mcmahoniel Profile Banner
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ Profile
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ

@mcmahoniel

Followers
267
Following
502
Statuses
2K

@[email protected] // #infosec // #research // #bugbounty // ViBndWJodHVnIGp1bmcgVidxIHFiIGpuZiwgVidxIGNlcmdyYXEgViBqbmYgYmFyIGJzIGd1YmZyIHFybnMtemhncmYu

::1
Joined March 2007
Don't wanna be here? Send us removal request.
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
5 years
the entire @bryanfuller-verse is a tom paris voyager holodeck creation, this is canon
0
0
4
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
6 months
i’m a big fan of #1password but anything that leaks private information from your vault should be an opt in. even worse, the icons themselves weren’t encrypted until recently (the linked support article still says they aren’t). so local access also leaks vault data.
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
9 months
want to use totp #twofactorauthentication on @Twitch? you must attach a phone number to your account and consent to receiving phone calls and texts from twitch. don't trust twitch and want to remove your phone number after you set it up? you'll lose totp 2fa. 😐
Tweet media one
Tweet media two
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
11 months
the #meta #iaap couldn’t arbitrarily intercept/decrypt traffic, it captured specific traffic on consenting devices only. i’m sure it violated #snapchat terms, but calling it a cyberattack is hyperbole bordering on misinformation. is dlp a cyberattack? (don’t answer that.)
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
#amazon has it out for me
Tweet media one
0
0
2
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
interesting caveats for #apple #visionpro / #visionOS 1.0.* international early adopters hoping to buy in the #us (from : it only supports us english, requires a us apple id, and zeiss will not accept optical prescriptions from non-us opticians (‼️).
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
tfw you spend 20 minutes manually pausing and resuming a download because airport wifi truncates anything over 30 sequential megabytes πŸ’€
0
0
1
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
a third #phishing tweet just got posted, not even going to waste my time with a screenshot this time. how is this account still around? cc/ @steam_support
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
round 2! same tweet, new url. old tweet deleted. #phishing sites now behind @cloudflare. same functionality: <url>/invite works, redirs to a single char substitution. all others throw a fake 404 page, including dev tools. new #twitter #x #verification enables credential theft.
Tweet media one
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
@NahamSec looks like rapid7 has gotten into the brand protection game: πŸ™„ hopefully it won’t take long for them to realize this is a false positive, but i suspect we’ll see this from more companies in the future.
0
0
8
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
round 2! same tweet, new url. old tweet deleted. #phishing sites now behind @cloudflare. same functionality: <url>/invite works, redirs to a single char substitution. all others throw a fake 404 page, including dev tools. new #twitter #x #verification enables credential theft.
Tweet media one
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
"verified" account βœ… linking to #steam account #phishing page βœ… algorithmically recommended to me βœ… clearly the system works. #twitter #x #xitter
Tweet media one
Tweet media two
Tweet media three
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
"verified" account βœ… linking to #steam account #phishing page βœ… algorithmically recommended to me βœ… clearly the system works. #twitter #x #xitter
Tweet media one
Tweet media two
Tweet media three
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
1 year
@maldr0id i also had this happen. i didn't have to update my profile but it looks like i was flagged for being on number of new networks/in a new region.
0
0
1
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
duality of man #dc31 #defcon31 #defcon
Tweet media one
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
.@newrelic is being acquired by private equity. 5 months ago, they wrote a blog post warning @sumologic users that they can't trust the company/product after it was acquired... by the same pe firm. 🀣 unsurprisingly, said blog post has now been scrubbed.
Tweet media one
Tweet media two
4
74
338
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
to everyone overwriting their #reddit posts before deleting their account, remember that there’s no evidence #reddit doesn’t keep multiple revisions
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
.#reddit just revealed their api pricing and it’s… not great (or particularly surprising). justifying the increase as a response to #llm / #chatgpt training, just like #twitter (ignoring that the content is user-generated). πŸ’Έ from #apollo for reddit:
1
0
1
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
blocking single-use/disposable credit cards is a dark pattern. ⚠️ #discord doesn't allow single-use cards for #discordnitro, doesn't facilitate one-time payments, and auto-renews without warning when your free trial/month/year subscription is up.
Tweet media one
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
visiting shady cc processor: "remember the credit card number. it is safe." πŸ‘€ #infosec
Tweet media one
0
0
0
@mcmahoniel
π“ŠˆπŸŒ¬π•žπ•”π•žπ•’π•ͺπ•™β˜°π•žπŸ’¦π“Š‰βΌ
2 years
that didn't take long πŸ˜‚
Tweet media one
0
0
0