pry0cc Profile Banner
pry0cc Profile
pry0cc

@pry0cc

Followers
31,229
Following
1,165
Media
2,947
Statuses
45,356

Austin, TX
Joined February 2015
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@pry0cc
pry0cc
4 months
Really can’t see the fucking screen mate
@mgdotdev
Michael
4 months
What stops you from coding like this?
Tweet media one
729
33
1K
59
3K
87K
@pry0cc
pry0cc
5 years
How to dox a hacker and get their address: Ask them: ❌ OSINT Wizardry: ❌ Offer them free stickers: ✅
33
255
1K
@pry0cc
pry0cc
4 years
How to get a P1 XSS in 10 seconds. 1. Find site 2. Find open port 80 3. Visit with Chrome Then I suddenly remember, just: CTRL+SHIFT+J Console > type in the console, alert('hacked') ENTER BOOM! P1 XSS! 🔥 Easy as that! 🤯😇 #bugbounty
Tweet media one
104
211
1K
@pry0cc
pry0cc
3 years
If anybody ever tells you your idea is dumb - just read this post and keep going :)
Tweet media one
29
239
960
@pry0cc
pry0cc
2 years
I’m sorry, what’s Active Directory? Do you mean AzureAD on Prem?
53
87
966
@pry0cc
pry0cc
3 years
This happens all the time. 1. Company hires talented person 2. Person single handedly builds critical stuff that needs building and fights for it 3. Management underpay that person 4. That person leaves 5. The company flails because they didn’t know what they had
Tweet media one
14
156
920
@pry0cc
pry0cc
4 years
The saddest thing about IT & Cybersecurity is that 99% of the problems we're facing are not technical. They're cultural, management and budget-related. Implementing basic security controls, patching regularly, segmenting your network, EDR/AV on everything, it's basic shit.
21
181
719
@pry0cc
pry0cc
4 years
Hey you, If you want to upgrade your cat, try bat. alias cat="bat --style=grid" It does automatic syntax highlighting, will automatically 'less' itself if your file is too large, and detects automatically when you pipe it so it doesn't inject colors.
Tweet media one
19
152
721
@pry0cc
pry0cc
2 years
So I applied… and…. I got the job! 😃 Offensive Security Engineer @ AWS, starting in 2 weeks. Wish me luck :)
@AustinSturm
Austin Sturm
2 years
Hey, I am hiring (Virtual US Support) to help me run the Bug Bounty program over here at AWS. Looking for an experienced TPM and Security Engineer that want to help drive new program initiatives, expand our program, build a community and of course day-to day operations.
5
33
118
81
7
706
@pry0cc
pry0cc
4 years
Ok, hear me out. If you’re just starting offensive security / learning to hack. Learn your fundamentals, Linux shell, windows shell, networking, HTTP. Then watch every single one of @ippsec ’s videos and break them down and take notes. Then follow along. You’ll get good quick 👍
23
126
698
@pry0cc
pry0cc
4 years
OK! I'm going to talk to you today about the Flipper Zero. You may not have heard about it, but it's fucking epic.
Tweet media one
29
167
650
@pry0cc
pry0cc
4 years
HEY! SERIOUSLY. Do not ever underestimate the power of OSINT when doing pentests or webapps (especially if its scoped tightly) I just got root user MySQL creds this way - expand this and I'll explain how I did it. 👇👇👇
18
169
625
@pry0cc
pry0cc
4 years
Hacking is usually 99% 'jus trying shit' and 1% "FUCK YEA IM A GENIUS"
23
80
577
@pry0cc
pry0cc
3 years
Little word to employers in the security space: There are barely any qualified and experienced people in this field. *Only* hiring experts is *not* sustainable. We need to get into the mindset of hiring and investing in people early on. Don’t buy a grown tree, buy a seed.
18
95
565
@pry0cc
pry0cc
3 years
If you could share one bash trick to a friend hacker what would you share? 🧵🪡🔥👇
138
111
531
@pry0cc
pry0cc
5 years
Hey. You. The one judging me for being young. Yes I am 20, yes my girlfriend is older than me, yes I founded a cybersecurity forum at 16, yes I never went to Uni, yes I already nearly have 2 years xp as a pentester / security pro. Stop 👏 judging 👏 me 👏 by 👏 my 👏 age.
65
29
525
@pry0cc
pry0cc
3 years
Getting married in a few hours! 🔥😍
60
2
519
@pry0cc
pry0cc
5 years
DAMNN People just be dropping ClamAV 0days like its hot 👌🔥🔥🔥 And on Pastebin, anonymously!
4
216
491
@pry0cc
pry0cc
1 year
Oh yeah, you like Linux? Name 10 Linux distros.
Tweet media one
103
42
449
@pry0cc
pry0cc
3 years
Want to "hack" into something for the first time in under 1 hour? (For moderate technical) If you're new - this is a fun way to get started (it's how I got started). Get an app called "fing" on your phone, join client network, scan for devices, then port scan each device. 1/2
18
79
443
@pry0cc
pry0cc
3 years
If you want to make a pentester go crazy, give them a non-vulnerable web app and tell them it’s vulnerable to a vulnerability and it’s easy to find and exploit. Then watch them melt down.
38
44
428
@pry0cc
pry0cc
5 years
She got me this. I’m literally the happiest dude alive rn
Tweet media one
15
43
431
@pry0cc
pry0cc
4 years
This is insanely hard to resist.
Tweet media one
7
44
401
@pry0cc
pry0cc
3 years
I don’t know who needs to hear this, STOP SENDING YOUR RESUME AS A DOCX SEND IT AS A PDF YOU FUCKING DONUT
52
24
399
@pry0cc
pry0cc
4 years
Man, Axiom is building a pretty impressive portfolio of tools. aquatone httprobe subfinder assetfinder gf masscan sn0int kxss jq SecLists gobuster nmap waybackurls amass anti-burl Golang (setup, path configured, latest version) hakrawler
14
164
400
@pry0cc
pry0cc
3 years
Most people running vuln scans don’t know how to interpret the results
37
23
393
@pry0cc
pry0cc
3 years
Pentesting expectation: Hacking into the mainframe, EDR evasion, physical penetration, sliding past blue teamers. Pentesting reality: Taking a screenshot of a password reset page that responds "invalid email" if the email is invalid.
5
40
347
@pry0cc
pry0cc
2 years
Cybersecurity caption this 👇
Tweet media one
13
20
336
@pry0cc
pry0cc
4 years
Doing internet scanning research? I have a list of IP ranges owned by top cloud providers, AWS, Azure, GCP, Godaddy, Linode, Rackspace. All ready for internet research with masscan!
Tweet media one
13
120
340
@pry0cc
pry0cc
4 years
Wow I did not know this! proxychains -q zsh Now all your connections are tunneled through your SOCKS proxy! how sick is that!
6
80
329
@pry0cc
pry0cc
4 years
Ok. Today is the day. It's not finished - but it's good enough to release. A set of utilities for managing and setting up your own hacking infrastructure on DO, preinstalls all the packages you could ever want for #redteam and #BugBounty !
Tweet media one
23
113
321
@pry0cc
pry0cc
4 years
How to get a P1 in 45 seconds. 1. Subfinder and resolve IPs 2. Find open port 80 Then I suddenly remember, just: nc -v host 80 P1! 🔥🔥🔥😵 Easy as that! 😇 #bugbounty
43
46
321
@pry0cc
pry0cc
3 years
STOP PUSHING SECRETS TO REPOS
30
44
320
@pry0cc
pry0cc
3 years
More secure than a password manager when locked in a safe or not? What do you think? 🤔
Tweet media one
54
43
310
@pry0cc
pry0cc
5 years
To everybody trying to break into security. YOU DON’T NEED KALI. Install pretty much any Linux distro, you’ll be covered. Why would you daily Ubuntu and then run a Kali VM? Doesn’t make any sense to me. Stop worrying about your OS and start learning about actually hacking.
28
53
311
@pry0cc
pry0cc
4 years
If you were going to build a cybersecurity sticker starter pack, what would you include? 😅 Let me know below! Might be working on something 👀👇
Tweet media one
37
47
299
@pry0cc
pry0cc
4 months
Tweet media one
1
1
307
@pry0cc
pry0cc
3 years
People who WFH, how long is the transition between you waking up and starting your workday? If you start at 8, what time do you get out of bed? 😅
370
7
306
@pry0cc
pry0cc
3 years
I know a lotta infosec people also carry firearms. Drop your EDC Concealed carry setup below I’m excited to get my own!
149
13
287
@pry0cc
pry0cc
4 years
Im super proud to announce I will be joining @Truesec as a Senior Cyber Security Consultant! 🎉🎉🔥 I’m listed alongside some absolute industry legends here, and for that I am very humbled! Looking forward to preventing breaches and having fun! 🔥❤️👌🏼
71
8
294
@pry0cc
pry0cc
3 years
Going to show ya’ll how to solve a problem that took me way too long to solve. 🧐 How do you extract all the URL’s for web servers from an nmap scan? & How do you account for vhosts when doing so? The old way to discover web servers on a list of targets was one of two ways 🧵
14
86
295
@pry0cc
pry0cc
3 years
Incase you weren't already aware - I maintain a custom wordlist generator called "relevant wordlists". Every couple months I scrape headlines from news sources all over the world and put the unique words into a wordlist. This is useful for cracking! 🔥
Tweet media one
8
86
290
@pry0cc
pry0cc
4 years
Ya boi just got promoted. 😎 We also might happen to be looking for a new hire in UK or US, fully remote.
34
15
286
@pry0cc
pry0cc
3 years
age=$((age+1)) 🎉✌️
59
6
282
@pry0cc
pry0cc
4 years
Peeps - you don't need a MacBook Pro to hack. All you really need is a light laptop that can run Linux or a cheap Macbook and then just abuse the shit out of the cloud. It's seriously the way. I built all of 0x00sec on a HQ Compaq 2710p, with a broken screen.
22
23
281
@pry0cc
pry0cc
3 years
Cheeky 2 week honeymoon in NJ and then back to the UK while the paperwork processes…. ✌️🔥🇺🇸😴
Tweet media one
12
0
278
@pry0cc
pry0cc
4 years
Oh my god. These guys reverse-engineered Stuxnet, and then wrote working C code from those reverse engineered binaries. HUGE props to these guys, this is amazing.
2
109
275
@pry0cc
pry0cc
3 years
wear it like a sash of honour
Tweet media one
25
13
273
@pry0cc
pry0cc
2 years
You prolly don’t need a mentor. I mean, they can help. But you don’t need somebody to handhold you into being a hacker. Go get OSCP, hackthebox and do bug bounty, get a few reports, then get a job. In that order. That’s it. It might take you 5 years. Be patient.
19
40
271
@pry0cc
pry0cc
3 years
From Stranger to DA // Using PetitPotam to NTLM relay to Domain Administrator - TRUESEC Blog ✌️ Just dropped my first blog for ⁦ @Truesec ⁩ on how to use PetitPotam to relay to AD CS to get DA. 🔥🙌🏽 Let me know what you think! And please share! 😁
6
118
277
@pry0cc
pry0cc
2 years
First day @ AWS was a success 😁💯
15
2
270
@pry0cc
pry0cc
4 years
I recently learned that you can do: nmap -T4 -iL ips -sV --top-ports 2000 -oA scan/%d-%m-%y And provide %d %m %y to format the date into the output file! Pretty cool! 🔥
5
57
275
@pry0cc
pry0cc
5 years
Guys seriously. You HAVE to start doing hacktheboxes. They’re so hard for a newbie to start, but you eventually learn enough to start owning boxes. And that’s where the magic happens. You can develop experience artificially.
14
29
269
@pry0cc
pry0cc
4 years
Do you want to hear a piece of my secret to success? Failure. Fail often. Everytime you make a mistake, you have an opportunity to learn. Take risks. Try things out. If it fails 99% of the time - amazing. You have a 1% success and you can learn 99% of the time :)
16
60
262
@pry0cc
pry0cc
4 years
Just tested axiom-scan w/ masscan, full port range 0-65535 on 10k IP addresses. Took 19 minutes across 10 instances. That's 9 IP's per second using full port ranges :D We found 118,635 total services.... in 19 minutes....
Tweet media one
17
24
258
@pry0cc
pry0cc
3 years
You can learn everything in this list with a good level of competency within 5 years
@Sukriti_Macker
Sukriti Macker
3 years
This is just 😂 So.. people applying for the role of Full Stack Web Developer this for you 🤣
Tweet media one
78
1K
6K
21
32
251
@pry0cc
pry0cc
4 years
I've recently shifted my entire pentest and hacking methodology to using axiom instances for everything. I don't hack from my local box anymore. Let me show you how I hack these days: 1) Spin up an instance, axiom-init 👇👇🔥
7
58
259
@pry0cc
pry0cc
4 years
This is fucking scary. A security researcher found with Chase bank you could send negative balances to other accounts and accumulate thousands in travel points. They reported it, Chase bank closed all their accounts...😠
Tweet media one
10
104
257
@pry0cc
pry0cc
3 years
DEF CON is cancelled due to COVID
9
25
246
@pry0cc
pry0cc
2 years
🚨HOW TO GET RCE ON AWS IN 60 SECONDS 🚨 1. Register an account 2. Spin up an EC2 instance 3. SSH in Boom, you just got RCE on a cloud provider.
11
32
251
@pry0cc
pry0cc
3 years
Windows, can you stop fucking turning on real-time protection after I turn it off, you’re deleting my work. You fucker.
22
15
244
@pry0cc
pry0cc
5 years
@HackingLZ I figured it out. alias nmap="grc nmap" ;) You're welcome.
Tweet media one
15
76
244
@pry0cc
pry0cc
3 years
Do you ever just look at code and think "what the fuck" ?
29
15
242
@pry0cc
pry0cc
4 years
Tip for pentesters: If you have a windows lab, watch the event log as you own the network. Watch the event IDs and learn them! A SOC is going to analyse those IDs and use it to track you, if you can tell them what they should’ve seen in the logs post test- it’s super helpful!
3
27
242
@pry0cc
pry0cc
4 years
Finding bugs in pentests is way easier than bug bounty IMO I find the dumbest shit in my pentests
23
14
237
@pry0cc
pry0cc
5 years
Excuse me - what the actual fuck is automated penetration testing? 🙃
83
36
235
@pry0cc
pry0cc
2 years
Does anybody know of good resources to brush up on code review and identifying vulnerabilities in code?
29
38
234
@pry0cc
pry0cc
4 years
🚨 ANNOUNCEMENT 🚨 I’m proud to announce that today, I will be transitioning the #axiom base image from Ubuntu to Hannah Montana Linux! 🔥🔥👌🏼 I hope you all enjoy this fantastic upgrade of a base image!!!
Tweet media one
18
21
233
@pry0cc
pry0cc
4 years
Does anybody else use two browsers for web testing? One for research and one for testing?
47
8
230
@pry0cc
pry0cc
4 years
Ok. It's live! A new blog post - it was time for Delta to get some love, that is where I have used this most at @NaviSecCyber Unmasking and Bypassing WAF's including #CloudFlare ! 🔥✅ I really hope you like it :) #redteam #bugbounty
8
81
223
@pry0cc
pry0cc
3 years
Just released a little utility with the help of the legend @hakluke 🏆 It converts nmap xml to IP:Port notation, and it’s in Go, which means you can run it as a binary which is insanely useful for me personally. E.g tew nmap.xml | httpx
6
51
223
@pry0cc
pry0cc
3 years
How did I not know about this resource? XSS Cheatsheet!
Tweet media one
4
44
213
@pry0cc
pry0cc
3 years
What Websites and RSS feeds do you get cybersecurity news from?
38
28
213
@pry0cc
pry0cc
2 years
Office vs WFH ❤️
5
29
210
@pry0cc
pry0cc
3 years
I can't run Nmap without -sV these days, it feels wrong
20
18
204
@pry0cc
pry0cc
3 years
Somebody needs to figure out how to hire and make really good use of the people who want to go from general IT Helpdesk skills and level up to a security practitioner in some aspect. There are thousands of people in this place begging to get into infosec that hit hiring walls
22
27
202
@pry0cc
pry0cc
3 years
This is what happens when y’all say HTML is a programming language and not markup 😭🤣
@GovParsonMO
Governor Mike Parson
3 years
We want to be clear, this DESE hack was more than a simple “right click.” THE FACTS: An individual accessed source code and then went a step further to convert and decode that data in order to obtain Missouri teachers’ personal information. (1/3)
Tweet media one
Tweet media two
2K
40
130
8
25
201
@pry0cc
pry0cc
3 years
Sigh... Every time....
Tweet media one
9
33
205
@pry0cc
pry0cc
4 years
Oh? You're a hacker? Name every single port....
55
10
203
@pry0cc
pry0cc
3 years
I can't explain why but the feeling when this works never feels gets old :P
Tweet media one
20
18
202
@pry0cc
pry0cc
3 years
Married 🥂
39
1
206
@pry0cc
pry0cc
4 years
Fuck "ip addr" man Ifconfig / net-tools all fucking day.
14
18
203
@pry0cc
pry0cc
2 years
Marriage Visa Approved 🎉 Im coming home soon to be with @loquaciousloka forever ❤️🥂🍾
29
2
201
@pry0cc
pry0cc
2 years
If you wanna feel needed, get really good at regex 💫
10
11
196
@pry0cc
pry0cc
5 years
When you don’t have a requirements.txt so you just pip install a new dependency every time you run it.
@kashthefuturist
Dr. Kash Sirinanda
5 years
#DrKashCaptionChallenge .... Caption this...
388
675
1K
7
33
196
@pry0cc
pry0cc
4 years
Just #goodvibes and axiom fleet development 🔥👊🏼 This is axiom-scan performing a distributed nmap scan across a fleet of instances, then outputting to a bootstrap HTML searchable page. Thanks to @stokfredrik for bouncing ideas off of, 100% credit to him for the XSL idea!
4
32
196
@pry0cc
pry0cc
3 years
Ok... So it seems that you can enumerate & validate o365 emails using ffuf 👇 Scrapes the /GetCredentialType endpoint matching regex.. 🥳 ffuf -w emails.txt -X POST -d '{"username":"FUZZ"}' -u https://login.microsoftonline[.]com/common/GetCredentialType -mr 'IfExistsResult":0'
Tweet media one
4
46
202
@pry0cc
pry0cc
3 years
I've taken a small detour away from Offensive Security and been doing Linux Forensics & Incident Response. I really enjoy this new field of IR, it is a lot like pentesting and enumerating just backwards. With a different perspective.
10
10
190
@pry0cc
pry0cc
4 years
Pssst Did you know I dropped an article last night on WAF Bypasses using OSINT & a bunch of other tricks?
2
56
192
@pry0cc
pry0cc
4 years
- Google dorked site - Found open HTTP dir - Navigated there - was patched - Viewed Google Cache, Error log path was exposed - Copied that same path to the / of the site, downloaded 300MB of web error logs. - Parsed the errors found creds in plaintext.
5
28
191
@pry0cc
pry0cc
4 years
I just uploaded my first proper cybersec video to YouTube! First time I've edited in a little while :) Felt good to get my creative on :P ---------------------- Axiom Demo - Resolving 6 million domains in 5 minutes with 100 instances! 🔥🎉
13
33
189
@pry0cc
pry0cc
6 years
I'm so surprised this method still works to bypass Windows Defender.
1
65
189
@pry0cc
pry0cc
4 years
My amazing girlfriend @akolsuoicauqol is taking her CISM exam RIGHT NOW! She has been studying so hard for this, and I’m so proud of her no matter what the outcome is :) 🎉
Tweet media one
13
2
184
@pry0cc
pry0cc
2 years
FYI to y’all: I don’t hold any certs - none. I left school at 16. I had a website, a GitHub repo and a hackthebox rank. Lots of companies are waking up to the reality that the talent in this industry don’t require letters to their name, they have code.
Please do me a favor. Talk to your hiring departments and ask them to look at an individuals success in online cyber ranges the same as certs. We need to open more pathways into this industry.
31
79
506
15
26
186
@pry0cc
pry0cc
4 years
I just wrote a keybind to take the image from my clipboard, run it through OCR (extract the text), and then copy the output to my clipboard. Now I can copy-paste text THROUGH images 😍
11
44
185
@pry0cc
pry0cc
5 years
Project Crobat is really the fastest DNS enumeration method yet Being fully opensourced in the near future :) Supports full wildcard on domain index too. Search by {domain}.* and pull all subdomains.
1
32
184
@pry0cc
pry0cc
3 years
Just found 10 SQL Injections within the first 30 minutes of this test 🥳
4
7
175
@pry0cc
pry0cc
4 years
WAF Bypasses are a really common finding on pentests lately - they're easy to do but can have quite a big impact if they have vulns hiding underneath. Should I do a writeup? Is it even worth talking about or is it too skiddy? :P Let me know.
24
6
174
@pry0cc
pry0cc
3 years
Tweet media one
15
13
176
@pry0cc
pry0cc
2 years
GitHub - johnnyxmas/ScanCannon: Combines the speed of masscan with the reliability and detailed enumeration of nmap This has some cool bash code to steal
2
44
169