugs I've seen in Tomcat servlets in the past. Do I suspect there will be more issues on the internal networks? Yes. Comment Below Video:
youtu.be/Du4d7Q4R51Q
11 months ago
0
0
0
The jc-action/changed-files attack, was it new and novel? If you look at the gist of the python memdump.py script, you may have noticed that this was just a copy of an existing set of research studies from pwnhub and others—link in the video's description.
youtu.be/lqPoWd7CbTE
11 months ago
0
1
1
This is super interesting. An attacker gained access to a popular "plug-in" (the best way I could describe it) to your CI/CD pipeline in a Github Action that would do change file detection in your runs.
www.stepsecurity.io/...
1/n
loading . . .
Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity
tj-actions/changed-files
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
11 months ago
2
1
1
The other day, one of my coworkers asked me a question, and it was around: what do you currently recommend for C2 in a Red Team Engagement? Now, this question comes up a ton. In practice, we have been using Cloudflare because it just "works," but what if that no longer works?
11 months ago
1
0
0
On the road, so I recorded this over the week. Bug fixes for last week.
bit.ly/4kNdqgk
loading . . .
Bug Fixes for the Week of March 2nd
Let's talk about what I got wrong; in this case, it was Amnesty International's Cellebrite article. I wanted to clarify all the things that I got wrong. Well...
https://youtu.be/qN1PuwcZusA
12 months ago
0
0
0
Do you all think Manus AI Is a threat. I thought I'd give some folks a fun one for a video update:
bit.ly/41ylBEo
loading . . .
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
https://youtu.be/qCyic1-aWMc
12 months ago
0
0
0
Healthcare IT is a total mess. Microsoft is injecting some funding in it:
bit.ly/4i4ts3I
loading . . .
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
https://youtu.be/XRggU2ukQLQ
12 months ago
0
0
0
Everyone is alarmed by a "Webcam" used to deploy ransomware as a nothing-burger. The article should highlight that ransomware actors are not just automating the attack but actively looking into a network. If you have a vulnerable non-windows device, it will be used.
12 months ago
0
0
0
You want to execute malware in a sandboxed environment. You want to do this self-hosted or in the cloud in your environment. What do you choose? (Yes, I know that online analysis tools exist). Comment Below
#security
#cybersecurity
#onlinesafety
#privacy
#technology
12 months ago
0
1
1
Quantum Curious? Today's topic is Post Quantum Cryptography, more or less. #security #cybersecurity #onlinesafety #privacy #technology #crypto
bit.ly/3XuoNja
loading . . .
Post Quantum Cryptography
What happens after PQC?
https://youtu.be/_xxjZhjnloU
12 months ago
0
1
1
I don't yet know the full implications of this, but being able to "patch" your Microcode such that, idk, XOR compares always return true for specific functions would be bad.
bit.ly/3F4V3TP
loading . . .
Blog: Zen and the Art of Microcode Hacking
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking
12 months ago
0
0
0
Yesterday on a Podcast Interview I did with the ktrlpanel I ended it with a butchered quick explaination of Shors Algorithm and Quantum Computing. For those curious the idea is this. Quantum Computing should be able to, using a QFT, factorize prime numbers quickly.
12 months ago
1
1
0
I'm posting this here while experimenting with different media. The focus, currently, is on short-form videos on a different Cyber Security Topic (
bit.ly/YTMosesFrostShow). I am
however going to expand that at some point.
loading . . .
The Moses Frost Show
Share your videos with friends, family, and the world
https://bit.ly/YTMosesFrostShow
12 months ago
0
1
0
Mozilla Foundation is changing its Terms of Service and has decided to remove its promise never to sell your data, I.E., they can sell it. This has people in a tizzy; what alternative web browsers do you recommend? Comment Below!
bit.ly/3QEAekE
12 months ago
0
0
0
Can multiple LLMs working in Tandem evaluate CTF Challenges? Some interesting research coming out of NYU.
arxiv.org/html/2406....
12 months ago
1
1
0
reposted by
mosesrenegade
netbiosX
about 1 year ago
loading . . .
Attacking an EDR - Part 1
For some fun and a fair bit of profit
https://her0ness.github.io/2023-08-03-c2-Attacking-an-EDR-Part-1/
0
1
2
reposted by
mosesrenegade
netbiosX
about 1 year ago
loading . . .
GitHub - AI-Voodoo/Red_Reaper_v2: Stage 1: Sensitive Email/Chat Classification for Adversary Agent Emulation (espionage). This project is meant to extend Red Reaper v1 which was presented at RSA San F...
Stage 1: Sensitive Email/Chat Classification for Adversary Agent Emulation (espionage). This project is meant to extend Red Reaper v1 which was presented at RSA San Francisco 2024. - AI-Voodoo/Red_...
https://github.com/AI-Voodoo/Red_Reaper_v2
0
3
1
reposted by
mosesrenegade
Catalin Cimpanu
about 1 year ago
Daniel Grzelak has released Awseye, a so-called Shodan for AWS, an OSINT and reconnaissance service that tracks and analyzes publicly accessible AWS data
awseye.com
1
73
29
reposted by
mosesrenegade
netbiosX
about 1 year ago
Modifying Impacket to avoid detection
loading . . .
Notion – The all-in-one workspace for your notes, tasks, wikis, and databases.
A new tool that blends your everyday work apps into one. It's the all-in-one workspace for you and your team
https://n7wera.notion.site/Modifing-Impacket-to-avoid-detection-4df93e4bdbdc439988d79864774af569
1
10
5
reposted by
mosesrenegade
Nicolas Grégoire
about 1 year ago
I’ve to say that I’m impressed by how
@xbow.com
managed to identify this SSRF vulnerability (and bypass a MIME filter on its way) 🤖
loading . . .
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
https://xbow.com/blog/xbow-2fauth-ssrf/
2
17
14
reposted by
mosesrenegade
netbiosX
about 1 year ago
loading . . .
GitHub - matro7sh/BypassAV: This map lists the essential techniques to bypass anti-virus and EDR
This map lists the essential techniques to bypass anti-virus and EDR - matro7sh/BypassAV
https://github.com/matro7sh/BypassAV
0
6
2
reposted by
mosesrenegade
netbiosX
about 1 year ago
loading . . .
GitHub - matro7sh/myph: shellcode loader for your evasion needs
shellcode loader for your evasion needs. Contribute to matro7sh/myph development by creating an account on GitHub.
https://github.com/matro7sh/myph
0
5
4
Makes sense… but not what I expected…
aws.plainenglish.io/you-have-mis...
loading . . .
You have Misunderstood AWS Availability Zones
What You Knew About AWS Availability Zones Is Only Half the Story
https://aws.plainenglish.io/you-have-misunderstood-aws-availability-zones-47cdea0a168a
over 1 year ago
0
0
0
chrome://serviceworker-internals/ That is all...
over 1 year ago
0
0
0
reposted by
mosesrenegade
Laila Bougria
over 1 year ago
The Azure Service Bus emulator is finally here! 🎉🎉🎉 This will make local development and local testing so much easier and also cheaper!👌🏼 But remember, as with any emulator, you still want to test against the real service as well 😅
add a skeleton here at some point
1
14
7
reposted by
mosesrenegade
Patrick Gray
over 1 year ago
Credit to
@campuscodi.risky.biz
with surfacing this one... and yeah... it didn't get much coverage outside of
risky.biz
add a skeleton here at some point
0
12
3
reposted by
mosesrenegade
Jason Scott
over 1 year ago
Emulation in the browser is BACK at
@archive.org
- 250,000 programs playable with a click. But let's get you to our #1 title:
archive.org/details/msdo...
loading . . .
Oregon Trail, The : MECC : Free Borrow & Streaming : Internet Archive
Important Technical Note:Thank you for enjoying the Oregon Trail! If your browser gives the error FAILED TO CONFIGURE EMULATOR upload loading, try opening...
https://archive.org/details/msdos_Oregon_Trail_The_1990
15
355
89
reposted by
mosesrenegade
Chris DiSalle
over 1 year ago
#Linux
lacks a resource like the Windows Master File Table ($MFT). I've developed this
#Velociraptor
artifact to collect metadata from files and folders recursively in selected paths to create a bodyfile. This may bring an MFT-like feel to filesystem analysis.
#dfir
github.com/chrisdfir/Ve...
loading . . .
https://github.com/chrisdfir/VelociraptorArtifacts/blob/main/Linux.Forensics.BodyFile.yaml
3
31
14
reposted by
mosesrenegade
Mark Morowczynski
over 1 year ago
If you wanted to hear about the sessions the Azure Security podcast talks through it with Michael Howard & Nic Fillingham.
azuresecuritypodcast.azurewebsites.net
.
add a skeleton here at some point
0
11
2
reposted by
mosesrenegade
Mark Morowczynski
over 1 year ago
First, if you aren't familiar with oAuth application consent, we did a few sessions on this topic a few years ago. You can watch the one
@baileybercik.bsky.social
and I did
www.youtube.com/watch?v=oqb3...
. Start by checking what your current application permissions are. /2
loading . . .
How attackers can use applications for sustained persistence and how to find it - September 2021
YouTube video by Microsoft Community Learning
https://www.youtube.com/watch?v=oqb3n7UUgpk
1
2
3
reposted by
mosesrenegade
Merill Fernando 💚
over 1 year ago
Please like and repost to let everyone know. Don't forget to add your profiles to
bluesky.ms
loading . . .
Search bluesky.ms
Use this page to search for the Microsoft community on bluesky.ms.
https://bluesky.ms
5
11
6
reposted by
mosesrenegade
Csaba Fitzl
over 1 year ago
🍎🐛🎙️Following my
#poc2024
talk we are releasing a blogpost series at Kandji, detailing the vulnerabilities of diskarbitrationd and storagekitd I discussed in my "Apple Disk-O Party" talk. First part is out, and covers CVE-2024-44175.
www.kandji.io/blog/macos-a...
loading . . .
Uncovering Apple Vulnerabilities: The diskarbitrationd and storagekitd Audit Story Part 1
Kandji's Threat Research team performed an audit on the macOS diskarbitrationd & storagekitd system daemons, uncovering several (now fixed) vulnerabilities
https://www.kandji.io/blog/macos-audit-story-part1
0
0
1
reposted by
mosesrenegade
Merill Fernando 💚
over 1 year ago
🦋 Introducing
bluesky.ms
👏 = A crowdsourced database of anyone and everyone in the Microsoft community on Bluesky. 👉 Add yourself and anyone you know today 👈 🫂 All are welcome. This is my v1, I'll add options to directly follow from the site itself but first 👇 LET'S FILL IT UP! 🙏
loading . . .
Search bluesky.ms
Use this page to search for the Microsoft community on bluesky.ms.
https://bluesky.ms/
58
606
301
reposted by
mosesrenegade
Tanya Janca | SheHacksPurple
over 2 years ago
I've been nominated for Mentor of the year for the SANS Difference Makers Awards. Please vote for me? 🙏
sans.org/u/1sVU
1
14
4
Cross posting is a challenge and maintaining so many disparate feeds suck. Anyone have any good ideas for managing the deluge of platforms?
over 2 years ago
1
0
0
cat << EOF > post
over 2 years ago
1
1
0
you reached the end!!
feeds!
log in