Christoph Meyer (@chmeycom) 's Twitter Profile
Christoph Meyer

@chmeycom

Security Engineer

ID: 1167916205900009472

linkhttps://chmey.com calendar_today31-08-2019 21:45:19

44 Tweet

52 Takipçi

182 Takip Edilen

Christoph Meyer (@chmeycom) 's Twitter Profile Photo

This year, I finally got the time to fully participate in #Hacktoberfest. I'd love to contribute to some Python lib or other project. Maybe also NodeJS, hmmm..

Christoph Meyer (@chmeycom) 's Twitter Profile Photo

Published my (incomplete) #MIPS disassembler and emulator that I wrote a while ago in #Python: github.com/chmey/mips-dis…

Robert Merget (@ic0nz1) 's Twitter Profile Photo

Do you like crypto? Are you interested in new attack techniques? Then this is something for you: We present raccoon-attack.com a novel cryptographic vulnerability in the SPECIFICATION of TLS Credits: Marcus Brinkmann, Nimrod Aviram, juraj somorovsky, Johannes Mittmann Jörg Schwenk

Do you like crypto? Are you interested in new attack techniques? Then this is something for you: We present raccoon-attack.com a novel cryptographic vulnerability in the SPECIFICATION of TLS Credits: <a href="/lambdafu/">Marcus Brinkmann</a>, <a href="/NimrodAviram/">Nimrod Aviram</a>, <a href="/jurajsomorovsky/">juraj somorovsky</a>, Johannes Mittmann <a href="/JoergSchwenk/">Jörg Schwenk</a>
Christoph Meyer (@chmeycom) 's Twitter Profile Photo

Urban mobility in Rotterdam is way beyond what I'm used to from the Ruhr area. Rental bikes and electric scooters, carsharing and electric mini cars, all around the city and frequently used.

Urban mobility in Rotterdam is way beyond what I'm used to from the Ruhr area. Rental bikes and electric scooters, carsharing and electric mini cars, all around the city and frequently used.
Chris Sanders 🔎 🧠 (@chrissanders88) 's Twitter Profile Photo

Look at this slice of awesome. The new Wireshark version in dev (3.3.0) has a packet diagram view. A fantastic teaching and learning tool! When released, I'll be making pretty extensive use of this in my classes! Great job Gerald Combs and Wireshark Foundation team.

Christoph Meyer (@chmeycom) 's Twitter Profile Photo

Solche Interessen werden von Regierungsmitglieder und -innen durchgesetzt, die einer Partei zugehörig sind, die für die Mehrheit der Bevölkerung nicht wählbar ist.

Mare Liberum e.V. i.A. (@teammareliberum) 's Twitter Profile Photo

Wir haben gewonnen! Das Verwaltungsgericht Hamburg erklärt die #Schiffssicherheitsverordnung von #Scheuer für europarechtswidrig und damit auch die auf dieser Grundlage erfolgte Festsetzung unserer Schiffe für unwirksam. #ScheuerRücktritt #ForRefugees

Wir haben gewonnen! Das Verwaltungsgericht Hamburg erklärt die #Schiffssicherheitsverordnung von #Scheuer für europarechtswidrig und damit auch die auf dieser Grundlage erfolgte Festsetzung unserer Schiffe für unwirksam. #ScheuerRücktritt #ForRefugees
Christoph Meyer (@chmeycom) 's Twitter Profile Photo

Here's a local Python3 API for resolving IPs to ASN data. Useful for pentesting and threat analysis! github.com/chmey/py-iptoa…

Christoph Meyer (@chmeycom) 's Twitter Profile Photo

I've written a post about using dnsrecon during the recon phase of a pentest. After scanning, a report parsing tool automatically groups the results by record type and queries an IP2ASN resolver. chmey.com/automating-dom…

Simone Margaritelli (@evilsocket) 's Twitter Profile Photo

You can force any v8/Electron process to execute arbitrary js code (child_process, http, etc) by forcefully enabling and abusing the builtin debug mechanism ... here's VS Code executing Calc, but I suspect any Electron app is susceptible 🔥 it works with SIP enabled on macOS

You can force any v8/Electron process to execute arbitrary js code (child_process, http, etc) by forcefully enabling and abusing the builtin debug mechanism ... here's VS Code executing Calc, but I suspect any Electron app is susceptible 🔥 it works with SIP enabled on macOS
Christoph Meyer (@chmeycom) 's Twitter Profile Photo

That's similar to users getting tricked to paste JS into the browser console. Bookmarklets should run in isolation like file:/// or should be removed.