Stu Kennedy Profile Banner
Stu Kennedy Profile
Stu Kennedy

@NoobieDog

Followers
2,459
Following
1,479
Media
565
Statuses
12,708

Maker, Hacker, Security Researcher, Motorsport Enthusiast!

GTFO
Joined June 2011
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@NoobieDog
Stu Kennedy
4 years
Words to live by: The Internet:🌐 "Assume they ARE watching, ACT appropriately" Surveillance:🕵️ "Don't impregnate the people you're surveiling" Life:🧬 "Be Kind! Be Humble!"
3
7
22
@NoobieDog
Stu Kennedy
7 months
BitLocker Key retrieval on a Windows 11, Lenovo X1 Carbon Gen 11 via SPI Sniffing. The TPM on the backside of the Motherboard, there are various test pads.
Tweet media one
20
219
1K
@NoobieDog
Stu Kennedy
4 years
@iancanwrite @TimelessP I lold, but expect a van ;)
3
4
603
@NoobieDog
Stu Kennedy
5 months
Vulnerability Disclosure: Me: Hi, do you have a contact to discuss vulnerabilities in your product? Them: Na fam, chill! We got this!! 🤨
Tweet media one
25
26
561
@NoobieDog
Stu Kennedy
1 month
So 4 month ago, i started an interview process to joing a "hardware hacking team" in the UK, however the company is global. The job advert was for a "Senior Hardware Hacker" and was being handled by a recruitment agency. I applied and got a response withing 24 hours. 1/*
18
15
455
@NoobieDog
Stu Kennedy
4 years
Found the perfect tshirt!
Tweet media one
8
33
221
@NoobieDog
Stu Kennedy
7 months
I'm starting a TPM-Sniffing repo with data on what devices are vulnerable to these kind of attacks and a list of great research that goes with it. @ghidraninja @en4rab @lucasteske @qrs @wrongbaud and many more. Please share
5
78
194
@NoobieDog
Stu Kennedy
3 years
log4j inlcuded ;)
Tweet media one
7
30
141
@NoobieDog
Stu Kennedy
1 month
So the code i was asked to review live is from this course More specifically, this code. I had never seen it before. 13/*
6
3
136
@NoobieDog
Stu Kennedy
1 month
I guess i need to learn more about code reviews for a decent role in hardware hacking... good job things like @OpenSecTraining exists and have great courses! onwards and upwards! 12/*
7
2
121
@NoobieDog
Stu Kennedy
5 years
Today. I get married. 😬
26
0
111
@NoobieDog
Stu Kennedy
1 month
The CTF process was fun, and there were multiple areas id expect to be covered for a hardware hacker. - Code Review - Hardware Protocols and Analysis - Firmware Analysis - Web Applications - Crypto 5/*
1
0
110
@NoobieDog
Stu Kennedy
1 month
After a lenghty call with the recruiter (who actually was a nice guy, but didnt really understand the job role/expertise that was on offer/or being wanted) it was decided to put me through to the company offering the job. 2/*
2
0
107
@NoobieDog
Stu Kennedy
1 month
After 5 mins, he clearly isnt interested and cuts the call short, not really talking about my thought process of what i was trying to show, bits i was looking at in the code. Its like he wanted me to directly see a stack or Int overflow etc.. My brain doesnt work like that. 9/*
3
0
106
@NoobieDog
Stu Kennedy
1 month
weeks pass and I do not hear back at all. i chased both the Admin and CTF reviewer from the company for feedback or advice to move forward. I chased the recruiter... All ghosted me! 11/*
3
0
105
@NoobieDog
Stu Kennedy
1 month
A day or so passes and i get a nod from the recruiter that the company is "VERY" interested in me and would i be willing to have a quick chat about the role with a senior. I have the call, but its not about the job/role, more that i live 2 hours away from the office... 3/*
1
0
103
@NoobieDog
Stu Kennedy
3 years
Today, DID NOT go to plan! Im ok!
Tweet media one
24
0
102
@NoobieDog
Stu Kennedy
1 month
He goes on to further explain that 90% of the job is "Code Reviews" and that i should have a better understanding of vulns in code... He then asks me to do a ten min real-time code review of 620 lines of C code, live while screen sharing. So feeling the pressure, but i agree 8/*
2
0
100
@NoobieDog
Stu Kennedy
4 months
@nikgeneburn Please for the sanity of every player! Fix the raid waiting times.. 25mins is outrageous time to wait regardless if beta or not! PVE times are even worse! 2-3mins max! All this tells me is, your network engineering isn’t great and BSG don’t know how to scale!!
34
0
96
@NoobieDog
Stu Kennedy
1 month
Regardless, i get put through to another call to an onboarding admin, who asks about my experiance etc.. but they were questions that my CV answers in detail. Did they have my CV? I get through to the CTF part of the interview process. 4/*
1
0
97
@NoobieDog
Stu Kennedy
7 months
I have 6 Laptops to extract BitLocker keys from, Dell, Gigabyte, HP and PC Specialist. Will detail and record progress as i go!
7
8
92
@NoobieDog
Stu Kennedy
1 month
I say thank you for the time and express that although i dont know as much as i probably should with code reviews, its something im willing to learn, and that its good that i excelled in the "hardware hacking" parts. We end the call. 10/*
1
0
93
@NoobieDog
Stu Kennedy
1 month
I do all the challenges, feel good about most of it apart from the Crypto and Code Review side of things, but i try my best. Highly detailed report gets sent! 2 weeks pass and i finally get a CTF review call. 6/*
1
0
91
@NoobieDog
Stu Kennedy
1 month
The call starts well, the person reviewing the report is a Senior Hardware Hacker (not in the UK). He explains that he is happy with most of the report but obviously i lack in Code reviews.. But did really well in the "Hardware Hacking" based parts... 7/*
1
0
91
@NoobieDog
Stu Kennedy
1 month
@CheddarB0b42 I believe they wanted a vuln researcher/reverse engineer, if that was the case, I’d have never gone for the roll. But I really was heavily focused on hardware hacking.
0
0
72
@NoobieDog
Stu Kennedy
1 month
Apologies for the spelling mistakes, tired and fat fingers ;)
4
0
62
@NoobieDog
Stu Kennedy
7 months
Soldering direct to these pads allowed the @saleae logic analyser to sniff the SPI communications and find the VMK :D
Tweet media one
2
5
62
@NoobieDog
Stu Kennedy
5 years
So today was my last day at @PenTestPartners . I cant thank each and every one of them enough! Much love to the whole company... Ive now got a bit of time off. Do some hobbies, eat some food, fight some people! Keep hacking, Keep Pwning! HAVE A GREAT WEEKEND! <3
6
1
61
@NoobieDog
Stu Kennedy
2 years
Tweet media one
10
0
58
@NoobieDog
Stu Kennedy
3 years
W O O T
Tweet media one
2
3
55
@NoobieDog
Stu Kennedy
6 years
👏DO 👏NOT👏USE 👏SECURITY 👏AS 👏STRETCH 👏GOALS👏 @cybergibbons
Tweet media one
2
13
53
@NoobieDog
Stu Kennedy
3 years
All BugBounties should now only accept log4j submissions but 100% donate the bounty to the maintainers of log4j instead of the beg bounties skids using copy and paste
5
1
55
@NoobieDog
Stu Kennedy
1 year
So its been exactly 1 month i've stayed drug free... you may be thinking WTF Stu, but... Prescribed Opioids are dangerous as fuck! Please seek help and get off them ASAP 12 years is a long time! Was for me and its not been easy but i feel so much better! My DMs are open!
5
0
52
@NoobieDog
Stu Kennedy
4 years
Tweet media one
2
4
50
@NoobieDog
Stu Kennedy
11 months
Every lab has its differences, @dcuthbert has a bloody xray machine for example! But if you wanna know where to start, @wrongbaud has built a fantastic set of pages to follow with great examples! To set up your own hardware hacking lab.
1
13
52
@NoobieDog
Stu Kennedy
3 years
@ghidraninja cheers for this brother! Lovely bit of kit
Tweet media one
1
1
41
@NoobieDog
Stu Kennedy
3 years
Mercedes: £1200 for a new maf unit.. Me: I dont need a new MAF unit, i need a MAF Sensor... Mercedes: £1200 or GTFO Me: Find Actual MAF sensor from Bosche, £89 Me: Replaces sensor, Car is working great again! Fucking dealers and the prices are silly!
5
0
45
@NoobieDog
Stu Kennedy
7 months
Tweet media one
2
5
43
@NoobieDog
Stu Kennedy
5 years
Bottom line. I did not leave @PenTestPartners be cause they were shit, far from it, great bunch of people, great jobs and loads of fun. I left because “I” wanted to step away from consultancy and wanted to try something a bit different! Please stop with the DMs asking!
2
4
42
@NoobieDog
Stu Kennedy
3 years
Id be interested to see what hardware is vulnerable to log4j Might start a github repo to list shit @cybergibbons @arturo182 @CyberAntani @GossiTheDog @dcuthbert Down?
4
4
36
@NoobieDog
Stu Kennedy
6 years
Today is my first day at @PenTestPartners . Let the hacking commence!
10
0
38
@NoobieDog
Stu Kennedy
5 years
A blog series i have been working on for some time. Alot of Fails but some wins and more to come! Long version: Short Version: Enjoy @PenTestPartners @pwntestpartners
1
9
36
@NoobieDog
Stu Kennedy
5 years
@nixcraft i always plug it into somebody elses computer first ;)
2
0
35
@NoobieDog
Stu Kennedy
6 years
Slowly slowly getting there! Need a bookcase and shelves i think
Tweet media one
6
3
33
@NoobieDog
Stu Kennedy
3 years
Know thy roots! @sensepost
Tweet media one
1
2
32
@NoobieDog
Stu Kennedy
4 years
Wake up, log into twitter, see the infosec industry killing itself again, close twitter, get back into bed! Sigh...
4
3
32
@NoobieDog
Stu Kennedy
4 years
@cherepanov74 looks to me like a impant GSM bug, something like this
Tweet media one
1
1
32
@NoobieDog
Stu Kennedy
3 years
If you use the #UkraineRussia conflict as a marketing ploy! You are a complete cunt!
1
2
30
@NoobieDog
Stu Kennedy
1 year
And another one!
Tweet media one
2
0
28
@NoobieDog
Stu Kennedy
4 years
Yeet!
5
0
30
@NoobieDog
Stu Kennedy
3 years
How nice would it be to be 100% honest on a CV. Instead of “hardworking, passionate, team player” Put “I will put everything into my work until you either puss me off or treat me like a mug, then ill fuck you all up” Hmm 🧐 @cybergibbons
1
0
28
@NoobieDog
Stu Kennedy
4 years
Today! Today i hate cars
Tweet media one
7
0
28
@NoobieDog
Stu Kennedy
5 years
@cornerpirate Mine is from this beautiful bastard! His name is “Noobie” and was my “dog”. ❤️
Tweet media one
4
0
27
@NoobieDog
Stu Kennedy
4 years
So after having the head skimmed, ported and polished, i had new valve guides installed then they needed reaming! That took a while! After that, had to lap the valves in and then give the head the final deep clean before installing all the new parts! #vr6 #corrado
Tweet media one
Tweet media two
Tweet media three
8
0
28
@NoobieDog
Stu Kennedy
3 years
@cybergibbons you have alot to answer for!
1
3
27
@NoobieDog
Stu Kennedy
4 years
100% NOT sketchy at all!
Tweet media one
Tweet media two
10
0
27
@NoobieDog
Stu Kennedy
5 years
pentesters, take note, this annoyed me for a few days!
1
7
26
@NoobieDog
Stu Kennedy
4 years
I enjoyed this great artical! nice work!
@WithSecure
WithSecure™
4 years
New report on @FSecureLabs : Hunting for backdoors in counterfeit Cisco devices Read up on the tear down of 2 counterfeit Cisco switches.
Tweet media one
1
27
47
3
4
26
@NoobieDog
Stu Kennedy
7 months
@ghidraninja Yes Sir, latest release, Fully updated/patched
1
0
25
@NoobieDog
Stu Kennedy
7 months
This is for reference only! Thanks to @ghidraninja and @en4rab for assistance and DM's
2
1
23
@NoobieDog
Stu Kennedy
10 years
Python HTTP Directory Scanner (DirBuster) Proxy/BasicHTTP/Verbose/Requests/User-agents #python #pentest @ToolsWatch
1
14
22
@NoobieDog
Stu Kennedy
9 months
Thread: This year i ran a full season in competitive racing. I have calculated about a £13K cost for the whole season from start to finish (race entry, tires, fuel, transportation, parts, etc...) There were times where i lived on pot noodles for a week to save money to race
Tweet media one
2
0
23
@NoobieDog
Stu Kennedy
4 years
Its not broke and works very well, so im going to strip it 100% down and rebuild like new but with race parts! It wont be cheap, but it will be worth it!
Tweet media one
6
0
21
@NoobieDog
Stu Kennedy
3 years
All registered for this years racing! And new licence dropped today! Woot
Tweet media one
1
1
22
@NoobieDog
Stu Kennedy
4 years
If you feel you have an argument against this thread... go fuck yourself... BE KIND BE HUMBLE Its disgusting how some people act!
2
2
22
@NoobieDog
Stu Kennedy
4 years
For those that asked (most of you didnt) here is me giving all opsec up and spilling my beans! Cars are important to me! My race car is important to me Im giving you and everybody an insight into my life If your going to abuse me/it Please subscribe
5
2
22
@NoobieDog
Stu Kennedy
2 years
Absolutely enjoyed @Steel_Con #steelcon yesterday! Met some great people and caught up with some great friends! @ZephrFish @myexploit2600 John @ghostie_ And many more. Didnt get to see @scriptmonkey_ but I’m sure i will another time! Great con and very inclusive!
4
4
21
@NoobieDog
Stu Kennedy
4 years
Here is a question: Is it possible to be part of/and good in Infosec if you dont have a twitter accout? How do you share research? How do you see/learn latest things?
14
1
21
@NoobieDog
Stu Kennedy
2 years
Tweet media one
2
1
19
@NoobieDog
Stu Kennedy
4 years
I love car weekends
Tweet media one
6
0
20
@NoobieDog
Stu Kennedy
9 months
I wrote a 77 page “blog” that describes how I hacked a baby camera. However it doesn’t have the finish id hoped! Still fun, still learned! Will publish soon
2
0
20
@NoobieDog
Stu Kennedy
5 years
Really needed somebody to talk too today! Instead, i went for a 2 hr walk down the thames river in Reading! It really helped clear my head! Tomorrow is always another day! #mentalhealth #goodtotalk #MentalHealthMatters
6
1
20
@NoobieDog
Stu Kennedy
4 years
Hacker/followers! Just wanna say! I love yall! If you ever want to talk, dm me!
1
1
20
@NoobieDog
Stu Kennedy
5 years
Thank you all for your wonderful messages and comments ❤️
Tweet media one
5
0
19
@NoobieDog
Stu Kennedy
3 years
Just incase you didnt see these earlier!!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
1
19
@NoobieDog
Stu Kennedy
6 years
Brilliant Blog post and research. Well done @xoreipeip
@gcluley
Graham Cluley
6 years
Virgin Media has fixed multiple vulnerabilities in its Super Hub 3.0 broadband modem (14 months after being told about them) that could enable hackers to remotely monitor network traffic and execute commands
Tweet media one
4
32
37
2
8
18
@NoobieDog
Stu Kennedy
4 years
Tweet media one
2
4
17
@NoobieDog
Stu Kennedy
5 years
2
1
17
@NoobieDog
Stu Kennedy
5 years
Brilliant!
@Newlockie
newlock.ie
5 years
@BadLocksmithing the homeowner has lived here for a year, they never noticed
7
10
34
4
2
15
@NoobieDog
Stu Kennedy
3 years
Lol
Tweet media one
2
0
18
@NoobieDog
Stu Kennedy
3 years
fuck apple... treat people better! *yes i own an iphone
2
5
18
@NoobieDog
Stu Kennedy
7 years
Nice and Easy Snoop-NG replacement, not as feature rich ;) @sensepost @glennzw
0
11
17
@NoobieDog
Stu Kennedy
5 years
Created and ordered my first PCB! So fucking excited!
3
0
17
@NoobieDog
Stu Kennedy
3 years
What a day! Car was flawless
7
0
18
@NoobieDog
Stu Kennedy
3 years
Things i have learned this weekend! (thread) 1: Devs have a shitty time supporting there FREE code to the masses, as users are needy bitches and DONT RTFM! As a dev of some tools, its hard sometimes to squash bugs, test and make things work 100% all the time
2
0
17
@NoobieDog
Stu Kennedy
6 years
I HATE REPORTING!!! 🤬
6
1
17
@NoobieDog
Stu Kennedy
4 years
Anybody else find this look appealing!
Tweet media one
6
0
17
@NoobieDog
Stu Kennedy
5 years
Awesome work and research from @leonjza as usual! Top tier right here folks!
@leonjza
_leon_jacobs(💥)
5 years
Very, very hacky, but got a #meterpreter running on an iOS 13.1 device after some inspiration from @timwr , using a mettle dylib and @fridadotre . All without a jailbreak ofc. Not a lot of useful meterpreter iOS features, but science... :)
Tweet media one
7
84
205
0
5
15
@NoobieDog
Stu Kennedy
3 years
Channeling my inner Schumacher!! 😂
2
0
17
@NoobieDog
Stu Kennedy
4 years
I need answers!
Tweet media one
1
3
17
@NoobieDog
Stu Kennedy
4 years
Another 50 ear protectors going out to local health care outfits! Printer will keep going until it breaks!
Tweet media one
1
0
17
@NoobieDog
Stu Kennedy
4 years
Head bolted down, chain covers on, rocker cover on, coolant system on! Its the game of putting it back together and hoping its sealed 😂
Tweet media one
3
0
16
@NoobieDog
Stu Kennedy
4 years
Today is a sad but happy day! To be part of the Plakk, to be part of this top-tier group of awesome people, has/was and still is one of the best times of my life. SP will always live on in my ethics and foundations! Long Live @sensepost Here is to the future! <3
Tweet media one
0
3
16
@NoobieDog
Stu Kennedy
6 years
Is it normal for your car to MiTM your data connection? (Phone tether) example. Phone is @VodafoneUK , @MercedesBenz web services (in car browser at least) proxies traffic to Germany. Will play more over weekend @dcuthbert
Tweet media one
Tweet media two
3
4
16
@NoobieDog
Stu Kennedy
4 years
@GossiTheDog @Fox0x01 Another day, another drama (although serious) but nothing to do with INFOSEC... or the community.
1
0
16