Joshua Wright's Avatar

Joshua Wright

@joswr1ght.bsky.social

Professional hacker, accidental educator. Rhode Island is not an island.

280 Followers  |  159 Following  |  34 Posts  |  Joined: 02.03.2024  |  2.1802

Latest posts by joswr1ght.bsky.social on Bluesky

Thatโ€™s me! ๐Ÿ™Œ

16.03.2025 11:52 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

On Thursday I presented at Way West Hackinโ€™ Fest in Denver to a group of friends, colleagues, and my son! I appreciate this community of people who come together to learn, to be supportive, and to have fun! (Slides and hopefully video shared soon.) Thank you #wwhf!

08.02.2025 13:46 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Making Hacking Accessible The guide on how to make hacking accessible

I have a friend who became blind in her 50s almost overnight. Helping her with using computers has helped me understand the need for better accessibility in a way that I never understood before.

We can all do better in making technology more accessible. Please do.

bees.substack.com/p/making-hac...

01.02.2025 16:33 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you! Delta 400 cost always seemed hard to justify when HP5 does the job. A little enlarger filtering does indeed go a long way.

30.01.2025 13:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What do you prefer about Delta 400 vs. HP5? The blacks in these photos look fantastic, but maybe thatโ€™s post-processing?

30.01.2025 12:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Deepseek R1 Explained by a Retired Microsoft Engineer
YouTube video by Dave's Garage Deepseek R1 Explained by a Retired Microsoft Engineer

This video from Dave Plummer really helped me understand the implications and methods behind DeepSeek. Worth a listen! youtu.be/r3TpcHebtxM?...

28.01.2025 18:49 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Today I realized Iโ€™m the person people at work turn to when they have Git questions or problems.

Me.

How did we fall so far? ๐Ÿ˜ฌ

10.01.2025 18:04 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Happy birthday to the unusual number of my cybersecurity friends who all have January 1st birthdays on Facebook! ๐Ÿง๐Ÿง๐Ÿง

02.01.2025 13:47 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Ghostty Ghostty is a fast, feature-rich, and cross-platform terminal emulator that uses platform-native UI and GPU acceleration.

Ghostty 1.0 is now available and it's amazing. ghostty.org #terminal #macos #linux

28.12.2024 11:59 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Reminds me of the set of Tiny Music Desk. Maybe youโ€™ll play there someday!

28.12.2024 14:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Whoa, nicely done!

28.12.2024 14:54 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

TIL โ€œflag plantingโ€ exists outside of CTF cyber competitions. ๐Ÿง

15.12.2024 15:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I feel like those kind of shows were my favorite when I was younger and a rarity today. Glad you got to catch them!

14.12.2024 17:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Love that talk title!

14.12.2024 11:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - iknowjason/edge: Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean. Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean. - iknowjason/edge

TIL about github.com/iknowjason/e..., a useful utility to assist in figuring out โ€œwhat cloud provider/region is this entity deployed in?โ€

$ ./edge -single 140.179.144.130
โ€ฆ
[INF] Matched IP [140.179.144.130] to Cloud Service [API_GATEWAY] and Region [cn-north-1]

14.12.2024 02:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Just avoid cliches like the plague.

13.12.2024 23:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

13.12.2024 22:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Important for parents/anyone guiding/mentoring kids-especially middle/high school: make sure they know ChatGPT etc are mostly WRONG and should never be used as sole sources!! Itโ€™s an important lesson because the (VC-fueled) tech media fawns over the lie engines as if theyโ€™re the second coming.

10.12.2024 16:59 โ€” ๐Ÿ‘ 6    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Sure, but any sigsegv in a kernel module is a possible pathway to root on a system where you donโ€™t have root access.

Iโ€™m really just trying to offer a bright outlook to your driver crash. ๐Ÿ˜‚

10.12.2024 15:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

On the plus side, every kernel module crash is an opportunity for privilege escalation? ๐Ÿคทโ€โ™‚๏ธ

10.12.2024 15:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
a red among us character with horns and the word sus on it 's face . ALT: a red among us character with horns and the word sus on it 's face .

I find this reporting โ€ฆ

10.12.2024 15:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

A crash of what nature? ๐Ÿง

10.12.2024 15:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Man near bear in forest with text โ€œIf you meet a bear in the forest, just ask him to review your pull request so he pretends he didn't notice you and goes awayโ€

Man near bear in forest with text โ€œIf you meet a bear in the forest, just ask him to review your pull request so he pretends he didn't notice you and goes awayโ€

04.12.2024 17:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Here, here. --break-system-packages is unnecessarily foolish.

03.12.2024 17:41 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

For the love of all holy just buy film.

03.12.2024 16:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Risky Business  Weekly (771): Palo Alto's firewall 0days are very, very stupid
YouTube video by Risky Business Media Risky Business Weekly (771): Palo Alto's firewall 0days are very, very stupid

"Our job is to make it safe, not to tell [users] not to click on things on the *thing clicking machine that we gave them*" @metlstorm.risky.biz

I'm planning on repeating this quote quietly to myself at least once a week for the rest of my days.

www.youtube.com/watch?v=Rxye...

03.12.2024 14:57 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2

AI has taught me many things.

First and foremost is that I hate bulleted lists. #ai

02.12.2024 22:00 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Itโ€™s not a good bouldering session without some scrapes!

01.12.2024 19:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - Invicti-Security/brainstorm: A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery - Invicti-Security/brainstorm

As a pen tester, I'd be uncomfortable submitting my methodology fusing only Brainstorm (AI endpoint fuzzer) due to the non-deterministic nature of the tool. Maybe more valuable to integrate with strong list-based discovery and some AI-driven endpoint identification? github.com/Invicti-Secu...

30.11.2024 13:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs Brainstorm is a new, smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery

Article by Bogdan Calin on using local LLMs to improve endpoint/file discovery. I'm not sure how practical this is for pen testers, but optimizing requests to avoid WAFs is real. www.invicti.com/blog/securit...

30.11.2024 13:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@joswr1ght is following 20 prominent accounts