I did a stupid thing and now it's on github. I was curious if I can issue commands from a server via serverHello, execute them on the client and pass the output back via the clientHello. Turns out you can make bytes to anything.
Blog: medium.com/p/24ac04bc6472
23.11.2025 12:22
π 0
π 0
π¬ 0
π 0
If there's interference in an oversimplified case, what if we consider motive? Fake First seems.. sensible :)
01.10.2025 13:32
π 1
π 0
π¬ 0
π 0
While truth occurs, its truthful reporting is unlikely. Stating a non binary fact to be true is frequently accompanied by arbitrary lines drawn in the sand by the storyteller. Whoever tells the tale, leaves a nuance that muddles the truth.
01.10.2025 13:32
π 1
π 0
π¬ 1
π 0
Conference banner with text: I'm speaking at DefCamp 2025. The title of the presentation: TLS Protocol Manipulation: a (very) low throughput C2 channel. Date and location: 13-14 November, Bucharest, Romania
If you have a high enough tolerance to pain, you can make bytes do anything
17.09.2025 09:28
π 0
π 0
π¬ 0
π 0
This was so good!
23.07.2025 16:04
π 1
π 0
π¬ 0
π 0
Taking them to the SHITTER: an analysis of vendor abuse of security research in-the-wild
aff-wg.org/2025/07/13/t...
(There is no benefit modulating my voice for anyone's comfort. This is my fair take, but unapologetic truth. This phenomena has gone unchecked for too long)
14.07.2025 14:05
π 10
π 7
π¬ 1
π 0
I reached the same conclusion after reading his autobiography. Nothing like a man's own words to betray him
14.07.2025 07:49
π 0
π 0
π¬ 0
π 0
+1 for adoption fatigue
13.07.2025 16:25
π 5
π 0
π¬ 0
π 0
So accurate. Ever since I read it, half my windows conversations start with "when I was reading Windows Security Internals". I'm knowingly accepting being annoying, that's how good James' book was
02.07.2025 08:58
π 0
π 0
π¬ 0
π 0
It was amazing! And it wouldn't have happened without Chris Brenton's and Troy Wojewoda's courses on Antisyphon. Top notch content, keep doing you :)
01.07.2025 16:07
π 1
π 0
π¬ 0
π 0
The more I look at his website, the more I wonder where this man and his bottle have been all my life
27.06.2025 20:11
π 0
π 0
π¬ 0
π 0
I was looking for a prism but now that sounds just so plain
27.06.2025 20:07
π 0
π 0
π¬ 1
π 0
The code and slides are both on my github. For any feedback, I'd be grateful.
27.06.2025 18:57
π 0
π 0
π¬ 0
π 0
TLS data exfiltration: smuggling bytes with ClientHello
This is a bit of research on a very low throughput (65 bytes) data exfiltration via TLS ClientHello message fields, using GREASEβ¦
TLS data exfiltration: smuggling bytes with ClientHello is a very low throughput "technique". Not really a technique, more like a way for me to learn networking protocols.
Blog post here: medium.com/@haarlems/tl...
27.06.2025 18:57
π 0
π 0
π¬ 1
π 0
I failed and kept on failing until I didn't.
What started as frustration at not solving a network forensics challenge on the @antisyphontraining.bsky.social cyber range on @metactf.bsky.social led to my first research.
Yesterday, it was also my first time presenting at BSides Bucharest!
27.06.2025 18:57
π 1
π 0
π¬ 2
π 0
Cover of book Linkers and Loaders by John R. Levine. The image shows a construction crane lifting several steel beams against an orange and purple sky. I assume it is a nod to the theme of building software components
How many linker errors while patching openssl does it take before you seek salvation in a 1999 book?
12.05.2025 17:43
π 1
π 0
π¬ 0
π 0
I need this on a tshirt
08.05.2025 12:46
π 2
π 0
π¬ 0
π 0
I once heard a network engineer comment that the speed of light is too slow, and that has haunted me ever since.
07.05.2025 18:21
π 32
π 6
π¬ 5
π 0
RUMOURS are TRUE π€·ββοΈ
PHRACK will be releasing a SPECIAL #71.5 πHARDCOVERπ at www.offensivecon.org BERLIN ("The π
-Day Edition").
Main #72 release THIS SUMMER at MULTIPLE conferences (main release at WHY2025). β€οΈ
28.04.2025 10:16
π 13
π 5
π¬ 1
π 0
Is it malware or is it enhanced endpoint telemetry
27.04.2025 07:45
π 0
π 0
π¬ 0
π 0
@tiraniddo.dev did us all a solid with this one, I totally agree
27.04.2025 04:35
π 2
π 0
π¬ 0
π 0
This looks like something @jags.bsky.social could do an easy 6 minute rant on
25.04.2025 15:10
π 2
π 0
π¬ 0
π 0
Haha some bits hit too close to home
25.04.2025 15:04
π 1
π 0
π¬ 0
π 0
This is your reminder to stick it to the bank man.
25.04.2025 14:15
π 0
π 0
π¬ 0
π 0
Tried to make a donation to the @archive.org. The bank canceled the transaction and blocked my card for suspicious activity. I donated another way. And tripled it out of spite.
Which project are u fighting the big banks to support today?
25.04.2025 14:15
π 0
π 0
π¬ 1
π 0
A tool that neutralizes traffic noise but keeps the sound of birds chirping
12.04.2025 12:15
π 0
π 0
π¬ 1
π 0
Haha, I love the "like some black market charlatan" bit. So accurate
12.04.2025 12:06
π 0
π 0
π¬ 0
π 0
But most importantly, I love it when he addresses researchers.
In between this and @gentilkiwi.bsky.social's BlueHatIL call to inspire hackers to create their own tools.. it's a good day for research!
11.04.2025 14:44
π 0
π 0
π¬ 0
π 0
Also touching on the culture shift that "values the ability to fully subvert security and not the ability to inform securityβ. I believe the work of offensive teams serving the blue team cannot be emphasized enough.
My favorite bit is when he says it's not about βhackery malware things" :)
11.04.2025 14:44
π 0
π 0
π¬ 1
π 0