geech

@captaingee.ch

cybercrime connoisseur && exploitz engineering enthusiast | synapse fanboy | second breakfast enthusiast

even wearing my flynn's arcade shirt to the theater wasn't enough to save that movie ;( great vfx, great soundtrack, bad movie. long live tron: legacy, the only sequel to tron.

working on a simple web chal and was too lazy to write the ui myself, gemini almost turned this into a second challenge 🙃 age of llm==age of free xss?

Bild

I wrote a new blog with Mandiant IR + FLARE on some new intrusion activity by a group we track as UNC6148, likely using a mix of n-day and 0-day exploits to compromise SonicWall SMA 100 series VPN appliances. They have some nifty post-exploitation tooling as well cloud.google.com/blog/topics/...

Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud Blog

A financially-motivated threat actor is targeting fully patched end-of-life SonicWall devices to deploy a backdoor known as OVERSTEP.

cloud.google.com

if you need to use AggresIve styling, dark patterns, popups, and anti-user defaults to get people to use your new features, maybe they are not good features :)

Too many OPSEC experts out there, I’m an OOPSEC expert. Lmk if you need help adding The Atlantic to YOUR pc small group chats. Signal and more!

reverse engineering and thinking about reducing problem spaces to hit vulnerable code paths is hard. fuzzing however, is both "easy" and "fast" - lazy ftw (may work, may not work, we'll see. need a @digitalocean.com sponsorship lol)

my arch laptop hasnt crashed once since districtcon and has been busy since then, so im just going to chalk it up to "cold dark room is scary to gnome" and pretend this never happened see you at the next talk where it will inevitably happen again

today i used a debugger so bad that you have to nop sled it when inserting breakpoints to ensure they get hit in the place you want. yes i wrote the debugger but thats besides the point