Dominic White
@singe.bsky.social
1.2K followers 730 following 550 posts
Hacker at Orange Cyberdefense's SensePost Team https://hello.singe.za.net/
Posts Media Videos Starter Packs
singe.bsky.social
Turgid with blood even.
singe.bsky.social
Rewatching this banger of a talk, that we’re now spoiled with two versions of; the original DEFCON 33 main stage talk, and the follow up RomHack 2025 talk with the PipeTap additions.

DEFCON https://youtube.com/watch?v=zSBf2CMKlBk
RomHack https://youtube.com/watch?v=_39UbCePFfw
Reposted by Dominic White
Reposted by Dominic White
timmedin.bsky.social
I think about this often.
What is a real world bad guy's level of effort for cracking?
How long do they spend?
How big is their cracker?
Do they have multiple crackers?
How do they distribute the load?
raphaelmudge.bsky.social
My understanding from @timmedin.bsky.social is RC4 risk is mitigable w/ a properly (service account std differs from user account) strong password. If it was never cracked by a pen tester, because their level of effort vs. adversary effort differed--how would Ascension know it wasn't strong enough?
Reposted by Dominic White
singe.bsky.social
Looking forward to the #romhack live stream on Saturday to see three of my favs - @titon, @leonjza & @albinowax
Reposted by Dominic White
ellearmageddon.bsky.social
i don’t think i’m autistic because my mom took tylenol while she was pregnant with me, i’m pretty sure it’s because she decided to reproduce with a guy who had an engineering degree, a ham radio hobby, and an inability to wear clothing not made from natural fibers
singe.bsky.social
I still remember listening to Halcyon On & On landing in Vegas for my first BlackHat/DC in 2008.
singe.bsky.social
Oooh ooh, did you bite the one end off and drink milk through it like an adult or chew it dry and dainty like some sort of psychopath? Well done on the talk (I haven’t seen it yet, is there a recording or too soon?)
singe.bsky.social
That was so interesting. When they placed a new case sealant strip that was perfectly aligned to the new case I was pretty sure this stuff is possible due to major leaks out of the factories producing the new iPhones.
Reposted by Dominic White
dirkjanm.io
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
dirkjanm.io
singe.bsky.social
That’s a great description!
singe.bsky.social
I’m struggling with my emotions this game. I keep wanting to look away in frustration but then the play is constantly compelling and intense.
singe.bsky.social
I had occasion to hack on some Wordpress’es and realised there’s a ton of surface area exposed over the "new" REST interfaces. Here's a small utility to convert it into a OpenAPI/Swagger file so you can explore it in your pentests/bug bounty work. github.com/sensepost/wp...
It turns this into this, with two screenshots, one of a browser showing the /wp-json endpoint and the other with a swagger-ui view of the same.
singe.bsky.social
That made me laugh out loud.
Reposted by Dominic White
tashjoeza.bsky.social
When FW De Klerk died someone on Twitter scolded me for sharing an old Private Eye cover about Verwoed's assassination (it was celebratory). "What if that was your grandpa?"

Neither of my grandpas were war criminals and, if they were, I hope people would chat huge shit when they died.
phaezen.bsky.social
"Don't speak ill of the dead"

Why not? Why do people get to be insufferable arseholes thier entire lives and then suddenly we have to treat them like saints?
singe.bsky.social
It used to be that “not supporting the murder of people I don’t like” wasn’t a controversial stance.

Yes, even if they called for my murder.
singe.bsky.social
I’ve been watching the inside track on this one, it’s super cool.
leonjza.bsky.social
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
The proxy view for PipeTap, a Windows Named Pipe Analysis Tool
Reposted by Dominic White
leonjza.bsky.social
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
The proxy view for PipeTap, a Windows Named Pipe Analysis Tool