Offensive Xwitter – Telegram
Offensive Xwitter
19.4K subscribers
908 photos
48 videos
21 files
2.09K links
~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://news.1rj.ru/str/OffensiveTwitter/546
Download Telegram
😈 [ lkarlslund, Lars Karlslund ]

Stuck on a network with no credentials? No worry, you can anonymously bruteforce Active Directory controllers for usernames over LDAP Pings (cLDAP) using my new tool - with parallelization I get 10K usernames/sec
https://t.co/ETeKR4OVFP

🔗 https://github.com/lkarlslund/ldapnomnom

🐥 [ tweet ]
🔥1
😈 [ splinter_code, Antonio Cocomazzi ]

After more than 2 years, RunasCs got a big update! 🥳

Biggest changes:
- NetworkCleartext (8) default logon type
- UAC bypass (when admin pass is known)

Enjoy :D

https://t.co/WgAH4qpbZ6

🔗 https://github.com/antonioCoco/RunasCs/releases/tag/v1.4

🐥 [ tweet ]
😈 [ mrd0x, mr.d0x ]

Stealing Access Tokens From Office Desktop Applications

https://t.co/12bMrugfe9

🔗 https://mrd0x.com/stealing-tokens-from-office-applications/

🐥 [ tweet ]
😈 [ cube0x0, Cube0x0 ]

A new blog post about relaying YubiKeys is up and tools have been uploaded to GitHub!
This would not have been possible without the previous work of @_EthicalChaos_ so big thanks to him
https://t.co/zfEV7RUAV5

🔗 https://cube0x0.github.io/Relaying-YubiKeys/

🐥 [ tweet ]
😈 [ an0n_r0, an0n ]

Here is why NetNTLMv1 should be disabled in prod networks ASAP. Besides cracking the hash back to NTLM (and then forging Silver Tickets) is straightforward, there is also a lesser known but immediate relay attack path by removing the MIC and doing RBCD abuse. Demo in screenshots.

🐥 [ tweet ]
Forwarded from Offensive Xwitter Eye
😈 [ aniqfakhrul, Aniq Fakhrul ]

Thanks for the detailed poc! You can also do this without password by relaying ms-efsrpc to target computer, store the socks session and use it with printerbug

🐥 [ tweet ][ quote ]
😈 [ alukatsky, Alexey Lukatsky ]

Последние нашумевшие взломы (Uber, Okta, Microsoft, LastPass, Cisco и т.п.) объединяет одно - обход MFA. Не пора ли выбросить ее на свалку или все-таки у этой защитной меры есть шанс на достойное существование и надо просто правильно ее использовать? https://t.co/IRNwbbj2lU

🔗 https://lukatsky.ru/technology/vzlom-uber-cisco-i-okta-ili-ne-pora-li-vykinut-mfa-na-pomoyku.html

🐥 [ tweet ]
😈 [ gentilkiwi, 🥝🏳️‍🌈 Benjamin Delpy ]

Want to play with Djoin file ? Citrix SSO passwords?

A new #mimikatz 🥝release here for you!

> https://t.co/kG0WlIHOlQ

(no digital signature, OpenSource certificates are expensive😒)

🔗 https://github.com/gentilkiwi/mimikatz

🐥 [ tweet ]
😈 [ ippsec, ippsec ]

Uploaded a video on detecting Responder when it is setup to respond to LLMNR Requests. Nothing fancy, and there are tools that have done this for a long time like Respounder. However, we keep it simple with just powershell and a scheduled task https://t.co/0DOccIhMHF

🔗 https://youtu.be/h_cWWL-yyb0

🐥 [ tweet ]
😈 [ Markak_, Zhenpeng Lin ]

I just released the #DirtyCred version of exploit to CVE-2022-2588 (an 8-year-old bug) along with a brief write-up. Ideally, the exploit could work on different distros if the kernel is vulnerable. Feel free to check it out at https://t.co/IUuvuoLUbX!

🔗 https://github.com/Markakd/CVE-2022-2588

🐥 [ tweet ]
👹 [ snovvcrash, sn🥶vvcr💥sh ]

I’m not a big fan of the Cyberpunk 2077 game itself but these new #Edgerunners series are surprisingly very cool and full of the classic “high tech, low life” spirit 🤤

🐥 [ tweet ]

реально супер топ, зацените
🔥5
😈 [ LittleJoeTables, Moloch ]

I've collected a few community tutorials/guides/resources for Sliver, feel free to send us more!

https://t.co/FRiBbHpVWa

🔗 https://github.com/BishopFox/sliver/wiki/Community-Guides

🐥 [ tweet ]
😈 [ gregdarwin, Greg Darwin ]

Cobalt Strike 4.7.1 is live. This is a patch release to fix an issue with the sleep mask, and a vulnerability in the teamserver. Full details on the blog: https://t.co/Jug1Qg3ede
If you may want to revert back to 4.7 at some point, make a backup of your CS folder before updating.

🔗 https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/

🐥 [ tweet ]