
solst/ICE of Astarte
@IceSolst • 31,384 subscribers
Voidweaver @AstarteSecurity - Pentester turned seceng turned meeting canceller - meetup https://t.co/E4rlINC0U6 - conf tracker https://t.co/tReNhuhANF
Shorts
Videos

I "ported" hashcat to the GBA, the ultimate password cracking rig ever (my dumbest project yet). The monstrously powerful 16.78 MHz ARM7TDMI chip does an astronomical 727 SHA256 hashes per second!! which is about thirty million times slower than a modern cracking rig. 350 days of continuous cracking on this bad boy could be done in about 1 second with a modern GPU-accelerated cracking rig.
solst/ICE of Astarte126,779 views • 3 days ago

I wrote Task Unmanager: keeps killing processes Russian Roulette style, until your machine crashes
solst/ICE of Astarte1,803,335 views • 6 months ago

LiteLLM hack summary: What is it, why it's smart to target it, and how it happened (so far)
solst/ICE of Astarte155,324 views • 3 months ago

Pentest tools tier list: learn about which tools are actually used in pentests, and why, with Andy Swift Please comment why you disagree and what we've missed!! The three S-tier tools have a shared attribute: They only do ONE thing, but do it really well and reliably
solst/ICE of Astarte49,126 views • 3 months ago

What Half-Life's resonance cascade incident taught me about "AI Security"
solst/ICE of Astarte44,809 views • 3 months ago

NEW TOOL: It's a fully in-browser binary/file analysis tool with a hex editor. Features: - Hex editor and you can save the edited file - Mach-O symbols - ELF and PE basic metadata - Zip file contents - Fully client-side in-browser, so it is private and the files are never sent anywhere This is meant as a basic and quick tool to check simple metadata and do hex edits. If you need something more robust for malware analysis consider other tools like Malcore™ aka Malcore.io™ or just use a cli/native tool. Shoutout to Battle Programmer Yuu for inspiring me to use Unifont that I stole from tmp.0ut (it looks so good!) The code is all generated by Claude in Cursor and hosted on Github Pages. I don't really do any binary analysis, so if you have suggestions for improvements, let me know. (this is technically 'early access' and i haven't tested it too much)
solst/ICE of Astarte142,852 views • 1 year ago

1-minute summary of the Claude security-review bypass
solst/ICE of Astarte40,028 views • 5 months ago

New video: dawgyg - WoH covered a lot, including: how AI-generated bug bounty reports are a burden on OSS (FFmpeg mentioned), transitioning from bug hunting to working in-house on an AppSec team, the early blackhat days, and multiple appearances of his cats. 30sec clip:
solst/ICE of Astarte33,940 views • 5 months ago

Spicy take: SOC the hardest security job, given industry expectations. Also IMO external SOCs are useless: You just get alerted twice, once by your tools, and another by the external SOC, just forwarding the alert with no extra context. What do you think? Check out the latest video with spencer on pentesting Active Directory
solst/ICE of Astarte24,497 views • 5 months ago

Full episode below with Tib3rius Everything you've wanted to know about web app pentests
solst/ICE of Astarte20,590 views • 5 months ago

Here is the demo of SBOM-Tools by the OG legend Alex Matrosov (IQ 999999)
solst/ICE of Astarte18,035 views • 4 months ago
No more content to load