Dominic White @singe.bsky.social · 18/08/2026I love @RoganDawes@infosec.exchange’s Apostille for cloning x509 certificate chains to make certs look identical to users when they're forced to eyeball them when a rogue AP presents a different cert. But I wanted something more portable with fewer deps. You can grab GOpostille 👇 132
Dominic White @singe.bsky.social · 05/08/2026 The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: github.com/aircrack-ng/aircrack-ng/… 022
Dominic White @singe.bsky.social · 01/08/2026My fortune cookie is even giving me sh*t about maintaining our WiFi hacking course. 040
Dominic White @singe.bsky.social · 01/08/2026Year 25 of SensePost training at BlackHat, I think this is my 17th time. 160
Dominic White @singe.bsky.social · 30/07/2026BlackHat airport advertising is up but this is the only one that unintentionally makes any sense to a hacker. 040
Dominic White @singe.bsky.social · 29/07/2026I always love the care our training ops team puts into our BlackHat training swag but the war games mainframe and WiFi themes are both close to my heart. Thanks Darryn & Andre! 022
Dominic White @singe.bsky.social · 29/07/2026I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” info.defcon.org/defcon34/con... 111
Dominic White @singe.bsky.social · 27/07/2026Every time we give our wifi hacking training @blackhatevents.bsky.social, we need to help people understand the vagaries of aircrack's airodump-ng, until now, because @shifttymike.bsky.social fixed it! 230
Dominic White @singe.bsky.social · 25/07/2026I really like this evaluation matrix from @RoelofTemmingh’s @BSidesJoburg keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong” 010
Dominic White @singe.bsky.social · 13/06/2026Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768 104
Dominic White @singe.bsky.social · 09/06/2026A quick run through the new iOS 27 beta system settings and I noticed: 1 You need to join a waitlist to access new Siri 2 it now shows what type of WiFi is in use when connected 3 it may not be new - but there’s an “impersonation risk detection” feature that can be shared with apps 100
Dominic White @singe.bsky.social · 08/03/2026We must never again allow ourselves to dehumanise each other. 120
Dominic White @singe.bsky.social · 05/03/2026Time to exploit reducing? Zero day clock? Pepperidge farm remembers the early 2000’s. 010
Dominic White @singe.bsky.social · 28/02/2026I AI generated this punk song a week ago. Kind of saw it coming. Wish we could move on from rhyming the death and misery. 000
Dominic White @singe.bsky.social · 22/02/2026Over the years I’ve always used some app to prevent my Mac from locking during long running tasks like password cracking sessions or more recently agentic workflows. But they’re poorly maintained or over complicated. So I made my own. NoLock does what it says on the tin github.com/singe/NoLock 181
Dominic White @singe.bsky.social · 18/02/2026I'm impressed by how light weight the Apple on-device Foundation LLM is for Apple Intelligence, so I vibe'd a small macOS tool (26.0+) to interact with them. It supports GUI and CLI and tool calling. Even big responses fail to move the CPU/GPU by a single percentage. Link below. 154
Dominic White @singe.bsky.social · 26/01/2026I updated that Burp Global Match & Replace plugin to use the Montoya API, be able to target specific Burp tools (or apply globally), extend the rule matching syntax, and give you a view per request and response of the changes. github.com/singe/burp_g... 021
Dominic White @singe.bsky.social · 19/01/2026In Portswigger's Burp I needed a way to do Match & Replace globally across all utilities, not just the proxy so I wrote an extension github.com/singe/burp_g... 040
Dominic White @singe.bsky.social · 16/01/2026The number of times people have tried to kill Net-NTLMv1 eh? youtu.be/lm7Cuktpnb4?... 142
Dominic White @singe.bsky.social · 15/01/2026I figure the conical burr cup has a mix of extraction flavours all mixed together (due to the initial distribution and higher number of fines). The flat burr made my boring beans taste boring and punished sooner with wrong grind size (but rewards so much more on right). Enjoying these at the moment. 000
Dominic White @singe.bsky.social · 01/11/2025T’was 0xC0N Jozi today. That makes number 9, finally beating ZaC0N’s run of 8 years. It’s such a special con because it’s small and full of passionate attendees - no corporate wage slaves there for a day off work, just a bunch of hackers new and old. 050
Dominic White @singe.bsky.social · 28/10/2025Just added SOCKS support to this reverse tunnelling tool github.com/singe/contun... 021
Dominic White @singe.bsky.social · 19/10/2025I missed Spinach & was tired of writing hard code that LLMs struggled to help with. So I decided to recreate the functionality of Spinach in a discord world. And so Cabbage was born. Cabbage is private for now, but it’s been so cathartic writing something easy and fun. And vhata saved Spinach’s DB! 120
Dominic White @singe.bsky.social · 12/09/2025I had occasion to hack on some Wordpress’es and realised there’s a ton of surface area exposed over the "new" REST interfaces. Here's a small utility to convert it into a OpenAPI/Swagger file so you can explore it in your pentests/bug bounty work. github.com/sensepost/wp... 0142
Dominic White @singe.bsky.social · 08/09/2025Cyble wanted this blog post taken down … Barbra Streisand (woo ooh ooh woo woo) 060
Dominic White @singe.bsky.social · 07/09/2025Total eclipse blood moon our side of the planet right now. 0111
Dominic White @singe.bsky.social · 15/08/2025Interested in the release of hashcat 7 I retested my (now three year old) ntcrack against it. It made me smile to see it's still faster. github.com/sensepost/ntcrack 030
Dominic White @singe.bsky.social · 09/08/2025Later today, as Las Vegas hovers at its peak temperature on the 33rd iteration of DEFCON, @leonjza.bsky.social will take everyone in Track 4 on a wild ride through vuln ridden bloatware installed on many of the machines in the room and the world. info.defcon.org/content/?id=60380 040
Dominic White @singe.bsky.social · 28/07/2025My attempt to create a custom feed to group skeets by semantic similarity using embeddings is so far better at finding bots than it is at grouping meaningful content. 111
Dominic White @singe.bsky.social · 20/07/2025The original poster was circa 1987 groups.google.com/g/comp.unix.... and contained way more nuance and in-jokes. 140
Dominic White @singe.bsky.social · 20/07/2025An AI remix of an old unix magazine cover somewhat updated for the modern age. 290
Dominic White @singe.bsky.social · 28/06/2025This mural in our Paris office is getting me excited. I’m done with this northern hemisphere heat wave. Bring on the cold! 030
Dominic White @singe.bsky.social · 15/06/2025Today in unexpected things vuln researchers can use LLM’s for. 020
Dominic White @singe.bsky.social · 04/06/2025Wifi hacking can be a useful tool, but people are out here grinding on WPA2 handshake cracking tutorials & menu driven attack tooling. When we built the 3rd and latest iteration of the wifi hacking course for BlackHat - we did it to show what really works and how it really works. 1/7 132
Dominic White @singe.bsky.social · 31/05/2025I’ve been playing with LLM agents for cyber tasks and found models that work to be inconsistently ok and very expensive and @nickpending.bsky.social’s blogs perfectly echo what I’ve been feeling nickpending.substack.com/p/the-syst… 030
Dominic White @singe.bsky.social · 28/05/2025Jeff @thedarktangent.bsky.social raises a possible driver for vigilante hack back - ineffectual law enforcement response. Super powered organisations may resort to “private armies”. 010
Dominic White @singe.bsky.social · 22/05/2025I’m really enjoying nerve for building agents, but found myself wanting to limit tool output to reduce input tokens or avoid tripping message length limits, so I made this PR github.com/evilsocket/nerve/pull/58 For example, this page parameter was auto added by nerve. 002
Dominic White @singe.bsky.social · 14/05/2025If you're Russian and encrypted, it's for free, if you're Russian gov and you're encrypted, it's for free. If you're Russian and encrypted, and you really can't decrypt it, if you're Russian and encrypted - it's for free. 031
Dominic White @singe.bsky.social · 09/05/2025Some of these lockbit ransom negotiations are … This one from a financial services company that definitely knows better. 020
Dominic White @singe.bsky.social · 16/04/2025Finally getting to play with evilsocket's nerve. As usual he's provided a super accessible way to play with something that otherwise needs a lot more scaffolding. Here it is doing a code audit of jollyexec and producing six patches to correct the issues. 120
Dominic White @singe.bsky.social · 14/04/2025Amazing that despite numerous C2 comms to this IP from malware, it's still clean as a whistle on VT. So much for all that vaunted threat intel helping us clean up malicious comms. www.virustotal.com/gui/ip-addre... 020
Dominic White @singe.bsky.social · 03/04/2025That @staaldraad.conch.cloud, always ahead of his time. This time by 15 years. 150