Show more

@sjvn That's too bad. I thought ATT&CK was published for the common good and they were interested in getting feedback on things to add. I didn't perceive it so much as an instrument of US Policy. (I'm now hearing a Fleetwood Mac song in my mind. "You can go your own way...")

PSA for all the VARs and consultancies out there. When submitting an RFP response or a proposal, please make sure the grammar is right. It's distracting if it's wrong. Also, if you're re-using a proposal from another customer, please remove references to the other customer.

@sjvn Why did they create a new framework instead of working with MITRE to build ATT&CK? Lots of vendors and their customers are already using it.

Day85: Banged on academy.htb. Wordlists matter. Grr.

Day84: Poked at a box on another platform. Looks like BlueKeep is the way in, but metasploit module is for x64 and the target is x86. Found a PoC for x86, but I'm fighting python module dependencies. I need to get better at venv, I guess. Then the clock ran out, so I can't pick at it until tomorrow.

ath0 boosted

"A gentle reminder to everyone who uses hashtags. If you capitalize them , people using screen readers hear the words individually. Not capitalizing means it's read as a string of gobbledygook and so excludes visually impaired people."

@th3j35t3r Couple of things stood out. 1) What's that accent? and 2) Says FBI shouldn't be weaponized, but should look at Hunter's laptop.

Day83.1 Update: Finished 2nd box. Reset box and switched to meterpreter shell instead of trying to use command shell. Worked great.

Day83: Hands on keyboard today! Worked on a pair of TryHackMe boxes. One down pretty quickly. Some progress on the second. Using msfconsole and msfvenom on that one. Issue w/getting handler and payload to match. Don't use it a whole lot, so more googling than I like.

Day81: Started Practical Web Application Security and Testing class from mttaggart

Day80: Read ch 3 of _Web Application Hacker’s Handbook_. (fixed unfortunate typo)

Day 79: Didn’t make time to get hands on keyboard today. Started _Web Application Hacker's Handbook_ and got through first two chapters. While it’s 11 years old, still seems pretty relevant.

Day78: Went along with the Alh4zr3d stream on a PG Play box. Rated as hard. Got a bead on the foothold. Slowing down to make some notes. Make brain wrinkles and have something to come back to in the future--tags, MF!

Day77: I finished last night's target on Offsec PG Practice. Started in on a new one today. Bluekeep is a spooky vuln. Should be done w/that one soon.

@asmitty Pryor, Murphy, Chappelle, Rock, and I have to give Cedric some love since he's from 'round these parts. I like Sykes, too, and I've heard some Red Foxx from before his show--so I reckon I should give them honorable mentions.

Show more

ath0

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.