Sign in

el_d33

@eld33-original.bsky.social
64 followers 226 following 18 posts

Security Amateur. Reluctant cyborg. Cryptography enthusiast. Coffee aficionado.

PostsRepliesMedia
Reposted by el_d33
Filippo Valsorda @filippo.abyssdomain.expert · 11/09/2026
Oh damn I had not seen the details of the MicroTik RCE: the client can send a public RSA key with correct N and e = 1 and the server will use it. Two primitives/protocol things that would have prevented it: if RSA was defined with a fixed e, and if SSH clients sent a key hash instead.
github.com
CVE-2026-67276 - GitHub Advisory Database
RouterOS does not compare the complete RSA public key...
26016
Reposted by el_d33
Rebane @rebane2001.bsky.social · 24/02/2026
i built an entire x86 CPU emulator in CSS (no javascript) you can write programs in C, compile them to x86 machine code with GCC, and run them inside CSS lyra.horse/x86css/
1332610858
Reposted by el_d33
Émilio Gonzalez @res260.xyz · 11/01/2026
Avec toute la polémique autour de X actuellement, c'est un excellent timing pour envoyer un email à nos élus pour leur demander de lâcher Twitter/X. Il y a plus de chance que ça fonctionne si on est plusieurs à le demander! www.assnat.qc.ca/fr/deputes/i... #assnat #assnatqc #polqc
assnat.qc.ca
Députés - Assemblée nationale du Québec
Ouvrir
042
Reposted by el_d33
Phrack Zine @phrack.org · 08/01/2026
The Conscience of a Hacker, also known as The Hacker Manifesto, turns 40 today! Written by Loyd "The Mentor" Blankenship, its spirit still resonates with hackers and makers everywhere. A cornerstone of hacker culture. phrack.org/issues/7/3 #HackThePlanet #HackerManifesto
17246
Reposted by el_d33
Nicolas Grégoire @agarri.fr · 24/11/2025
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published 📅 - March 24th to 27th, in French 🇫🇷 - April 14th to 17th, in English 🇬🇧 hackademy.agarri.fr/2026 PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
hackademy.agarri.fr
Agarri
Training
086
Reposted by el_d33
WarthogTK @warthogtk.bsky.social · 19/10/2025
CVE-2025-59287 WSUS Remote Code Execution | HawkTrace hawktrace.com/blog/CVE-202...
hawktrace.com
CVE-2025-59287 WSUS Remote Code Execution
A technical WSUS advisory for CVE-2025-59287: unsafe deserialization in Windows Server Update Services that allows remote code execution.
011
el_d33 @eld33-original.bsky.social · 28/09/2025
To drive the car with sunglasses, you need to fool the car. www.reddit.com/r/Ioniq5/s/x... Clever solution
reddit.com
From the Ioniq5 community on Reddit
Explore this post and more from the Ioniq5 community
020
Reposted by el_d33
WarthogTK @warthogtk.bsky.social · 19/09/2025
XSS-Leak: Leaking Cross-Origin Redirects blog.babelo.xyz/posts/cross-...
blog.babelo.xyz
XSS-Leak: Leaking Cross-Origin Redirects
In this post, I will introduce XSS-Leak (“Cross-Site-Subdomain Leak”), a technique for Chromium-based browsers that leaks cross-origin redirects, …
011
Reposted by el_d33
Ian Coldwater 🧊🚫 @lookitup.baby · 16/09/2025
Today is the 30th anniversary of Hackers
the cast of Hackers (1995) posing in a series of adjacent phone booths
7135741035
Reposted by el_d33
Scoubi @scoubi.bsky.social · 20/08/2025
Interested in hands-on learning of #DetectionEngineering and #ThreatHunting ? We still have a few tickets left for @DEATHCon2025 in #Montreal We are lucky enough to have 4 Workshops Leaders with us that will be able to hosts a Live Play of their workshop and help you complete it!
eventbrite.ca
DEATHcon Montreal - On Site
2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
212
Reposted by el_d33
Scoubi @scoubi.bsky.social · 20/08/2025
Buy your tickets here : www.eventbrite.ca/e/deathcon-montreal-on-site-tickets-1422785262019
eventbrite.ca
DEATHcon Montreal - On Site
2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
121
Reposted by el_d33
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 20/08/2025
May I ask you a a favour? If you have bought one of my books, and you liked it, would you consider submitting a review on Amazon? If you have feedback for me, please DM me, I am always looking to improve. twp.ai/9PUohM
013
el_d33 @eld33-original.bsky.social · 28/07/2025
Tom Lehrer just passed away :-(
000
el_d33 @eld33-original.bsky.social · 11/07/2025
New challenge coin
Rcmp Cybercrime Investigative Unit C Division challenge coin
020
el_d33 @eld33-original.bsky.social · 07/07/2025
New challenge coin!
Challenge coin for Sûreté du Québec Division Technologique
010
Reposted by el_d33
depths of wikipedia @depthsofwikipedia.bsky.social · 03/07/2025
very into these inconvenient, extremely long and pointy shoes that spread across europe in the 14th century and made everyone so horny and effeminate that the church went full on moral panic mode and a bunch of kings made them illegal!!! also everyone got bunions
They were a controversial fashion and faced criticism from several quarters. In 1368, Charles V of France issued an edict banning their construction and use in Paris. An English poem from 1388 complained that men were unable to kneel in prayer because their toes were too long.[37] The c. 1440 morality play Castle of Perseverance includes the footwear in the "advice" that Humanum Genus ("Mankind") gets from Superbia ("Pride"): "Look that thou blow mickle boasts with long crakows on thy shoes".[38][d]

In 1463, Edward IV passed a sumptuary law that "no knight under the state of a lord, esquire, gentleman, nor other person shall use nor wear after the... feast of Saint Peter any shoes or boots having pikes passing the length of two inches" (5 cm).[39][40] In 1465, they were banned in England altogether, so that all cordwainers and cobblers within the City of London and environs were prohibited from making shoes with pikes more than 2 inches long.[28]: 117 [41]
19818128
el_d33 @eld33-original.bsky.social · 27/06/2025
New challenge coin for the collection
Side A of the Cybercrime Investigative Team coinSide B of the RCMP Cyber Investigative Team challenge coin
000
el_d33 @eld33-original.bsky.social · 25/06/2025
JPEG should be pronounced 'JFEG'
000
el_d33 @eld33-original.bsky.social · 24/06/2025
New challenge coin for the collection
Covert Access & interception team challenge coinRCMP challenge coin (other side)
120
Reposted by el_d33
Louis Dion-Marcil @ldionmarcil.bsky.social · 23/06/2025
wrote some words about vulnerabilities i found in Aviatrix during a red team cloud.google.com/blog/topics/...
cloud.google.com
Trix Shots: Remote Code Execution on Aviatrix Controller | Google Cloud Blog
Red team case study detailing the discovery of two critical vulnerabilities in the Aviatrix Controller software.
041
Reposted by el_d33
Whitney Merrill @wbm312.bsky.social · 22/06/2025
Identifying birds using the Merlin Bird ID is real life Pokémon.
4516
el_d33 @eld33-original.bsky.social · 16/06/2025
New challenge coin to the collection
Challenge coin for the Montreal Police Video Surveillance Unit
010
el_d33 @eld33-original.bsky.social · 12/06/2025
New challenge coin to the collection
Challenge coin for the SPVM technical crimes division
120
Reposted by el_d33
Pavel @spavel.bsky.social · 08/06/2025
Agile Development was invented in the Soviet Union.
Shturmovshchina was a common Soviet work practice of frantic and overtime work at the end of a planning period in order to fulfill the planned production target. The practice usually gave rise to products of poor quality at the end of a planning cycle.
23772152
el_d33 @eld33-original.bsky.social · 05/06/2025
Got a cool new challenge coin!
Challenge coin from Fintrac/Canafe
010
Reposted by el_d33
Deviant Ollam ツ @deviantollam.bsky.social · 28/05/2025
...and this is a reminder that her federal register number is part of her mailing address which all of you can still totally use to send her notes, encouragement, and more... Kara Sternquist Register Number 44404061 FMC Carswell Federal Medical Center P.O. Box 27137 Fort Worth, TX 76127 🧵✊
2363
Reposted by el_d33
Deviant Ollam ツ @deviantollam.bsky.social · 28/05/2025
Please try to join the hearing session tomorrow at 10:00 a.m. (her actual matter might not start until a little after the hour starts. She is the second session on the docket) Her attorney will be making a variety of arguments concerning violations of her rights and people being there matters. 🧵
1401
Reposted by el_d33
Deviant Ollam ツ @deviantollam.bsky.social · 28/05/2025
I know that loads of you have been following the story of my dear friend Kara who has been in the hellish federal system for over a year now. There is a big hearing happening tomorrow, Thursday the 29th, at 10:00 a.m. and you can listen in... www.ca2.uscourts.gov ...you showing support HELPS 🧵
A pair of hands is seen holding bars, as if from inside of a cell, and the bars are colored in the trans flag blue, pink, and white
612728
el_d33 @eld33-original.bsky.social · 15/05/2025
Day 1 of @northsec.io ! #nsec25
010
Reposted by el_d33
Gildas Cuisinier @gcuisinier.net · 07/05/2025
🎓 Vous avez 5 minutes ? Mon fils réalise un sondage pour son travail de fin d’études en sciences sociales sur le rap et son impact sur la société. Fan ou non, tous les avis comptent ! Merci pour votre aide ! docs.google.com/forms/d/e/1F... N'hésitez pas à partager :)
docs.google.com
Sondage - L'influence du rap sur la société
Dans le cadre de mon Travail de Fin d’Études en sciences sociales, je mène une recherche consacrée au rap et à son influence sur la société contemporaine. Ce questionnaire a pour objectif de recueilli...
025
Reposted by el_d33
Lisa Forte @lisaforte.bsky.social · 06/05/2025
Behind every good cyber security professional is an extremely hard working coffee machine.
912413
Reposted by el_d33
EricLaw 🎻 @ericlawrence.com · 23/04/2025
Lol. Today I learned that 1593 is not a secure PIN. learn.microsoft.com/en-us/window...
221
el_d33 @eld33-original.bsky.social · 11/04/2025
Rao!
110
Reposted by el_d33
foxinSOCKS5 @foxinsocks5.bsky.social · 09/04/2025
My kid just showed me how he bypasses his iOS screen time limit and my mind is blown! FaceTime someone and share your screen with them, then give them screen control, and voila, magically your screen time is turned off. WTF Apple, your screen time controls are utter garbage.
452
Reposted by el_d33
Lisa Forte @lisaforte.bsky.social · 05/03/2025
Equality isn’t women talking about women in cyber it is women talking about cyber.
46012
Reposted by el_d33
George Takei @georgetakei.bsky.social · 31/01/2025
This is what the government did with 120K+ Japanese Americans in 1942. I know. I was there in those camps.
34539889931613
Reposted by el_d33
Émilio Gonzalez @res260.xyz · 31/01/2025
Fellow cybersecurity folks: Make sure to follow @northsec.bsky.social if you came to bluesky from Twitter! Great conference in Montreal and probably the biggest on-site CTF in the world.
035
el_d33 @eld33-original.bsky.social · 16/01/2025
New challenge coin!
030
Reposted by el_d33
Jeff Steck @jefstec.bsky.social · 18/12/2024
An "electrical stimulation" collar that is supposed to reduce the likelihood of having a child with autism, "especially for women who are taking [SSRIs] or who are using cocaine." Patented yesterday. US 12168121
Patent drawing of a person wearing what looks like a cervical collar that has a built-in "stimulator device 50"
112472128
Reposted by el_d33
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658
Reposted by el_d33
Louis Dion-Marcil @ldionmarcil.bsky.social · 06/12/2024
I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec cloud.google.com/blog/topics/...
cloud.google.com
Bridging the Gap: Elevating Red Team Assessments with Application Security Testing | Google Cloud Blog
Red team and targeted external assessments should incorporate application security expertise to better simulate modern adversaries.
0187
Reposted by el_d33
Nicolas Grégoire @agarri.fr · 22/11/2024
On Monday (aka November 25th), the tickets for Northsec 2025 (conferences, trainings or CTF) will be available for sale 🇨🇦
053