Sign in

HD Moore

@hdm.io
2.1K followers 1.4K following 109 posts
PostsRepliesMedia
HD Moore @hdm.io · 06/08/2026
The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD: blog.calif.io/p/the-taking...
090
HD Moore @hdm.io · 18/03/2026
runZero Hour 0x1C is live NOW: www.youtube.com/live/EF633eU...
031
HD Moore @hdm.io · 13/10/2025
JawnCon (jawncon.org) 0x02 just wrapped! I wish I could make it this year, but settled for catching the talks on the live stream: Main Stage Day 1: www.youtube.com/live/Cvf-mAd... Man Stage Day 2: www.youtube.com/watch?v=bcr6... Classroom Day 2: www.youtube.com/watch?v=1aML...
JawnCon closing session - stats on badges, speakers, bandwidth, and money raised for FU Cancer
051
HD Moore @hdm.io · 02/10/2025
@SectorCa 2025 is fantastic! I last attended in 2008 and holy cow has it grown. Great to see Brian and Bruce still involved. Excellent talks, really sharp crowd, zero attitude, and everyone is incredibly friendly. You can find the slides from my morning keynote at hdm.io/decks/Sector...
SecTor Briefings: The Once and Future Rules of Cybersecurity - day two keynote by HD Moore
010
HD Moore @hdm.io · 06/09/2025
Looking forward to seeing all you hackers in meatspace! I'm bouncing between tracks and sharing slides (Unconference today + Track 2 tomorrow) on the Discord. If you're at @blueteamcon.com this weekend, please say hi, I look like this:
A picture of HD Moore wearing plaid shirt, blue lanyard, and green backpack.
091
HD Moore @hdm.io · 13/08/2025
If you missed this talk at BH/DC last week, it's worth a read: "From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion". Awesome work from Shu-Hao, Tung (123ojp) covering practical attacks on GRE and VxLAN tunnels: media.defcon.org/DEF%20CON%20...
DEF CON title slide for "From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion"
2122
HD Moore @hdm.io · 10/08/2025
Thank you to everyone who made it out for my DEF CON 33 presentation, "Shaking Out Shells With SSHamble", you can find the materials online at hdm.io/decks/MOORE%... This deck includes some lightly-censored zero-day (more decks @ hdm.io)
A top-level overview of the presentation presented as a grid of thumbnails, showing 42 slides.
094
HD Moore @hdm.io · 09/08/2025
Hello DEF CON! Tomorrow (Saturday/August 9th) I'll be speaking with Nicole Schwartz on Forging Strong Cyber Communities in Uncertain Times at 1pm in W205 (TDI) and then shortly after on Shaking Out Shells with SSHamble at 3pm in Track 2 (LV1), with even more shells. Hope to see you there!
061
HD Moore @hdm.io · 05/08/2025
BSides Las Vegas 2025 is incredible. Amazing turn-out, fantastic staff, and the sheer variety of content, speakers, and activities sets the bar for what a hacker con should be. You can find the slides from my talk, "Turbo Tactical Exploitation: 22 Tips for Tricky Targets" at hdm.io/decks/BSides...
0126
HD Moore @hdm.io · 09/07/2025
Hello Austin Gophers! The July ATX Go Meetup is TONIGHT (July 9th). The meetup includes lightning talks, pizza, beverages, and general discussion. Have a neat idea? A quick talk related to Go? Something to show-and-tell? www.meetup.com/atxgolang/ev...
010
HD Moore @hdm.io · 21/06/2025
Do you enjoy guzzling real-time TLS certificate allocations, but don't want to use a third-party service (crt.sh, CertStream, etc.)? Drink straight from the Certificate Transparency log firehose using ctail: $ go run github.com/hdm/ctail@latest -f -m '^autodiscover\.' github.com/hdm/ctail
32611
HD Moore @hdm.io · 01/04/2025
Tired of using boring web browsers to manage your exposure with runZero? Nostalgic for the days of clean, MS-DOS terminal graphics? Ditch your modern trappings and visualize your network map using the best visualization tool of all time, ToneLoc: www.runzero.com/blog/subnet-...
A screenshot of ToneLoc, a wardialing program from the 1990s, displaying network scan data from the 2020s
073
HD Moore @hdm.io · 25/03/2025
Hoping this helps someone else. When setting up a Supermicro AS-1015A-MT 1U w/H13SAE-MF & Ryzen processor, trying to boot Debian 12 or Proxmox 8.3 media results in "Welcome to Grub" and the machine stalling. The fix? Disconnect the display and use the IPMI KVM (!) forum.proxmox.com/threads/inst...
030
HD Moore @hdm.io · 25/03/2025
Today, Wiz (Woogle?) released an advisory detailing an attack chain they’ve dubbed IngressNightmare, which, if left exposed and unpatched, can be exploited to achieve remote code execution by unauthenticated attackers. Read more at www.runzero.com/blog/ingress...
062
HD Moore @hdm.io · 22/03/2025
Good morning from Bootstrap`25[1] in Austin, Texas! Haroon Meer kicks us off with "Security Products Don't Have To Suck", which makes many great points, but among those that most security industry "awards" are hot garbage play-to-win trophies: 1. cfp.ringzer0.training/ringzer0-boo...
A photo from the UT Thompson Center auditorium with banners on the right for the ringzer0 conference and Trend Micro ZDI (a top sponsor). On the project screen is the text "If you build it, they will not come" with a picture of a baseball on a field.
1120
HD Moore @hdm.io · 18/03/2025
Pat Gray, Founder of Risky Business, Joins Decibel as Founder Advisor. Great interview at www.decibel.vc/articles/pat...
030
HD Moore @hdm.io · 20/02/2025
Congratulations to Charles Blas for winning the runZero hacktop raffle at CruiseCon 2025! This is a GPD Pocket 3 running Ubuntu Mate, preloaded with a fully licensed, offline version of the runZero Platform. You can find pictures and Charle's take at: buff.ly/4b6w0vz
A set of three photos taken by Charles Blast, the first shows the GPD Pocket 3 (hacktop) with the runZero console loaded, sitting in front of a normal-sized laptop. The second photo shows a SpaceX rocket launch over the water of Cape Canaveral. The third photo shows the Royal Caribbean ship, Voyager of the Seas, docked off of CoCo Key
031
HD Moore @hdm.io · 07/02/2025
This is still one of my favorite photos from DEF CON 9 (2001). It was taken with an actual film camera from behind the security desk (and about a foot from the staff) in the Imperial Palace. The "diskette" warning is about the Keno machine, the 3.5" floppy contained the random seed for the day.
A photo of a metal box with a label stating "Keno Diskette" and a sticky note saying "Be very careful not to catch diskette in the lock mecs.", next to an alarm panel and keypads for each hotel of the hotel. The alarm code is "1234".
0110
HD Moore @hdm.io · 10/01/2025
Orange Tsai & splitline's "WorstFit" research into Windows unicode "BestFit" encoding is 🔥 🔥 🔥 (and mostly unpatched)! buff.ly/3PQNT81 This work brings back memories of IIS and ASP (classic) unicode exploit-dev.
074
HD Moore @hdm.io · 01/12/2024
It was much easier to replace my ESXi lab servers with Proxmox than to download a security update[1. see alt text] for ESXi post-Broadcom. Now ESXi runs as a scan target inside of Proxmox and all is well.
A screenshot of the runZero console showing an ESXi 8 VM running under Proxmox.

ESXi 8 can no longer update from the esxcli software command due to arcane "out of memory" errors as on the online repo is now bigger than the 300m limit for the python script. The workarounds now trigger tamper errors in ESXi. To download an offline zip of the Depot now requires an active Broadcom support contract. The final alternative is downloading the installer ISO and running the upgrade from the physical console, but this also requires a support contract. Security incidents based on unpatched ESXi are going to be even more of a thing in 2025.
2150
HD Moore @hdm.io · 21/11/2024
Hello Austin hackers! Tonight is the November AHA meetup (shifted back a week to avoid holiday overlap). Same place and time as usual (Mister Tramps, talks start at 7:00pm). Haven't been to an AHA before? Check out the meeting info (and bring a ~5-10m lightning talk): takeonme.org
The AHA logo (AHA)
051
HD Moore @hdm.io · 12/11/2024
Secure your IoT devices by (accidentally) encasing them in concrete. Fortunately this is a POE doorbell and doesn't require battery changes. It does prevent someone from easily getting to the reset button under the bottom lip; does this count as embedded security?
A photo of a Ring video doorbell that was accidentally embedded in concrete.
070
HD Moore @hdm.io · 12/11/2024
If the NSA[1], GrapheneOS[2], and Apple[3] all believe that rebooting your mobile phone regularly is something that protects your data, you might consider automating it. 1. buff.ly/3xhyTtU 2. buff.ly/40OLdhw 3. buff.ly/3UIbQB0
A screenshot of the Apple iOS Shortcuts application, showing the details for a shortcut that automatically restarts the device every day.
42112