@glyann Profile picture

Yann

@glyann

SOC Analyst, Admin Sys, Cybersecurity Consultant

Joined March 2008
Similar User
BZHack photo

@asso_bzhack

ESD Cybersecurity Academy photo

@esd_academy

ZeyRoxx photo

@Zey_Roxx

Lucie photo

@mllejedi

k_lfa 🇫🇷 photo

@K_lfaa

Pierre_Adams photo

@Peter80702224

VirtualSamurai photo

@VirtualSamuraii

jean vivine photo

@JeanVivine

Poltergiss photo

@P0lterg1ss

croucroute photo

@_croucroute_

Bub  photo

@_Bubulle

Égalité Discriminations AcDijon photo

@EgaliteAcDijon

Yann Reposted

Cybersecurity is too much. Can I just go get a law degree or something and charge $1000/minute somewhere? 1. No one is shifting left. 2. No one is securing anything by design. 3. Productivity and capitalism will always win. 4. Devs don’t focus on security as much, it’s all…


Yann Reposted

Oops.

Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital



Yann Reposted

I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions We all know vulnerabilities exist. This isn't an injection, XSS, or RCE. But the crazy thing about it? It took 2 hours to discover. 🤯 Here's the story of #AutoWarp👇 (1/10)


Yann Reposted

#ESETresearch discovered a trojanized IDA Pro installer, distributed by the #Lazarus APT group. Attackers bundled the original IDA Pro 7.5 software developed by @HexRaysSA with two malicious components. @cherepanov74 1/5

Tweet Image 1
Tweet Image 2

Yann Reposted

[thread 🧵] this is a sub-thread about Kerberos Constrained Delegation (KCD) and abuse scenarios.

Tweet Image 1

Yann Reposted

Fantastic Windows Logon types and Where to Find Credentials in Them, by @chiragsavla94 alteredsecurity.com/post/fantastic…


Yann Reposted

[thread] Did you know that ssh tries to authenticate with stored keys BEFORE the key specified with -i in the command line ? I just noticed this, the hard way 😐. Let's imagine you have more than 5 keys loaded in your ssh agent. When authenticating to a remote server, you get:

Tweet Image 1

Yann Reposted

[thread] Tired of using complex payloads to get access to the os module in Server Side Template Injections on jinja2 ? I have new awesome payloads for you 😎 {{ self._TemplateReference__context.cycler.__init__.__globals__.os }} More information ➡️ podalirius.net/en/articles/py…


Yann Reposted

Un petit doc qui permet de savoir si nous sommes vulnérable.

Tweet Image 1

Yann Reposted

Le groupe Babuk s’est fait remarquer ce début d'année, par le succès rapide de cyberattaques ciblées via son rançongiciel contre de grandes entreprises. L'analyse de nos experts dans les #CyberSeChronicles : bit.ly/3fpqBU7


Yann Reposted

Looking for hashes of known good Exchange files? Here are hashes from the Exchange team: github.com/microsoft/CSS-…

Tweet Image 1
Tweet Image 2

Yann Reposted

New blog post out NOW! Microsoft Exchange Zero Day’s – Mitigations and Detections. blueteamblog.com/microsoft-exch… #infosec #CyberSecurity #security #SOC #Blueteam #cyberdefense #infosecurity #CyberSec #siem


Yann Reposted

Here's a threat on some overpowered technologies to slow down attackers that you can implement _now_. First, re-implement LAPS (microsoft.com/en-us/download…) at your peril. 1/14


Yann Reposted

Sysmon for Linux coming ... twitter.com/markrussinovic…

Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital



Yann Reposted

CVE-2020-16898 (Windows TCP/IP RCE) is beaten by CVE-2020-16952 (SharePoint post auth file inclusion leading to RCE). CVE-2020-16952 has an exploit out and when combined with password spraying/phishing for creds s a threat right now - reddit.com/r/blueteamsec/…


Yann Reposted

Build your own AD with 0 effort. 1) blog.focal-point.com/how-to-build-a… 2) Populate it github.com/davidprowe/Bad… 3) Add misconfigurations medium.com/@vartaisecurit


Yann Reposted

#infosec caption it. I start. When you realize that you are better off with #sysmon + ELK, than with $2M SIEM license quota filled with firewall log data

Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital



Yann Reposted

If you are bored by breaking software written by underpayed developers or evading security configurations set by overworked administrators - try a new challenge and do the world a favor ...

This post is unavailable.

Loading...

Something went wrong.


Something went wrong.