Max @_mxms
rpisec Cascadia Joined December 2010-
Tweets10K
-
Followers2K
-
Following412
-
Likes6K
Fortunately this http.sys bug was an internal find by our team. This one thanks to @_mxms, @fzzyhd1 and everyone who contributes to our tooling and automation.
Do you want to gamble on fat bears for charity? #FatBear2020 is here. Get your brackets in before the 30th! Details here: gist.github.com/yrp604/088bd20…
These, combined with recent @WIRED reporting on Chinese espionage campaign Operation Skeleton Key targeting the Taiwan Semiconductor Industry (wired.com/story/chinese-…), suggests possibility of an explosion of new homegrown semiconductor companies in the mainland.
There’s also a format string bug going the opposite direction (when your phones name is %p%p%p...)
There’s also a format string bug going the opposite direction (when your phones name is %p%p%p...) https://t.co/QqEfSRVIot
The second annual infosec fat bear bracket is here. Let’s gamble on some fat bears for charity. Brackets due ASAP. dpaste.de/OZ1U
It's not obvious from the advisory, but the same code runs in RDP client. The issues have been patched in both. This would have allowed a malicious server to compromise a client without any alerting behavior, or a MitM attack with a warning confirmation.
August Patch Tuesday includes fixes for our internal finds in RDP, including RCE and remote info disclosure, and affecting Win 10 latest. The team successfully built a full exploit chain using some of these, so it's likely someone else will as well. Patch and enable NLA.
August Patch Tuesday includes fixes for our internal finds in RDP, including RCE and remote info disclosure, and affecting Win 10 latest. The team successfully built a full exploit chain using some of these, so it's likely someone else will as well. Patch and enable NLA.
Did anyone find / exploit the serialization bugs in TelOoOgram during DEF CON CTF?
We've built tools for fuzzing based on emulation of a process snapshot captured via minidump. We're considering open sourcing the tool, and I'm curious about interest level from the rest of the world. (1/3)
#RealWorldCTF2018 RPISEC has successfully pwned the Safari browser and spawned a calculator on the victim host at their first attampt during the demostration!
Vectorized Emulation: Hardware accelerated taint tracking at 2 trillion instructions per second gamozolabs.github.io/fuzzing/2018/1…
After Trump was elected, I felt unsafe. I thought that electing a man as president who has assaulted women would normalize that behavior, make assault seem inconsequential to a perpetrator. Right now, I feel worse. It’s normalized, all right.
So what’re we supposed to be doing about the ongoing calls from numbers in our area code? It’s old...
Came in 1st in CSAW 2018 Quals! Kudos to all who played, it was a tough competition this year! See y'all at finals!
Came in 1st in CSAW 2018 Quals! Kudos to all who played, it was a tough competition this year! See y'all at finals!
Honored to be speaking at the Forbes 30 under 30 cyber security panel in Boston this October! #under30summit
Control my living room lightbulb: lights.hawkhe.art
My first technical analysis piece at @RecordedFuture! TL;DR: 1) Chinese backdoor with a daily 180 second entry-window found in Tibet 2) Qinghua University infrastructure, connected to backdoor, scanning #BeltandRoad partners/ US gov entities denouncing #USChinaTradeWar.
My first technical analysis piece at @RecordedFuture! TL;DR: 1) Chinese backdoor with a daily 180 second entry-window found in Tibet 2) Qinghua University infrastructure, connected to backdoor, scanning #BeltandRoad partners/ US gov entities denouncing #USChinaTradeWar.
@oooverflow @defcon I think the scoreboard has been sorted backwards
Excited we got 10th at #defconctf. Thanks to @oooverflow for hosting. Congrats to all the other teams, it was a hard fought battle. See you all next year!

Brendan Dolan-Gavitt @moyix
30K Followers 6K Following Building offsec agents: https://t.co/G9EtnC2Gl3 PGP https://t.co/3WXr0RfRkv
LiveOverflow 🔴 @LiveOverflow
155K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
Perri Adams @perribus
7K Followers 993 Following @Dartmouth ISTS Fellow & @SAISHopkins Adjunct Prof., inter alia. Former @DARPA, @DEFCON CTF, etc. @DistrictCon, @hexacon_fr, @LABScon_io is CFP Review Boards
Axel Souchet @0vercl0k
13K Followers 544 Following ¯\_(ツ)_/¯, blogging on https://t.co/36oOc8Mgha and posting codes on https://t.co/P83Oen94Rc.
Zion Leonahenahe Basq... @mahal0z
2K Followers 268 Following Native Hawaiian Hacker | Prev Co-captain of @Shellphish | PhD Student in Comp Sci @ASU l Decompiler Research | Mastodon: @[email protected]
Richard Johnson @richinseattle
18K Followers 3K Following Computer Security, Reverse Engineering, and Fuzzing; Training & Publications @ https://t.co/mloVP6rPB7; hacking the planet since 1995; Undercurrents BOFH
Conrad Kramer @conradev
11K Followers 2K Following Co-Founder @SoftwareAppsInc, previously @BelferCenter, Shortcuts @Apple. you should copy that floppy
Ubreakaw @Ubreakaw32079
26 Followers 1K Following
Jarod @stewartjarod
526 Followers 2K Following Creating Booking Software for Adventures 🏕️📅 Lilikoi @ https://t.co/pbjX0tX0Ax
Alex Rebert @ayper
523 Followers 665 Following Security @ Google. Previously co-founder of @ForAllSecure. Opinions here are my own. @[email protected]
Adriaan Jacobs @a3_jacobs
69 Followers 115 Following Systems security researcher and PhD student at DistriNet, KU Leuven
Sven @SvenHoeper
2 Followers 1K Following
WATER_PAKMEN @Babimuu12
3 Followers 47 Following
Leo @leolin113
55 Followers 2K Following
0x00ne @0x00l62120
22 Followers 218 Following For computer repairs dm we talk || data science and analytics
tejas krishna @tejaskrshna
57 Followers 2K Following
Kumar Anshuman @Anshuman9187
4 Followers 447 Following
Nicolas Vivet @nizox
234 Followers 558 Following Infosec enthusiast, Software Engineer at @DatadogHQ, former @SqreenIO
yeshuibo @yeshuibo
106 Followers 6K Following
Gerrard Tai @gerrard_tai
183 Followers 522 Following ex csgo pro for team "Counter-Terrorists" | pwn with @seetf_sg
vierito5 @vierito5
2K Followers 4K Following Gneeeeeeeeeeinfoseeeeeeeeeeeec. Broken villain, former something.
Bùi Quang Hiếu �... @tykawaii98
699 Followers 631 Following MSRC MVR 2021 - Researcher @crowdfense - Tweets are my own
David ⚡⚛⚡ @__db... @dbph
915 Followers 3K Following /me yet another random hacker. (@atlassian). Journalist as defined by the Evidence Act 1995. Subject to gdpr as an EU citizen.
Michael Paktinat @michaelpaktinat
340 Followers 5K Following Data/Systems Analyst/Engineer training you on computer things.
hawkedota @hawkedota
53 Followers 1K Following
`Ivan @Ivanlef0u
11K Followers 3K Following
muricula @muricula
12 Followers 296 Following
Bikash Dash @Memport
173 Followers 2K Following गते शोको न कर्तव्यो भविष्यं नैव चिंतयेत्। वर्तमानेन कालेन वर्तयंति विचक्षणाः॥ Vuln Research♧Exploitation♧Fuzzing♧PenTest
Reggae77x @reggae77x
3 Followers 144 Following
masecu @masecu2
0 Followers 249 Following
melina @melina_almasi
314 Followers 1K Following
S4mbl4ck S4mbl4ck @s4mbl4ck
9 Followers 378 Following
EG888 @EG_888
35 Followers 668 Following I'am retweting a lot of pixel art wich (I think) looks good
WSA @jhg93887193
4 Followers 129 Following
Oldboy @oldboy_sonnt
57 Followers 940 Following A boy with old face. Women hate that. I'm Jisoo I'm OK
amigo go @goamiygo
2 Followers 337 Following
0r3ak @0xTback
84 Followers 961 Following
Meastro @Kazaniom
0 Followers 180 Following
fluffy banana @_fluffy_banana_
5 Followers 444 Following Interested in coffee, threat intelligence, threat hunting, malware analysis, digital forensics and incident response.
Shameer @Shameer93150925
17 Followers 1K Following
Alex | RWA.xyz @aeksco
575 Followers 2K Following building @rwa_xyz + @codotype | relentlessly curious and creative
Brendan Dolan-Gavitt @moyix
30K Followers 6K Following Building offsec agents: https://t.co/G9EtnC2Gl3 PGP https://t.co/3WXr0RfRkv
Halvar Flake @halvarflake
44K Followers 3K Following Choose disfavour where obedience does not bring honour. I do math. And was once asked by R. Morris Sr. : "For whom?" @[email protected]
Project Zero Bugs @ProjectZeroBugs
35K Followers 0 Following A bot that posts the latest blog posts and disclosures from Google's Project Zero
mdowd @mdowd
32K Followers 747 Following Internet Hacker. Founder of @vigilant_labs. Previously, co-founder of Azimuth Security (now L3Harris Trenchant)
Jordan Wiens @psifertex
6K Followers 1K Following Worst developer among many good ones making https://t.co/XCCx7ECxEH Posting over on https://t.co/BdeDxso5n7 as well.
Adam Doupé @adamdoupe
5K Followers 1K Following Former DEF CON CTF organizer. Associate Professor @ASU. Web, system, and network security. Loves CTFs. Hacks w/ @shellphish. Hosts @ctfradiooo. Open DMs.
David Weston (DWIZZZL... @dwizzzleMSFT
25K Followers 2K Following Corporate Vice President, OS Security and Enterprise @Microsoft
lcamtuf @lcamtuf
38K Followers 498 Following Substack: https://t.co/yFvmNisGW3 Homepage: https://t.co/iFAXZxCO5H
Stefan Esser @i0n1c
115K Followers 464 Following CEO of @Antid0tecom (former CEO of @SektionEins) (contact: [email protected])
Perri Adams @perribus
7K Followers 993 Following @Dartmouth ISTS Fellow & @SAISHopkins Adjunct Prof., inter alia. Former @DARPA, @DEFCON CTF, etc. @DistrictCon, @hexacon_fr, @LABScon_io is CFP Review Boards
Axel Souchet @0vercl0k
13K Followers 544 Following ¯\_(ツ)_/¯, blogging on https://t.co/36oOc8Mgha and posting codes on https://t.co/P83Oen94Rc.
Zion Leonahenahe Basq... @mahal0z
2K Followers 268 Following Native Hawaiian Hacker | Prev Co-captain of @Shellphish | PhD Student in Comp Sci @ASU l Decompiler Research | Mastodon: @[email protected]
Tavis Ormandy @taviso
130K Followers 631 Following Vulnerability researcher at Google. This is a personal stream, opinions expressed are mine. I'm also @[email protected]
comex @comex
153K Followers 288 Following Mastodon: @[email protected] / https://t.co/MZ1EDnKsAI | Cohost (inactive): https://t.co/BkMXfegtxe
Conrad Kramer @conradev
11K Followers 2K Following Co-Founder @SoftwareAppsInc, previously @BelferCenter, Shortcuts @Apple. you should copy that floppy
jvoisin @dustriorg
961 Followers 0 Following This account is inactive, use the following instead: - https://t.co/V1HC4hS2oJ - https://t.co/8xth5l1Rn8 - https://t.co/BPuGer3Owz
Michal Melewski @carste1n
3K Followers 343 Following Security Engineer @ Cloudflare, ex-Google ISE, I use bad software and bad machines for the wrong things. My writing: https://t.co/Z7uucr5BYW
Lee Holmes @Lee_Holmes
19K Followers 784 Following Partner Security Architect, Azure Security. PowerShell developer, fanatical hobbyist, and author of the PowerShell Cookbook. @[email protected]
Jonathan Protzenko @_protz_
873 Followers 393 Following Principal Cheese Researcher at Microsoft Research. I tweet about cheese, and occasionally formal verification, cryptography (HACL*/EverCrypt), type systems, etc
Felix Gröbert @fel1x
4K Followers 623 Following Principal Engineer, Product Security Engineering at Google Cloud. Opinions own. Tweets deleted periodically.
Jessica Payne @jepayneMSFT
30K Followers 32 Following Security Person at Microsoft, currently in Windows Defender Security Research. Opinions are my own.
Alison Huffman @ohnonull
283 Followers 634 Following Homebody security gal | , ex-Google, ex-Microsoft , ex-etc... | Speaking for myself likes are not endorsements (I probably just lol'ed)
lukas @dreselli
923 Followers 384 Following CTFs and research in fuzzing/concolic at the UCSB SecLab, co-captain of @shellphish, lead Shellphish's AIxCC team with @cl4sm
Ben Kaiser @benhkaiser
418 Followers 687 Following Working on privacy and AI trust @DuckDuckGo. Previously a researcher @PrincetonCITP, @MITLL, and @RPI.
Dr. Silvia Cristina S... @silvia_stegaru
346 Followers 546 Following 👩🔬 Co-founder @codettero 💼Software Engineer @Adobe 🏷 She/her 💡 Views are my own 🚀
Mateusz Krzywicki @krzywix
2K Followers 807 Following 🐛 bugs and 🤯 exploits (Opinions are my own and not my employer)
max.rss @tekknolagi
2K Followers 895 Following Bread, beans, programming languages; fmr Chief Potato; he/him; cover photo credit xkcd proud owner of https://t.co/kUeNYzHHut https://t.co/q3ainEJ9sW
Jade @jadequery
24 Followers 41 Following Interested in computers and urbanism. Alumnus #RPISEC. she/they 🏳️⚧️
Bader @GH0S1
605 Followers 998 Following Hacking, F1, metal music, cooking, and other postings | CTF with Shellphish, b01lers, and WCSC | posts are my own | https://t.co/exhnuIJfFL gh0s1
Fist0urs @Fist0urs
850 Followers 333 Following Fun passwords/Windows are fun. Tweets are my lol not my employer. I don't understand twitter. I only tweet when I remember about this account. I'm MJ hee/hee
Mike Pizza @michaeljpizza
96 Followers 298 Following
Milo Trujillo @illegaldaydream
2K Followers 1K Following Systems scientist, engineer, activist. Research+practice with decentralized online social groups @ #DDoSecrets @CoMMLabNU @NUnetsi
Kate McInnes @kate_mcinnes
2K Followers 643 Following 🇦🇺 in Bay Area | lover of 🍷, ☀️, 🎵, ✈️, my puppy 🐶 and meeting new people | security engineering manager | views are my own
Alibaba Security Resp... @AsrcSecurity
4K Followers 3K Following Alibaba Security Response Center (ASRC), Point of Contact of all the Alibaba related vulnerabilities, cooperations, and so on.
Benjamin Chetioui - o... @_SIben_
1K Followers 1K Following Moving to Bluesky @[email protected] Working on the XLA GPU compiler @Google 🇨🇭 🇫🇷 PhD in PL from UiB 🇧🇻 Go player Previous @FlatNetworkOrg
Fish Wang @LtFish_
455 Followers 31 Following Reverse binaries sometimes. Love reading decompiled code. Would do anything for flags.
John McMaster @johndmcmaster
15K Followers 169 Following IC reverse engineering, #mtvre, CTO @LabsmoreLLC https://t.co/kTAlHvruKe https://t.co/ICN8cRMGIi
Brijesh Rakholia @rakholiabrijesh
125 Followers 895 Following Security Engineer @Microsoft MORSE Team
Ethan Burger @h_burguesa
200 Followers 1K Following security research, IoT / embedded defense, bug bounties. once wrote a paper on RE'ing hdds and got job offers from Russia & almost sued in the same week.
Mitch Altman @maltman23
7K Followers 0 Following Inventor of TV-B-Gone, Co-founder of Noisebridge (San Francisco hackerspace). Fediverse: @[email protected]
Jeremy Blackthorne @0xJeremy
1K Followers 422 Following Life-long student. Teacher. Marine. Instructor at @BosCybernetics. @RPISEC alumnus. السلام عليكم https://t.co/9GA7q1bmT5
Penny MacNeil @pennymacneil
258 Followers 180 Following
The Diana Initiative @DianaInitiative
10K Followers 2K Following 501c3 nonprofit To create a more inclusive infosec industry-Aug5 24-A diversity-driven conference committed to helping all underrepresented people in infosec
May → Bluesky 🦋 ... @SleepyEntropy
2K Followers 1K Following infosec & aurora chasing now on bluesky