Offensive Xwitter – Telegram
Offensive Xwitter
19.4K subscribers
908 photos
48 videos
21 files
2.09K links
~$ socat TWITTER-LISTEN:443,fork,reuseaddr TELEGRAM:1.3.3.7:31337

Disclaimer: https://news.1rj.ru/str/OffensiveTwitter/546
Download Telegram
Forwarded from Ralf Hacker Channel (Ralf Hacker)
Довольно интересная статья, как обходить EDR с помощью python)))

https://www.naksyn.com/edr%20evasion/2022/09/01/operating-into-EDRs-blindspot.html

#redteam #pentest #bypass
😈 [ n00py1, n00py ]

Web vulns you should look for on an internal pentest: XXE.

We often think of XXE as a way to read local files, but you can also use it to coerce auth. HTTP NTLM does not request signing so you can easily relay it to LDAP. Web service accounts are often over permissioned.

🐥 [ tweet ]
😈 [ HackerGautam, Frooti ]

Not only crawling but you can do Subdomain Enumeration using Wayback.

⬇️
curl --insecure --silent "http://web.archive.org/cdx/search/cdx" | sed -e 's_https*://__' -e "s/\/.*//" -e 's/:.*//' -e 's/^www\.//' | sed "/@/d" | sed -e 's/\.$//' | sort -u

#bugbounty #hacking #infosec

🐥 [ tweet ]
👹 [ snovvcrash, sn🥶vvcr💥sh ]

This is how easter eggs are found 😅 @_nwodtuhs @podalirius_

🐥 [ tweet ]
🔥2
😈 [ ORCx41, ORCA ]

decided to release this, a highly capable pe packer, with a lot of nice features
https://t.co/iedhKbTlzm

🔗 https://github.com/ORCx41/AtomPePacker

🐥 [ tweet ]
😈 [ g0h4n_0, g0h4n ]

Today I share with you #RustHound🦀. A new AD collector written in #Rust for #BloodHound!
It is cross-platform, cross-compiled and generates all json files needed.

Other modules will be available as under development!🔥

Hope you will enjoy it!

https://t.co/bxjCVyocfv https://t.co/8jEcSuEdEj

🔗 https://github.com/OPENCYBER-FR/RustHound

🐥 [ tweet ][ quote ]
😈 [ FortaliceLLC, Fortalice Solutions ]

NTLM Relaying to SCCM for the win 👀👀👀 Fortalice's @Tw1sm just added SCCM support to NtlmRelayX. Check out the PR at: https://t.co/hWfNeiuqxp

🔗 https://github.com/SecureAuthCorp/impacket/pull/1425

🐥 [ tweet ]
😈 [ mpgn_x64, mpgn ]

New update on CrackMapExec 🔽

➡️ Upload/download with MSSQL -guervild
➡️ Exploit KeePass (discover, trigger) @d3lb3_ 🔥
➡️ ACL read with LDAP @BlWasp_
➡️ Check ntlmv1 (postex) @Tw1sm
➡️ Check alwayselevated (postex) -bogey3
➡️ Improved export on cmedb @gray_sec

🪂

🐥 [ tweet ]
Forwarded from Offensive Xwitter Eye
👹 [ snovvcrash, sn🥶vvcr💥sh ]

Based on @dec0ne’s work on ShadowSpray I’ve pushed a small update to #pywhisker of @_nwodtuhs and @podalirius_ implementing the ‘spray’ action. Now you can pass a list of users and try to add the same Shadow Credentials for each of them with pywhisker from Linux 👌🏻

🐥 [ tweet ]
🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
😈 [ zux0x3a, Lawrence 勞倫斯 ]

Ported the pascal version to C#, and becomes even better while smuggling the payload using Created Service DisplayName
https://t.co/EhR9yNybF2
what's new? => https://t.co/t7Tkv2AW4O

🔗 https://github.com/0xsp-SRD/0xsp.com/tree/main/chopper
🔗 https://ired.dev/discussion/13/chopper-payload-smuggling/p1?new=1

🐥 [ tweet ]
😈 [ 0xdf_, 0xdf ]

Perspective from @hackthebox_eu is all about exploitation of a ASP.NET application. There's file read, ssrf, cookie signing, crypto, deserialization, and much more. Beyond Root has JuicyPotatoNG that's almost blocked but not.

🔗 https://0xdf.gitlab.io/2022/10/15/htb-perspective.html

🐥 [ tweet ]
😈 [ dr4k0nia, dr4k0nia ]

Time for another blog post :) This time Im writing about building my own string encryption obfuscator in C#. Featuring a simple XOR based cipher and unique per string encryption keys. Works from .NET Framework 4.6+ up to latest .NET
https://t.co/htjR6XdS1Q

🔗 https://dr4k0nia.github.io/dotnet/coding/2022/10/15/Encrypting-Strings-In-NET.html

🐥 [ tweet ]
😈 [ zux0x3a, Lawrence 勞倫斯 | لورانس ]

https://t.co/QOrhGwKctm
CredUI shellcoder runner shared !

🔗 https://ired.dev/discussion/comment/4/#Comment_4

🐥 [ tweet ]
😈 [ dr4k0nia, dr4k0nia ]

Alongside my latest blog post about string encryption in .NET Im also releasing the source code of my string encryption obfuscator. https://t.co/eQVP1ZVAjt

🔗 https://github.com/dr4k0nia/XorStringsNET

🐥 [ tweet ]
😈 [ 424f424f, rvrsh3ll ]

Minor update to my BOF_Collection to make compiling a bit easier. https://t.co/SP7Bp4QTxg

🔗 https://github.com/rvrsh3ll/BOF_Collection

🐥 [ tweet ]