0xdf_ Profile Banner
0xdf Profile
0xdf

@0xdf_

Followers
23K
Following
4K
Statuses
3K

Training Architect @ HackTheBox "Potentially a legit security researcher" he/him https://t.co/GCcLVlmdQK https://t.co/uQWVpw4nft 0xdf on discord

Joined January 2015
Don't wanna be here? Send us removal request.
@0xdf_
0xdf
2 days
MagicGardens from @hackthebox_eu has a ton in it! There's a bank trick and XSS via QRcode. There's a buffer overflow via large IPv6 packet. Docker Registry, Django deserialization, and a malicious kernel module as well.
4
20
90
@0xdf_
0xdf
4 days
RT @sarperavci: Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it…
0
309
0
@0xdf_
0xdf
4 days
@sarperavci Ha, you're right! Thanks
0
0
3
@0xdf_
0xdf
4 days
@sarperavci Very nice!
1
0
1
@0xdf_
0xdf
4 days
During #flareon11, I learned how to use a plugin to automate x64dbg with Python. In this video, I'll show how to set it up, get started, and then walk through my final tracing script.
3
44
180
@0xdf_
0xdf
5 days
#FlareOn11 prize arrived! Very neat!
Tweet media one
7
4
139
@0xdf_
0xdf
9 days
Trickster from @hackthebox_eu showcases vulnerabilities in PrestaShop, ChangeDetectionIO, and Prusaslicer! In Beyond Root I'll show a ModSecurity configuration that was blocking by user-agent string.
0
13
63
@0xdf_
0xdf
13 days
RT @KartikDurg: Check out the fourth article in our Attack Anatomy series, where we dive deep into the techniques employed by Mustang Panda…
0
2
0
@0xdf_
0xdf
13 days
@Chirag99Artani @hackthebox_eu I think it requires a very specific setup. Someone has to code an application that will be vulnerable to it. You have found real world struts applications with file upload to try it on?
1
0
0
@0xdf_
0xdf
15 days
@tripflag Awesome! Thanks for letting me know. I did figure out the proc thing too. I don't remember what I said in that video, but I actually made a video about it a while back, lol.
0
0
1
@0xdf_
0xdf
16 days
Caption from @hackthebox_eu has some really tricky by neat request smuggling and HTML injection to get XSS, bypassing HAProxy, and exploiting a thrift / Go log handler. I'll also show patched unintends using Bitbucket DB Viewer and some HAProxy bypasses.
1
28
80
@0xdf_
0xdf
22 days
Creating the krb5 file is the worst. I always seem to screw it up somehow. Now netexec does it for you!
@mpgn_x64
mpgn
22 days
--generate-krb5-file
Tweet media one
0
9
99
@0xdf_
0xdf
23 days
MonitorsThree from @hackthebox_eu, like Monitors and MonitorsTwo, starts with an instance of Cacti. This time I'll get creds from a different site, and abuse those to get RCE. For root, I'll abuse a CVE in Duplicati. In Beyond Root, I'll dig at port 8084
0
20
83
@0xdf_
0xdf
1 month
Sightless is a fun, easy-level box from @hackthebox_eu, with a couple CVEs to exploit in SQLPad and Froxlor. I'll play with some unintended exploits in Chrome debug and Froxlor, as well as an SSRF in SQLPad.
0
21
64
@0xdf_
0xdf
1 month
0
0
1
@0xdf_
0xdf
1 month
Loved the new #HolidayHack format this year, releasing challenges in 4 acts! I'll hack web and JS, curl and PowerShell, hardware and mobile apps. There are two SOC / SIEM like challenges, and ransomware decryption.
0
6
16
@0xdf_
0xdf
1 month
Just finished the first Grace Hopper talk from 1982 on the @NSAGov podcast feed, and it's so good. Her thoughts on what computers would be are fascinating. What a brilliant thinker, and she has quite a whit as well. Can't wait to listen to the second one.
0
4
28
@0xdf_
0xdf
1 month
I always enjoy playing @hackvent! I completely 23 of 24 challenges in 2024. Lots of codes, crypto, exploitation, obscure languages. Really nice Verilog, ransomeware, and PCAP challenges. Even a smart contract I learned a lot from!
1
3
29