Felipe Molina's Avatar

Felipe Molina

@felmoltor.me

Mastodon felmoltor@defcon.social. Now with more #OSCP than the previous version. Working @SensePost.com - Orange Cyberdefense https://blog.felipemolina.com/

100
Followers
211
Following
80
Posts
15.11.2024
Joined
Posts Following

Latest posts by Felipe Molina @felmoltor.me

Post image

Good night, Jupiter

21.02.2026 00:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

I can go sleep now with a more colourful photo of M42 obtained tonight 🌌

13.02.2026 23:51 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
13.10.2025 23:15 πŸ‘ 671 πŸ” 103 πŸ’¬ 14 πŸ“Œ 4
Post image

I'm still in the learning phase, but I feel pretty proud of my first M42 Nebula shot 🌌. Even taking it with a full moon and in the middle of the city, I got a decent photo.
Next time will be much better πŸ’ͺ🏼

01.02.2026 20:08 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

an easy way to remember the difference between ssh -L and ssh -R is to try both until it works

28.01.2026 01:28 πŸ‘ 179 πŸ” 14 πŸ’¬ 12 πŸ“Œ 0
A screenshot of the rule editing dialog with all the options described in the readme.

A screenshot of the rule editing dialog with all the options described in the readme.

I updated that Burp Global Match & Replace plugin to use the Montoya API, be able to target specific Burp tools (or apply globally), extend the rule matching syntax, and give you a view per request and response of the changes.
github.com/singe/burp_g...

26.01.2026 13:01 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail
23.01.2026 20:47 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A close up picture of the sun with a dozen sunspots or so

A close up picture of the sun with a dozen sunspots or so

Today I made my first portrait of the sun 🌞
You can even see the sunspots! The focal length of my telescope makes it impossible to take the picture of the whole sun, but I'll get to it soon.

23.01.2026 20:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
PoC authentication bypass for telnetd.

PoC authentication bypass for telnetd.

Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁.

github.com/leonjza/inet...

₁ seclists.org/oss-sec/2026...

21.01.2026 11:05 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

With a bit of zoom and colour correction

20.01.2026 12:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Yesterday I was able to catch, with my phone, Jupiter transitioning through the lens. A lot of margin for improvement (e.g. motor for the RA axis), but happy with the progress I'm making πŸ”­

20.01.2026 10:25 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

And a few more of this morning πŸŒ…

19.01.2026 09:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

A few photos I took this weekend 🐢🐦

19.01.2026 09:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
a man in a suit and white shirt is standing in front of a window and says `` i 'm an immortal '' . ALT: a man in a suit and white shirt is standing in front of a window and says `` i 'm an immortal '' .
16.01.2026 19:08 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

The number of times people have tried to kill Net-NTLMv1 eh?
youtu.be/lm7Cuktpnb4?...

16.01.2026 03:47 πŸ‘ 5 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
A planetary camera

A planetary camera

Uh, really excited to give my new toy a try tonight πŸ“ΉπŸ”­

15.01.2026 11:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A black box with a single red led similar to the Internet as depicted in IT Crowd

A black box with a single red led similar to the Internet as depicted in IT Crowd

I'm getting more and more disappointed with the Internet nowadays, so I made one for myself yesterday.

31.12.2025 22:40 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

A source shares some screenshots of the Lapsus ransomware gang celebrating the government shutdown as a disruption to the FBI investigations tracking them.

They also refer to Trump as "my king."

01.10.2025 15:07 πŸ‘ 32 πŸ” 21 πŸ’¬ 2 πŸ“Œ 1

Eso no se olvida nunca, lo llevo como el tatuaje de la mili de "Amor de GPO"

11.09.2025 17:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Gracias! Me va a venir genial esa lista para desconectar un poco del contenido americano.
Joder, no consigo recordar ese diagrama de Venn! Pero tampoco me acuerdo de lo que comΓ­ ayer, asΓ­ que...

11.09.2025 13:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Yeah, probably it's my fault (my follow list), combined with the insufficient user base of other countries here, and, probably, the algorithm used in the "Discovery" tab.

11.09.2025 09:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Maybe it's my fault, but I'm really missing non-US related content in Bluesky. Can we talk about other countries, please?
I don't want to go back to X 😒 πŸ™πŸΌ

11.09.2025 09:22 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
PipeTap WIP Demo
PipeTap WIP Demo YouTube video by Leon Jacobs

If you're at RomHack at the end of the month, come tell me your @github.com username and I'll give you early access to the @sensepost.com tool repo for PipeTap at the con! πŸ™ƒ

Below is a demo of the proxy in action.

www.youtube.com/watch?v=or8Y...

10.09.2025 13:41 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
The proxy view for PipeTap, a Windows Named Pipe Analysis Tool

The proxy view for PipeTap, a Windows Named Pipe Analysis Tool

I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)

10.09.2025 13:41 πŸ‘ 9 πŸ” 7 πŸ’¬ 2 πŸ“Œ 3
Three sides of a sand-coloured building surrounding a rectangular pool. The pool is edged by a low hedge and the water reflects the surrounding buildings and the blue sky above. In the foreground water trickles down into the pool from a smaller circular stone pool. The building at the far end has a carved, arched verandah and sits below a square tower. People stroll along the sides of the building.

Three sides of a sand-coloured building surrounding a rectangular pool. The pool is edged by a low hedge and the water reflects the surrounding buildings and the blue sky above. In the foreground water trickles down into the pool from a smaller circular stone pool. The building at the far end has a carved, arched verandah and sits below a square tower. People stroll along the sides of the building.

One of the pools in the Alhambra Palace complex in Granada.... had to be this one for #PalacesandGardens #Water #photography #dailyphoto #travel #Spain

04.09.2025 20:23 πŸ‘ 26 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1
A screenshot of two windows. The top is a view of the Microsoft SQL management GUI showing that β€œExtended Protection” is enabled for NTLM authentication. The bottom is a terminal showing an invocation of Impacket’s mssqlclient.py successfully connecting using channel binding.

A screenshot of two windows. The top is a view of the Microsoft SQL management GUI showing that β€œExtended Protection” is enabled for NTLM authentication. The bottom is a terminal showing an invocation of Impacket’s mssqlclient.py successfully connecting using channel binding.

Reverse engineering Microsoft’s SQLCMD.exe to implement Channel Binding support for MSSQL into Impacket’s mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself.

sensepost.com/blog/2025/a-...

31.07.2025 16:19 πŸ‘ 10 πŸ” 6 πŸ’¬ 0 πŸ“Œ 1
Preview
Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads Attackers are exploiting Proofpoint and Intermedia link wrapping to mask phishing payloads.

From June 2025 through July 2025, the Cloudflare Email Security team has been tracking a cluster of cybercriminal threat activity leveraging Proofpoint and Intermedia link wrapping to mask phishing payloads. Read more: cfl.re/4lUXBEE

30.07.2025 13:54 πŸ‘ 8 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Active Supply Chain Attack: npm Phishing Campaign Leads to P... Popular npm packages like eslint-config-prettier were compromised after a phishing attack stole a maintainer’s token, spreading malicious updates.

There's an ongoing npm supply chain attack taking place:

socket.dev/blog/npm-phi...

x.com/AikidoSecuri...

19.07.2025 11:53 πŸ‘ 21 πŸ” 10 πŸ’¬ 0 πŸ“Œ 0
BChecks/vulnerabilities-CVEd/CVE-2025-5777 - CitrixBleed 2.bcheck at main Β· felmoltor/BChecks BChecks collection for Burp Suite Professional and Burp Suite DAST - felmoltor/BChecks

The bcheck is here, ping me if you have comments or improvement suggestions: github.com/felmoltor/BC...

17.07.2025 06:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
CVE-2025-5777 - CitrixBleed 2 by felmoltor Β· Pull Request #253 Β· PortSwigger/BChecks BCheck Contributions BCheck compiles and executes as expected BCheck contains appropriate metadata (name, version, author, description and appropriate tags) Only .bcheck files have been added o...

I've created a pull request to detect CitrixBleed 2 into Burp's Bcheck repository: github.com/PortSwigger/...

17.07.2025 06:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0