Dominic White
@singe
Hacker at Orange Cyberdefense's SensePost Team
 The work from Mathy and friends showed that malicious channel switch announcements are a pretty good deauth primitive for management frame protection networks, so I added it to aircrack-ng: https://github.com/aircrack-ng/aircrack-ng/pull/2724
My fortune cookie is even giving me sh*t about maintaining our WiFi hacking course.
BlackHat airport advertising is up but this is the only one that unintentionally makes any sense to a hacker.
I always love the care our training ops team puts into our BlackHat training swag but the war games mainframe and WiFi themes are both close to my heart. Thanks Darryn & Andre!
I’ve seen a few dry runs of the absolutely fire talk Reino has prepped for everyone at DEFCON this year. Want to see multiple exploit chains on a widely deployed PED device deemed so impactful the vendor asked us to wait two years to disclose, then catch “Very Pwned” info.defcon.org/defcon34/con...
Every time we give our wifi hacking training @blackhatevents.bsky.social, we need to help people understand the vagaries of aircrack's airodump-ng, until now, because @shifttymike.bsky.social fixed it!
I really like this evaluation matrix from @RoelofTemmingh’s @BSidesJoburg keynote for judging quality in a flood of AI slop. The one that resonated with me in particular was: “Has this person ever paid a cost for being wrong”
Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768
A quick run through the new iOS 27 beta system settings and I noticed: 1 You need to join a waitlist to access new Siri 2 it now shows what type of WiFi is in use when connected 3 it may not be new - but there’s an “impersonation risk detection” feature that can be shared with apps
Time to exploit reducing? Zero day clock? Pepperidge farm remembers the early 2000’s.
I AI generated this punk song a week ago. Kind of saw it coming. Wish we could move on from rhyming the death and misery.
Over the years I’ve always used some app to prevent my Mac from locking during long running tasks like password cracking sessions or more recently agentic workflows. But they’re poorly maintained or over complicated. So I made my own. NoLock does what it says on the tin github.com/singe/NoLock
I'm impressed by how light weight the Apple on-device Foundation LLM is for Apple Intelligence, so I vibe'd a small macOS tool (26.0+) to interact with them. It supports GUI and CLI and tool calling. Even big responses fail to move the CPU/GPU by a single percentage. Link below.
I updated that Burp Global Match & Replace plugin to use the Montoya API, be able to target specific Burp tools (or apply globally), extend the rule matching syntax, and give you a view per request and response of the changes. github.com/singe/burp_g...
In Portswigger's Burp I needed a way to do Match & Replace globally across all utilities, not just the proxy so I wrote an extension github.com/singe/burp_g...
The number of times people have tried to kill Net-NTLMv1 eh? youtu.be/lm7Cuktpnb4?...
I figure the conical burr cup has a mix of extraction flavours all mixed together (due to the initial distribution and higher number of fines). The flat burr made my boring beans taste boring and punished sooner with wrong grind size (but rewards so much more on right). Enjoying these at the moment.
T’was 0xC0N Jozi today. That makes number 9, finally beating ZaC0N’s run of 8 years. It’s such a special con because it’s small and full of passionate attendees - no corporate wage slaves there for a day off work, just a bunch of hackers new and old.
Just added SOCKS support to this reverse tunnelling tool github.com/singe/contun...
I missed Spinach & was tired of writing hard code that LLMs struggled to help with. So I decided to recreate the functionality of Spinach in a discord world. And so Cabbage was born. Cabbage is private for now, but it’s been so cathartic writing something easy and fun. And vhata saved Spinach’s DB!
I had occasion to hack on some Wordpress’es and realised there’s a ton of surface area exposed over the "new" REST interfaces. Here's a small utility to convert it into a OpenAPI/Swagger file so you can explore it in your pentests/bug bounty work. github.com/sensepost/wp...
Cyble wanted this blog post taken down … Barbra Streisand (woo ooh ooh woo woo)