threw together a quick first blood discord bot for CTFd for an event im hosting next week gist.github.com/captainGeech...
02.08.2025 22:17 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0@captaingee.ch.bsky.social
cybercrime connoisseur && exploitz engineering enthusiast | synapse fanboy | second breakfast enthusiast
threw together a quick first blood discord bot for CTFd for an event im hosting next week gist.github.com/captainGeech...
02.08.2025 22:17 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0working on a simple web chal and was too lazy to write the ui myself, gemini almost turned this into a second challenge ๐
age of llm==age of free xss?
Being in tech and having a single modicum of critical thinking is just screaming "this isn't what LLMs are designed for" over and over as people shove a bunch of word predictors into critical decision making processes because some glorified used car salesmen told them it would fix all their problems
23.07.2025 18:10 โ ๐ 3961 ๐ 1368 ๐ฌ 52 ๐ 33I wrote a new blog with Mandiant IR + FLARE on some new intrusion activity by a group we track as UNC6148, likely using a mix of n-day and 0-day exploits to compromise SonicWall SMA 100 series VPN appliances. They have some nifty post-exploitation tooling as well
cloud.google.com/blog/topics/...
shuka should give a talk at anticon
10.07.2025 23:15 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Signal sticker pack metadata is fun
signal.art/addstickers/...
(this is even more egregious and frustrating when you do it for internal tools)
05.07.2025 15:41 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0if you need to use AggresIve styling, dark patterns, popups, and anti-user defaults to get people to use your new features, maybe they are not good features :)
05.07.2025 15:40 โ ๐ 2 ๐ 1 ๐ฌ 1 ๐ 0there is something so satisfying about writing rop chains, idk what it is, just a super fun puzzle
01.07.2025 00:57 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Picked a bad day to wear my Corellium t-shirt smh โ ๏ธ
techcrunch.com/2025/06/05/p...
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it.
cloud.google.com/blog/topics/...
why more JS engines don't have a native bogosort implementation is truly a wonder
26.04.2025 17:17 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0greetings fellow windows 11 upgrade refuser
01.04.2025 19:30 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0"And this is why using AppContainer with a packaged app is easier"
screw you microsoft i do what i want
learn.microsoft.com/en-us/window...
if you despise using Visual Studio as much as i do, here you go
github.com/captainGeech...
Too many OPSEC experts out there, Iโm an OOPSEC expert. Lmk if you need help adding The Atlantic to YOUR pc small group chats. Signal and more!
27.03.2025 17:12 โ ๐ 5 ๐ 0 ๐ฌ 0 ๐ 0hey microsoft, hot take, what if you didnt push ads for random games in your fucking operating system as notifications
09.03.2025 22:15 โ ๐ 7 ๐ 0 ๐ฌ 0 ๐ 0arrested development season 1 is the true peak of comedy
04.03.2025 00:08 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0lmfao this worked perfectly. thank you to "brute force to make up for my lack of brain cells"
02.03.2025 11:46 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0reverse engineering and thinking about reducing problem spaces to hit vulnerable code paths is hard.
fuzzing however, is both "easy" and "fast" - lazy ftw
(may work, may not work, we'll see. need a @digitalocean.com sponsorship lol)
my arch laptop hasnt crashed once since districtcon and has been busy since then, so im just going to chalk it up to "cold dark room is scary to gnome" and pretend this never happened
see you at the next talk where it will inevitably happen again
Department of Government Efficiency
23.02.2025 01:10 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0Now that my @districtcon.bsky.social talk is over, here is the official open-source release of implant.js! I think this represents a notable advancement in the state of the art for modular CNO implant frameworks.
Lots of detection info included as well.
github.com/captainGeech...
today i used a debugger so bad that you have to nop sled it when inserting breakpoints to ensure they get hit in the place you want.
yes i wrote the debugger but thats besides the point
If you want your own IDA sticker, come find me @districtcon.bsky.social ;)
16.02.2025 13:51 โ ๐ 5 ๐ 0 ๐ฌ 0 ๐ 0This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it.
LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis.
www.cyfirma.com/research/cl0...
c plus plus, more like c plus sucks
14.02.2025 00:17 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0