Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsWant to learn mobile reverse engineering and security analysis on iOS 📱🍎 but can't afford a training since you're a student? We'll do a free edition of day 1+2 of the Nullcon training end of February at TU Darmstadt. Drop me a DM if you're interested. Limited spaces, so better be fast 🔥
#iOS #security #reverseengineering
https://nullcon.net/berlin-2023/training/mobile-reversing-and-security-analysis/
Hey friends in #websec! Please remember to submit your research to the SecWeb workshop, a venue about building security for the web. The event is co-located with IEEE S&P in San Francisco (May 25) and our paper deadline os February 24th. We welcome new security flaws, solutions, wild ideas and even position papers. Let me know if you want to know more! https://secweb.work/2023.html
Please boost! 🔃
OK, so what does fidget mean? What information do you have around you, right now? Take a deeper look. Why is that WiFi AP named XNF998FE? Why is your laptop's serial number XY3327S? How often is that helicopter circling? Why are so many license plates from a particular state with a specific prefix? Look for the lack of entropy that is an encoded signal.
In the early Metasploit days this involved dumping function addresses of DLLs from a literal binder of DVDs. The opcode database and later analysis by folks like skape (matt miller) and spoonm made exploit development much easier as a result.
Scanning the internet is easy. Understanding all the data coming back takes a lifetime. Grab some data dumps and sift through specific protocols and fields. Toss Fiddler at a Windows thick client (or enable HTTP event tracing).
We are flooded in dodgy software, weak numeration, and information leaks. Stop for a bit, breath, pick one, and go deep.
HiP impressions: great schedule, lovely atmosphere. 10/10 would speak at again
Modern smart phones - we randomised the wifi Mac address
Also modern smart phones - "I'd like to request a dhcp lease and also I'd like to request to use 'joeblogsphone' as a hostname"
No one asked me about my thoughts on the #lastpass incident. I’m a little late, but here’s my lol jk.
DEFCON.social is now open - no more invite codes needed!
With the fix (🤞) to the federated image cache our new 30TB Block Storage server seems to be happy.
Next up we will enable search - just deciding between Elastic Search or Open Search, so any opinions welcome.
#MastoAdmin
Raise your hand if you don’t take proper notes but only rely on the shell history file. 🙋
OffensiveCon '23 CFP
https://cfp.offensivecon.org/offensivecon23/?s=09
Christmas Eve RCE ☑️
Let’s see how the reporting goes. :D
@akareilly dachte, m/w/d steht für männlich, weiß, deutsch 🤔
My pics of 2022 https://pixelfed.de/c/512299667272592240
📯 I'm happy to finally be able to release my #obsidian #writing style plugin to anyone interested!
The plugin helps you write better by pointing out problems in your writing beyond simple spelling mistakes. It's perfect if you use Obsidian for drafting blog posts, job openings, documentation, and other online content.
Read me more and grab it here: https://github.com/michenriksen/obsidian-writing-style
https://mastodon.social/@zackwhittaker/109444922219307775
Birdsite
Always impressed to see people talking BS and getting away with it.
Referral bounty & hiring
We’re paying referral bounties, up to six figures, details here:
https://www.lutasecurity.com/referralbounty
Questions: email info@Lutasecurity.com
We’re always hiring these listed roles, plus others depending on your experience (US only, remote, Contract to permanent):
https://www.lutasecurity.com/careers
Questions: email careeers@Lutasecurity.com



