Dmitry Janushkevich @lazyxor
Local privilege escalator. Give me a PoC and I will get you SYSTEM. Joined November 2015-
Tweets114
-
Followers21
-
Following71
-
Likes35
code signing is a pain? just use github.com/kpwn/921csbypa…!
QNX: 99 Problems but a Microkernel ain't one! - Slides & Whitepaper now on Labs. #Troopers labs.mwrinfosecurity.com/publications/9… labs.mwrinfosecurity.com/publications/q…
Just blogged: How your data is collected and commoditised via “free” online services ift.tt/1QWUr0M
Removed one layer of PE protection to find another one below it. How a 50k driver became 600k monster? Quite easy. Moar protection!!
New blog post, we hope it gives you the warm and fuzzies: foxglovesecurity.com/2016/03/15/fuz…
It still triggrrs a bunch of assert failures when installed on a checked build...
Been poking around ex-Aladdin HASP codes. PE protector for drivers: when you absolutely need to hamper debugging BSoDs. :(
I wonder if it is possible for infosec companies to have a separate media account for technical info / announces...
NCC Group Advisory: Win 10 USB Mass Storage driver arb code execution in kernel mode - nccgroup.trust/uk/our-researc… by Andy Davis - CVE-2016-0133
So, someone reported vulns in Flash using character names from Clannad. I approve that. :D
Looks like a #UAF in WMP!AbortSynch is patched in #MS16027 this #PatchTuesday #exploit #RE
"What do you want to be when you grow up?" "An honest, brave, compassionate human being." "No…I mean, how do you want to sell your labor?"
nt!SepCreateToken overallocates memory by sizeof(SID_AND_ATTRIBUTES) * GroupCount. Since NT4.
Made a SeDebugPrivilege escalation exploit, should run on all NT versions >= 5.0. Had some fun while writing it. Learned a thing or two.
Note that this week's SSL DROWN vulnerability in Internet encryption is because of encryption backdoors the US government forced in the 90s.
Hmm, any useful overflow victim objects I could create in paged pools?.. Kernel / executive doesn't seem to provide much.
Hey @digidotcom could you please publish your security contacts somewhere they could be found? Thanks.
When a driver crashes the box *before* you fuzz it (while discovering ioctl values), you know there must be something. :D
#DLLPlanting in Comodo AV Geekbuddy Allows Local Users to Elevate to SYSTEM #LPE #infosec #Exploits #146DaysLater github.com/CyberPoint/adv…

Mohsen Ahmadi @pwnslinger
809 Followers 4K Following Security Researcher, MS CS @ASU, @Shellphish, @riscure, @apple, @cisco; Entrepreneur @plugandplaytc 🇮🇷|🇺🇸
Edwin Webb @EWebb78072
0 Followers 175 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/rwrCNPHmdi
Look at my homepage @CliveJ72102
1 Followers 543 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please conta ct https://t.co/zhBB4SSGPF
Boris Larin @oct0xor
18K Followers 655 Following Former console hacker (PS3/PS4). Hunting in the wild 0-days at Kaspersky GReAT. All tweets are my own.
vlcnge @vlcnge
144 Followers 2K Following
Andrea @rgod777
441 Followers 100 Following Security Researcher, 5# MSRC Most Valuable Security Researcher 2019, multiple times ZDI Gold/Platinum/Diamond
YHZX_2013 @YHZX_2013
306 Followers 1K Following Entry level security engineer of Alibaba Orion Security Lab
.և. @subz3r0___
466 Followers 454 Following Grew up with #Phrack, #SecurityFocus #Packetstormsecurity #Milw0rm #Astalavista. Almost 2 decades in Cyber security. CISSP
0x00410041 @nahualito
1K Followers 866 Following Neural networks, Exploit Automation and anything that flies!!! You write it I reverse it. Thoughts, ideas and tweets are my own and not related to my employer.
Puzzor @Puzzorsj
1K Followers 626 Following PhD/Fuzzing/USENIX Security/MVSR 2020/Pwn2Own 2020/MSRC Top100 2016,2017/GeekPwn 2017
Boris Chuprin @noop_dev
373 Followers 205 Following Personal account of a sw dev. Shitposting mostly. Background: emudev, gamedev(rendering&AI), reversing, low-lvl opt.,some HPC&HFT. Retweet/follow != endorsement
glaimus @glaimus
46 Followers 314 Following
NCC Group Research & ... @NCCGroupInfosec
20K Followers 2K Following Technical account for global cyber security & resilience provider, NCC Group. This account is run alongside the @NCCGroupplc corporate account.
Puzzor @Puzzorsj
1K Followers 626 Following PhD/Fuzzing/USENIX Security/MVSR 2020/Pwn2Own 2020/MSRC Top100 2016,2017/GeekPwn 2017
Philippe Teuwen @doegox
4K Followers 1K Following If you can't root it you don't own it. doegox infosec exchange
Dmitry Nedospasov @nedos
7K Followers 321 Following Founder of @comput3ai. OG wallet researcher with @walletfail. Auditing wallets through @keylabsio. PhD in security, trainings @advsecio.
@mikko @mikko
229K Followers 930 Following Researcher and a best-selling author. Keynote talks at RSA, Black Hat & DEF CON. TED Speaker. Chief Research Officer at WithSecure.
Troy Hunt @troyhunt
240K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
Ryan Ackroyd @APT1337
7K Followers 207 Following Husband. Daddy. Teacher. Professional breaker and fixer of things. Possibly the friendliest cyber terrorist you will ever meet
Greg Linares (Laughin... @Laughing_Mantis
37K Followers 2K Following 20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
GrumpSec Spottycat �... @kyhwana
3K Followers 3K Following Spottycat, absurdist, geek, queer/pan, iconoclast, misanthrope, infosec, ham radio, furry, he/him? Mastodon: [email protected]
YOLO Crypto @yolocrypto
3K Followers 81 Following Crypto is hella YOLO! Former TSA, Internet of Cars, encrypting pacemakers, now BITCOIN!!! #YOLO
Dave Jones @eevblog
71K Followers 454 Following Professional Engineering Youtuber, inventor of that career path. Debunker of BS. Electronics + random opinions. Big on Freedoms. Certified Human https://t.co/zkA3b1gGkX
Hossein Lotfi @hosselot
6K Followers 60 Following Vulnerability researcher at ZDI (views are my own). Check #hosselot_tips for vulnerability research tips. 'A machine never faults. It reflects human's faults.'
FX of Phenoelit @41414141
18K Followers 519 Following Hacker, bearer of the 2017 Pwnie Lifetime Achievement Award, Experiment 626 type Otherwise applicable: I can neither confirm nor deny.![slipstream / raylee / Rye / Rai-chan [of Ring of Lightning]
Reverser, coder, beta collector, security researcher.
Mastodon: https://t.co/NOv3tSeg0K](https://pbs.twimg.com/profile_images/559354959611711490/UZRfLuHG.png)
slipstream/RoL @TheWack0lian
7K Followers 289 Following slipstream / raylee / Rye / Rai-chan [of Ring of Lightning] Reverser, coder, beta collector, security researcher. Mastodon: https://t.co/NOv3tSeg0K
Dark Reading @DarkReading
342K Followers 48 Following One of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
Matthew Green is on B... @matthew_d_green
150K Followers 1K Following I teach cryptography at Johns Hopkins. Mostly on BlueSky these days at https://t.co/GI4QlxZr2S.
Edward Snowden @Snowden
5.7M Followers 1 Following I used to work for the government, but now I work for the public.
Andrea Sindoni @invictus1306
891 Followers 96 Following Exploit Developer & Vulnerability Researcher - Former Android Tech Lead at @XI_Research
☣ KitPloit - Hacker... @KitPloit
119K Followers 3K Following Hacking and PenTest Tools for your Security Arsenal!
hasherezade @hasherezade
89K Followers 910 Following Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
CopperheadOS @CopperheadOS
6K Followers 193 Following Secure Android. CopperheadOS by @Copperheadsec. Release, product and community information.
Nikita Abdullin @0xABD
470 Followers 322 Following Security connoisseur, full-stack security specialist, hereditary tech-priest. Tweets are my personal opinions. Retweets are for informational purposes only.
Miroslav Stampar @stamparm
8K Followers 351 Following PhD, author of @sqlmap & @maltrail, CTF w/ @SuperGuesser, chess lover, problem solver
Leif Nixon 🌻 @leifnixon
3K Followers 719 Following I aim to misbehave. Preferred pronoun: whom. Ahforgetit tendency. 73% integrated. @[email protected]
Tanja Lange @hyperelliptic
6K Followers 175 Following
Nmap Project @nmap
139K Followers 459 Following Free and open source tool for network discovery, admin, and security auditing. Our tweetmaster is Gordon "Fyodor" Lyon. We're also on FB: https://t.co/RVkxWNikvW
Bernardo Rodrigues @bernardomr
993 Followers 586 Following When did punk rock become so safe? When did the scene become a joke?
Daniel J. Bernstein @hashbreaker
22K Followers 24 Following Designing cryptography (deployed now: X25519, Ed25519, ChaCha20, sntrup, Classic McEliece) to proactively reduce risks. Coined phrase "post-quantum" in 2003.
Igor Skochinsky (@Igo... @IgorSkochinsky
4K Followers 292 Following software developer at Hex-Rays*, hobby reverse engineer. Advanced cleartext hacker. 日本語おk *For Hex-Rays support/inquiries: https://t.co/rxVwo1npoQ
Travis Goodspeed @travisgoodspeed
26K Followers 4K Following Merchant of Dead Trees and Licensed Proselytizer of the Gospel of the Weird Machines with Pwnage, PoC, and Secular Rock.
PhysicalDrive0 @PhysicalDrive0
16K Followers 922 Following Malware Hunter / I've already taken the red pill!
Xylitol @Xylit0l
24K Followers 2K Following owner of https://t.co/PVTlUZSWgE and temari.fr - Security/Malware researcher, ethical carder, ex-treasurer of @Hack_Gyver and Temari fan ♥ #DIY #Electronic
Joanna Rutkowska @rootkovska
24K Followers 130 Following Long-term navigation at https://t.co/CfQ8ne1BLB & architect of @wildlandio. Previously founder of @QubesOS & Invisible Things Lab.
ς๏гєɭคภς0�... @corelanc0d3r
26K Followers 552 Following Corelan | Infosec Researcher&Trainer, Hacker | Outgoing Introvert (INFJ-A) | Book lover | Fountain pen affictionado | Chess amateur | Foodie
Alex Ionescu @aionescu
47K Followers 2K Following Chief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
`Ivan @Ivanlef0u
11K Followers 3K Following
Tarjei Mandt @kernelpool
17K Followers 564 Following