John Hammond Profile Banner
John Hammond Profile
John Hammond

@_JohnHammond

Followers
262,014
Following
2,507
Media
2,393
Statuses
7,745

Hacker. Cybersecurity Researcher @HuntressLabs ||

San Francisco, CA
Joined March 2015
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@_JohnHammond
John Hammond
11 months
OUR AIRPLANE CAN'T FIND THE MYSQL DATABASE 😱😱 @kaitlyn_devalk
Tweet media one
249
796
9K
@_JohnHammond
John Hammond
5 months
Fuck.
Tweet media one
@_JohnHammond
John Hammond
1 year
Don't worry everyone, the Internet is still a safe place.
Tweet media one
Tweet media two
Tweet media three
109
408
4K
122
433
7K
@_JohnHammond
John Hammond
18 days
Luke shared the URL from the original phishing email with me, so I'd like to showcase it a bit. Planning to record a video to walk through it, but don't have a chance to record for the next few hours... so will roll with a Twitter/X thread for now 🧵
Tweet media one
@linusgsebastian
Linus LinusMediaGroup
19 days
**BEWARE** The main LTT Twitter account has been hijacked. 4 minutes after I received this email I tried to log in, but the password had already been changed. By the time I could update the password, the 2FA had been deactivated/reactivated. I have contacted Twitter support.
Tweet media one
422
842
11K
80
652
6K
@_JohnHammond
John Hammond
2 years
Today I got a notification on my phone that YouTube had sent me a copyright report, claiming one of my videos violated copyright and my channel was going to receive a strike. Except, my video didn't violate copyright. And YouTube didn't really send me a copyright report.
Tweet media one
Tweet media two
168
2K
5K
@_JohnHammond
John Hammond
1 year
Don't worry everyone, the Internet is still a safe place.
Tweet media one
Tweet media two
Tweet media three
109
408
4K
@_JohnHammond
John Hammond
1 month
CrowdStrike Falcon agents are imploding right now and causing a Blue Screen of Death boot loop on every endpoint. Reports of massive outages globally.
79
1K
4K
@_JohnHammond
John Hammond
4 years
Tweet media one
61
757
4K
@_JohnHammond
John Hammond
3 years
aaaaand then code execution?? #log4j #minecraft
Tweet media one
55
628
3K
@_JohnHammond
John Hammond
1 month
This is CrowdStrike's Director of Overwatch, so I hope to help spread the word. I believe CS stopped these changes from being pushed out so machines late to the party wont get the faulty driver. Command in Safe Mode: del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
54
996
3K
@_JohnHammond
John Hammond
1 month
Jumped onto CNN to chitchat about the CrowdStrike shenanigans -- cheesy picture but quite a treat, thank you for letting me join you 🙏 Hug ops to all the folks still fighting fires for this thing. 🫂
Tweet media one
132
184
3K
@_JohnHammond
John Hammond
3 years
🤯🤯🤯 @offsectraining 🥇🩸?
Tweet media one
230
168
3K
@_JohnHammond
John Hammond
3 years
I've prepared a @RealTryHackMe room to demonstrate #log4j #log4shell CVE-2021-44228, explaining the vulnerability, attack vector, and more importantly, detection, mitigations and patching. Working with THM staff to get this in your hands -- it should be available soon.
Tweet media one
101
516
3K
@_JohnHammond
John Hammond
3 months
the moment i realized i made a grave mistake
Tweet media one
88
94
3K
@_JohnHammond
John Hammond
2 months
I'm on a 6-hour flight with Starlink, and I am using my GPD Pocket tiny laptop, to Parsec home to my desktop and access all my virtual machines and home lab server. Honestly I just think it is funny. 😂
Tweet media one
91
84
2K
@_JohnHammond
John Hammond
9 months
𝗧𝗵𝗮𝗻𝗸 𝘆𝗼𝘂. 🙂
143
47
2K
@_JohnHammond
John Hammond
3 years
If you say "documentation" three times in front of a mirror, it still won't appear.
61
286
2K
@_JohnHammond
John Hammond
3 years
👁️👄👁️well alrighty then
Tweet media one
60
280
2K
@_JohnHammond
John Hammond
7 months
⚠️Stay safe everybody! If you use a Crest or Colgate toothbrush, please update to KB-133769420 and install the latest kernel bugfixes for any external devices like your floss and mouthwash.
76
192
2K
@_JohnHammond
John Hammond
2 years
u sure?
Tweet media one
115
146
2K
@_JohnHammond
John Hammond
3 years
Meta... sploit?
72
199
2K
@_JohnHammond
John Hammond
1 year
The MOVEit Transfer exploitation is not just SQL injection(👀) We uncovered the very last stage of the attack chain to drop human2.aspx ultimately ends up gaining remote code execution ‼ We fully recreated the attack chain with a demo achieving a reverse shell & ransomware!
34
505
2K
@_JohnHammond
John Hammond
1 year
cybersecurity
Tweet media one
68
42
2K
@_JohnHammond
John Hammond
3 years
Does this outage count for cybersecurity awareness month festivities?
59
270
2K
@_JohnHammond
John Hammond
1 year
exposing this scammer at #PCC23
Tweet media one
73
85
2K
@_JohnHammond
John Hammond
2 years
Merry Christmas. 🎄 Here's to many more.
Tweet media one
54
12
2K
@_JohnHammond
John Hammond
1 month
the CROWD has STRUCK
49
196
2K
@_JohnHammond
John Hammond
1 month
A thread of new domains following the CrowdStrike catastrophe: 🧵
30
241
2K
@_JohnHammond
John Hammond
10 months
Session hijacking a Microsoft 365 account! Stealing their credentials and bypassing MFA prompt with Evilginx: a reverse-proxy phishing framework! We stage a phishing domain and email pretense, and gain full access to the victim account!
Tweet media one
28
319
2K
@_JohnHammond
John Hammond
11 months
The desktop is malware
Tweet media one
71
86
2K
@_JohnHammond
John Hammond
6 months
Wait, what?
Tweet media one
87
83
2K
@_JohnHammond
John Hammond
2 years
Don't forget, 0-days wouldn't happen if you had just bought that one vendor's EDR, MDR, XDR, NDR, RDR, NXDR, ODR, PDR, LDR, QDR, VDR, JDR, KDR, IDR, 1DR, 4DR, DDR, ZDR, YDR, ⧫DR, 🟋DR, 🙻DRR, DRDRDR, AIDR solutions they emailed you about after you got stickers from their booth.
74
181
2K
@_JohnHammond
John Hammond
2 years
Thank you robot overlords
Tweet media one
Tweet media two
Tweet media three
Tweet media four
33
135
2K
@_JohnHammond
John Hammond
2 years
400k nerds watch this nerd thank u 4 ur support
Tweet media one
68
26
1K
@_JohnHammond
John Hammond
11 months
almost done setting up my computer🥹
Tweet media one
228
70
1K
@_JohnHammond
John Hammond
2 years
Bro you literally just have to click on the red line????
Tweet media one
215
25
1K
@_JohnHammond
John Hammond
3 years
THANK YOU so much for _literally sending_ a birthday cake @Hacker0x01 !!!🎂 ♥️ 🥰🎉 A good light snack while we hold down the fort for the #hacktivitycon2021 CTF 😎 THANK YOU!!! 😍
Tweet media one
Tweet media two
117
42
1K
@_JohnHammond
John Hammond
7 months
CVE-2024-21413 sure does do the needful
Tweet media one
24
186
1K
@_JohnHammond
John Hammond
4 years
Does anyone else make a directory, change into that exact directory, and then list files in the newly created directory... knowing the directory is empty, because you literally JUST created it?
Tweet media one
158
93
1K
@_JohnHammond
John Hammond
3 years
🚨 BLACK FRIDAY SPECIAL 🚨 Today and today only, you can find all of my free education and content, online FOR FREE! After today's sale, everything will return to normal asking price: $0.00! 😱
63
101
1K
@_JohnHammond
John Hammond
4 years
Tweet media one
111
25
1K
@_JohnHammond
John Hammond
3 years
"Download failed: Virus detected" ... I know. That's why I want it. 😠
27
87
1K
@_JohnHammond
John Hammond
18 days
With that said, I am very grateful for the actor actively trying to send me the exact same phish. 😂 With a special note for me 🤣
Tweet media one
30
52
1K
@_JohnHammond
John Hammond
2 years
"Would you like to earn millions of dollars $$$ ?"
Tweet media one
Tweet media two
Tweet media three
Tweet media four
39
201
1K
@_JohnHammond
John Hammond
2 years
This might be the creepiest thing I have ever been pinged for, but uh, yes, that is me? 🙃
@CyberShen
Cyber Shen
2 years
@_JohnHammond is that you!?
Tweet media one
7
2
55
127
17
1K
@_JohnHammond
John Hammond
11 months
curl/libcurl HIGH CVE-2023-38545 seemed to have a patch diff out early?
Tweet media one
26
311
1K
@_JohnHammond
John Hammond
1 year
For @ScammerPayback 's People's Call Center event, it was @0dayCTF and I's personal project to write code to fool scammers into removing their webcam cover and showing their face. It was such an adrenaline rush to see it work.
Tweet media one
Tweet media two
Tweet media three
58
152
1K
@_JohnHammond
John Hammond
2 years
happy pres day
Tweet media one
36
6
1K
@_JohnHammond
John Hammond
8 months
merry christmas
Tweet media one
27
10
1K
@_JohnHammond
John Hammond
2 years
once again I have completed a trip around the sun
203
17
1K
@_JohnHammond
John Hammond
2 years
Halfway.
Tweet media one
84
21
1K
@_JohnHammond
John Hammond
2 years
im verified now
123
18
1K
@_JohnHammond
John Hammond
2 years
Want to know what a YouTube channel with half a million subscribers looks like behind the scenes? As we're cruising into 2023 and the new year, I'd like to peel back the curtain. I want to be as transparent as possible here, in the hopes that this might help other creators. 🧵
Tweet media one
49
91
1K
@_JohnHammond
John Hammond
1 year
imma bout to phish erry security researcher in da world
Tweet media one
Tweet media two
32
66
1K
@_JohnHammond
John Hammond
2 years
It has been a real treat seeing this post blow up and I am super flattered 😊 Seriously, thank you. After NahamCon CTF ends at the end of this month, I hope to finally showcase some Active Directory content and then start a "journey to OSEE" style thing. Hopefully.🤞
@Zer0F8th
🇺🇦 Zer0F8th
2 years
@ippsec & @_JohnHammond provide some of the best cybersecurity content
Tweet media one
22
101
1K
18
62
1K
@_JohnHammond
John Hammond
10 months
I live to serve
@vxunderground
vx-underground
10 months
. @_JohnHammond we'll mail you a complete copy of vx-underground if you promise to load all the malware samples onto a computer and bring it GeekSquad for repair
44
64
2K
29
53
1K
@_JohnHammond
John Hammond
4 months
People tend to say "work smarter, not harder", and I absolutely agree with that. But I do think there is some magic that happens when you do both... work smarter AND harder. Thank you for your support.
Tweet media one
70
24
1K
@_JohnHammond
John Hammond
11 months
diSaBLE SIgNAL LINK pReVIEWS aS FAST as HuMANLY POSSIBLE TO MITIGATE thiS ExtREME CRITICAL ZERO DAY VULNERABILITY ThAT NO ONE knOWS LITERALLY ANYTHING ABOUT UNPLUG INTERNET & THROW YOUR PHONE IN THE OCEAN BEFORE IT HACKS UR WHOLE LIFE NO CVE THO, NO DETAILS, DONT WORRY ABOUT IT
51
97
992
@_JohnHammond
John Hammond
1 month
CrowdStrike Preliminary Post Incident Review (PIR) is released:
Tweet media one
35
270
992
@_JohnHammond
John Hammond
10 days
oh, wait, f&$% lmfao
Tweet media one
95
32
1K
@_JohnHammond
John Hammond
7 months
Fun fact: Windows stores Wi-Fi passwords in plaintext! You can extract passwords with netsh.exe, but that's a child process that might be observed -- we can improve our tradecraft to extract Wi-Fi passwords with native Win32 API functions... in Rust 😎😈
Tweet media one
18
177
968
@_JohnHammond
John Hammond
1 year
What if you ran an nmap scan and ALL 65535 ports were open? You can waste a hacker's time by spoofing your attack surface and simulating real services so the adversary has no idea what to target. Cyber deception!
Tweet media one
24
172
963
@_JohnHammond
John Hammond
1 month
Alright who has a copy of the CrowdStrike driver, is that on VirusTotal yet?
47
50
962
@_JohnHammond
John Hammond
3 years
This was a pleasant surprise to have in the mail after getting back home from DEFCON -- thanks again @offsectraining !!
Tweet media one
45
25
936
@_JohnHammond
John Hammond
8 months
I LIVE IN THE FUTURE
Tweet media one
49
48
913
@_JohnHammond
John Hammond
8 months
2024 will be the year of linux on the desktop
81
79
900
@_JohnHammond
John Hammond
2 years
hey @BHinfoSecurity your booth looked lonely so i stole it sry @strandjs @debthedeb @BanjoCrashland
Tweet media one
24
28
893
@_JohnHammond
John Hammond
2 years
you shut your mouth
Tweet media one
37
55
875
@_JohnHammond
John Hammond
2 years
Active Directory content will slowly trickle out on my YouTube channel over the next many days. We will build a local VM environment, stage out our domain at will with PowerShell, and bounce back and forth between "building" and "breaking" AD concepts
26
126
881
@_JohnHammond
John Hammond
4 years
You can use some bash expansion tricks to do a crazy fast port scan. Super helpful if you are an internal network (because nmap through proxychains is horrific). No nmap? No problem.
Tweet media one
24
163
871
@_JohnHammond
John Hammond
3 years
celebrate national cybersecurity awareness month with a four week vacation in the woods
21
72
852
@_JohnHammond
John Hammond
2 years
I record a lot of videos that I think are complete garbage, with mistakes and rabbit holes and wasted time, and I don't think it will be useful for anyone or no one would watch. But I try to remind myself... doing it in the first place is better than not doing it at all.
78
28
850
@_JohnHammond
John Hammond
10 months
@vxunderground Bet, I can record everything and upload it
27
8
851
@_JohnHammond
John Hammond
2 years
Hey boss really sorry I'm not working this week but damn you should see this sunset
Tweet media one
Tweet media two
Tweet media three
Tweet media four
53
9
837
@_JohnHammond
John Hammond
1 month
the end of an era 😭
Tweet media one
117
16
830
@_JohnHammond
John Hammond
3 years
"Isn't it great when the security tool is vulnerable to the security problem"
24
74
806
@_JohnHammond
John Hammond
6 months
Lotta chatter around #ScreenConnect vulnerabilities now as folks are getting spun up. Fellow @HuntressLabs researchers and I were up all night to recreate the auth bypass and RCE exploit. I'm not a huge fan of giving a PoC to threat actors, but I do dig snazzy video demos 😜
24
158
819
@_JohnHammond
John Hammond
2 years
AHAHAHAHAHAHA
@whitecyberduck
Ayub | whitecyberduck
2 years
Offensive Security has banned ChatGPT from the OSCP exam
Tweet media one
32
248
1K
27
60
793
@_JohnHammond
John Hammond
3 years
oSiNt cHaLlEnGe wHeRe aM I?????????//////
Tweet media one
204
38
787
@_JohnHammond
John Hammond
3 years
My video showcasing the #log4j #vulnerability CVE-2021-44228 in Minecraft is up. This demonstrates the #Minecraft exploit but only uses that as a springboard to discuss more of the widespread risk and threats across the security landscape. #cve
20
190
794
@_JohnHammond
John Hammond
1 year
damn they really got me good there
Tweet media one
Tweet media two
33
55
800
@_JohnHammond
John Hammond
2 years
MS-MSDT "Follina" Office click-to-hack.
14
194
785
@_JohnHammond
John Hammond
6 months
I got the most obnoxious and hideous ski jacket as possible. I'm here to meme and troll. I unironically love it.
Tweet media one
134
11
775
@_JohnHammond
John Hammond
2 years
pinned
Tweet media one
47
34
750
@_JohnHammond
John Hammond
2 years
Hey Twitter, forgive me for my crowdsourcing -- what do you think is wrong in the infosec industry? From any perspective.
362
62
743
@_JohnHammond
John Hammond
9 months
oh fuck
Tweet media one
51
13
744
@_JohnHammond
John Hammond
4 years
If you see a /cgi-bin directory on a webserver, don't forget to gobuster inside that directory looking for extensions like .sh, .cgi, (and even .py, .pl, or more).... you might be able to find a Shellshock vulnerability. That bug is... still around...
Tweet media one
6
149
744
@_JohnHammond
John Hammond
2 years
Doomed to set up virtual machines my whole life.
53
39
735
@_JohnHammond
John Hammond
3 years
i FiNaLlY DiD iT aFtEr a LoNg HaRd TiMe i HaVe SuCcEsSfULlY CoMpLeTeD a OnE-DaY StReAk On THM!1111
Tweet media one
42
14
740
@_JohnHammond
John Hammond
18 days
I won't show the full URL, but here's the big link redacted and defanged. Cutesy that it is from a SendGrid tracking link. Obviously a juicy treat for attacker to be able to mass spam emails with a trusted/common delivery service like SendGrid, and a perk of click tracking.
Tweet media one
8
13
751
@_JohnHammond
John Hammond
1 month
Tweet media one
25
77
742
@_JohnHammond
John Hammond
4 months
Sir, this is an entire career path 😅
Tweet media one
11
35
726
@_JohnHammond
John Hammond
2 years
Tweet media one
11
57
711
@_JohnHammond
John Hammond
4 years
Hi yes hello Twitter I am going to tell you my deep dark secret please don't tell anyone I have no idea what I'm doing
44
31
713
@_JohnHammond
John Hammond
4 years
OSEP labs finally complete. Exam in 5 hours. LFG
Tweet media one
70
4
689
@_JohnHammond
John Hammond
9 months
I think am too late for the CounterStrike XSS party :(
Tweet media one
25
30
688
@_JohnHammond
John Hammond
11 months
Hey folks, big project for me at `var dayjob` — @HuntressLabs is hosting a free online CTF, releasing new challenges EVERY SINGLE DAY of October for Cybersecurity Awareness Month😱Malware analysis, DFIR, hacker tradecraft... game starts next Monday 10/2!
Tweet media one
5
202
676
@_JohnHammond
John Hammond
1 year
Thank you so much. Just four more! 😁
Tweet media one
48
15
679
@_JohnHammond
John Hammond
1 month
lmfao
Tweet media one
24
52
688
@_JohnHammond
John Hammond
2 years
🤩view from my office this morning 🥰😊💫 remote lyfe #blessed #workfromanywhere #blessedagain #remotelyfe #views #goals 🌈
Tweet media one
41
50
662
@_JohnHammond
John Hammond
5 months
Just observed APT activity using the "cd" command, be sure to add these TTPs to your detection logic 🚨
39
46
674