
solst/ICE of Astarte
@IceSolst • 31,384 subscribers
Voidweaver @AstarteSecurity - Pentester turned seceng turned meeting canceller - meetup https://t.co/E4rlINC0U6 - conf tracker https://t.co/tReNhuhANF
Shorts
Videos

I know what you are thinking. GBA too colorful. Too many buttons. Need buttery smooth e-ink display instead for password cracking activities. I “ported” hashcat to the Kindle (jailbreaked), the ultimate password cracking rig (my dumbest project yet). It does maybe like 50 hashes per second? It invokes a sha256sum process for each line in the wordlist. Horrible. You can improve it, but imagine optimizing the kindle password cracker, what are you doing with your life.
solst/ICE of Astarte157,394 次观看 • 4 天前

I "ported" hashcat to the GBA, the ultimate password cracking rig ever (my dumbest project yet). The monstrously powerful 16.78 MHz ARM7TDMI chip does an astronomical 727 SHA256 hashes per second!! which is about thirty million times slower than a modern cracking rig. 350 days of continuous cracking on this bad boy could be done in about 1 second with a modern GPU-accelerated cracking rig.
solst/ICE of Astarte128,583 次观看 • 4 天前

Pentest tools tier list: learn about which tools are actually used in pentests, and why, with Andy Swift Please comment why you disagree and what we've missed!! The three S-tier tools have a shared attribute: They only do ONE thing, but do it really well and reliably
solst/ICE of Astarte49,126 次观看 • 3 个月前

NEW TOOL: It's a fully in-browser binary/file analysis tool with a hex editor. Features: - Hex editor and you can save the edited file - Mach-O symbols - ELF and PE basic metadata - Zip file contents - Fully client-side in-browser, so it is private and the files are never sent anywhere This is meant as a basic and quick tool to check simple metadata and do hex edits. If you need something more robust for malware analysis consider other tools like Malcore™ aka Malcore.io™ or just use a cli/native tool. Shoutout to Battle Programmer Yuu for inspiring me to use Unifont that I stole from tmp.0ut (it looks so good!) The code is all generated by Claude in Cursor and hosted on Github Pages. I don't really do any binary analysis, so if you have suggestions for improvements, let me know. (this is technically 'early access' and i haven't tested it too much)
solst/ICE of Astarte142,852 次观看 • 1 年前

New video: dawgyg - WoH covered a lot, including: how AI-generated bug bounty reports are a burden on OSS (FFmpeg mentioned), transitioning from bug hunting to working in-house on an AppSec team, the early blackhat days, and multiple appearances of his cats. 30sec clip:
solst/ICE of Astarte33,940 次观看 • 5 个月前

Spicy take: SOC the hardest security job, given industry expectations. Also IMO external SOCs are useless: You just get alerted twice, once by your tools, and another by the external SOC, just forwarding the alert with no extra context. What do you think? Check out the latest video with spencer on pentesting Active Directory
solst/ICE of Astarte24,497 次观看 • 5 个月前
没有更多内容可加载