Advertisement ยท 728 ร— 90

Posts by Drew @hoodoer

Preview
MCP in Burp Suite: From Enumeration to Targeted Exploitation

Model Context Protocol servers often rely on SSE and WebSockets, which makes manual testing tricky. @hoodoer.bsky.social introduces MCP-ASD, a new Burp Suite extension designed to help testers identify, enumerate, and interact with MCP servers more effectively. trustedsec.com/blog/mcp-in-...

2 months ago 2 2 0 0
Video

Microsoft seems to be integrating #Copilot into everything. And we mean EVERYTHING. Find out what we have to say about it and how it relates to data security on the latest episode of the #SecurityNoise podcast! @hoodoer.bsky.social youtu.be/QsmdLJsvAkc

2 months ago 3 1 0 0

Nice to finally knock this off my to-do list. Hope it helps!

3 months ago 1 0 0 0

The path to tricking users to trigger this isn't so hard.

10 months ago 0 0 0 0

Yes!

11 months ago 2 1 0 0
CC13: JS-Tap Mark II: Attacking Web Apps With Even More Red Team Shenanigans
CC13: JS-Tap Mark II: Attacking Web Apps With Even More Red Team Shenanigans YouTube video by CactusCon

Apparently they did post it up, they just used the camera feed:
youtu.be/O7-zxAmP13o?...

11 months ago 1 0 1 0

The big features missing in that talk are the mimic feature that auto generates custom payloads and network traffic obfuscation.

Let me know if you have any questions, happy to help

11 months ago 1 0 0 0
Advertisement

I'm afraid the recording didn't work, my Mac doesn't play nice with conference recordings.

If there's a specific feature you're most interested in I can recommend another video that highlights that feature.

The readme has a demo section with links to a bunch of videos.

github.com/hoodoer/JS-Tap

11 months ago 0 0 1 0
checkIP.sh

I use "what's my IP" sites a ton to check my routing, got tired of bloated sites.

Made a simple service for this:
checkip.sh
or
checkip.sh?ip=8.8.8.8

Command line too (-L needed):
curl -L checkip.sh/cli

or for a specific IP instead of your source IP:
curl -L checkip.sh/cli?ip=8.8.8.8

11 months ago 0 0 0 0

I hope you're on the discord?

11 months ago 0 0 1 0

Are you in the ENC area? I may be biased but I think the PWN-252 group is pretty great ๐Ÿ˜‚

Bunch of us will be at the con. Bring a laptop and CTF with us.

11 months ago 1 0 1 0

Absolutely, one of my favorite cons all year

11 months ago 1 0 1 0

Looking forward to showing off the latest features. Hoping to have some fun conversations during the Livestream.

11 months ago 1 0 0 0

That's forboding ๐Ÿ˜ฌ

Good luck with whatever you're dealing with

11 months ago 2 0 1 0
Advertisement
Post image

The #eagles are Conowingo at feisty. One eagle catches, 3 more chase and it's fair game to steal food if you can. #birds #eagle #wildlife #photography

1 year ago 34 5 1 0

What this tells me is that since we talked at Shmoo you made the move.

Congratulations, this makes me happier than you can imagine. We miss it down there terribly. I hope you have a fantastic time โ™ฅ๏ธ๐Ÿฆ˜

1 year ago 1 0 0 0

It's their place in the universe to be insufferable. Share it widely, it's a solid take.

1 year ago 0 0 0 0

Interesting mix up of approaches. I mean, I do JavaScript C2 a lot, but that's for WebApps ๐Ÿคฃ

1 year ago 2 0 1 0
Preview
v2.2 Release: Network traffic obfuscation, lazy rendering, reverse filter search option, and fingerprinting fixes ยท hoodoer JS-Tap ยท Discussion #36 Development has been in a private branch for a little while, but this is the latest code. Network Obfuscation: You now have the option in app settings to turn on traffic obfuscation. If the browser...

I just pushed my private JS-Tap repo changes over to public for v2.2 release.

Network obfuscation, rendering improvements, reverse filter searching, and client fingerprinting that isn't completely broken now available.

Release notes:
github.com/hoodoer/JS-T...

Repo:
github.com/hoodoer/JS-Tap

1 year ago 1 0 0 0

CISA does have a top notch team, I hope they all find spots soon.

1 year ago 2 0 0 0
Waste.Gov โ€“ Tracking government waste.Waste.Gov โ€“ Tracking government waste.

This landing page does not inspire confidence in the security posture lol

waste.gov

1 year ago 1 1 1 0

This should be fun, this is a great tool.

1 year ago 1 0 1 0
Post image

Senior Security Consultant Whitney Phillips will be speaking at CactusCon next week! Her session "Tips and Tricks to Creating Your First Conference Talk" will take place on Feb 14 at 11am in the Career Village. Stop by our booth too if you'll be there! www.cactuscon.com/cc13-schedule

1 year ago 3 1 0 0
Advertisement

Anyone need a @cactuscon.com ticket? I think I have a spare

1 year ago 0 0 0 0
Preview
ShmooCon 2025 - YouTube You can reach me at https://twitter.com/Strong1Wind

The #ShmooCon 2025 talks have been uploaded
youtube.com/playlist?lis...

1 year ago 22 10 0 0

That was fun, glad to see you after all these years.

1 year ago 1 0 1 0

See all you fabulous nerds at ShmooCon

1 year ago 6 0 1 0

This is an impressive holiday celebration. Happy blowtorching.

1 year ago 1 0 1 0
Preview
Top 10 Blogs of 2024

It's that time of year again! We are excited to reveal our top 10 most read blogs of 2024 ๐Ÿฅณ
trustedsec.com/blog/top-10-...

1 year ago 7 4 0 0

That sounds pretty fucking awful, hope it worked man.

1 year ago 1 0 1 0