Red Blue Team – Telegram
Red Blue Team
5.02K subscribers
38 photos
5 videos
33 files
1.43K links
-> 20 June 2019

]-> RedTeam | BlueTeam | Pentest

[-> Blue Team @BlueTeamKit
Download Telegram
#getshell
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. CVE project by @Sn0wAlice
https://github.com/Live-Hack-CVE/CVE-2022-46020

#webshell
A polymorphic webshell generator

https://github.com/evaannn/delorean

@BlueRedTeam
#Red_Team

Sandman is a backdoor that meant to work on hardened networks during red team engagements.

Sandman works as a stager and leverages NTP (protocol to sync time & date) to download an arbitrary shellcode from a pre defined server.

Since NTP is a protocol that is overlooked by many defenders resulting wide network accessability.

https://github.com/Idov31/Sandman

@BlueRedTeam
redteam_with_onenote (1).pdf
576.3 KB
#Red_Team

RedTeam With OneNote Sections

1. Not affected by Protected View/ MOTW
2. Allows embedding Malicious Excel/Word/PPT files that will be played without protected view
3. Allows embedding HTA, LNK, EXE files and spoof extensions
4. Possible to format document in a way user are tricked into opening a malicious file or a link

@BlueRedTeam
🔥5👍1😁1
Friends, has anyone worked with sigtran? Message me:
@NetPwn

دوستان کسی با sigtran کار کرده به من پیام بده :
@NetPwn
#CVE-2023
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21556, CVE-2023-21679. CVE
https://github.com/Live-Hack-CVE/CVE-2023-21555

@BlueRedTeam
#Red_Team

I've had so much fun learning rust. This is an excellent example of the power of rust, no EDR unhooking, patching of ETW, syscalls, or LITCRYPT and it calls home against EDRs.  More to come soon .

https://twitter.com/Tyl0us/status/1627759675352424460‌

@BlueRedTeam