Carlos
deyavito.bsky.social
Carlos
@deyavito.bsky.social
Reposted by Carlos
November 28, 2024 at 10:28 PM
Reposted by Carlos
New platform, who dis? It me, and @johnnyspandex.bsky.social dropping some VPN client exploit freshness! 🌮🔒

Today, we're releasing NachoVPN, our VPN client exploitation tool, as presented at SANS HackFest Hollywood. Get it on the @amberwolfsec.bsky.social blog:

blog.amberwolf.com/blog/2024/no...
Introducing NachoVPN: One VPN Server to Pwn Them All
AmberWolf Security Research Blog
blog.amberwolf.com
November 26, 2024 at 10:47 AM
Reposted by Carlos
Chris just added

“Saw some other folks realize its actually really easy to use certificates to authenticate as other users on windows if you have access to the API.

We're now releasing our previously internal make_token_cert bof to auth using only a .pfx file :)”

github.com/trustedsec/C...
github.com
November 18, 2024 at 5:06 PM
Reposted by Carlos
How does the new iOS inactivity reboot work? What does it protect from?

I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.

naehrdine.blogspot.com/2024/11/reve...
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
naehrdine.blogspot.com
November 17, 2024 at 9:42 PM