home > posts
  • August 10, 2025
    HD Moore
    @hdm

    Thank you to everyone who made it out for my DEF CON 33 presentation, "Shaking Out Shells With SSHamble", you can find the materials online at https://hdm.io/decks/MOORE%20-%20Shaking%20Out%20Shells%20With%20SSHamble.pdf

    This deck includes some lightly-censored zero-day and I recommend tossing `sshamble scan -u root,admin,guest 22,24442,2222,70,222,10022,10399,2022,22222 --interact=all` at your local network to see what shakes out =D

    (PS. You can find most of my presentations at https://hdm.io/)

    ↪ reply
  • August 10, 2025
    HD Moore
    @hdm

    Are you an Austin-area software engineer who writes Go (or aspires to become one)? Join us Wednesday, August 13, 2025 for two hours of lightning talks and discussion, including recaps of awesome Go work presented at the Black Hat and DEF CON conferences. Have a short talk on Go (with or without security focus)? Bring it!

    This meetup is hosted by Capital Factory and runs from 6:30 PM to 8:30 PM CDT: https://www.meetup.com/atxgolang/events/305492505/?slug=atxgolang&eventId=305492505

    Please RSVP so we can accurately order enough pizza and drinks.

    ↪ reply
  • August 9, 2025
    HD Moore
    @hdm

    Hello DEF CON! Tomorrow (Saturday/August 9th) I'll be speaking with Nicole Schwartz on Forging Strong Cyber Communities in Uncertain Times at 1pm in W205 (TDI) and then shortly after on Shaking Out Shells with SSHamble at 3pm in Track 2 (LV1), with even more shells. Hope to see you there!

    1. https://calendar.google.com/calendar/u/0/r/month/2025/8/9?eid=NDBmOWhyMzZsaDBsYWU0MjRudHBkbHBjZ2ggY184YmI1ODdmNzM0NGNmNTJjNTIzY2Y2NWE1MGM4YzU3ODlhY2VlZDVlMGVkZTQyYWQzNjE4YjI2MzUwOTg4YjVmQGc
    2. https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60360

    ↪ reply
  • August 5, 2025
    HD Moore
    @hdm

    BSides Las Vegas 2025 is incredible. Amazing turn-out, fantastic staff, and the sheer variety of content, speakers, and activities sets the bar for what a hacker con should be. You can find the slides from my talk, Turbo Tactical Exploitation: 22 Tips for Tricky Targets, online at https://hdm.io/decks/BSidesLV%202025%20-%20%20Turbo%20Tactical%20Exploitation_%2022%20Tips%20for%20Tricky%20Targets.pdf

    It looks at least a bit of the video is on YT as well at https://www.youtube.com/watch?v=goERQMqAv50 (Ground Floor at 11am). Thank you to everyone who attended and to the BSides team for a wonderful experience!

    ↪ reply
  • July 16, 2025
    HD Moore
    @hdm

    runZero Hour #20 is LIVE NOW - This is an amazing episode that includes Rishi & Sandeep of https://projectdiscovery.io/; here to give us the backstory on their company and the Nuclei open source vulnerability scanner (already bigger and more popular than Metasploit!). Hit our YT live stream to hear about PD, Nuclei, and how runZero is working with PD and the community on open source security tools!

    https://www.youtube.com/watch?v=kLyukzprtDo

    ↪ reply
  • July 9, 2025
    HD Moore
    @hdm

    Hello Austin Gophers! The July ATX Go Meetup is TONIGHT (July 9th). The meetup includes lightning talks, pizza, beverages, and general discussion. Have a neat idea? A quick talk related to Go? Something to show-and-tell? https://www.meetup.com/atxgolang/events/305492502/

    The weather outside is lousy, you might as well hang out in a conference room with us nerds! =D

    ↪ reply
  • June 26, 2025
    HD Moore
    @hdm

    I'm excited to announce our "Out-of-Band" series; these articles focus on the security risks of management devices like BMCs, serial servers, and IP-enabled KVMs. "Out-of-Band, Part 1: The new generation of IP KVMs and how to find them" is now live at:
    https://www.runzero.com/blog/oob-p1-ip-kvm/

    ↪ reply
  • June 21, 2025
    HD Moore
    @hdm

    Do you enjoy guzzling real-time TLS certificate allocations, but don't want to use a third-party service (crt.sh, CertStream, etc.)? Drink straight from the Certificate Transparency log firehose using ctail:

    $ go run github.com/hdm/ctail@latest -f -m '^autodiscover\.'

    https://github.com/hdm/ctail

    ↪ reply
  • May 19, 2025
    HD Moore
    @hdm

    A PSA for why you should probably not use Postman (it can leak secrets to them): https://anonymousdata.medium.com/postman-is-logging-all-your-secrets-and-environment-variables-9c316e92d424

    ↪ reply
  • April 26, 2025
    HD Moore
    @hdm

    Hello from BSides San Francisco! I'm excited to speak at 1:30pm in the AMC IMAX today. If you'd like to catch up afterwards, I'll be at the runZero booth first and at the City View lounge later. If you couldn't make the trip, the streaming links are live at https://www.youtube.com/@BSidesSF/streams

    Hope to you see you there!

    ↪ reply
  • << View newer posts View older posts >>

Copyright 1998-2025 HD Moore