Log inSign up
James Forshaw
6,573 posts
Image
user avatar
James Forshaw
@tiraniddo
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
United Kingdom
tiraniddo.dev
Joined July 2009
336
Following
49.3K
Followers
  • Pinned
    user avatar
    James Forshaw
    @tiraniddo
    Mar 28, 2024
    This new book has finally arrived. Thank's to @nostarch as well as @billpollock for making it happen as well as @Lee_Holmes as my tech reviewer.
    A copy of the book Windows Security Internal, available from No Starch Press that was written by the author of this post.
    111K
  • user avatar
    James Forshaw
    @tiraniddo
    Dec 18, 2017
    My book's finally here, just in time for Xmas. Thanks to @billpollock and @nostarch for all their time and effort as well as my friend @k8em0 for doing the forward. Hope anyone who's bought it are seeing final copies arriving. And it's a dog on the cover BTW 🙂
    Image
  • user avatar
    James Forshaw
    @tiraniddo
    May 9, 2020
    You're not getting me that easily copper.
    met.police.uk website requesting location permission from the web browser.
  • user avatar
    James Forshaw
    @tiraniddo
    Aug 22, 2023
    My next book is finally in early-access at @nostarch, with the goal for release at the end of 2023. More details are available at nostarch.com/windows-securi…
    Sample copy of my next book, Windows Security Internals with PowerShell. The cover is purple with a picture of a cowboy riding a keyboard.
    74K
  • user avatar
    James Forshaw
    @tiraniddo
    Oct 21, 2021
    "Can you still relay authentication in a Windows domain if NTLM is disabled?", I asked myself. "Perhaps I should research that" I said. Here's a blog post about what I found out.
    Image
    Using Kerberos for Authentication Relay Attacks
    From projectzero.google
  • user avatar
    James Forshaw
    @tiraniddo
    Sep 15, 2021
    Gru meme. Ignore Windows Security, Focus on Azure Secuirty, Both Platforms Insecure.
  • user avatar
    James Forshaw
    @tiraniddo
    Sep 8, 2020
    Opened a fun bug (or is it backdoor?) in a "hidden" COM server which adds a certain Mr DeYoung as an Administrator to your computer with no password. bugs.chromium.org/p/project-zero….
    Windows login screen with Darrin DeYoung user name with no password requirement.
  • user avatar
    James Forshaw
    @tiraniddo
    Nov 16, 2019
    Published part 1 of a short series on AppLocker internals, no bypasses, just how the technology actually works on Windows 10 1909 and maybe some silly tricks along the way. tyranidslair.blogspot.com/2019/11/the-in…
  • user avatar
    James Forshaw
    @tiraniddo
    Jul 5, 2022
    Finally I can release details about my most serious RCG bug. RCE/EoP in LSASS via CredSSP. Reachable through RDP or WinRM if configured correctly. Will try and put together a blog about it at some point😁bugs.chromium.org/p/project-zero…
  • user avatar
    James Forshaw
    @tiraniddo
    Mar 12, 2017
    This only took me 4 years to write :-) Abusing default Windows Kernel Debugging settings to bypass the login screen. tyranidslair.blogspot.co.uk/2017/03/gettin…
  • user avatar
    James Forshaw
    @tiraniddo
    Jun 4, 2024
    Just because you get access denied accessing a folder, it doesn't mean you can't get access. A quick look at bypassing the security on the WindowsApps folder. tiraniddo.dev/2024/06/workin…
    65K
  • user avatar
    James Forshaw
    @tiraniddo
    Mar 20, 2022
    Written a quick blog post about abusing Kerberos to locally bypass UAC. Unclear if this technique has been documented before, but at the very least I describe why it works :) tiraniddo.dev/2022/03/bypass…
  • user avatar
    James Forshaw
    @tiraniddo
    Sep 25, 2019
    Written a new blog in my Windows Exploitation Tricks series, how to spoof the named pipe client PID. googleprojectzero.blogspot.com/2019/09/window…
  • user avatar
    James Forshaw
    @tiraniddo
    Feb 9, 2024
    I try an avoid this hellsite, but I did a quick dive into sudo in Windows and here are my initial findings. tiraniddo.dev/2024/02/sudo-o… The main take away is, writing Rust won't save you from logical bugs :)
    70K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement