mcgrewsecurity.com | Senior Cyber Fellow at @martinfederal | Offensive Computer Security; AI; Photography; DJ

Now I don’t know a lot about OnlyFans, but I do know those 42 people aren’t the ones generating the revenue
OnlyFans is now the world's most revenue efficient company. Just 42 employees, generating $37.6M each. Beating Apple and Nvidia.
Community note
This is a wholly dishonest claim. OnlyFans has a core staff of about 42 to 51 full-time employees but also uses hundreds of contractors for tasks like content moderation. "Content on the platform is user-generated and monetized..." en.wikipedia.org/wiki/OnlyFan
271
4,873
131,233
4,936,451
In one headline, CNN erases decades of whatever little progress we have made on user education
36
564
3,842
Replying to @FP_Champagne
Criminals have been using sophisticated tools to steal cars. And Canadians are rightfully worried.   Today, I announced we are banning the importation, sale and use of consumer hacking devices, like flippers, used to commit these crimes. 🔗: canada.ca/en/public-safety-c…
Community note
The flipper zero's sub-GHz wireless antenna can pick up the signals from car key fobs. However, playing them back to modern cars won't unlock them because of a feature called "rolling codes" that changes the code with each use. zdnet.com/article/7-cool
31
482
3,389
267,847
Replying to @JayFoxtrot
Fair, some might be among the revenue creators :)
1
3
3,430
199,088
BREAKING: The Secret Service has moved the president’s Twitter account to the bunker.
47
502
2,680
.@ResortsWorldLV is going to search our rooms daily to protect us from the “well-known hacking convention”.
208
166
1,509
708,767
If you find these in your child’s room, it’s time to have a serious talk with them about the dangers of hacking
100
119
1,199
107,243
You ever hear a word over and over again until it just sounds weird and meaningless
168
115
987
QAnon followers are attempting to use Ghidra to remove redactions from PDFs and I just wish I could be a fly on the wall
69
212
1,013
Hopefully this will dissuade any idea that my travel router is a hacking device.
32
55
919
39,585
Someone help me budget my family is starving
28
43
644
105,459
I hope I’m not spoiling anyone’s CFP prep with this 0day, but what if I told you it was possible to: - Be a hacker - Be an infosec pro - Party hard - Have circle of friends/backchannels - Not be shitty based on gender/race/garbage ideas *all of the above without compromising*
15
106
605
The only thing that can stop a bad guy with a Flipper Zero is a good guy with a Flipper Zero. I have a right to protect my family and community.
7
84
586
30,797
What OS is this? Wrong answers only.
1,219
90
580
Has anyone ever fumbled so hard as Broadcom has with VMWare
88
26
626
34,257
Just saw a t-shirt at Black Hat that said simply: “I don’t have purchase authority”. Smart!
9
84
557
Replying to @habibixyz_sol
Who says romance is dead
1
2
516
An aversion to snorting morphine
What's stopping you from becoming like him?
13
19
562
21,035
A client shipped one of our pentest appliances back to us with a new label
14
104
479
A buddy left his laptop in the lab, locked with facial recognition. I pulled up his Facebook picture on my phone and got in. Fucking lols
17
431
433
so... flipper zero is now forbidden on hand luggage across uk airports. just got mine seized by security. ffs!

ALT Frustrated Jason Segel GIF by NETFLIX

10
64
407
37,383
OpenAI just killed 1,000,000,000,000,000 Startups 🤯
8
25
438
24,484
hi thanks for considering my DEF CON village proposal
18
45
395
Look what they have on Temu 😂 local warehouse thankfully, could you imagine ordering this and it coming through customs from China
31
22
389
36,364
Replying to @redditships
🤷‍♂️ I mean I don’t know what else you can do at this point
3
2
322
Billionaires going goblin mode
My first job. And still the same great burger. Happy Sunday!
7
19
323
You know how much trouble I can cause with a laptop? Gonna ban laptops too?
9
20
293
8,449
You want sandworms?! Because that’s how you get sandworms
Norsonic Nor277 tapping machine for generating footstep sounds for building sound transmission testing.
11
37
276
Hacking toy seller gets insecure about continued development of tons of of hacking toys and goes on tilt. Real good look.
12
8
309
30,390
Update: They came back with a stapled set of pictures of wifi pineapples, jammers, like 3 or four pages of what you’d get from hak5, hacker warehouse, etc. I would recommend not leaving out anything with an antenna, or that resembles anything from the above. #defcon32
30
41
281
106,570
Until the model for the ad industry changes dramatically in a way that respects users’ privacy, security, and resources, I will continue to recommend that users and businesses implement as much ad blocking as technically possible.
Replying to @kirkulanis
Online websites and creators are supported by ads. I thought that was pretty common knowledge? Ad blocking is the exact same thing as piracy. Literally the exact same thing. Ppl will still do it and I've been guilty of it at times, but we just need to be aware of the impact- LS
11
47
256
I think everyone's first experience with IDA back in the day was probably: "this is what you use to hack games?" <drags an exe in> <takes one look at the screen> nope.gif

ALT Haha Good One GIF

12
18
277
I will be teaching a 4-hour workshop, “Introduction to Reverse Engineering With Ghidra” at @defcon 27, and I’ll fill you in with logistics as they’re sorted. Target audience is folks just getting started in RE. It’ll be fun, and I’m really looking forward to it.
19
39
261
The “dd” command originally stood for “carbon copy”, modified since “cc” was already taken by the C compiler.
11
23
258
50,502
In 2022 I am blocking the accounts of all promoted tweets on my timeline. I’m already about 700 in.
20
9
250
A @ResortsWorldLV security staff member just came by to check the room. I asked her what they’re looking for, and she said “we’re just making sure you’re not hacking our stuff”. Took a look around the room briefly and left. #defcon32
Resorts World, one of the hotels that has a block for the DEF CON hacking conference this week, says it will perform daily room searches, including those with a privacy sign “A well-known hacking convention will be held in Las Vegas during your stay”404media.co/hotel-to-search-…
42
37
263
87,631
Leave it alone. Red team’s gotta eat too.
You find a Raspberry Pi plugged into a network switch at work. What do you do?
3
23
249
RIP my mentions lol, anyways, here's some advice for any hotel when you're not in the room this week: - Keep your room looking uninteresting - Keep gear out of sight, especially stuff they may be trained on: WiFi Pineapples, Flippers, picks, anything that looks like those (1/4)
.@ResortsWorldLV is going to search our rooms daily to protect us from the “well-known hacking convention”.
15
27
248
76,330
Just put an order in for @defcon stickers. I'll have this, and another one to be revealed soon.
13
32
235
14,186
Recent #Qanon Ghidra nonsense. Apparently it's now a proxy, and good for web application, steganography, and social media analysis. Basically everything but what it actually does.
12
40
242
Replying to @_th1nk3r
your local retired ham graybeards will make you their hobby till they find you and sic the FCC on you
7
2
239
5,764
Yeah they didn’t blame it on the hackers then either lol
3
2
230
17,418
Is it infosec The Purge and nobody told me? So many people hitting live targets with log4j and talking about it openly
9
18
219
Don't fear the tool. Fear the vulns. Police are alerting on @flipper_net's potential for bypassing access control systems. I wouldn't call it a bypass. These are systems *missing* access control and relying on solely security by obscurity.
3
51
221
23,910
USB drives for “Intro to Reverse Engineering with Ghidra” are written and ready to go. ...there’s probably more efficient ways of bringing 1.6 terabytes of storage to @defcon 😂
13
29
214
Replying to @vxunderground
That’s just the entertainment system. You can rest well knowing all critical systems are probably running Windows CE or other such bullshit
8
6
227
10,589
RIP in Peace my notifications, I just got retweeted by a 1.7M follower account
13
1
210
How dare they call us crim... oh they're not talking about us
10
15
204
9,762
Old hackers know what this is
suggest a name for my ai start up?
28
9
222
26,786
Does a software bill of materials include all the stackoverflow answers you copy/paste from?
19
22
214
Replying to @MrNantendo
At first I thought “oh maybe they had an AI produce this”, then by the end I was like “maybe they should have had an AI produce this”
2
208
16,506
Watching more episodes of Star Trek: Next Generation last night it occurred to me that most of their problems would be mitigated by better network segmentation on the ship
11
34
195
lol no you didn't, that photo's from the FCC filing
7
11
183
The badge looks cool
10
18
188
21,325
cybercrime
If cybersecurity disappears tomorrow, what’s your plan B?
17
29
203
12,610
Replying to @tinyxtina_
I hope the next one is harder
7
187
Why would anyone want this
8
160
4,535
I think that my current favorite Linux distribution is Windows 10
9
18
165
All eleven @defcon speaker badges accounted for and on the wall for a group shot
12
4
167
14,914
At least Mitnick had the foresight to search “itni” when he did similar
Replying to @vxunderground
DAWG. They social engineered the United States judicial system (???), reset someone's password by pretending to be helpdesk, and LOOKED THEMSELVES UP
3
15
181
23,814
For ~14 years I've been obsessed with the way this Super Metroid walkthrough is full-justified in monospaced ASCII gamefaqs.com/snes/588741-sup…
15
89
160
I’m a dad (again)! Baby Hannah just born!
40
3
156
So I made it through a cool billion tokens on @OpenAI and they sent me this today. Bless 🙏
13
6
169
18,030
When we’re fired upon, do we count each bullet as a separate attack? Each step towards us? Every glance through binoculars?
Texas Dept of Information Resources reports 10k attempted cyberattacks per minute coming in from Iran, says ⁦@GovAbbott⁩. Be ‘particularly vigilant,’ he says. #Iran #txlege
10
31
141
Broke: Memory-unsafe languages are promoted by the vulndev/exploit industry to keep them in a job Woke: AI code generators were created by web app testers that want an easier time bypassing filters
4
33
157
Almost done packing
5
8
142
Ads on @CNN on iPhone completely redirect the browser to @amazon gift card scams. The whole business model of allowing advertisements to execute code is unsafe, irresponsible, and disrespectful of readers. Block every ad you technically can to protect yourself/employees/clients.
9
54
140
Nobody attending @defcon (or any other infosec con) is too cool/elite for you to approach to talk/hang. Take advantage of it.
9
38
139
Another speaker badge on the wall
6
152
9,435
My 5yo son just told me I’m the best hacker in the bathroom 👍 🚽
10
9
137
The "Popcorn Time" ransomware, circa 2016, allowed victims to decrypt by infecting two other victims. I think we'll see this concept revisited soon, but with targeted individuals being coerced into infecting their workplaces, either through files held for ransom or kompromat.
2
45
131
Wait'll the QAnon folks start interpreting Cult of the Dead Cow stuff
7
23
112
I’m happy to announce that my DEF CON 32 CFP entry was accepted, and I will be presenting “Reverse Engineering MicroPython Frozen Modules: Data Structures, Reconstruction, and Reading Bytecode” at #DEFCON32 in August. @defcon I’ll share more details once the schedule is posted.
17
12
132
13,057
Dear person with wifi pineapple ssid "STARBUCKS": turn it back on, I wasn't done with it
3
50
129
It must be a lot of fun to run NSA's social media
6
13
127
You can be mad at eBay for using your browser to port scan your local host, BUT the real issue here is that your browser is so complex and has so many features that it allows for this to happen, without any kind of indication or notification.
4
24
122
hey that was my license key too 🧐
9
7
115
apologies/you’re welcome to all my contacts that are about to get my nasty pics, browsing history, etc
41
9
122
25,558
If you're going to play around in various CTFs and hands-on things at @defcon, go ahead and install a VM from the "Kali Everything" ISO and run updates. It's way bigger than you need, but you won't have to rely on a connection to the internet to install that one tool you forgot.
7
15
121
19,855
Very important to bring your VA card with you on coup attempts
Replying to @telesurenglish
.@NicolasMaduro: Among the terrorist captured today they were 2 U.S. military officials from Texas. According to a member of the band they are "intermediaries with Trump's head of security". Their names are Luke Denman and Aaron Barry, members of the company Silver Corp.
7
21
94
Google would regain probably 90% of the good will they lost simply by turning Reader back on. Flip of the switch.
6
7
112
Congrats all. An amazing month. Cybersecurity awareness: solved 😎
13
10
114
15,351
I’ll mostly be posting on @defcon’s instance of a social networking platform, which they’ve blogged about recently on their site. It’s against the rules of Twitter now for me to link it, mention it’s name (even in my profile), or say what my name is there, but I’m easy to find.
4
13
110
84,485
how likely is it that you’re sitting on nginx 0day but bad enough at monetizing that you’d go for this
6
122
13,553
QAnon believers are getting closer and closer to shooting themselves in the feet with Ghidra. Thanks to @ktl_____ for pointing me at some recent chatter.
6
21
102
If you think this is wild, imagine this: you have infosec peers that are currently and *concurrently* doing their day job and moonlighting as blackhats, malware authors, etc.
14
8
110
Stickers for #DEFCON32 have arrived (‘feng for scale). I have 100 of each. I’ll reserve enough for workshop attendees and discord members first (pinned tweet)! @defcon
18
7
114
9,265
Moon’s haunted
NASA to buy lightweight, semi-automatic rifles defence-blog.com/news/nasa-t…
12
36
107
Replying to @vxunderground
It’s important to have a hobby
2
117
8,385
This thing is going to be expensive
New photo of the back of the Flipper One heise.de/news/l-f-Neues-Foto… USB-C 24 pin GPIO SMA M.2 expansion (S3 Key B) / USB3.0 / PCIe 2.1 #SoftwareDefinedRadio #SDR #FlipperZero #FlipperOne
9
5
117
9,586
You don’t have to “divide” the community, you just have to throw out the trash
3
14
100
“Alleged” doing a lot of heavy lifting here lol
10
103
don’t worry y’all i’m bringing a flipper zero, an esp8266 deauther, and a yagi. the sphere doesn’t stand a chance
16
7
107
12,897
Bonus tip: People searching your room might just steal shit with a "danger to the property" handwave because it's cool, they want it, and they figure you haven't got much recourse. The world's a shitty place (5/4)
2
1
111
5,024
The NSA posted a bit more info about the open source public release of GHIDRA nsa.gov/resources/everyone/g…
3
73
118