Manu Kiesel's Avatar

Manu Kiesel

@rtfmkiesel.bsky.social

something something πŸ₯yber

88 Followers  |  65 Following  |  45 Posts  |  Joined: 06.12.2023  |  1.5435

Latest posts by rtfmkiesel.bsky.social on Bluesky

Compromised Donor Emails: A post-mortem – Pi-hole

well, there goes the empty HIBP dashboard...

pi-hole.net/blog/2025/07...

the vendor's response is fcking mental

github.com/impress-org/...

31.07.2025 23:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

BloodHound v8.0 is here! πŸŽ‰

This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID.

Read more from Justin Kohler: ghst.ly/bloodhoundv8

🧡: 1/7

29.07.2025 13:13 β€” πŸ‘ 13    πŸ” 10    πŸ’¬ 1    πŸ“Œ 1
VirusTotal VirusTotal

I'm not a (Android-) malware analyst. Maybe someone you know wants to take a closer look at this. Download via og site or
www.virustotal.com/gui/file/6fe...

7/7

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Static cryptography in a malware version of "Bitchat"

Static cryptography in a malware version of "Bitchat"

And unhackable cryptography 6/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
References to RayV2 in a malware version of "Bitchat"

References to RayV2 in a malware version of "Bitchat"

Also proxies 5/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
References to cryptocurrency stuff in a malware version of "Bitchat"

References to cryptocurrency stuff in a malware version of "Bitchat"

It has references to a lot of cryptocurrency stuff 4/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Permissions requested by a malware version of "Bitchat"

Permissions requested by a malware version of "Bitchat"

It wants a few permissions 3/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Download URL for a malware version of "Bitchat"

Download URL for a malware version of "Bitchat"

The fake one distributes a ~500MB APK via myhuaweicloud while linking to the og source code. 2/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
bitchat

🚨 To everyone wanting to try out the new p2p chat app Bitchat: Be aware, there is already at least one fake website: bitchats(dot)app! 🚨

The legit one, based on the GitHub account, is bitchat.free.

1/X

28.07.2025 19:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Generate a "roadrecon auth" command by extracting tokens from portal.azure.com Generate a "roadrecon auth" command by extracting tokens from portal.azure.com - roadrecon_azure_portal.js

gist.github.com/rtfmkiesel/1...

22.07.2025 14:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
matelab.ch - The Swiss Mate Index Compare mate-based beverages

πŸ‡¨πŸ‡­ πŸ§‰ With Landi's Farmer Mate, we're now at 54 mate-based beverages! It also takes the spot for cheapest 1 mg of caffeine per beverage, as it is just 1 Rp cheaper than Migros Lamate.

Also, the site had a small re-design.πŸ‘Ύ

matelab.ch

22.07.2025 07:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

wtf is going on with @github.com... I need to login to view a (public) repo?

16.07.2025 05:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
matelab.ch The Swiss Mate Index

πŸ‡¨πŸ‡­ πŸ§‰ With Migros Lamate, we're now at 52 mate-based beverages! It also claimed the spot for cheapest 1 mg of caffeine per beverage.

matelab.ch

05.07.2025 20:29 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

BloodHound Queries For All
queries.specterops.io

18.06.2025 08:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Thanks for the feedback. Yea it was because I was not logged in, I was not able to see the tweets.

10.06.2025 10:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
BSides Zurich on X: "πŸ”₯ Save the Date: #BSidesZH Summer BBQ!Β πŸ”₯ Join us on 28 August 2025 for a relaxed evening of great food, drinks, and conversation at theΒ #BSidesZH #BBQΒ β€” the perfect chance to connect with fellow #infosec enthusiasts in a cozy, informal setting. /Cc @SecurityBSides https://t.co/JFyrmmTme0" / X πŸ”₯ Save the Date: #BSidesZH Summer BBQ!Β πŸ”₯ Join us on 28 August 2025 for a relaxed evening of great food, drinks, and conversation at theΒ #BSidesZH #BBQΒ β€” the perfect chance to connect with fellow #infosec enthusiasts in a cozy, informal setting. /Cc @SecurityBSides https://t.co/JFyrmmTme0

A wow...

If you are not logged in, the profile page won't show posts. But a direct link still works.

x.com/BSidesZurich...

10.06.2025 09:50 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Did they?

10.06.2025 09:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

I'm not affiliated with BSides Zurich btw. Their social media situation seems a bit fcked as X and Mastodon both seem dead.

Does somebody know someone there?
@defconch.bsky.social or maybe @candid.bsky.social ?

Also, the date is wrong on the page :P

10.06.2025 09:34 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
BSides Zurich BBQ on 28th August 2025

BSides Zurich BBQ on 28th August 2025

bsideszh.ch

10.06.2025 09:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
A German tech news site with about a 70/30 ratio of ads to content

A German tech news site with about a 70/30 ratio of ads to content

Seriously, wtf happened to the web? How do people live without ad block?

10.06.2025 07:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A very insecure sudoers file

A very insecure sudoers file

task failed successfully

21.05.2025 17:36 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
UUIDs Don’t Replace Authorization | Manu Kiesel An IMHO on why blindly trusting UUIDs is bad

Better late than never, here is my take on the somewhat recent internet beef around UUIDs

mkiesel.ch/posts/uuids-...

12.05.2025 18:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If your website's main function is searching something, the cursor should be inside the search field by default. ffs...

30.04.2025 12:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
pocs/Cordaware at main Β· cyllective/pocs A repository containing various PoC payloads. Contribute to cyllective/pocs development by creating an account on GitHub.

Some of the PoCs now online

github.com/cyllective/p...

28.04.2025 15:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

3 milliseconds to admin β€” Our analyst John Ostrowski turned a DLL hijacking into a reliable local privilege escalation on Windows 11. He chained opportunistic locks, and API hooking to win the race to CVE-2025-24076 & CVE-2025-24994. Read his blog post: blog.compass-security.com/2025/04/3-mi...

15.04.2025 09:00 β€” πŸ‘ 21    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

youtube[.]com/feeds/videos.xml?channel_id=UCy0tKL1T7wFoYcxCe0xjN6Q

The channel ID/URL can be found by searching for "application/rss+xml" or "channel_id" in the HTML source while viewing someone's channel page. (The forbidden F12 button)

2/2

31.03.2025 18:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Algorithms are breaking how we think
YouTube video by Technology Connections Algorithms are breaking how we think

I highly recommend @techconnectify.bsky.social "Algorithms are breaking how we think"

www.youtube.com/watch?v=QEJp...

Since I get all my "news" via RSS feeds, I can add one more way of getting YouTube content:

You can subscribe to YouTube channels by RSS!

1/2

31.03.2025 18:46 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Persistence with VSCode plugin backdoors How to achieve persistence by backdooring installed VSCode plugins

g00d read πŸ‘Ύ Shameless self plug ... it also does not validate the checksum of installed extensions

mkiesel.ch/posts/vscode...

01.03.2025 20:57 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Screenshot showing the execution of the proof-of-concept named PowerChell in comparison to a typical PowerShell prompt. In particular, it shows that PowerChell is able to bypass the Constrained Language Mode (CLM).

Screenshot showing the execution of the proof-of-concept named PowerChell in comparison to a typical PowerShell prompt. In particular, it shows that PowerChell is able to bypass the Constrained Language Mode (CLM).

In this blog post, I explain how I was able to create a PowerShell console in C/C++, and disable all its security features (AMSI, logging, transcription, execution policy, CLM) in doing so. πŸ’ͺ

πŸ‘‰ blog.scrt.ch/2025/02/18/r...

19.02.2025 09:13 β€” πŸ‘ 43    πŸ” 20    πŸ’¬ 2    πŸ“Œ 2

I did a thing again...

Also, πŸ”₯ take: Missing "HttpOnly" is not directly a vulerability/eligible for a CVE...

18.02.2025 10:04 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@rtfmkiesel is following 20 prominent accounts