Will Hunt

Hacker, trainer, speaker, musician. Co-founded In.security

Will Hunt boosted:
2025-06-30

We have a poll going about when the next competitive event should be. We currently have it pinned for October but based on community feedback, that is likely to change!

If you want to voice your thoughts, consider dropping by and casting your vote. This could affect the competitive schedule in perpetuity, so be sure to drop by if you want a say! Poll is open for ~13 days.

discord.com/invite/eABKrn2d6q

Will Hunt boosted:
2025-06-21

Congratulations to our winners of the June 2025 Casual Jabbercracky!

1st place: Stealthsploit wielding a Bone-Chilling Chainsaw of Unhashed Passwords
2nd place: A8B394321E77E0F7 wielding a 20733 Year Old Curved Saber of Eternal Night
3rd place: AlMcWhiggin wielding a As Seen On TV Rubber Chicken

Thank you much to all of the competitors! See you next month!

#jabbercracky

Jabbercracky LeaderboardJabbercracky Line Graph of Points Over Time
Will Hunt boosted:
2025-06-18

~48 hours left for the June event!

#jabbercracky

My talk from Security Fest is now live for any interested security enthusiasts, pentesters, red teamers and password crackers. Fun fact, my voice is that annoying in real life too.

youtube.com/watch?v=ArLhwcpWMdU

Following my Security Fest talk yesterday I've released Hashcatalyst, a wrapper that helps automate non-distributed workflows by chaining multiple attacks with no downtime.

github.com/stealthsploit/Hashc

#hashcat

For my Security Fest talk next week I'll be releasing a new tool to help automate non-distributed hashcat workflows, allowing people to chain multiple attacks with no downtime.

Keep your eyes peeled!

Wordpress’s new bcrypt implementation is prehashed with SHA-384? Not good if so as it facilitates password shucking attacks? Surely better to enforce a length limit?

Hopefully you've patched CVE-2025-24054. Whilst on the topic, as far as NTLM disclosure is concerned for REMOTE attackers, block SMB on egress (if someone's already inside then you've got bigger problems).

Kinda shouldn't need to be said in 2025 but kinda needs to be said 🤷‍♂️

Will Hunt boosted:
Anant Shrivastava aka anantshrianant@anantshri.info
2025-04-19

A reflective take on how modern systems—from social media to certifications—reward surface-level wins over deep effort. This post explores how we’ve learned to game metrics, optimize for the minimum, and lose sight of meaning in the process. It asks: what happens when the game replaces the goal?

https://blog.anantshri.info/weve-all-learned-to-game-it/

#Incentives #Metrics #Optimization #SystemDesign #DigitalCulture #BlogPost #Writing #Fediverse #FOSS #WorkCulture #TechPhilosophy

Will Hunt boosted:
2025-04-17

@MissConstrue @csgraves

Oh yes, there are better ways than Hasselhoffing them. In which case then, are you also aware of....

The Duck Song
youtube.com/watch?v=MtN1YnoL46Q

Where can you see Lions?
youtube.com/watch?v=FbYtASAakAI

Narwhals
youtube.com/watch?v=ykwqXuMPsoc

Magical Trevor (several episodes, but 1 is the best)
youtube.com/watch?v=au3-hk-pXsM

We've sold out our Defending Enterprises training at Security Fest on June 2-3!

Only 7 tickets remain for our Hacking Enterprises training, hope to see you there!

securityfest.com/

Hilarious. Free entry level ESXi hypervisor is back 😂

broad-cloud.nl/free-esxi-entry

A nice spreadsheet of C2 frameworks for easy comparison of everything from licensing and implementation through to payload support and capabilities.

docs.google.com/spreadsheets/d

Created and maintained by @c2_matrix

@angrylinus when one door closes, another opens! Stay optimistic

@alsternerd ah good spot, edited. Thanks.

@the_turtle the question is…with this bypass, why would you want to?

Persist with your local accounts. Don't succumb to MS's need for you to be online.

Useful as MS has removed the BypassNRO script from preview builds

Windows 11 setup screen allowing users to create local accounts and bypass the forced online account creation. Press Shift + F10 for a command prompt, then enter start ms-cxh:localonly

We've got two great community talks lined up on our Discord server!

Wed 21st May @ 19:00 BST, Jon Bonacci will be delivering "Ransomware Unmasked: The Evolution, Tactics, and Defense Playbook"

and then on Tues 22nd July @ 20:00 BST, Joseph Deskin will be presenting "Cobalt Strike 101".

Hope to see you there 🎉

discord.gg/aCgUbE8ePD

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst