Cas van Cooten's Avatar

Cas van Cooten

@casvancooten.com

@chvancooten on the bird app ๐Ÿฆ --- Benevolently malicious offensive security enthusiast || OffSec Developer & Malware Linguist || NimPlant & NimPackt author || @ABNAMRO Red Team

607
Followers
122
Following
61
Posts
01.11.2024
Joined
Posts Following

Latest posts by Cas van Cooten @casvancooten.com

Post image

Not thinking about infosec for a while ๐Ÿฅฐ

25.04.2025 19:00 ๐Ÿ‘ 27 ๐Ÿ” 0 ๐Ÿ’ฌ 6 ๐Ÿ“Œ 0
Post image

BTW - I don't see this as a vulnerability. It is (clearly) by design, just something to be cautious with for all the vibe coders out there :)

The @vscode.dev is doing an excellent job here - they even disable Copilot entirely in untrusted (restricted) workspaces.

18.04.2025 15:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

quack.py needs work still

18.04.2025 14:46 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

10/10 no notes, excellent blending in

18.04.2025 14:36 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Post image

Pretty fun proof of concept - VS Code's `copilot-instructions.md` allows for blatant backdooring of agents if any AI agents or edits are run from an untrusted repository. It can seemingly fulfil the user's request, but actually implement (and hide) some nefarious side activities ๐Ÿ˜‚

18.04.2025 14:33 ๐Ÿ‘ 6 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Very glad I'm not going - at least for this year. We'll see if (or when?) this situation crystallizes out ๐Ÿ˜…

12.04.2025 06:02 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

This is actually so good ๐Ÿ‘Œ

01.04.2025 02:26 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Yes! Already made plans to link up ๐Ÿ™Œ

31.03.2025 12:42 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Touched down in Singapore! Looking forward to Black Hat Asia. Hope to see many of you around!

31.03.2025 11:40 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

This must be the most informative graphic contained in the Microsoft docs
learn.microsoft.com/en-us/opensp...

18.03.2025 12:55 ๐Ÿ‘ 6 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Doing it out of spite. Love it! ๐Ÿ˜‚

12.03.2025 20:53 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Yeah on sunny days I sometimes get 15-20kWh from my panels of which almost everything is returned to grid ๐Ÿ˜…. I guess it's not really about that number though, but more the question "does 2.7kWh last you until the next sunrays" maybe. And the 800W extra is nice to cover peak usage that exceeds solar

12.03.2025 19:20 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Good stuff! Definitely subscribing to your opinions on it in the future ๐Ÿ˜‚. 2.7kWh ain't much but it's enough to bridge the night on solar I guess!

12.03.2025 18:41 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I've been keeping an eye on these! What is your experience so far? Seems like a great solution in between nothing and a ridiculously expensive all-out battery setup. Too much uncertainty regarding saldering for me to buy anything yet tho ๐Ÿ˜‚

12.03.2025 17:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Truly mask off at this point.. it's saddening

09.03.2025 21:11 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

I was invited to present Nimplant at Black Hat Asia 2025 in Singapore this April! If you're around, please do reach out to talk offensive development, modern programming languages, or how to use (or detect) Nimplant in your ops. Looking forward to it!

www.blackhat.com/asia-25/arse...

08.03.2025 10:28 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

That's very cool! I briefly looked into adding plugins the "classical" way as well but backdooring an existing one seems much cleaner. Nice post!

01.03.2025 22:32 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Abusing VS Code's Bootstrapping Functionality To Quietly Load Malicious Extensions Wow, been a while since my last blog ๐Ÿ˜…. During some research I came across a technique variation which I felt was interesting enough to share in a brief blog post. It relates to how the bootstrapping ...

Recently came across a pretty neat technique to silently load (malicious) VS Code extensions using its bootstrapping and portability features. Thought it was interesting enough to warrant my first blog post in 4 years ๐Ÿ™ƒ

Check it out ๐Ÿ‘‡
casvancooten.com/posts/2025/0...

28.02.2025 15:57 ๐Ÿ‘ 7 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Leuk Johannes, dank!

13.01.2025 09:51 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Haha yeah this sounds familiar ๐Ÿ˜…. The smaller the feature the more bugs will pop up ๐Ÿ˜‚

02.01.2025 18:29 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Great updates! Thanks for sticking with the maintenance, still very useful in work automations! ๐Ÿ”ฅ

02.01.2025 17:59 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

First day back after leave, man does my brain feel the same trying to remember what all I did before ๐Ÿ˜‚๐Ÿ˜‚

23.12.2024 12:14 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thumb 11/10, will definitely watch first thing after holiday ๐Ÿ˜‚

08.12.2024 18:41 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
a puppet master poster shows a hand holding a puppet on strings ALT: a puppet master poster shows a hand holding a puppet on strings
02.12.2024 14:38 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Lol 75% thought leader, must be because I interact with @xpnsec.com too much ๐Ÿ˜‚
blueskyroast.com/roast/casvan...

02.12.2024 08:32 ๐Ÿ‘ 6 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
a group of people are screaming and laughing in a crowd ALT: a group of people are screaming and laughing in a crowd

let's goooo

01.12.2024 19:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Agreed, they're so much fun as a collectible.. maybe we should start re-using badges, new badge for first-time con visitors, firmware update for existing badge holders? ๐Ÿ˜‚

28.11.2024 11:04 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I think it's the latter for most? Less frustrations with the platform maybe, and/or not willing to juggle multiple platforms (temporarily) potentially

26.11.2024 18:41 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Unfortunately there are still too many capable and informative folks on there :(. At least to the degree I'm not comfortable burning my account with fire just yet. @xpnsec.com is doing a great job with influencing everyone to move over here, though!

26.11.2024 16:04 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0

My ears were ringing when this was presented at RedTreat. Time for round two with this blog and tool release ๐Ÿ˜… ๐Ÿ”ฅ

26.11.2024 16:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0