Pierre Milioni Profile
Pierre Milioni

@b1two_

Followers
263
Following
604
Statuses
68

Joined November 2018
Don't wanna be here? Send us removal request.
@b1two_
Pierre Milioni
13 days
RT @Synacktiv: In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research. Discov…
0
100
0
@b1two_
Pierre Milioni
25 days
RT @Synacktiv: A few months ago, Microsoft released a critical patch for CVE-2024-43468, an unauthenticated SQL injection vulnerability in…
0
63
0
@b1two_
Pierre Milioni
1 month
RT @Synacktiv: We really love relaying authentication: you can now also perform NTLM relaying on SCCM Management and Distribution points th…
0
39
0
@b1two_
Pierre Milioni
1 month
Thrilled to see it merged! Note: some tools may not integrate well (without tweaks) with ntlmrelayx due to, for instance, concurrent LDAP connections, SMB queries before LDAP communications, or starttls. Check this PR comment for details and workarounds:
@Synacktiv
Synacktiv
1 month
You can now use LDAP/LDAPs protocols with the SOCKS proxy of ntlmrelayx thanks to the PR from @b1two_ (now merged upstream). Here is an example with ldeep using relayed authentication from HTTP to LDAPs :
Tweet media one
1
10
39
@b1two_
Pierre Milioni
2 months
RT @_dirkjan: Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID…
0
119
0
@b1two_
Pierre Milioni
4 months
RT @Synacktiv: GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas @alexisdaniza
0
34
0
@b1two_
Pierre Milioni
5 months
RT @_xpn_: Thanks to @0hexit's PR, DPoP auth support has now been added to CloudNine for Okta which is used in agent versions >3.18.0 \o/ h…
0
10
0
@b1two_
Pierre Milioni
5 months
RT @Synacktiv: We just rewrote the AsOutsider part of #AADInternals in Python to enhance compatibility and ease of use in Linux environment…
0
42
0
@b1two_
Pierre Milioni
6 months
RT @zyn3rgy: [Tool & Blog release] - smbtakeover, a technique to unbind/rebind port 445 without loading a driver, loading a module into LSA…
0
116
0
@b1two_
Pierre Milioni
7 months
RT @Synacktiv: Want to know how we prevented some CI/CD supply chain attacks against Microsoft, FreeRDP, AutoGPT, Ant-Design, Cypress, Exca…
0
28
0
@b1two_
Pierre Milioni
8 months
RT @hugow_vincent: I've converted my @sstic talk on #GitHub action exploitation to a series of blogspots with additional details, here is t…
0
7
0
@b1two_
Pierre Milioni
9 months
RT @slowerzs: I wrote a blogpost on injecting code into a PPL process on Windows 11, without abusing any vulnerable driver.
0
247
0
@b1two_
Pierre Milioni
9 months
RT @_r_netsec: AWS CloudQuarry: Digging for Secrets in Public AMIs
0
5
0
@b1two_
Pierre Milioni
9 months
RT @Synacktiv: In his latest blogpost, @yaumn_ analyzes MDI's detection of PKINIT authentication, explains how to bypass it and releases In…
0
48
0
@b1two_
Pierre Milioni
10 months
RT @GrehackConf: Hey folks, We're back, with a great new logo that's right up there with the weather ❄️🥶 And save the date: this year #G
0
18
0
@b1two_
Pierre Milioni
1 year
RT @Synacktiv: Bored of managing multiple proxychains configurations? @hugoclout developed bbs, a swiss army knife proxy manager for red te…
0
41
0
@b1two_
Pierre Milioni
1 year
RT @Synacktiv: Our ninjas, @myr463 and @b1two_, have uncovered various vulnerabilities in Peplink Balance Two devices, including command in…
0
13
0
@b1two_
Pierre Milioni
1 year
RT @_dirkjan: It's been quiet for a while around bloodhound Python, however I'm happy to share that I am now maintaining the project at my…
0
206
0
@b1two_
Pierre Milioni
1 year
RT @mariuszbit: ☢️ClickOnce + AppDomain Manager Injection (aka signed EXE + DLL sideloading) is the new Initial Access Hotness❤️ Check out…
0
126
0
@b1two_
Pierre Milioni
1 year
RT @hexacon_fr: Last sponsor we want to introduce is a special one: it's @Synacktiv, the company organizing #HEXACON2023. Leader in offen…
0
55
0