Felipe Molina @felmoltor.me · 26/06/2026A beautiful crescent moon 😃 Good enough for my 130/900 Skywatcher + a phone video 000
Reposted by Felipe MolinaDebra's Astrophotography @debraceravolo.bsky.social · 20/06/2026Venus emerging from behind the Moon after being occulted for an hour by the Moon on June 17, 2026. Clouds made it difficult to photograph but in the end, they added to the scene. #astrophotography #astronomy #venusmoon 29872125
Felipe Molina @felmoltor.me · 20/04/2026My first attempt at capturing the Milky Way went not as bad as I thought (I still need to upskill with the foreground shot, but I'm getting there) 120
Reposted by Felipe MolinaTib3rius @tib3rius.bsky.social · 01/04/2026IPv6 addresses are too hard to memorize. That ends today, with the launch of my new, free service: sentence2IPv6 ❌ 0788:7b06:edcb:24f1:a2ff:08f0:6525:be66 ✅ The lazy chickens explode awkwardly beneath the mad toilet while ugly dogs eat the imaginary bacon. is.gd/gyxSQG 64912
Felipe Molina @felmoltor.me · 13/02/2026I can go sleep now with a more colourful photo of M42 obtained tonight 🌌 020
Felipe Molina @felmoltor.me · 01/02/2026I'm still in the learning phase, but I feel pretty proud of my first M42 Nebula shot 🌌. Even taking it with a full moon and in the middle of the city, I got a decent photo. Next time will be much better 💪🏼 020
Reposted by Felipe MolinaDavid Buchanan @retr0.id · 28/01/2026an easy way to remember the difference between ssh -L and ssh -R is to try both until it works 1217514
Reposted by Felipe MolinaDominic White @singe.bsky.social · 26/01/2026I updated that Burp Global Match & Replace plugin to use the Montoya API, be able to target specific Burp tools (or apply globally), extend the rule matching syntax, and give you a view per request and response of the changes. github.com/singe/burp_g... 021
Felipe Molina @felmoltor.me · 23/01/2026Today I made my first portrait of the sun 🌞 You can even see the sunspots! The focal length of my telescope makes it impossible to take the picture of the whole sun, but I'll get to it soon. 110
Reposted by Felipe Molina💥 leonjza @leonjza.bsky.social · 21/01/2026Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁. github.com/leonjza/inet... ₁ seclists.org/oss-sec/2026... 043
Felipe Molina @felmoltor.me · 20/01/2026Yesterday I was able to catch, with my phone, Jupiter transitioning through the lens. A lot of margin for improvement (e.g. motor for the RA axis), but happy with the progress I'm making 🔭 130
Reposted by Felipe MolinaDominic White @singe.bsky.social · 16/01/2026The number of times people have tried to kill Net-NTLMv1 eh? youtu.be/lm7Cuktpnb4?... 142
Felipe Molina @felmoltor.me · 31/12/2025I'm getting more and more disappointed with the Internet nowadays, so I made one for myself yesterday. 030
Reposted by Felipe MolinaAndy Greenberg @agreenberg.bsky.social · 01/10/2025A source shares some screenshots of the Lapsus ransomware gang celebrating the government shutdown as a disruption to the FBI investigations tracking them. They also refer to Trump as "my king." 23121
Felipe Molina @felmoltor.me · 11/09/2025Maybe it's my fault, but I'm really missing non-US related content in Bluesky. Can we talk about other countries, please? I don't want to go back to X 😢 🙏🏼 120
Reposted by Felipe Molina💥 leonjza @leonjza.bsky.social · 10/09/2025If you're at RomHack at the end of the month, come tell me your @github.com username and I'll give you early access to the @sensepost.com tool repo for PipeTap at the con! 🙃 Below is a demo of the proxy in action. www.youtube.com/watch?v=or8Y...youtube.comPipeTap WIP DemoYouTube video by Leon Jacobs 122
Reposted by Felipe Molina💥 leonjza @leonjza.bsky.social · 10/09/2025I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :) 297
Reposted by Felipe MolinaNfknanna @nfknanna.bsky.social · 04/09/2025One of the pools in the Alhambra Palace complex in Granada.... had to be this one for #PalacesandGardens #Water #photography #dailyphoto #travel #Spain 1262
Reposted by Felipe MolinaSensePost @sensepost.com · 31/07/2025Reverse engineering Microsoft’s SQLCMD.exe to implement Channel Binding support for MSSQL into Impacket’s mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself. sensepost.com/blog/2025/a-... 0106
Reposted by Felipe MolinaCloudflare @cloudflare.social · 30/07/2025From June 2025 through July 2025, the Cloudflare Email Security team has been tracking a cluster of cybercriminal threat activity leveraging Proofpoint and Intermedia link wrapping to mask phishing payloads. Read more: cfl.re/4lUXBEEcfl.reAttackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloadsAttackers are exploiting Proofpoint and Intermedia link wrapping to mask phishing payloads. 082
Reposted by Felipe MolinaCatalin Cimpanu @campuscodi.risky.biz · 19/07/2025There's an ongoing npm supply chain attack taking place: socket.dev/blog/npm-phi... x.com/AikidoSecuri...socket.devActive Supply Chain Attack: npm Phishing Campaign Leads to P...Popular npm packages like eslint-config-prettier were compromised after a phishing attack stole a maintainer’s token, spreading malicious updates. 02110
Felipe Molina @felmoltor.me · 17/07/2025I've created a pull request to detect CitrixBleed 2 into Burp's Bcheck repository: github.com/PortSwigger/...github.comCVE-2025-5777 - CitrixBleed 2 by felmoltor · Pull Request #253 · PortSwigger/BChecksBCheck Contributions BCheck compiles and executes as expected BCheck contains appropriate metadata (name, version, author, description and appropriate tags) Only .bcheck files have been added o... 100
Felipe Molina @felmoltor.me · 14/07/2025I wrote a tool to detect orphan scripts at a scale using Scrapy as its foundation: JsJack. Finding vulnerabilities in high-volume traffic sites was more challenging than I initially expected, but I learned many other things from this experience: blog.felipemolina.com/posts/jsjack/blog.felipemolina.comJsJackA tool to find orphan scrips and two interesting cases 000
Reposted by Felipe MolinaTaggart @taggart-tech.com · 14/07/2025Oh neato, a 13 year-old vuln in (checks notes) all US trains that allowed anyone to control the brakes? Cool cool cool.tomshardware.comSecurity vulnerability on U.S. trains that let anyone activate the brakes on the rear car was known for 13 years — operators refused to fix the issue until nowWireless hardware to seriously disrupt rail transport costs less than $500. 32412
Reposted by Felipe MolinaEugene Vinitsky 🍒 @eugenevinitsky.bsky.social · 10/07/2025Well, a single week was enough to provide a convincing case that a Wikipedia equivalent for LLMs is necessary i.e. decentralized LLM training and serving 410117
Reposted by Felipe MolinaFernando Blanco 🦋 🏳️🌈 🏳️⚧️ @fernandoblancopsy.com · 11/07/2025Y luego tenemos a unos cuantos gurús educativos proponiendo que el alumnado "le pregunte las dudas" a ChatGPT... 2147
Reposted by Felipe MolinaCatalin Cimpanu @campuscodi.risky.biz · 10/07/2025These arrests are the definition of "don't shit where you eat" 1111
Reposted by Felipe MolinaAdam Baldwin @evilpacket.net · 10/05/2025The finding was for "JWT weak HMAC secret" and it said the secret was literal "secret" A range of emotions pushed me in various directions at once. What? no.!? yes!!!!!!! let's verify... 151
Felipe Molina @felmoltor.me · 18/06/2025All hail the stupid king! Me! 🤴 In 2024 forgot that I was running a Mongo Express in a docker container without authentication (AS IT WAS ONLY INTERNALLY EXPOSED). Later, I randomly did some tests with Nginx to expose port 8081 and forgot about it... Fast forward to June 2025: 110
Felipe Molina @felmoltor.me · 13/06/2025If this is true, this is the best news I've read this week! Excited to activate my nostalgia mode with Spaceballs 2! www.ign.com/articles/spa...ign.comSpaceballs 2 Will See Rick Moranis Return as Dark Helmet as Mel Brooks Sequel Trailer Plots a Course for 2027 - IGNMoviemaking icon Mel Brooks and Amazon MGM Studios have published a special trailer to announce that Spaceballs 2 is moving full steam ahead with plans to premiere in 2027. 010
Felipe Molina @felmoltor.me · 13/06/2025I programmed some time ago a crawler with Scrapy to detect orphan JavaScript scripts in target domains. I think I'll release that tool soon ☺️ 000
Reposted by Felipe MolinaClément Labro @itm4n.bsky.social · 11/06/2025🆕 New blog post! "Checking for Symantec Account Connectivity Credentials (ACCs) with PrivescCheck" This blog post is not so much about PrivescCheck, but rather brings additional insight to the original article published by MDSec on the subject. 👉 itm4n.github.io/checking-sym... #redteam 074
Felipe Molina @felmoltor.me · 11/06/2025I was talking with someone about dependency confusion and suply chain attacks and I was confused myself with the feasibility of doing this in 2025, so I decided to take a practical aproach and create my own tool 🔨 to detect Orphan and Mispelled packages 📦: sensepost.com/blog/2025/de...sensepost.comSensePost | Depscanner: find orphaned packages before the bad guys doLeaders in Information Security 053
Reposted by Felipe MolinaJasmine 🌌🔭 @astrojaz.bsky.social · 03/06/2025sombrero galaxy - hubble vs webb: 644953
Reposted by Felipe MolinaJasmine 🌌🔭 @astrojaz.bsky.social · 05/06/2025i still think about the jwst saturn picture a lot 1350265
Reposted by Felipe MolinaDominic White @singe.bsky.social · 04/06/2025Wifi hacking can be a useful tool, but people are out here grinding on WPA2 handshake cracking tutorials & menu driven attack tooling. When we built the 3rd and latest iteration of the wifi hacking course for BlackHat - we did it to show what really works and how it really works. 1/7 132
Felipe Molina @felmoltor.me · 04/06/2025I finished watching the last chapter of The Leftovers yesterday. Oh, man! Not many series got me so hooked up to the TV and sitting at the edge of my seat as this one has. ❤️ 000
Reposted by Felipe MolinaDominic White @singe.bsky.social · 28/05/2025I’m seeing a large disconnect between “thought leader” takes about AI aiding attackers versus hands-on practical use - but I’d love a wider view. If we look at deepfakes, malware & phishing as the most common places people believe attackers are advantaged by AI one by one 1/5 103
Reposted by Felipe MolinaGrace @gracekind.net · 28/05/2025Wow, a comment on HN I actually agree with! 4464175